CN104144172A - Cloud platform system and method based on desktop virtualization technology - Google Patents

Cloud platform system and method based on desktop virtualization technology Download PDF

Info

Publication number
CN104144172A
CN104144172A CN201310162435.1A CN201310162435A CN104144172A CN 104144172 A CN104144172 A CN 104144172A CN 201310162435 A CN201310162435 A CN 201310162435A CN 104144172 A CN104144172 A CN 104144172A
Authority
CN
China
Prior art keywords
user
virtual machine
virtual
management system
server
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201310162435.1A
Other languages
Chinese (zh)
Inventor
王志恒
王旭
李江
周绪宏
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
CHINA EXECUTIVE LEADERSHIP ACADEMY PUDONG
Shanghai Hongdy Network Science & Technology Co Ltd
Original Assignee
CHINA EXECUTIVE LEADERSHIP ACADEMY PUDONG
Shanghai Hongdy Network Science & Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by CHINA EXECUTIVE LEADERSHIP ACADEMY PUDONG, Shanghai Hongdy Network Science & Technology Co Ltd filed Critical CHINA EXECUTIVE LEADERSHIP ACADEMY PUDONG
Priority to CN201310162435.1A priority Critical patent/CN104144172A/en
Publication of CN104144172A publication Critical patent/CN104144172A/en
Pending legal-status Critical Current

Links

Landscapes

  • Information Transfer Between Computers (AREA)

Abstract

The invention discloses a cloud platform system implemented with the desktop virtualization technology within the cloud computing scope. The cloud platform system mainly comprises a network management system, a server-side program and a client-side program. The network management system is used for managing user accounts in a unified mode and deploying virtual desktops in a concentrated mode; an operation instruction of an administrator is sent to the server-side program through the network management system, and the server-side program completes specific operations and returns information. Related information of the user accounts and the virtual desktops is all stored in a database. The network management system can inquire about or set the user accounts, the virtual desktops and the like. The server-side program monitors the operation instruction sent from the network management system and completes the specific operations such as virtual disk copying, virtual machine configuration and virtual machine starting. A virtual desktop operating system can carry out selection according to a template. The client-side program logs into interfaces, after users input user names and passwords, identity authentication is firstly carried out through the network management system of the cloud platform system, then information of the virtual desktops of the users is obtained, and finally the virtual desktops operated on a cloud server are connected and logged in.

