Device usage range control method and apparatus, computer device, computer-readable storage medium, and computer program product
By receiving requests to take devices out of the office, generating geofence areas, and predicting device locations, the system solves the data security problem when employees take devices out of the office and enables timely access control of enterprise data.
Patent Information
- Application Number
- CN202411042727.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-31
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-07-31
AI Technical Summary
When employees take company mobile devices to work outside the office, it leads to lower data security for the company.
By receiving requests to take the device out of the area, a geofence area is generated, and the device location is predicted within each positioning cycle. A second request to take the device out of the area is generated for review, and if the request is not approved, access permissions are set to be blocked.
It improves the security of enterprise data, avoids the lag in adjusting permissions only after devices exceed preset limits, and ensures timely control of data access.
Smart Images

Figure CN118921671B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer network technology, and in particular to a method, apparatus, computer equipment, computer-readable storage medium, and computer program product for controlling the scope of use of a device. Background Technology
[0002] Employees often have access to company data that is prohibited from being leaked, such as business data and customer data, through the company's mobile devices. However, employees often need to carry company mobile devices with them when working outside the office, resulting in lower data security. Summary of the Invention
[0003] Therefore, it is necessary to provide a method, apparatus, computer equipment, computer-readable storage medium, and computer program product that can improve the security of enterprise data by addressing the aforementioned technical issues of low enterprise data security.
[0004] In a first aspect, this application provides a method for controlling the scope of use of equipment, including:
[0005] Upon receiving a first application to take a mobile device out of the house, the application will be reviewed.
[0006] If the first application for carrying items outside the home is approved, a geofence area corresponding to the first application for carrying items outside the home will be generated.
[0007] Within each positioning cycle, based on the acquired positioning location, the position of the mobile device in the next positioning cycle is predicted; the acquired positioning location includes the positioning location within the positioning cycle and the positioning location of the mobile device in the positioning cycle prior to the current positioning cycle.
[0008] If the predicted location does not fall within the geofence area, a second outbound carrying request is generated for the mobile device, and the second outbound carrying request is reviewed.
[0009] If the second application for carrying out the device fails to pass the review, the access permission for the enterprise data corresponding to the mobile device will be set to prohibited.
[0010] In one embodiment, the first outing application is an application sent by an employee requesting to take the mobile device out through a corresponding first terminal, and the first outing application carries the employee's employee identifier;
[0011] The review of the first application for carrying items outside the home includes:
[0012] Determine the reviewer corresponding to the employee;
[0013] The first application for carrying items outside the home is sent to the second terminal corresponding to the reviewer; the reviewer reviews the first application for carrying items outside the home through the second terminal, and the second terminal is used to return the review result of the first application for carrying items outside the home.
[0014] The review of the second application for carrying items outside the home includes:
[0015] The second application for carrying items outside the home is sent to the second terminal; the reviewer reviews the second application for carrying items outside the home through the second terminal; the second terminal is used to return the review result of the second application for carrying items outside the home.
[0016] In one embodiment, after setting the access permission of the mobile device corresponding to enterprise data to denied, the method further includes:
[0017] Generate warning information for the mobile device;
[0018] The warning information is sent to the first terminal.
[0019] In one embodiment, predicting the location of the mobile device in the next positioning cycle based on the acquired location includes:
[0020] Based on the obtained location, the moving speed and direction of the mobile device are determined;
[0021] Using the location within the positioning period from the acquired positioning locations as the starting point of movement, the position of the mobile device in the next positioning period is predicted based on the movement speed and direction.
[0022] In one embodiment, after reviewing the first application for carrying items outside the home, the method further includes:
[0023] If the first application for carrying the device outside fails to pass the review, the access permission of the mobile device will be set to prohibited.
[0024] In one embodiment, the first outing application specifies at least one outing location;
[0025] The generation of the geofence area corresponding to the first outbound carry application includes:
[0026] Generate the first geofence region corresponding to each outing location specified in the first outing application;
[0027] The first geofence regions corresponding to each departure location are integrated to obtain a second geofence region including each first geofence region, which serves as the geofence region corresponding to the first outbound carrying application.
[0028] Secondly, this application also provides a device for controlling the range of use of an equipment, comprising:
[0029] The first review module is used to review the first application for carrying a mobile device outside the home upon receiving the first application for carrying the mobile device outside the home.
[0030] The region generation module is used to generate the geofence region corresponding to the first application for carrying out the first time if the application is approved.
