A one-stop management and control platform based on Internet mobile communication terminals

By dynamically adjusting the management and control strategies of mobile communication terminals through a one-stop management and control platform and combining hardware and access risk indexes, the problems of fixed resource allocation and insufficient security protection in existing technologies are solved, achieving more efficient and secure device management.

CN119052825BActive Publication Date: 2025-10-28SHANXI JIAXUN XINDA TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202411154130.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-22
Publication Date
2025-10-28
Estimated Expiration
2044-08-22

AI Technical Summary

Technical Problem

Existing technologies have shortcomings in terms of security and efficiency of mobile communication terminals. Fixed resource allocation, insufficient targeted security measures, and inadequate timeliness of risk identification result in a lack of improvement in device security and usage efficiency.

Method used

This paper provides a one-stop management and control platform based on Internet mobile communication terminals. Through the device information integration module, operation monitoring module, management and control trigger judgment module and device management and control execution terminal, it realizes dynamic adjustment of management and control strategies, and conducts comprehensive assessment and targeted management in combination with hardware and access risk index.

Benefits of technology

It improves the management and control of mobile communication terminals, enhances the security and efficiency of equipment, reduces the risk of enterprise information leakage, and provides multi-dimensional, flexible risk assessment and timely risk defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119052825B_ABST
    Figure CN119052825B_ABST
Patent Text Reader

Abstract

This invention belongs to the field of mobile terminal management and control technology, specifically disclosing a one-stop management and control platform based on Internet mobile communication terminals. The platform includes a device information integration module, a device operation monitoring module, a management and control trigger judgment module, a management and control trigger analysis module, a database, and a device management and control execution terminal. By monitoring operational information, performing management and control trigger judgments, and confirming the managed device and management information when the judgment result is positive, this invention effectively solves the problem of fixed resource configurations. It fully considers the actual usage of mobile terminals, enabling dynamic adjustment of management and control strategies, ensuring the efficiency and security of mobile communication terminal use, and thus improving the management and control effect of mobile communication terminals. Furthermore, by effectively combining the specific operation type of the mobile communication terminal in confirming management and control information, it achieves targeted management and improves the reliability and effectiveness of mobile communication terminal security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of mobile terminal management and control technology, and more specifically, relates to a one-stop management and control platform based on Internet mobile communication terminals. Background Technology

[0002] With the development of mobile technology, mobile devices such as smartphones and tablets have become an indispensable part of daily life and work. Against this backdrop, mobile devices also face increasing security challenges, such as data breach risks, malware threats, and unauthorized access. To better cope with the increasingly complex threat environment, it is necessary to manage and control mobile communication terminals.

[0003] Existing technologies, such as the mobile terminal management method and system disclosed in Chinese invention patent application CN106559258A, dynamically determine the predefined virtual group to which a mobile terminal in an enterprise mobility management (EMM) system currently belongs. In response to determining that the mobile terminal belongs to a certain virtual group, a management policy corresponding to that virtual group is sent to the mobile terminal, causing the mobile terminal to execute the management policy. This enables real-time, dynamic management of mobile terminals, protecting enterprise security and improving efficiency.

[0004] Existing technology, such as the Chinese invention patent application with authorization announcement number CN109041059B, discloses a mobile terminal security authentication method, control platform, and mobile terminal. This method receives verification information sent by the mobile terminal. The verification information includes the mobile terminal's identification information, memory card identification information, SIM card information, and user authentication information. The method verifies the verification information, sends the verification result to the mobile terminal, and controls the operation of the mobile terminal based on the verification result. This mobile terminal security authentication method, by verifying the authenticity of the mobile terminal's identification information, memory card identification information, SIM card information, and user authentication information, achieves multi-layered security authentication of the mobile terminal. By controlling the operation of the mobile terminal based on the verification result, it can more effectively ensure the security of mobile terminal use.

[0005] Regarding the two technical solutions mentioned above, it is clear that the current focus of mobile communication terminal management is mainly on security and efficiency. However, the current management at the security and efficiency levels still has the following shortcomings: 1. The current resource configuration is fixed, such as fixed network configuration, and the management strategy is not dynamically adjusted according to the actual usage of the mobile terminal to reduce unnecessary resource consumption, which results in a certain lack of improvement in usage efficiency.

[0006] 2. Currently, security measures focus primarily on basic authentication and access control, without taking into account the specific operational types of devices. For example, there are no specific operational settings for devices when accessing sensitive corporate information. This results in insufficient reliability and effectiveness of device security measures, and consequently, an inability to further reduce the risk of corporate information leakage.