Description

A kind of cloud plateform system and method based on desktop virtual technology
Technical field
The present invention relates to a kind of cloud platform.Specifically, relate to the desktop virtual technology of using in cloud computing category and realize a kind of cloud plateform system.This cloud plateform system mainly comprises card system, network management system, server, client-side program.It has network management system unified management user account, concentrates and dispose virtual machine; Create user account and virtual machine speed fast; Transmission data encipher, guarantees safety; Operating system, application program support are many; Access rights are controlled strict; The connection protocol of supporting is many; Client once mounting, is used throughout one's life, and auto-update, does not need the plurality of advantages such as refitting.
Background technology
Certain institute is throughout the year for student provides training service.Training class is many; Training class's first phase is followed first phase; Each issue training class is changeable, long one or two months are short one or two week; Each issue student of training class is numerous, at most people more than seven or eight hundred, at least 100 people; Trainee also comprises foreign personage sometimes.
Each issue student of training class is during training and learning, between apartment house, the ground such as classroom, library, meeting room is used computer, is individual privacy and the data security that guarantees student, must reinstall/recovery operation system and application software.The demand characteristics of institute's computer service comprises: and (1) student's quantity is many/and computer is many, the system of at every turn resetting time and effort consuming; (2) student's term short, the refitting/recovery system cycle is frequent; (3) operating system demand is many, Chinese and English operating system; (4) network access authority is controlled strictly, needs to arrange whether allow to access internal, external network; (5) safety requirements is high, the used computer of student, and document, use vestige, internet records etc. must be removed.
Although by means of can install rapidly/recovery operation of tool software systems such as network, reduction cards, also will spend a large amount of time check software and network service, and often need the variety of issue for the treatment of system, spended time can be longer.If the task that it is pressed for time, IT safeguards is more arduous.
Cloud plateform system described in the invention can provide good cloud platform IT service for each student, and when each issue training class starts, student registers to registration hall, obtains an all-purpose card, and all-purpose card can have a meal, stays, consume in institute whereby; Enter classroom, library, meeting room study.The ground such as student can be between apartment house, classroom, library, rely on all-purpose card to connect the own proprietary cloud desktop system of login, as used local desktop system.Anywhere, any moment login connects is same desktop system, facilitates student's work and study, effectively protected student's privacy and data security.
Certain institute disposes and uses after cloud plateform system, is IT maintenance management, guarantees that individual privacy, data security bring great convenience.Following is 2 kinds of patents close with the present invention.
(1) patent CN102324076A " a kind of unified all-purpose card payment system and method based on cloud computing ", a set of unified payment system has been described, focus on the unified access interface that standard is provided, it (is the SIM-Pass of China Telecom that shielding adopts different payments to realize technology; The NFC of CHINAUNICOM; The RF-SIM of China Mobile) difference, makes to adopt user's payment data of different means of payment to manage in unified payment system.Although this patent has been mentioned, unification payment system is deployed in to high in the clouds, by providing maximized flexibility and autgmentability a kind of like this thinking to the capacity, the performance that pay, the method for the concrete enforcement of cloud computing and related system is not described.
(2) patent CN102800038A " the wisdom education E cartoon system platform based on Internet of Things and cloud computing ", has described a wisdom education E cartoon system platform, comprising: IaaS unit, PaaS unit, SaaS unit, data acquisition unit, perception terminal.Its essence is this system is carried out to modularization, convert the service (service) of different levels to, " IaaS unit is using infrastructure as service, is responsible for transmitting and processing the information that sensing layer obtains; PaaS unit is to using cloud computing to go out platform as base, utilizes RFID, data communication technology to form a comprehensive service platform ".This and traditional IaaS, PaaS definition all has very large difference, because traditional IaaS, the object of PaaS is resource-sharing, generally can only not be confined to some system platforms.
Fundamental difference of the present invention and above-mentioned patent is: a kind of cloud plateform system that the present invention has used the desktop virtual technology in cloud computing category to realize clearly.The definition providing on wikipedia (Wiki) is: desktop virtual (Virtual Desktop Infrastructure) is a kind of computation model based on server, and it carries out trustship unified management by all desktop virtual machines in data center; User can obtain the experience of complete PC simultaneously.User can pass through thin-client, or similarly equipment is experienced at local area network (LAN) or the remote access acquisition user consistent with conventional P C.So desktop virtual can be thought the combination of operating system Intel Virtualization Technology+remote access technology.Novelty of the present invention and creativeness are embodied in following 6 points.
(1) network management system unified management, concentrated deployment.When student reports for work registration, keeper is that student creates user account and virtual machine by network management system; Can inquiring user account, managing virtual machines; When leaving, student files, delete virtual machine.
(2) establishment user account and virtual machine speed are fast; By network management system, being that each student's create account user and virtual machine are average only needs 3 seconds, can be rapidly, on a large scale for student creates virtual desktop, reduce operating time and the maintenance cost of IT maintenance.
(3) transmission data encipher, guarantees safety.The transmission of data between all-purpose card, network management system, server, client-side program all passed through SSL/TLS and encrypted, and guarantees that data can not intercepted and eavesdrop in network transmission process.
(4) operating system, application program support are many.Network management system has customized the template of different operating system and application program in advance, comprises the operating systems such as Chinese WinXP, Win7, Linux, also comprises English edition operating system.
(5) access rights are controlled strict.Network management system can be controlled arbitrarily each user virtual machine access Intranet, outer net (Internet) authority, guarantees that campus network information, network are only had the user of authority to access.
(6) client once mounting, auto-update, does not need refitting.IT attendant does not need to arrive apartment each room installing operating system and application software again.All rooms client is all the same, and during use, client input username and password connection login runs on the virtual machine on server, and the data in client file system any variation can not occur, at ordinary times as long as check that whether network is unimpeded.
By cloud plateform system described in the invention, greatly alleviate time and the human cost of the information portion IT of Liao Gai institute maintenance management, originally before each issue training class between apartment house, 1,000 multiple computers of classroom, library, meeting room, numerous IT attendants need time several days just can complete, only need now a people just can all complete half an hour, and maintenance cost and the time few.
Summary of the invention
Implementation system of the present invention is a kind of cloud plateform system, refers to Fig. 1.The system of cloud platform mainly comprises: card system 1200, network management system 1300, server 1400, client-side program 1500.User between these system/modules authenticates, the relation of transfer of data, screen transmission and framework as shown in Figure 1.
The present invention combines cloud platform and all-in-one campus card, by all-purpose card, can connect the proprietary virtual desktop of login user at any one client login point of school, refers to Fig. 1.
(1) when new life reports, when the registration of registration hall, by card system 1200, be a user account of each association's establishment, one or more virtual desktops.
(2) student can login by cloud client 1501,1502,1503 any one point between classroom, library, apartment house, in card reader, insert all-purpose card, system can read user's all-purpose card information automatically, and carry out authentication to network management system 1300, by obtaining user's virtual desktop information after authentication, if user has a plurality of virtual desktops, show the list of user's virtual desktop; If only have a virtual machine desktop, system is the virtual desktop from the login user that is dynamically connected according to connection protocol.
(3), if user pulls out all-purpose card, the virtual desktop of connection disconnects automatically.User's privacy and personal data safety have effectively been guaranteed.
After training course finishes, the term of validity of student's all-purpose card virtual desktop has also arrived, and just can not again connect the virtual desktop system of logining student.All-purpose card user's virtual desktop system files automatically, preserves 1 year in order to inquiry; After 1 year the virtual disk of this user's virtual desktop deleted or backup.If this student participates in the training of other courses again later, the virtual desktop on all-purpose card can activate use again.