[0031] A periodic positioning module is used to predict the location of the mobile device in the next positioning cycle based on the acquired positioning location within each positioning cycle; the acquired positioning location includes the positioning location within the positioning cycle and the positioning location of the mobile device in the positioning cycle before the current positioning cycle.
[0032] The second review module is used to generate a second outbound carrying application for the mobile device if the predicted location does not fall within the geofence area, and to review the second outbound carrying application.
[0033] The access control module is used to set the access permissions for the mobile device corresponding to the enterprise data to prohibited if the second application for carrying out the device fails to pass the review.
[0034] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0035] Upon receiving a first application to take a mobile device out of the house, the application will be reviewed.
[0036] If the first application for carrying items outside the home is approved, a geofence area corresponding to the first application for carrying items outside the home will be generated.
[0037] Within each positioning cycle, based on the acquired positioning location, the position of the mobile device in the next positioning cycle is predicted; the acquired positioning location includes the positioning location within the positioning cycle and the positioning location of the mobile device in the positioning cycle prior to the current positioning cycle.
[0038] If the predicted location does not fall within the geofence area, a second outbound carrying request is generated for the mobile device, and the second outbound carrying request is reviewed.
[0039] If the second application for carrying out the device fails to pass the review, the access permission for the enterprise data corresponding to the mobile device will be set to prohibited.
[0040] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0041] Upon receiving a first request to take a mobile device out of the house, the first request to take the mobile device out of the house is reviewed; and the mobile device;
[0042] If the first application for carrying items outside the home is approved, a geofence area corresponding to the first application for carrying items outside the home will be generated.
[0043] Within each positioning cycle, based on the acquired positioning location, the position of the mobile device in the next positioning cycle is predicted; the acquired positioning location includes the positioning location within the positioning cycle and the positioning location of the mobile device in the positioning cycle prior to the current positioning cycle.
[0044] If the predicted location does not fall within the geofence area, a second outbound carrying request is generated for the mobile device, and the second outbound carrying request is reviewed.
[0045] If the second application for carrying out the device fails to pass the review, the access permission for the enterprise data corresponding to the mobile device will be set to prohibited.
[0046] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:
[0047] Upon receiving a first request to take a mobile device out of the house, the first request to take the mobile device out of the house is reviewed; and the mobile device;
[0048] If the first application for carrying items outside the home is approved, a geofence area corresponding to the first application for carrying items outside the home will be generated.
[0049] Within each positioning cycle, based on the acquired positioning location, the position of the mobile device in the next positioning cycle is predicted; the acquired positioning location includes the positioning location within the positioning cycle and the positioning location of the mobile device in the positioning cycle prior to the current positioning cycle.
[0050] If the predicted location does not fall within the geofence area, a second outbound carrying request is generated for the mobile device, and the second outbound carrying request is reviewed.
[0051] If the second application for carrying out the device fails to pass the review, the access permission for the enterprise data corresponding to the mobile device will be set to prohibited.
[0052] The aforementioned device use scope control method, apparatus, computer equipment, computer-readable storage medium, and computer program product firstly, upon receiving a first outbound carrying request for a mobile device, review the first outbound carrying request; then, if the first outbound carrying request is approved, generate a geofence area corresponding to the first outbound carrying request; next, within each positioning cycle, based on the acquired positioning location, predict the location of the mobile device in the next positioning cycle; the acquired positioning location includes the positioning location within the positioning cycle and the positioning location of the mobile device in the positioning cycle before the positioning cycle; then, if the predicted location does not fall within the geofence area, generate a second outbound carrying request for the mobile device and review the second outbound carrying request; finally, if the second outbound carrying request is not approved, set the access permission of the mobile device corresponding to enterprise data to prohibited access. The device usage range control method based on the above process reviews the first outbound carrying application. If the review is approved, a corresponding geofence area is generated. Then, based on the location of the mobile device in each positioning cycle, the location of the mobile device in the next positioning cycle is predicted. If the predicted location exceeds the geofence area, a corresponding second outbound carrying application is generated and reviewed. If the review is not approved, the access permission of the mobile device is set to prohibited, thereby preventing the mobile device from accessing enterprise data and improving the security of enterprise data. Attached Figure Description
[0053] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0054] Figure 1 This is an application environment diagram of the device usage range control method in one embodiment;
[0055] Figure 2This is a flowchart illustrating a device usage range control method in one embodiment;
[0056] Figure 3 This is a flowchart illustrating the steps of predicting the location of a mobile device in the next positioning cycle based on the acquired location in one embodiment.