[0007] 3. Insufficient timeliness of risk identification. Currently, the focus is mainly on identifying and defending against external intrusion risks, with insufficient attention paid to equipment status, resulting in weak risk defense. Summary of the Invention

[0008] In view of this, in order to solve the problems mentioned in the background technology, a one-stop management and control platform based on Internet mobile communication terminals is proposed.

[0009] The objective of this invention can be achieved through the following technical solution: This invention provides a one-stop management and control platform based on Internet mobile communication terminals, including: a device information integration module, used to import the setting information of each mobile communication terminal currently installed by the enterprise, construct a setting information set, and treat each mobile communication terminal as a target device.

[0010] The equipment operation monitoring module is used to monitor the current operating information of each target device.

[0011] The control trigger judgment module is used to determine whether the control of the target device has been triggered based on the current operating information. If so, the control trigger analysis module is started; otherwise, the process is returned to the device operation monitoring module.

[0012] The control trigger analysis module is used to confirm the controlled devices and their control information.

[0013] The database is used to store the normal temperature range of each hardware component of the target device, the reference battery consumption curve under each initial battery capacity, the risk permission set, and the risk weight settings corresponding to each application.

[0014] The equipment management execution terminal is used to configure and adjust the managed equipment based on the management information of the managed equipment.

[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) The present invention effectively solves the problem of the current resource configuration being fixed by monitoring the operation information, making control trigger judgments, and confirming the control equipment and control information when the judgment result is yes. It fully considers the actual usage of the mobile terminal, realizes the dynamic adjustment of the control strategy, thereby reducing unnecessary resource consumption, ensuring the efficiency and security of the use of the mobile communication terminal, and also improving the control effect of the mobile communication terminal.

[0016] (2) This invention analyzes the hardware risk index and access risk index, and then makes a control trigger judgment. This makes up for the lack of current security protection that focuses too much on basic identity verification and access control. It improves the timeliness and coverage of mobile communication terminal control, and also solves the problem of insufficient timeliness and comprehensiveness of current risk identification. It fully considers the impact of device status and improves the security of mobile communication terminal corresponding risk defense.

[0017] (3) By analyzing network risk factors and combining the average access program risk weight, average background program risk weight, risk access application ratio, and risk background application ratio to conduct access risk index analysis, this invention can comprehensively evaluate the security status of the device from different perspectives, avoid the one-sidedness that may be caused by a single indicator, and provide multi-dimensional, flexible and dynamic risk assessment, thereby ensuring the reliability, authenticity and representativeness of the access risk index analysis results.

[0018] (4) By conducting risk analysis and feasibility analysis of closing background applications, this invention confirms control information, effectively combines the specific operation type of mobile communication terminals, and achieves targeted control, thereby improving the reliability and effectiveness of mobile communication terminal security and further reducing the risk of enterprise information leakage. Attached Figure Description

[0019] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This is a schematic diagram of the system module connections of the present invention.

[0021] Figure 2 This is a schematic diagram of the overall control process of the present invention.

[0022] Figure 3 This is a schematic diagram of the control trigger analysis module of the present invention. Detailed Implementation

[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0024] Please see Figure 1 and Figure 2 As shown, the present invention provides a one-stop management and control platform based on an Internet mobile communication terminal, including: a device information integration module, a device operation monitoring module, a management and control trigger judgment module, a management and control trigger analysis module, a database, and a device management and control execution terminal.

[0025] In the above, the equipment information integration module is connected to the control trigger judgment module and the control trigger analysis module, respectively. The control trigger judgment module is connected to the equipment operation monitoring module, the database and the control trigger analysis module, respectively. The control trigger analysis module is also connected to the equipment control execution terminal.

[0026] The device information integration module is used to import the setting information of each mobile communication terminal currently installed by the enterprise, construct a setting information set, and treat each mobile communication terminal as a target device.

[0027] Specifically, the settings include, but are not limited to, setting the memory compression ratio, setting the data transmission compression ratio, setting the memory compression ratio threshold, and setting the data transmission compression ratio threshold.

[0028] The equipment operation monitoring module is used to monitor the current operating information of each target device.

[0029] Specifically, the current operating information includes, but is not limited to, operating status, device hardware information, connection information, and access information, where the operating status is either off or on.