Refer to Fig. 1, network management system 1300 unified management user accounts, the concentrated virtual machine of disposing, network management system is specified keeper's operation to send to server program 1400 control system, by the latter, completes concrete operation return messages.The relevant information of student's user account and virtual machine is all kept in database.Network management system 1300 network management systems can inquiring user accounts information, inquiry, controls virtual machine etc.
Refer to Fig. 1, the operations such as the establishment, operation, shutdown, deletion of each virtual machine have been concentrated on server program 1400 control program backstages.Server program 1400 is monitored the operational order that network management system 1300 is sent, and completes concrete operation, comprises the copy of virtual disk, the startup of the configuration of virtual machine, virtual machine.VME operating system can, according to stencil-chosen, comprise Chinese and English WinXP, Windows 7, Linux etc.After virtual machine creating is got well and moved, cloud client 1501,1502,1503 can connect this virtual machine desktop of login.
Refer to Fig. 1, cloud client 1501,1502,1503 card reader read student's all-purpose card information, first to network management system 1300, carry out authentication, and network management system 1300 is communicated by letter with card system 1200, checks authority and validity date that this user has; Authentication by after obtain the information of virtual machine, such as server address and port; Then client starts downloadable authentication, connects logging program and directly connects and run on the virtual machine on Cloud Server 1401,1402,1403, as used local desktop system, can use USB device etc.Once network management system is checked through user's virtual desktop to after date, can automatically cut off the connection of this client.
The management platform of at present several large main cloud computing producers relies on username and password sign-on access when login, once username and password is illegally stolen, to management system, without random operation, can cause catastrophic consequence.Cloud desktop system of the present invention is being logined network management system 1300 keeper/other administrative staff, domestic consumer connects each stage of login virtual machine in cloud client 1501,1502,1503, capital prompting user input in real time sends to the short-message verification code of user mobile phone, guarantees it is that I operate.
(1) user inputs username and password when cloud client 1501,1502 or 1503 login, and system automatically connects NM server and authenticates, and checks that whether username and password is correct, sends error message to client login interface after authentification failure.
(2) after authentication is passed through, if it is first in certain cloud client 1501,1502 or 1503 logins that system detects this user, phone number when network management system 1300 is registered to this user sends identifying code, and user receives after the note of identifying code, the checking that input receives on login interface; After identifying code effectively passes through, continue to connect login virtual desktop, guarantee it is that I operate.If this user logins first in certain cloud client 1501,1502 or 1503, do not need input validation code.
(3) if user forgets Password, can give password for change by cloud client 1501,1502 or 1503 login interfaces, require password to send to user mobile phone with short message mode.
(4) user virtual machine or keeper login after the time of setting continuously, and system also can be sent short messages and be notified current login of user how long to use.
The present invention has developed note authentication module, and installation and operation, on the server of management system, by calling the SMS platform interface of China Mobile, sends note, receives note to registered user.Note authentication module comprises sending module, receiver module, parsing module, processing module.
Accompanying drawing explanation
Fig. 1. the Organization Chart of cloud platform.
Fig. 2. the method for multithreading copy virtual machine virtual disk.
Fig. 3. network management system creates user virtual machine flow chart.
Fig. 4. server program creates user virtual machine flow chart.
Fig. 5. client-side program login process figure.
Embodiment
Refer to Fig. 1, cloud plateform system mainly comprises card system 1200, network management system 1300, server 1400, client-side program 1500.Embodiment is described below.
network management system:
Refer to Fig. 1, the network management system 1300 of cloud platform provides service with WEB website (Apache+PHP+MySQL) form, and with https protocol access, keeper can operate after opening webpage login authentication.Each issue student's of training class accounts information is mainly kept in card system, and cloud platform network management system is used MySQL database to preserve student's user account information, virtual machine information, Template Information etc.User account information comprises the information such as student number, name, password, sex, phone, address, mail, class; Virtual machine information comprises computer name, CPU, internal memory, virtual disk, connection protocol, connectivity port etc.; Template Information comprises operating system, mounting software list of virtual machine etc.; Keeper can create one or more virtual machines for each user.
Network management system 1300 administrator/user by cloud platform can inquiring user accounts information and the virtual machine information having; Can check the running status of virtual machine; Can control this virtual machine startup, shutdown, suspend, restart, the operation such as preservation, recovery.
The process that keeper creates user account and virtual machine is as follows.
Step (1) is inserted into reader by student's all-purpose card, obtains user basic information, such as user ID, user name, password etc.
Step (2) is according to information such as the user ID of obtaining from all-purpose card, user name, passwords, in network management system, create a user account and virtual machine, virtual machine is specified CPU, internal memory, virtual disk, connection protocol etc., select some Cloud Servers (1401,1402 or 1403), system is written to Database Systems by user account information and virtual machine information.
Step (3) network management system 1300 is initiated SOCKET connection request with the port 5999 of backward appointment Cloud Server 1401,1402 or 1403.SOCKET connects after foundation, sends the configuration information of newly-built virtual machine, and the configuration information of virtual machine is the character string of a JSON form, for example:
{"method":"createVm","param":{"vm_uuid":"161c51d8-9497-1d56-d5bf-7a06ba468628","vm_name":"user1001","vm_vcpu":"1","vm_memory":"2","vm_disksize":"30","vm_protocol":"spice","vm_templateuuid":"aaaaaaaa-1111-1111-1111-111111111111"}}
Method method is createVm, the parameter p aram UUID that comprises virtual machine, title, CPU, internal memory, virtual disk, agreement, Template Information etc.
Step (4) server end module 1400 starts to process after receiving the request that creates virtual machine, specifically please refer to server-side processes flow process, after complete operation, to network management system 1300, sends return messages.Successfully return to SUCCESS message; Unsuccessfully return to FAILED message.
When keeper starts a certain virtual machine of operation, network management system inquiry virtual machine creating is on which station server, then to 5999 ports of this server, initiate SOCKET connection request, SOCKET sends the control information to this virtual machine after connecting foundation, by Cloud Server 1401,1402 or 1403, is completed concrete operation and is returned results.
Network management system 1300 has individual system server program, and listening port 5998 receives the connection request of sending from server end module 1400, client modules 1500, the card system 1200 of cloud platform.Connection between the system service program of network management system and server end module 1400, client modules 1500, card system 1200, transfer of data are all passed through SSL/TLS agreement and are encrypted, and guarantee the fail safe of transfer of data.
Network management system 1300 is also monitored Cloud Server 1401,1402 and 1403 operation conditionss, once the virtual machine on a certain station server or this server goes wrong, system is fast quick-recovery user's virtual machine on other Cloud Servers automatically.
Network management system 1300 mainly comprises a Web website, MySQL Database Systems, a system service program (monitoring, reception, processing, forwarding messages).If expand the scope of application of the virtual desktop system application of cloud platform, only need to add Cloud Server, network management system 1300 does not need to change.
server:
Refer to Fig. 1, each Cloud Server 1401,1402 and 1403 of cloud platform all moves a system service program, listening port 5999.Once the connection request that receives network management system 1300 and send, newly open this connection request of thread process.In this thread, analytic parameter, and complete concrete operation according to its method method, comprise establishment virtual machine, start virtual machine, close virtual machine, suspend virtual machine, restart virtual machine, preserve virtual machine, recover virtual machine etc.
Refer to Fig. 4, to create virtual machine instance, SOCKET carries out the following step after connecting foundation in newly-built thread.
After step (1) resolve command parameter, know method=createVm.
Step (2) is further resolved the parameter that creates virtual machine, obtains computer name, CPU, memory size, connection protocol, template type etc.
After step (3) has been resolved parameter, verify, such as current server has created and moved how many virtual machines, can accept this request etc.
Step (4), as accepted request, starts to copy the virtual disk of template.
After step (5) virtual disk copies, virtual machine distributes Mac address, connectivity port, network TAP equipment etc. for this reason.
Step (6) creates the XML configuration file that starts this virtual machine.