[0057] Figure 4 This is a flowchart illustrating the steps for generating the geofence area corresponding to the first outbound carry application in one embodiment;
[0058] Figure 5 This is a flowchart illustrating the device usage range control method in another embodiment;
[0059] Figure 6 This is a flowchart illustrating a security-oriented device usage range control method in one embodiment;
[0060] Figure 7 This is a structural block diagram of a device usage range control device in one embodiment;
[0061] Figure 8 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0062] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0063] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0064] The device usage range control method provided in this application embodiment can be applied to, for example, Figure 1The application environment shown includes a server 102 for the office platform, mobile devices 104 for the enterprise, first terminals 106 for employees, and second terminals 108 for auditors. The server 102, mobile devices 104, first terminals 106, and second terminals 108 communicate via a network. The server 102 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The mobile devices 104 can be, but are not limited to, various laptops, smartphones, tablets, etc.; the first terminals 106 and second terminals 108 can be, but are not limited to, various personal computers, laptops, smartphones, tablets, etc.
[0065] Specifically, firstly, upon receiving a first outing application for mobile device 104 from first terminal 106, server 102 reviews the application via second terminal 108. Then, if the first outing application is approved, server 102 generates a geofence corresponding to the application. Next, within each positioning cycle, server 102 obtains the location of mobile device 104 within that cycle and predicts its location in the next positioning cycle based on the obtained location. The obtained location includes both the location within the current cycle and the location within previous cycles. Then, if the predicted location does not fall within the geofence, server 102 generates a second outing application for mobile device 104 and reviews it via second terminal 108. Finally, if the second outing application fails to pass review, server 102 sets the access permission for enterprise data corresponding to mobile device 104 to "deny."
[0066] In one exemplary embodiment, such as Figure 2 As shown, a method for controlling the usage range of a device is provided, which is applied to... Figure 1 Taking server 102 as an example, the explanation includes the following steps:
[0067] Step S202: Upon receiving a first application to carry a mobile device outside the home, the first application to carry the mobile device outside the home is reviewed.
[0068] The server is the server corresponding to the office platform, which is connected to a database used to store enterprise data. As is easy to understand, enterprise data includes business data that is prohibited from being disclosed, customer data, etc.
[0069] Mobile devices are those used by enterprises for office work. These devices have the enterprise's office platform applications installed, and with the appropriate access permissions, they can access the database connected to the office platform, thereby accessing enterprise data. For example, in the case of a bank, when account managers are out handling business for clients, they need to carry office tablets provided by the bank for on-the-go work. Through these tablets, account managers can access the bank's enterprise data, such as clients' personal information and business information.
[0070] Among them, the first application for carrying mobile devices outside the workplace is an application sent by an employee who wants to carry mobile devices outside the workplace through the corresponding first terminal.
[0071] Specifically, the first terminal has the company's office platform application installed. Employees log in to their office account on the first terminal and, when they need to take the company's mobile device to work outside the office, fill in their employee ID, the device ID of the mobile device to be taken, and the location of the trip through their office account on the office platform, thereby generating a first outing application for the mobile device. The first outing application is then sent to the server through the first terminal. After receiving the first outing application, the server reviews the first outing application through the second terminal corresponding to the reviewer.
[0072] Step S204: If the first application for carrying out the vehicle is approved, generate the geofence area corresponding to the first application for carrying out the vehicle.
[0073] The geofence region is used to represent the preset usage range for mobile devices; the server uses the geofence region as the basis for controlling the usage range of mobile devices.
[0074] Specifically, if the first outing application is approved, the server uses geofencing technology to generate a geofencing area corresponding to the first outing application, based on the outing location specified in the first outing application.
[0075] In practical applications, the office location to which the mobile device belongs (for example, the office location to which the office tablet of a branch belongs is the location of the branch) and the out-of-home location are included in the geofence area; furthermore, the server generates a geofence area starting from the office location to which the mobile device belongs and ending at the out-of-home location, and controls the usage range of the mobile device based on the generated geofence area.
[0076] Step S206: Within each positioning cycle, based on the acquired positioning location, predict the location of the mobile device in the next positioning cycle.
[0077] The acquired location includes the location within the positioning period and the location of the mobile device within the positioning period before the current positioning period (i.e., the historical positioning period).
[0078] It should be noted that after generating the geofence area, the server will begin location tracking of the mobile device until it returns to its designated office location. Specifically, within each location cycle, the server obtains the mobile device's location within that cycle. Then, based on the mobile device's location within that cycle and its location in previous historical location cycles, the server calculates the mobile device's movement information, such as speed and direction. Next, based on the calculated movement information, the server predicts the mobile device's location in the next location cycle.