[0030] The device hardware information includes the current memory usage ratio, the monitored temperature of each hardware component at each cumulative running time point, the rated battery capacity, and the remaining battery capacity at each cumulative running time point.

[0031] Connection information includes network speed and signal strength at each connection point in time.

[0032] Access information includes cumulative access duration, accessed applications, application permission list, background applications, access duration and access count of each background application. The application permission list stores the relevant application permissions, the number of accessed applications associated with each relevant application permission, and the number of associated background applications.

[0033] The control trigger judgment module is used to determine whether the control of the target device has been triggered based on the current operating information. If so, the control trigger analysis module is started; otherwise, the process is returned to the device operation monitoring module.

[0034] Specifically, determining whether the target device control is triggered includes: S1, extracting the operating status from the current operating information, wherein the operating status is one of shutdown and startup.

[0035] S2. If the operating status of all target devices is off, this will not be used as the judgment result. Otherwise, extract device hardware information, connection information, and access information from the current operating information, analyze the hardware risk index and access risk index of each target device, and denot them as λ respectively. i and γ i , where i represents the target device number, i = 1, 2, ..., n.

[0036] S3. Define the target device with a hardware risk index greater than 0 as condition 1, and define the target device with an access risk index greater than 0 as condition 2.

[0037] S4. If neither condition 1 nor condition 2 is true, then it will be used as the judgment result; otherwise, it will be used as the judgment result.

[0038] This invention analyzes hardware risk index and access risk index to determine control triggers, thus addressing the shortcomings of current security measures that focus too much on basic identity verification and access control. This improves the timeliness and coverage of mobile communication terminal control, and also solves the problem of insufficient timeliness and comprehensiveness in current risk identification. It fully considers the impact of device status and enhances the protection of mobile communication terminals against corresponding risks.

[0039] Furthermore, the analysis of the hardware risk index of each target device in step S2 includes: Y1, extracting the current memory usage ratio from the device hardware information.

[0040] Y2. Extract the monitored temperatures of each hardware component at each cumulative operating time point from the equipment hardware information to confirm the hardware temperature interference ratio.

[0041] It should be added that the hardware components include the CPU and battery, among others.

[0042] Y3. Extract the rated battery capacity and the remaining battery capacity at each current cumulative running time from the device hardware information, and calculate the difference between the two to obtain the battery consumption at each current cumulative running time.

[0043] Y4. Extract the remaining battery capacity at the starting time point from the remaining battery capacity at each current cumulative running time point, and use it as the target starting battery capacity.

[0044] Y5. Construct an actual battery consumption curve with the cumulative running time as the horizontal axis and the battery loss as the vertical axis, denoted as curve A.

[0045] Y6. Extract the reference battery consumption curve under the target initial battery capacity from the database, and denote it as curve B.

[0046] Y7. Compare curve A and curve B to obtain the length of the overlapping curve. Record the ratio of the length of the overlapping curve to the length of curve A as the battery consumption matching ratio.

[0047] Y8. Set the weights for memory usage ratio, hardware temperature interference ratio, and battery consumption matching ratio, and calculate the hardware risk index λ for each target device using a linear regression function. i .

[0048] Understandably, step Y2 confirms the hardware temperature interference ratio, including: Y21, extracting the normal temperature range of each hardware component corresponding to the target device from the database.

[0049] Y22. Statistically count the cumulative number of operating time points where the monitored temperature is not within the normal temperature range. This number is taken as the number of temperature disturbance time points. The ratio is then compared with the cumulative number of operating time points, and the ratio is recorded as the deviation temperature duration ratio.

[0050] Y23. The number of hardware components whose deviation temperature duration ratio is greater than the set reference deviation temperature duration ratio is taken as the number of deviation components, and compared with the total number of hardware components to obtain the deviation component number ratio k. b .

[0051] It should be added that the specific value of the reference deviation temperature duration ratio can be 0.3.

[0052] Y24. Select the maximum value from the deviation temperature duration ratios of each hardware component, and use it as the first deviation temperature duration ratio k. c1 .

[0053] Y25. Calculate the average of the deviation temperature duration ratios of each deviation component to obtain the second deviation temperature duration ratio k. c2 .

[0054] Y26, Set k c1 k c2 and k b The weights are calculated by weighted summation to obtain the hardware temperature interference ratio.