Step (7) starts virtual machine by libvirt storehouse according to the XML configuration file of virtual machine.
Step (8) transmits a reply message to network management system 1300.
Server 1400 service control programs, on open source software KVM, Libvirt basis, have been developed Virtual Machine Manager control program, thereby control better, managing virtual machines desktop system.VM_Manager program is controlled all virtual machines for managing, and each concrete virtual machine is controlled by libvirt storehouse in program inside.All virtual machines on Cloud Server 1401,1402 and 1403 are all in the control range of VM_Manager program like this.The querying command that network management system 1300 is sent, VM_Manager program sends to network management system 1300 by the virtual machine information on this station server and running status, simultaneously can also be according to the authority information of virtual machine in new database more.
Server 1400, except accepting the connection request from network management system 1300, also can be accepted the connection request of client-side program 1500.User is when cloud client 1501,1502,1503 connects login virtual machine, passed through after network management system 1300 authenticating user identifications, main and Cloud Server end 1401,1402,1403 connects, the screen transmission of virtual machine, directly transmission between cloud client 1501,1502,1503 and Cloud Server end 1401,1402,1403 of customer incident.
Each virtual machine moving in cloud desktop system has a virtual disk, adopts duplicate copy mode during copy virtual disk.
In linux system, copy virtual disk and generally use cp order, but because the priority ratio of cp copy process is higher, in copy virtual disk process, can greatly take the cpu resource of whole linux system; And virtual disk files is larger, the time is long.If also moving a plurality of virtual machines on server, the very big impact of meeting is moving the performance of virtual machine.
How, in the situation that not affecting server and moving virtual machine performance, the copying speed of accelerating virtual machine virtual disk is one of target of the present invention.The present invention has developed a kind of command tools of multithreading copy virtual machine virtual disk, this command tools has the priority of common process, in copy procedure, according to source file size, create a plurality of threads and copy virtual disk, accelerate virtual machine virtual disk copying speed, also do not affect the performance of moving virtual machine on server simultaneously.
This command tools implementation is as follows, refers to Fig. 2.
(1) judgement parameter, such as source file (in Fig. 2, virtual disk files 2010), object file (in Fig. 2, virtual disk files 2020), each thread copies data size.If there is no assigned source file or object file, prompting makes mistakes, and provides Correct, returns.
(2) open source file, if open source file failure, prompting makes mistakes, and provides error message, returns.
(3) obtain source file size, if can not obtain source file size, prompting makes mistakes, and provides error message, returns.
(4) according to each thread copies data size of input parameter, if input parameter is not specified each thread copies data size, acquiescence is 256M.According to the source file size of obtaining in step (3), the size of each thread copies data, calculate and need how many threads (Fig. 2 center line number of passes is N), last thread process is lower than the remainder of each thread copies data size.
(5) Thread Count calculating according to step (4), creates a plurality of threads, and the offset address that each thread starts copied files is delivered to each thread as parameter.
(6) each thread is resolved the offset address that starts copied files from parameter, completes the copy of specific data size.
(7) host process waits for that all threads return, and prints beginning copy time, finishes copy time, expends time in, and finishes.
Server 1400 mainly comprises the modules such as message sink, message parse, command process, Virtual Machine Manager, data processing and service error correction.
client-side program:
Refer to Fig. 1, the client modules 1500 of cloud platform is deployed in the cloud client 1501,1502,1503 between the classroom, library, apartment house of institute, and every computer is furnished with a card reader, for reading all-purpose card information.
Refer to Fig. 5, the design cycle of client login connecting virtual machine is as follows.
Step (1) student inserts after all-purpose card, and system reads user profile automatically, obtains ID, name, virtual machine UUID of student etc.
Step (2) program is initiated SOCKET connection request to 5998 ports of network management system 1300; SOCKET connects after foundation, sends user's authentication request; Network management system 1300 is received after this connection request, to card system 1200, carries out authentication, and authentication is by returning to SUCCESS message; Authentification failure returns to FAILED message.If program is received the message of authentification failure, disconnect and being connected with the SOCKET of network management system 1300, at main interface, eject authentification failure dialog box, and provide failure cause.
After step (3) authentication is passed through, program continues to send the request of obtaining virtual machine information to network management system 1300, and network management system is received after this request, in Database Systems, inquires about the virtual machine information that this user has.
Step (4) client modules 1500 is received after the virtual machine information that network management system 1300 sends, which station server parameter is resolved, such as this virtual machine is positioned at? what does is connection protocol? does is connectivity port how many? does is secure port how many? what does is dynamic password? the virtual machine term of validity? etc. information.
Step (5) knows that virtual machine state is not running status if client modules 1500 is resolved, and need to initiate SOCKET connection request to server 5999 ports at this virtual machine place, after SOCKET connection is successfully established, sends and starts virtual machine request.
After the operation of step (6) virtual machine, client modules 1500, according to the connection protocol of resolving in step (4), is used different linker login virtual machines.If SPICE agreement is used the direct connection server+port+secure port+dynamic password of spice client-side program.If RDP agreement is used the virtual machine on freerdp client-side program connection server; Other agreements, similar processing.After successful connection, can see virtual desktop, as used local desktop system.If connection failure, can eject the dialog box of makeing mistakes, and provides error message.
Step (7) user inserts USB portable hard drive or USB flash disk, and first kernel has detected USB device and inserted; Then notify user program; User program reinforms the Agent program of virtual machine, loads USB and drives.User can see real USB device in virtual desktop system, can read and write, and even can format USB hard disk.User pulls out USB device, is also that first kernel detects USB device and remove; Then notify user program; User program reinforms the Agent program of virtual machine, load-off of USB apparatus.
Step (8) user pulls out all-purpose card, after client modules 1500 detects, stops immediately the connection of virtual machine, and initiates SOCKET connection request to 5998 ports of network management system 1300; SOCKET connects after foundation, sends user's disconnection request; Network management system 1300 is received after this connection request, the state of renewal virtual machine, logout time etc.
Client-side program 1500 logging programs are arranged in cloud client (common computer or cloud terminal) 1501,1502,1503, cloud client 1501,1502,1503 has been installed hardware configuration has been required to lower (SuSE) Linux OS, and self-defined login interface, client modules 1500 logging programs have been installed simultaneously.All cloud clients 1501,1502,1503 are all equally to configure, perhaps hardware configuration is different, but installed after the (SuSE) Linux OS of supporting lower hardware configuration, just can the fine computer that stably moves terminal, unique different be IP address, MAC Address.Student, no matter from which cloud client 1501,1502 or 1503 logins, can connect and sign in to own proprietary virtual machine.
After 1501,1502,1503 logins of cloud client, as used local operation system, can carry out office software office operation; Displaying video, music; Surf the web; Access local USB flash disk, hard disk, CD-ROM drive etc.After logining successfully, the information such as IP address of cloud client 1501,1502,1503 are sent to network management system 1300.Which cloud client connection is network management system 1300 can inquire about signs in to virtual machine.According to IP address or MAC Address and geographical position binding information, network management system 1300 and then can inquire from the login of which cloud client and connect this virtual machine.
After installing, client modules 1500 just no longer needs to safeguard, because only used the most basic function of the (SuSE) Linux OS of cloud client 1501,1502,1503 operations, operating system file and configuration are without any change, so generally do not need to safeguard cloud client, only check that whether netting twine, network be available.
When user uses virtual desktop, do not need the virtual machine of being concerned about oneself to be based upon on which Cloud Server, virtual machine as oneself is based upon " high in the clouds ", even if a certain virtual machine goes out present condition, can not connect, network management system 1300 network supervisors capture after problem, rapidly reconstruct user's virtual machine on other Cloud Servers.Middle process is extremely short, and the virtual desktop that user perceives oneself not obviously in " high in the clouds ", switching has occurred.
Client-side program 1500 login systems comprise that reading all-purpose card module, user authentication module, message sink module, message processing module, connection login module, USB monitors module etc.