[0079] Step S208: If the predicted location does not fall within the geofence area, generate a second outbound carry application for the mobile device and review the second outbound carry application.
[0080] Specifically, the server determines whether the predicted location falls within a geofence area. If the predicted location falls within a geofence area, it means that the employee carrying the mobile device is still moving according to the outing plan. If the predicted location does not fall within a geofence area, it means that the employee carrying the mobile device may not be moving according to the outing plan. Therefore, the server generates a second outing application for the mobile device based on the employee identifier, device identifier, outing location, and predicted location of the first outing application, and reviews the second outing application through the second terminal corresponding to the reviewer.
[0081] It should be noted that although the server generates a geofence area starting from the mobile device's office location and ending at its out-of-home location, the boundary of the geofence area is not the mobile device's office location or out-of-home location. The mobile device's office location and out-of-home location should be included within the geofence area, and the distance between them and the boundary of the geofence area should be greater than a preset distance to avoid misjudging that the predicted location exceeds the geofence area.
[0082] Step S210: If the second application for carrying out the device fails to pass the review, set the access permission for the mobile device corresponding to the enterprise data to be denied.
[0083] Specifically, if the second application for mobile device access fails to pass the review, the server will set the access permission of the mobile device corresponding to the enterprise data to be prohibited. This prevents the mobile device from accessing the enterprise data when it is about to go beyond the pre-set geofence area (use range), thereby controlling the use range of the mobile device and improving the security of the enterprise data.
[0084] In the aforementioned device usage range control method, firstly, upon receiving a first outbound carrying request for a mobile device, the server reviews the first outbound carrying request; then, if the first outbound carrying request is approved, the server generates a geofence area corresponding to the first outbound carrying request; next, within each positioning cycle, the server predicts the location of the mobile device in the next positioning cycle based on the already acquired positioning location; the acquired positioning location includes the positioning location within the positioning cycle and the positioning location of the mobile device in the positioning cycle before the current positioning cycle; then, if the predicted location does not fall within the geofence area, the server generates a second outbound carrying request for the mobile device and reviews the second outbound carrying request; finally, if the second outbound carrying request is not approved, the server sets the access permission for the mobile device corresponding to enterprise data to prohibited access. The device usage range control method based on the above process reviews the first outbound carrying application. If the review is approved, a corresponding geofence area is generated. Then, based on the location of the mobile device in each positioning cycle, the location of the mobile device in the next positioning cycle is predicted. If the predicted location exceeds the geofence area, a corresponding second outbound carrying application is generated and reviewed. If the review is not approved, the access permission of the mobile device is set to prohibited, thereby preventing the mobile device from accessing enterprise data and improving the security of enterprise data.
[0085] In one exemplary embodiment, the first outing application is an application sent by an employee requesting to take a mobile device out of the office via a corresponding first terminal.
[0086] In step S202 above, the first application for carrying out of the premises is reviewed, which specifically includes the following: determining the reviewer corresponding to the employee; sending the first application for carrying out of the premises to the second terminal corresponding to the reviewer; the reviewer reviews the first application for carrying out of the premises through the second terminal, and the second terminal is used to return the review result of the first application for carrying out of the premises.
[0087] The first terminal is used by employees for office work, and the second terminal is used by auditors for office work. Both the first and second terminals have the company's office platform application installed, and employees and auditors log in to their office accounts under the office platform on their respective terminals.
[0088] In this context, the person responsible for reviewing an employee's application is their supervisor.
[0089] Specifically, when an employee needs to take a company mobile device out of the office, they log in to their office account on a first terminal, fill in their employee ID, the device ID of the mobile device to be taken, and the departure location on the office platform, thus generating a first outing application for that mobile device. This first outing application is then sent to the server via the first terminal. Upon receiving the first outing application, the server, based on the employee ID in the application, identifies the employee's supervisor in the employee system and designates that supervisor as the corresponding reviewer. The server then sends the first outing application to a second terminal logged into the reviewer's office account, prompting the reviewer to review the application. The reviewer reviews the first outing application via the second terminal. If the reviewer allows the employee to take the mobile device out, the first outing application is approved; if the reviewer does not allow the employee to take the mobile device out, the first outing application is rejected. After the review, the second terminal returns the review result (approved or rejected) to the server.
[0090] In step S208 above, the review of the second application for carrying out the vehicle includes the following: sending the second application for carrying out the vehicle to the second terminal; the reviewer reviews the second application for carrying out the vehicle through the second terminal; and the second terminal returns the review result of the second application for carrying out the vehicle.