[0055] It should be added that the first and second deviation temperature duration ratios reflect the most severe and average situations, respectively. Combined with the deviation component number ratio, this provides a better reflection of the overall system health. The hardware temperature disturbance ratio is determined by comprehensively considering three parameters—the highest deviation temperature duration ratio, the average deviation temperature duration ratio of deviation components, and the deviation component number ratio—rather than directly using the highest or average deviation temperature duration ratio. This approach provides a more comprehensive reflection of the temperature disturbance situation of the entire system, rather than just the state of a single component, and offers a more accurate risk assessment, reducing errors caused by relying on a single indicator.

[0056] In one specific embodiment, the first deviation temperature duration ratio reflects the highest deviation temperature duration ratio among all deviation components, which typically represents the most severe temperature deviation in the system. The second deviation temperature duration ratio is the average of the deviation temperature duration ratios of all deviation components, which reflects the overall temperature deviation level. The deviation component number ratio reflects how many hardware components are in a temperature deviation state.

[0057] It's also important to note that the ratio of the number of skewed components doesn't necessarily indicate that the actual temperature deviations of these components are all severe. Focusing solely on the number of skewed components might overlook the actual temperature deviations of some. In such cases, even with a large number of component temperature deviations, if their deviation temperature duration ratios are not high, the impact on overall system performance may be relatively small. Therefore, by allocating less weight to the ratio of the number of skewed components, we can ensure that the evaluation results focus more on the severity of temperature deviations rather than simply counting the number of skewed components. Thus, the ratio of the number of skewed components, k, is set accordingly. b The weight is the smallest, and the first deviation temperature is consistently higher than k. c1 Second deviation temperature duration ratio k c2 All of these are due to reaction temperatures exceeding the target level; a reference deviation temperature duration ratio k can be set. c1 Second deviation temperature duration ratio k c2 The weights are the same; for example, the first deviation temperature is longer than k. c1 Second deviation temperature duration ratio k c2 The weight can be 0.4, and the number of deviation parts is equal to k. b The weight can be 0.2.

[0058] It needs further explanation that setting the weight of the first and second deviation temperature duration ratios to be equal allows for consideration of both the most severe scenarios and the overall average level during the assessment. This results in a more balanced risk assessment outcome, avoids excessive bias towards extreme or average cases, makes the assessment more objective, and ensures that the highest and average deviation temperature duration ratios are considered at the same level, improving the robustness of the assessment results. This ensures that even if some components experience abnormal temperature deviations, it will not have an excessive impact on the overall assessment.

[0059] Understandably, the specific calculation process for the hardware risk index of each target device in step Y8 is as follows: The memory usage ratio, hardware temperature interference ratio, and battery consumption matching ratio of each target device are denoted as k. i 、k′ i and k″ i .

[0060] Calculate the hardware risk index λ for each target device. i , k0, k1, and k2 represent the reference memory usage ratio, hardware temperature interference ratio, and battery consumption matching ratio, respectively, and r0, r1, and r2 represent the weights of the memory usage ratio, hardware temperature interference ratio, and battery consumption matching ratio, respectively, with r0 + r1 + r2 = 1.

[0061] It's worth noting that memory usage ratio refers to the ratio of currently used RAM to total available RAM. High memory usage can lead to instability in the operating system or applications, increasing the risk of malware attacks. Furthermore, issues like memory leaks can also lead to the disclosure of sensitive information; therefore, setting the memory usage ratio has the highest weight. Hardware temperature interference ratio refers to the degree to which device temperature affects its normal operating capabilities. Overheating can affect device stability and performance, and may even cause automatic shutdown or other malfunctions. These malfunctions may make the device vulnerable to attacks or prevent the proper use of security measures such as encryption in emergencies. In addition, overheating can affect the quality of wireless signal transmission and reception, thus impacting communication security. Therefore, setting the emergency temperature interference ratio has a lower weight. Battery consumption matching ratio reflects the degree of match between actual battery consumption and expected battery life. In some cases, if a battery depletion causes a sudden device shutdown, it may interrupt ongoing secure communications or force users to replace or charge the battery without taking appropriate safety precautions, thus increasing security risks. In addition, some malware may indicate its presence through abnormally high battery consumption. Since battery consumption is not a direct cause of communication security, the weight of the battery consumption matching ratio is set to the minimum, i.e., r0>r1>r2. For example, k0, k1 and k2 can take values ​​of 0.45, 0.3 and 0.25 respectively.