Claims (7)

1. take desktop virtual technology as a basic cloud plateform system, the design apparatus of described cloud plateform system comprises:
1) card system;
2) network management system;
3) server;
4) client-side program.
2. network management system according to claim 1, mainly comprises a Web website, MySQL Database Systems, a system service program (monitoring, reception, processing, forwarding messages), it is characterized in that:
1) unified management user account, the concentrated virtual machine of disposing, network management system is specified keeper's operation to send to server, by the latter, completes concrete operation return messages;
2) relevant information of student's user account and virtual machine is all kept in database;
3) user account information can be inquired about, be arranged to network management system; Inquiry, control virtual machine etc.
3. server according to claim 1, mainly comprises the modules such as message sink, message parse, command process, Virtual Machine Manager, data processing and service error correction, it is characterized in that:
1) server has been concentrated the operation such as establishment, operation, shutdown, preservation, deletion of each virtual machine on backstage;
2) server is monitored the operational order that network management system is sent, and completes concrete operation, comprises the copy of virtual disk, the startup of the configuration of virtual machine, virtual machine;
3) VME operating system can, according to stencil-chosen, comprise Chinese and English WinXP, Windows 7, Linux etc.; After virtual machine creating is got well and moved, cloud client can connect this virtual machine of login.
4. client-side program according to claim 1, mainly comprises and reads the modules such as all-purpose card, user authenticate, message sink, Message Processing, connection login, USB monitoring, it is characterized in that:
1) cloud client card reader reads user's all-purpose card information, first to network management system, carries out authentication, and network management system is communicated by letter with card system, checks authority and validity date that this user has;
2) authentication by after obtain the information of virtual machine, such as server address and port; Then client starts downloadable authentication, and logging program directly connects and runs on the virtual machine on Cloud Server;
3), once network management system is checked through user's virtual desktop to after date, can automatically cut off this client to the connection of virtual machine.
5. cloud plateform system according to claim 1, one of its feature is the method for its all-purpose card auto connect virtual desktop:
1) the present invention combines cloud platform and all-in-one campus card, by all-purpose card, can, at any one client login point of school, connect the proprietary virtual desktop of login user;
2), when new life registers, by card system, be that each student creates a user account, one or more virtual desktops;
3) any one login point that student can be between classroom, library, apartment house, in card reader, insert all-purpose card, system can read user's all-purpose card information automatically, and carry out authentication to management system, by obtaining user's virtual desktop information after authentication, if user has a plurality of virtual desktops, show the list of user's virtual desktop; If only have a virtual machine desktop, system is the virtual desktop from the login user that is dynamically connected according to connection protocol;
4), if user pulls out all-purpose card, the virtual desktop of connection disconnects automatically; User's privacy and personal data safety have effectively been guaranteed.
6. cloud plateform system according to claim 1, two of its feature is that its note authentication mechanism guarantees the method for validated user login:
1) cloud desktop system is connecting each stage of login virtual machine keeper/other administrative staff in login management system, domestic consumer, and the short-message verification code that all can point out user's input in real time to send to user mobile phone guarantees it is operation in person;
2) user inputs username and password when client is logined, and system automatically connects NM server and authenticates, and checks that whether username and password is correct, sends error message to client login interface after authentification failure;
3) after authentication is passed through, if system detects this user, login first in certain client, phone number when management system is registered to this user sends identifying code, and user receives after the note of identifying code, the checking that input receives on login interface; After identifying code effectively passes through, continue to connect login virtual desktop, guarantee it is that I operate; If this user logins first in certain client, do not need input validation code;
4), if user forgets Password, can, by the password of giving for change on login interface, require password to send to user mobile phone with short message mode;
5) user virtual machine or keeper login after the time of setting continuously, and system also can be sent short messages and be notified current login of user how long to use;
6) the present invention has developed note authentication module, and installation and operation, on the server of management system, by calling the SMS platform interface of China Mobile, sends note, receives note to registered user; Note authentication module comprises sending module, receiver module, parsing module, processing module.
7. cloud plateform system according to claim 1, three of its feature is the method for its multithreading copy virtual machine virtual disk:
1) the present invention has developed a kind of command tools of multithreading copy virtual machine virtual disk, and this command tools has the priority of common process, in copy procedure, according to source file size, with multithreading, copies virtual disk;
Can not affect the performance of moving virtual machine on server;
2) this command tools implementation is as follows 1. 2. 3. 4. 5. 6. 7.:
1. judge parameter, such as source file, object file, each thread copies data size; If there is no assigned source file or object file, prompting makes mistakes, and provides Correct, returns;
2. open source file, if open source file failure, prompting makes mistakes, and provides error message, returns;
3. obtain source file size, if can not obtain source file size, prompting makes mistakes, and provides error message, returns;
4. according to each thread copies data size of input parameter, if input parameter is not specified each thread copies data size, acquiescence is 256M;
3. the source file size of obtaining according to step, the size of each thread copies data, calculate and need how many threads, and last thread process is lower than the remainder of each thread copies data size;
5. the Thread Count 4. calculating according to step, creates a plurality of threads, and the offset address that each thread starts copied files is delivered to each thread as parameter;
6. each thread is resolved the offset address that starts copied files from parameter, completes the copy of specifying size data;
7. host process waits for that all threads return, and prints beginning copy time, finishes copy time, expends time in, and finishes.
CN201310162435.1A 2013-05-06 2013-05-06 Cloud platform system and method based on desktop virtualization technology Pending CN104144172A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201310162435.1A CN104144172A (en) 2013-05-06 2013-05-06 Cloud platform system and method based on desktop virtualization technology