[0091] Specifically, the server sends the second travel permit application to the second terminal corresponding to the reviewer, prompting the reviewer to review the application. The reviewer reviews the application through the second terminal. If the reviewer determines that the movement of the mobile device (employee) is reasonable, the application is approved. If the reviewer determines that the movement of the mobile device (employee) is unreasonable, the application is rejected. After the reviewer's review, the second terminal returns the review result (approved or rejected) to the server.
[0092] In practical applications, after the reviewer reviews the second application for carrying out mobile devices through the second terminal, even if the application is approved, the server will continue to locate and track the mobile device, predict the location of the mobile device in the next location cycle, and judge the predicted location and geofence area, thereby realizing the control of the usage range of the mobile device.
[0093] In this embodiment, the server can realize the approval of employees' applications to take mobile devices out for work through information interaction with the first terminal and the second terminal, thereby protecting the company's data security when mobile devices are taken out for work.
[0094] In an exemplary embodiment, after setting the access permission of the mobile device corresponding to the enterprise data to be denied in step S210 above, the following is further included: generating warning information for the mobile device; and sending the warning information to the first terminal.
[0095] Specifically, after the server sets the access permission of the mobile device to be denied, it will also generate a warning message for the mobile device and send the warning message to the first terminal logged in with the office account of the employee who is carrying the mobile device. This will remind the employee that they are about to exceed the geographical area fence, so that the employee can adjust their travel route in time and initiate a new first outbound carrying request to the server based on the new outbound location to remove the access permission that is denied to corporate data, thereby avoiding affecting the work outside the office.
[0096] In practical applications, after the server receives a new first outgoing carry request, it will return to step S202.
[0097] In this embodiment, by sending early warning information to employees, the server can prompt them to adjust their travel routes and promptly re-initiate the first outing request, thereby avoiding disruption to employees' normal work and ensuring both employee work efficiency and customer business experience.
[0098] In one exemplary embodiment, such as Figure 3 As shown, in step S206 above, based on the acquired location, the prediction of the mobile device's location in the next positioning cycle specifically includes the following steps:
[0099] Step S302: Based on the obtained location, determine the moving speed and moving direction of the mobile device.
[0100] Step S304: Using the location within the positioning cycle of the acquired positioning location as the starting point of movement, predict the position of the mobile device in the next positioning cycle based on the movement speed and direction.
[0101] Specifically, the server calculates the mobile device's speed and direction of movement based on the acquired location of the mobile device within the current positioning cycle and its location within historical positioning cycles, combined with kinematic knowledge. Then, using the mobile device's location within the current positioning cycle as the predicted starting point, the server predicts the mobile device's location in the next positioning cycle based on the calculated speed and direction of movement.
[0102] In practical applications, in order to improve the accuracy of movement speed and direction, the number of acquired locations is fixed as a first number, that is, the acquired locations include the location of the mobile device within the current positioning cycle and the location of the mobile device within the second number of positioning cycles before the current positioning cycle; wherein, the first number is equal to the second number plus 1.
[0103] In practical applications, to improve the accuracy of movement speed and direction, the server can also assign different weights to each acquired location according to the time sequence, and combine the weights corresponding to each location to calculate the movement speed and direction of the mobile device.
[0104] In this embodiment, the server can predict the location of the mobile device based on its location within each positioning cycle. This allows for the early assessment of the reasonableness of the mobile device's (employee's) movement based on the predicted location and geofence area, thereby avoiding the lag in adjusting permissions only after the mobile device (employee) has exceeded the geofence area and improving the security of enterprise data.
[0105] In one exemplary embodiment, after reviewing the first application to carry the device outside, the method further includes the following: if the first application to carry the device outside fails to pass the review, the access permissions of the mobile device are set to be denied.
[0106] Specifically, the auditor reviews the first application for taking the mobile device out of the office through a second terminal. If the auditor does not allow the employee to take the mobile device out of the office, the first application for taking the mobile device out of the office will not be approved. In other words, if the first application for taking the mobile device out of the office is not approved, the server will set the access permission of the mobile device to the enterprise data to be prohibited, thereby ensuring that the mobile device cannot access the enterprise data and realizing the control of the scope of use of the mobile device.
[0107] In this embodiment, if the first outbound carry-on application fails, the server sets the access permission to "deny," which ensures that mobile devices cannot access enterprise data, thereby improving the security of enterprise data.
[0108] In one exemplary embodiment, the first outing application carries at least one outing location, thereby enabling employees to apply for multiple outing locations at once, avoiding frequent applications when employees need to go to multiple outing locations.
[0109] like Figure 4 As shown, generating the geofence area corresponding to the first outbound carry application involves the following steps:
[0110] Step S402: Generate the first geofence area corresponding to each outing location of the first outing application.
[0111] Step S404: Integrate the first geofence regions corresponding to each outbound location to obtain a second geofence region including each first geofence region, which serves as the geofence region corresponding to the first outbound carry application.
[0112] Specifically, for each outing location carried in the first outing application, the server generates a first geofence region corresponding to that outing location, starting from the office location to which the mobile device belongs and ending at that outing location. Then, the server integrates the first geofence regions corresponding to each outing location to obtain a second geofence region that includes all the first geofence regions, which serves as the geofence region corresponding to the first outing application.
[0113] In this embodiment, the server first generates a corresponding first geofence region for each outbound location, and then integrates the first geofence regions to obtain a second geofence region that includes all the first geofence regions. This second geofence region serves as the geofence region corresponding to the first outbound carry application. This improves the rationality and accuracy of geofence region generation, thereby avoiding misjudgment that the predicted location exceeds the geofence region, and thus improving the accuracy of device usage range control.
[0114] In one exemplary embodiment, the office platform application installed on the mobile device has location permissions enabled by default, and the server uses the office platform application installed on the mobile device to locate and track the mobile device.
[0115] In one exemplary embodiment, the mobile device is equipped with a hardware positioning module that can communicate with a server, and the server uses the hardware positioning module to locate and track the mobile device.
[0116] In one exemplary embodiment, when the server detects that a mobile device has left its designated office location without authorization through an application of the office platform installed on the mobile device or a hardware positioning module installed on the mobile device, the server sets the access permission of the mobile device to be denied.
[0117] In one exemplary embodiment, such as Figure 5 As shown, another method for controlling the range of device usage is provided, which can be applied to... Figure 1 Taking the server in the example, the following steps are included:
[0118] Step S502: Receive the first application for carrying mobile devices sent by the employee who applied to take the device out through the corresponding first terminal.
[0119] Step S504: The first application for carrying out of the premises is sent to the second terminal corresponding to the employee's reviewer, so that the reviewer can review the first application for carrying out of the premises through the second terminal.
[0120] Step S506: If the first application for carrying out the mobile device fails to pass the review, set the access permission of the mobile device to be blocked. If the first application for carrying out the mobile device passes the review, generate the geofence area corresponding to the first application for carrying out the mobile device and start the location tracking of the mobile device until the mobile device returns to its office location.
[0121] Step S508: Within each positioning cycle, based on the positioning locations obtained in each positioning cycle, predict the location of the mobile device in the next positioning cycle.
[0122] Step S510: If the predicted location does not fall within the geofence area, generate a second outbound carry application for the mobile device.
[0123] Step S512: The second application for carrying out of the premises is sent to the second terminal of the employee's corresponding reviewer, so that the reviewer can review the second application for carrying out of the premises through the second terminal.
[0124] Step S514: If the second application for carrying out the device fails to pass the review, set the access permission for the mobile device corresponding to the enterprise data to be denied.
[0125] In this embodiment, firstly, the server, through information interaction with the first and second terminals, enables the approval of employee and review personnel's applications for mobile device removal from work, thereby protecting corporate data security when mobile devices are taken out of the office. Secondly, based on the location of the mobile device within each positioning cycle, the server can predict the location of the mobile device, facilitating the advance judgment of the rationality of the mobile device (employee)'s movement based on the predicted location and geofence area. When the predicted location exceeds the geofence area, a corresponding second application for removal from work is generated and approved. If the approval fails, the access permission of the mobile device is set to prohibited, preventing the mobile device from accessing corporate data. This also avoids the lag in adjusting permissions only after the mobile device (employee) exceeds the geofence area, thus improving the security of corporate data.
[0126] To more clearly illustrate the device usage range control method provided in the embodiments of this application, the following specific embodiment is used to describe the device usage range control method in detail. However, it should be understood that the embodiments of this application are not limited thereto. Figure 6 As shown, in one exemplary embodiment, this application also provides a method for controlling the scope of device use for security purposes, specifically including the following steps:
[0127] 1. Employees initiate applications.
[0128] Employees submit applications to take their equipment to work outside the office.
[0129] 2. Approval from higher authorities.
[0130] The server sends the employee's application to the supervisor, who then approves it and decides whether to allow the employee to take the equipment out of the office based on the specific circumstances.
[0131] 3. Geographic fence drawing.