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201310162435.1A CN104144172A (en) 2013-05-06 2013-05-06 Cloud platform system and method based on desktop virtualization technology

Publications (1)

Publication Number Publication Date
CN104144172A true CN104144172A (en) 2014-11-12

Family

ID=51853240

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201310162435.1A Pending CN104144172A (en) 2013-05-06 2013-05-06 Cloud platform system and method based on desktop virtualization technology

Country Status (1)

Country Link
CN (1) CN104144172A (en)

Cited By (47)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104601367A (en) * 2014-12-05 2015-05-06 国云科技股份有限公司 AD domain based virtual desktop management method
CN104702624A (en) * 2015-03-27 2015-06-10 深圳市研唐科技有限公司 Method and system for logging virtual machine based on Cloud Stack platform
CN104932939A (en) * 2015-07-03 2015-09-23 成都怡云科技有限公司 Cloud desktop system supporting system migration
CN105046423A (en) * 2015-07-01 2015-11-11 安徽海澄德畅电子科技有限公司 Book management device
WO2015184814A1 (en) * 2014-11-17 2015-12-10 中兴通讯股份有限公司 Terminal configuration method, device and terminal
CN105389185A (en) * 2015-11-16 2016-03-09 北京汉柏科技有限公司 Method and apparatus for processing boot storm of virtual cloud desktops
CN105516368A (en) * 2016-02-03 2016-04-20 浪潮软件股份有限公司 Cloud desktop client, server and method and system for implementing cloud desktop
CN105721613A (en) * 2016-04-22 2016-06-29 广州优达信息科技有限公司 Method and system for virtual desktop to close cloud terminal through one touch
CN106020980A (en) * 2015-05-21 2016-10-12 中国科学院计算技术研究所 Virtual desktop oriented VCPU (Virtual Central Processing Unit) scheduling method
WO2016202105A1 (en) * 2015-06-19 2016-12-22 中兴通讯股份有限公司 Method for realizing data sharing between client and virtual desktop, client and system
CN106330816A (en) * 2015-06-17 2017-01-11 北京神州泰岳软件股份有限公司 Method and system for logging in cloud desktop
CN106533758A (en) * 2016-11-10 2017-03-22 河南智业科技发展有限公司 Enterprise cloud desktop management platform of OpenStack cloud desktop
CN106875765A (en) * 2016-12-28 2017-06-20 新华三技术有限公司 A kind of electronic classroom implementation method and device based on VDI
CN107454085A (en) * 2017-08-11 2017-12-08 安徽状元郎电子科技有限公司 A kind of campus Multifunctional education cloud desktop
CN107491503A (en) * 2017-07-31 2017-12-19 苏州大成有方数据科技有限公司 A kind of multifunctional client information management system
CN107517232A (en) * 2016-06-16 2017-12-26 北京易讯通信息技术股份有限公司 The scheduling system of cloud desktop
CN107612913A (en) * 2017-09-20 2018-01-19 贵州恒昊软件科技有限公司 A kind of on-line bid system and method
CN107659577A (en) * 2012-02-01 2018-02-02 亚马逊科技公司 Account management method and system for multiple websites
CN108021426A (en) * 2017-12-29 2018-05-11 上海海加网络科技有限公司 A kind of desktop cloud system
CN108365966A (en) * 2017-12-29 2018-08-03 河南智业科技发展有限公司 A kind of no BIOS designs cloud microterminal
CN108833473A (en) * 2018-05-08 2018-11-16 刘俊 A kind of intelligence system carrying out operation and processing in server end
CN109240794A (en) * 2018-08-06 2019-01-18 深圳宇翊技术股份有限公司 A kind of desktop virtual technology reconstruct PIS train station subsystem
CN109922159A (en) * 2019-03-27 2019-06-21 宁波大学 A kind of method of the two-way virtual link in cloud between internet of things equipment
CN109960551A (en) * 2017-12-26 2019-07-02 中国电信股份有限公司 Cloud desktop services method, platform and computer readable storage medium
US10362019B2 (en) 2011-07-29 2019-07-23 Amazon Technologies, Inc. Managing security credentials
CN110278235A (en) * 2018-03-16 2019-09-24 上海远动科技有限公司 SCADA mobile monitor desktop system based on cloud
CN110278200A (en) * 2019-06-06 2019-09-24 武汉晶众科技有限公司 A kind of intelligence desktop management system and method
CN110503586A (en) * 2019-08-30 2019-11-26 陕西科技大学 A kind of artificial intelligence information management cloud platform system and its operation method
US10505914B2 (en) 2012-02-01 2019-12-10 Amazon Technologies, Inc. Sharing account information among multiple users
WO2020015702A1 (en) * 2018-07-20 2020-01-23 中兴通讯股份有限公司 Teaching template management method, device, and computer readable storage medium
CN110806901A (en) * 2019-11-05 2020-02-18 西安雷风电子科技有限公司 Multi-desktop dynamic switching system and method
CN110958206A (en) * 2018-09-26 2020-04-03 山东华软金盾软件股份有限公司 Data security method for mobile equipment application based on virtualization
CN111090512A (en) * 2020-01-15 2020-05-01 成都喜马科技发展有限公司 Automatic switching method and system for computer classroom software system
CN111291429A (en) * 2020-01-21 2020-06-16 李岗 Data protection method and system
CN111294373A (en) * 2018-12-07 2020-06-16 中国移动通信集团山东有限公司 Information management and control system based on mobile industry cloud desktop architecture
CN112068846A (en) * 2020-08-07 2020-12-11 福建升腾资讯有限公司 Application distribution method, device and medium based on dual systems
CN112085988A (en) * 2020-09-11 2020-12-15 北京信息科技大学 Virtual simulation experiment system and method for penetration attack
CN112199157A (en) * 2020-10-16 2021-01-08 深圳无域科技技术有限公司 Cloud environment management method
CN112328374A (en) * 2019-12-30 2021-02-05 江苏省未来网络创新研究院 Comprehensive evaluation system and method based on virtualized real-operation environment
CN112749053A (en) * 2020-12-14 2021-05-04 北京同有飞骥科技股份有限公司 Intelligent fault monitoring and intelligent repair management system based on cloud platform
CN113051039A (en) * 2021-04-21 2021-06-29 的卢技术有限公司 Virtual cloud office system login method and system based on cloud computing
CN113709113A (en) * 2021-08-03 2021-11-26 中国大唐集团科学技术研究总院有限公司 Cloud desktop security and credibility authentication method based on three-terminal separation design
US11444936B2 (en) 2011-07-29 2022-09-13 Amazon Technologies, Inc. Managing security credentials
CN115314410A (en) * 2022-08-10 2022-11-08 深圳市吉祥腾达科技有限公司 Soft AC client simulation and authentication automatic test method and system
CN116483517A (en) * 2023-04-27 2023-07-25 安芯网盾(北京)科技有限公司 Virtual machine control method, device and system
CN116760546A (en) * 2023-08-18 2023-09-15 湖南省通信建设有限公司 Modularized password service method based on cloud environment
CN117591415A (en) * 2023-11-28 2024-02-23 中国大唐集团科学技术研究总院有限公司 Safety function testing system and method for integrated machine cloud portal platform