[0132] Once the application is approved by the superior, the server draws a geofence area based on the employee's stated travel location in the application.
[0133] 4. Real-time monitoring and security measures.
[0134] If superiors do not allow employees to take their devices to work outside the office, the server will trigger security measures on the devices to protect the security of the corporate data that the devices can access.
[0135] If a supervisor allows an employee to take their device to work outside the office, the server will continuously monitor the device's location during that time. Based on the location, the server will calculate the device's speed, direction, and other movement information, and then predict the device's next location based on this information. If the device's next location exceeds the drawn geofence area, the server will automatically notify the supervisor and request additional approval.
[0136] If superiors allow employees to continue moving the equipment, the server will not take any equipment security measures.
[0137] If a manager does not allow an employee to continue moving the device, the server will trigger security measures on the device to protect the security of the enterprise data that the device can access.
[0138] 5. Information recording.
[0139] The server records the location of the monitored devices until the devices return to their respective office locations, and records all operation steps and results for future reference and query.
[0140] In this embodiment, on the one hand, by recording the device's location in real time, the server can predict the device's movement range in advance and trigger security measures for the device when it is about to exceed the geofence area. This risk warning can promptly detect potential security risks, providing time for timely action. On the other hand, once the device's location is about to exceed the preset geofence area, the server can immediately and automatically notify superiors, avoiding the escalation of risks due to human negligence or delays. This rapid response mechanism helps the organization make quick decisions and reduce potential losses. Furthermore, automatic notification and additional approval are carried out when the device is about to exceed the geofence area, thus improving approval efficiency and reducing potential risks.
[0141] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps.
[0142] Based on the same inventive concept, this application also provides a device for implementing the device usage range control method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more device usage range control embodiments provided below can be found in the limitations of the device usage range control method described above, and will not be repeated here.
[0143] In one exemplary embodiment, such as Figure 7 As shown, a device for controlling the scope of device use is provided, comprising: a first review module 702, a region generation module 704, a periodic positioning module 706, a second review module 708, and an access control module 710, wherein:
[0144] The first review module 702 is used to review the first application for carrying a mobile device outside the home upon receiving the first application for carrying the mobile device outside the home.
[0145] The region generation module 704 is used to generate the geofence region corresponding to the first outbound carrying application if the first outbound carrying application is approved.
[0146] The periodic positioning module 706 is used to predict the location of the mobile device in the next positioning cycle based on the acquired positioning location within each positioning cycle; the acquired positioning location includes the positioning location within the positioning cycle and the positioning location of the mobile device in the positioning cycle before the positioning cycle.
[0147] The second review module 708 is used to generate a second outbound carrying application for mobile devices when the predicted location does not fall within the geofence area, and to review the second outbound carrying application.
[0148] The access control module 710 is used to set the access permissions of the mobile device corresponding to the enterprise data to prohibited if the second application for carrying out the ...
[0149] In one exemplary embodiment, the first outing application is an application sent by an employee requesting to take a mobile device out of the office via a corresponding first terminal.
[0150] The first review module 702 is also used to determine the reviewer corresponding to the employee; send the first outing application to the second terminal corresponding to the reviewer; the reviewer reviews the first outing application through the second terminal, and the second terminal is used to return the review result of the first outing application.
[0151] The second review module 708 is also used to send the second application for carrying out the vehicle to the second terminal; the reviewer reviews the second application for carrying out the vehicle through the second terminal; the second terminal is used to return the review result of the second application for carrying out the vehicle.
[0152] In one exemplary embodiment, the device range control device further includes an early warning module for generating early warning information for the mobile device and sending the early warning information to a first terminal.
[0153] In an exemplary embodiment, the periodic positioning module 706 is further configured to determine the moving speed and moving direction of the mobile device based on the acquired positioning location; and to predict the position of the mobile device in the next positioning cycle based on the moving speed and moving direction, using the positioning location within the positioning cycle of the acquired positioning location as the starting point of the movement.
[0154] In one exemplary embodiment, the access control module 710 is further configured to set the access permissions of the mobile device to prohibited if the first application for carrying the device outside fails to pass the review.
[0155] In one exemplary embodiment, the first outing application carries at least one outing location.
[0156] The region generation module 704 is used to generate a first geofence region corresponding to each outing location carried in the first outing application; and to integrate the first geofence regions corresponding to each outing location to obtain a second geofence region including each first geofence region, which serves as the geofence region corresponding to the first outing application.
[0157] The modules in the aforementioned range control device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0158] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 8As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores enterprise data. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements a device usage range control method.
[0159] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0160] In one exemplary embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.
[0161] In one exemplary embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above-described method embodiments.
[0162] In one exemplary embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above-described method embodiments.
[0163] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0164] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0165] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for controlling the usage range of equipment, characterized in that, The method includes: Upon receiving a first application to take a mobile device out of the house, the application will be reviewed. If the first application for carrying items outside the home is approved, a geofence area corresponding to the first application for carrying items outside the home will be generated. Within each positioning cycle, based on the acquired positioning location, the position of the mobile device in the next positioning cycle is predicted; the acquired positioning location includes the positioning location within the positioning cycle and the positioning location of the mobile device in the positioning cycle prior to the current positioning cycle. If the predicted location does not fall within the geofence area, a second outbound carrying request is generated for the mobile device, and the second outbound carrying request is reviewed. If the second application for carrying out the device fails to pass the review, the access permission for the enterprise data corresponding to the mobile device will be set to prohibited. The step of predicting the location of the mobile device in the next positioning cycle based on the acquired location includes: Based on the obtained location, the moving speed and direction of the mobile device are determined; Using the location within the positioning period from the acquired positioning locations as the starting point of movement, the position of the mobile device in the next positioning period is predicted based on the movement speed and direction. The step of generating the geofence region corresponding to the first outing application includes: generating a first geofence region corresponding to each outing location carried in the first outing application; and integrating the first geofence regions corresponding to each outing location to obtain a second geofence region including each first geofence region, which serves as the geofence region corresponding to the first outing application. The step of determining the moving speed and moving direction of the mobile device based on the acquired location includes: assigning different weights to each acquired location according to a temporal relationship, and calculating the moving speed and moving direction of the mobile device according to the weights.
2. The method according to claim 1, characterized in that, The first application for taking the mobile device out is an application sent by the employee who requests to take the mobile device out through the corresponding first terminal; The review of the first application for carrying items outside the home includes: Determine the reviewer corresponding to the employee; The first application for carrying items outside the home is sent to the second terminal corresponding to the reviewer; the reviewer reviews the first application for carrying items outside the home through the second terminal, and the second terminal is used to return the review result of the first application for carrying items outside the home. The review of the second application for carrying items outside the home includes: The second application for carrying items outside the home is sent to the second terminal; the reviewer reviews the second application for carrying items outside the home through the second terminal; the second terminal is used to return the review result of the second application for carrying items outside the home.
3. The method according to claim 2, characterized in that, After setting the access permission for the mobile device corresponding to enterprise data to "deny," the method further includes: Generate warning information for the mobile device; The warning information is sent to the first terminal.
4. The method according to claim 1, characterized in that, After reviewing the first application for carrying items outside the home, the process also includes: If the first application for carrying the device outside fails to pass the review, the access permission of the mobile device will be set to prohibited.
5. The method according to any one of claims 1 to 4, characterized in that, The first application for carrying items outside the premises involves at least one location outside the premises.
6. A device for controlling the range of use of equipment, characterized in that, The device includes: The first review module is used to review the first application for carrying a mobile device outside the home upon receiving the first application for carrying the mobile device outside the home. The region generation module is used to generate the geofence region corresponding to the first application for carrying out the first time if the application is approved. A periodic positioning module is used to predict the location of the mobile device in the next positioning cycle based on the acquired positioning location within each positioning cycle; the acquired positioning location includes the positioning location within the positioning cycle and the positioning location of the mobile device in the positioning cycle before the current positioning cycle. The second review module is used to generate a second outbound carrying application for the mobile device if the predicted location does not fall within the geofence area, and to review the second outbound carrying application. The access control module is used to set the access permissions of the mobile device corresponding to the enterprise data to prohibited if the second application for carrying out the device fails to pass the review. The periodic positioning module is further configured to: determine the moving speed and moving direction of the mobile device based on the acquired positioning location; and, taking the positioning location within the positioning period of the acquired positioning location as the starting point, predict the position of the mobile device in the next positioning period based on the moving speed and moving direction. The region generation module is further configured to: generate a first geofence region corresponding to each outing location carried in the first outing application; integrate the first geofence regions corresponding to each outing location to obtain a second geofence region including each first geofence region, which serves as the geofence region corresponding to the first outing application. The step of determining the moving speed and moving direction of the mobile device based on the acquired location includes: assigning different weights to each acquired location according to a temporal relationship, and calculating the moving speed and moving direction of the mobile device according to the weights.
7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Audit authorization method and device, electronic equipment and medium
CN116782233A
Early warning method and device, computer equipment, storage medium and program product
CN117354718A