Cited By (63)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10362019B2 (en) 2011-07-29 2019-07-23 Amazon Technologies, Inc. Managing security credentials
US11444936B2 (en) 2011-07-29 2022-09-13 Amazon Technologies, Inc. Managing security credentials
US10505914B2 (en) 2012-02-01 2019-12-10 Amazon Technologies, Inc. Sharing account information among multiple users
US11381550B2 (en) 2012-02-01 2022-07-05 Amazon Technologies, Inc. Account management using a portable data store
CN107659577A (en) * 2012-02-01 2018-02-02 亚马逊科技公司 Account management method and system for multiple websites
CN107659577B (en) * 2012-02-01 2019-04-16 亚马逊科技公司 Account management method and system for multiple websites
WO2015184814A1 (en) * 2014-11-17 2015-12-10 中兴通讯股份有限公司 Terminal configuration method, device and terminal
CN105677304A (en) * 2014-11-17 2016-06-15 中兴通讯股份有限公司 Terminal configuration method and device, terminal
CN104601367B (en) * 2014-12-05 2018-02-09 国云科技股份有限公司 A kind of virtual desktop management based on AD domains
CN104601367A (en) * 2014-12-05 2015-05-06 国云科技股份有限公司 AD domain based virtual desktop management method
CN104702624A (en) * 2015-03-27 2015-06-10 深圳市研唐科技有限公司 Method and system for logging virtual machine based on Cloud Stack platform
CN106020980A (en) * 2015-05-21 2016-10-12 中国科学院计算技术研究所 Virtual desktop oriented VCPU (Virtual Central Processing Unit) scheduling method
CN106330816A (en) * 2015-06-17 2017-01-11 北京神州泰岳软件股份有限公司 Method and system for logging in cloud desktop
CN106330816B (en) * 2015-06-17 2019-09-27 北京神州泰岳软件股份有限公司 A kind of method and system logging in cloud desktop
WO2016202105A1 (en) * 2015-06-19 2016-12-22 中兴通讯股份有限公司 Method for realizing data sharing between client and virtual desktop, client and system
US10708339B2 (en) 2015-06-19 2020-07-07 Zte Corporation Method for realizing data sharing between client and virtual desktop, client and system
CN106330999A (en) * 2015-06-19 2017-01-11 中兴通讯股份有限公司 Client and system, and method for realizing data sharing between client and virtual desktop
CN106330999B (en) * 2015-06-19 2020-08-21 南京中兴软件有限责任公司 Method, client and system for realizing data sharing between client and virtual desktop
RU2683620C1 (en) * 2015-06-19 2019-03-29 ЗетТиИ Корпорейшн Method of the data sharing implementation between the client and the virtual desktop, the client and the system
CN105046423A (en) * 2015-07-01 2015-11-11 安徽海澄德畅电子科技有限公司 Book management device
CN104932939A (en) * 2015-07-03 2015-09-23 成都怡云科技有限公司 Cloud desktop system supporting system migration
CN105389185A (en) * 2015-11-16 2016-03-09 北京汉柏科技有限公司 Method and apparatus for processing boot storm of virtual cloud desktops
CN105516368A (en) * 2016-02-03 2016-04-20 浪潮软件股份有限公司 Cloud desktop client, server and method and system for implementing cloud desktop
CN105721613A (en) * 2016-04-22 2016-06-29 广州优达信息科技有限公司 Method and system for virtual desktop to close cloud terminal through one touch
CN107517232A (en) * 2016-06-16 2017-12-26 北京易讯通信息技术股份有限公司 The scheduling system of cloud desktop
CN106533758A (en) * 2016-11-10 2017-03-22 河南智业科技发展有限公司 Enterprise cloud desktop management platform of OpenStack cloud desktop
CN106875765A (en) * 2016-12-28 2017-06-20 新华三技术有限公司 A kind of electronic classroom implementation method and device based on VDI
CN107491503A (en) * 2017-07-31 2017-12-19 苏州大成有方数据科技有限公司 A kind of multifunctional client information management system
CN107454085A (en) * 2017-08-11 2017-12-08 安徽状元郎电子科技有限公司 A kind of campus Multifunctional education cloud desktop
CN107612913A (en) * 2017-09-20 2018-01-19 贵州恒昊软件科技有限公司 A kind of on-line bid system and method
CN109960551A (en) * 2017-12-26 2019-07-02 中国电信股份有限公司 Cloud desktop services method, platform and computer readable storage medium
CN108365966A (en) * 2017-12-29 2018-08-03 河南智业科技发展有限公司 A kind of no BIOS designs cloud microterminal
CN108021426A (en) * 2017-12-29 2018-05-11 上海海加网络科技有限公司 A kind of desktop cloud system
CN110278235A (en) * 2018-03-16 2019-09-24 上海远动科技有限公司 SCADA mobile monitor desktop system based on cloud
CN108833473A (en) * 2018-05-08 2018-11-16 刘俊 A kind of intelligence system carrying out operation and processing in server end
WO2020015702A1 (en) * 2018-07-20 2020-01-23 中兴通讯股份有限公司 Teaching template management method, device, and computer readable storage medium
CN109240794A (en) * 2018-08-06 2019-01-18 深圳宇翊技术股份有限公司 A kind of desktop virtual technology reconstruct PIS train station subsystem
CN110958206A (en) * 2018-09-26 2020-04-03 山东华软金盾软件股份有限公司 Data security method for mobile equipment application based on virtualization
CN111294373A (en) * 2018-12-07 2020-06-16 中国移动通信集团山东有限公司 Information management and control system based on mobile industry cloud desktop architecture
CN109922159B (en) * 2019-03-27 2021-10-08 宁波大学 Cloud bidirectional virtual connection method between Internet of things devices
CN109922159A (en) * 2019-03-27 2019-06-21 宁波大学 A kind of method of the two-way virtual link in cloud between internet of things equipment
CN110278200A (en) * 2019-06-06 2019-09-24 武汉晶众科技有限公司 A kind of intelligence desktop management system and method
CN110503586A (en) * 2019-08-30 2019-11-26 陕西科技大学 A kind of artificial intelligence information management cloud platform system and its operation method
CN110806901B (en) * 2019-11-05 2023-07-28 西安雷风电子科技有限公司 Multi-desktop dynamic switching system and method
CN110806901A (en) * 2019-11-05 2020-02-18 西安雷风电子科技有限公司 Multi-desktop dynamic switching system and method
CN112328374A (en) * 2019-12-30 2021-02-05 江苏省未来网络创新研究院 Comprehensive evaluation system and method based on virtualized real-operation environment
CN112328374B (en) * 2019-12-30 2024-04-30 江苏省未来网络创新研究院 Comprehensive evaluation system and method based on virtualized real operation environment
CN111090512A (en) * 2020-01-15 2020-05-01 成都喜马科技发展有限公司 Automatic switching method and system for computer classroom software system
CN111291429A (en) * 2020-01-21 2020-06-16 李岗 Data protection method and system
CN112068846A (en) * 2020-08-07 2020-12-11 福建升腾资讯有限公司 Application distribution method, device and medium based on dual systems
CN112068846B (en) * 2020-08-07 2023-11-10 福建升腾资讯有限公司 Application distribution method, device and medium based on dual systems
CN112085988A (en) * 2020-09-11 2020-12-15 北京信息科技大学 Virtual simulation experiment system and method for penetration attack
CN112199157A (en) * 2020-10-16 2021-01-08 深圳无域科技技术有限公司 Cloud environment management method
CN112199157B (en) * 2020-10-16 2023-11-24 深圳无域科技技术有限公司 Cloud environment management method
CN112749053A (en) * 2020-12-14 2021-05-04 北京同有飞骥科技股份有限公司 Intelligent fault monitoring and intelligent repair management system based on cloud platform
CN113051039A (en) * 2021-04-21 2021-06-29 的卢技术有限公司 Virtual cloud office system login method and system based on cloud computing
CN113709113A (en) * 2021-08-03 2021-11-26 中国大唐集团科学技术研究总院有限公司 Cloud desktop security and credibility authentication method based on three-terminal separation design
CN115314410A (en) * 2022-08-10 2022-11-08 深圳市吉祥腾达科技有限公司 Soft AC client simulation and authentication automatic test method and system
CN116483517A (en) * 2023-04-27 2023-07-25 安芯网盾(北京)科技有限公司 Virtual machine control method, device and system
CN116483517B (en) * 2023-04-27 2024-01-26 安芯网盾(北京)科技有限公司 Virtual machine control method, device and system
CN116760546A (en) * 2023-08-18 2023-09-15 湖南省通信建设有限公司 Modularized password service method based on cloud environment
CN116760546B (en) * 2023-08-18 2023-10-31 湖南省通信建设有限公司 Modularized password service method based on cloud environment
CN117591415A (en) * 2023-11-28 2024-02-23 中国大唐集团科学技术研究总院有限公司 Safety function testing system and method for integrated machine cloud portal platform

Similar Documents

Publication Publication Date Title
CN104144172A (en) Cloud platform system and method based on desktop virtualization technology
US11916911B2 (en) Gateway enrollment for Internet of Things device management
US11281457B2 (en) Deployment of infrastructure in pipelines
US11902268B2 (en) Secure gateway onboarding via mobile devices for internet of things device management
US9525684B1 (en) Device-specific tokens for authentication
CN108965480A (en) Cloud desktop login management-control method, device and computer readable storage medium
US8964990B1 (en) Automating key rotation in a distributed system
JP2018116708A (en) Network connection automation
WO2016127756A1 (en) Flexible deployment method for cluster and management system
US20100146500A1 (en) Method and system for installing a software application on a mobile computing device
CN104144173A (en) Campus cloud platform system and method based on distributed virtual service technology
JP6637940B2 (en) Forced encryption on connected devices
US8908868B1 (en) Key rotation with external workflows
US20150326557A1 (en) Relay device, relay method, and program
CN107872440B (en) Identity authentication method, device and system
CN107040518A (en) A kind of private clound server log method and system
CN115118705B (en) Industrial edge management and control platform based on micro-service
US10491589B2 (en) Information processing apparatus and device coordination authentication method
CN108289074B (en) User account login method and device
US9021558B2 (en) User authentication based on network context
US20130305334A1 (en) Single sign-on for disparate servers
US9973488B1 (en) Authentication in a multi-tenant environment
CN115941217B (en) Method for secure communication and related products
US10498710B2 (en) System, relay client, control method, and storage medium having password reset for authentication
CN110808943B (en) Client connection emergency management method, client and computer readable storage medium

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C02 Deemed withdrawal of patent application after publication (patent law 2001)
WD01 Invention patent application deemed withdrawn after publication

Application publication date: 20141112