[0062] It should also be noted that the specific values ​​of the reference memory usage ratio, hardware temperature interference ratio, and battery consumption matching ratio will be comprehensively set based on the device type and the device's application specifications. The application specifications are provided by the device manufacturer. For example, k0, k1, and k2 can be set to 0.6, 0.7, and 0.8, respectively.

[0063] Furthermore, step S2 analyzes the access risk index of each target device, including: J1, setting the network risk factor σ for each target device based on the connection information. i .

[0064] J2. Extract each access application from the access information and extract the setting risk weight of each access application from the database. Calculate the average access application risk weight by taking the mean.

[0065] J3. Extract the background applications from the access information, and similarly analyze the average background application risk weight to obtain the average background application risk weight.

[0066] J4. Extract the risk permission set from the database, extract the application permission list from the access information, and then extract the relevant application permissions. Record the relevant application permissions located in the risk permission set as risk permissions.

[0067] It's important to note that risky permissions require explicit user authorization and involve access to sensitive information or functions on the device, such as location, storage, accounts, and cameras. In contrast, normal permissions typically do not require explicit user authorization and can be used by applications. These permissions have a smaller impact on device security but can still provide useful functionality, such as viewing network status, changing network connections, and allowing applications to access the internet.

[0068] J5. Extract the number of access applications associated with each risk permission from the application permission list, and filter out the maximum value as the number of risky access applications.

[0069] J6. Count the number of accessed applications and calculate the ratio of the number of risky accessed applications to the total number of accessed applications, which is used as the risky access ratio.

[0070] J7. Extract the number of background applications associated with each risk permission from the application permission list, and set the risk background application ratio in the same way as the risk access program ratio setting method.

[0071] J8. The average access procedure risk weight, average background procedure risk weight, risky access procedure ratio, and risky background procedure ratio for each target device are denoted as η. i η′ i f i and f′ i .

[0072] J9. Calculate the access risk index γ for each target device. i , η0 is the application risk weight set for reference, and f0 is the risk ratio set for reference.

[0073] It should be added that, in a specific embodiment, η0 can be 0.5 and f0 can be 0.4.

[0074] This invention analyzes network risk factors and integrates the average access program risk weight, average background program risk weight, risk access application ratio, and risk background application ratio to conduct access risk index analysis. This allows for a comprehensive assessment of device security from different perspectives, avoiding the one-sidedness that may result from a single indicator. It provides multi-dimensional, flexible, and dynamic risk assessment, thereby ensuring the reliability, authenticity, and representativeness of the access risk index analysis results.

[0075] Understandably, step J1 sets network risk factors for each target device, including: J11, extracting the connection network speed and connection signal strength at each connection time point from the connection information, and creating a network speed sequence and signal strength sequence for each target device.

[0076] J12. For each target device, the network speed sequence and signal strength sequence are compared one by one with the set reference connection network speed and reference connection signal strength.

[0077] It's important to note that normal network speeds for computer equipment are typically between 10Mbps and 100Mbps. You can choose either an end value or an intermediate value as a reference connection speed. For example, you can use 10Mbps or 50Mbps as a reference connection speed. To ensure the network risk factor settings accurately reflect actual conditions, specifically, 50Mbps can be used as a reference connection speed. Computer equipment connection signal strength is usually expressed in dBm. A good connection signal strength is generally between -50dBm and -70dBm. The closer to -50dBm, the better the signal; the closer to -70dBm, the worse the signal. For example, -70dBm can be used as a reference connection signal strength.

[0078] J13. If the comparison results of all values ​​in the network speed sequence and the signal strength sequence corresponding to a target device are greater than or equal to 0, then 0 is taken as the network risk factor of the target device; otherwise, the target device is recorded as a deviation device.

[0079] J14. The number of values ​​in the connection network speed sequence and connection signal strength sequence corresponding to the statistical deviation device that are less than the specified values ​​are denoted as M0 and M1, respectively.

[0080] J15. Calculate the standard deviation of the network speed and signal strength at each connection time point. Use the results as the network speed fluctuation and signal strength fluctuation, respectively, and record them as follows: and

[0081] J16, M0, M1, and Importing the Sigmoid function, the network risk factor τ of the deviation device is output, and thus the network risk factor σ of each target device is obtained. i , σ i It can take the value 0 or τ, where τ>0.

[0082] It should be added that the specific formula for the network risk factor τ of the deviation device is as follows: k3 is the deviation connection ratio set as a reference. and These represent the network speed fluctuation and signal strength fluctuation, respectively, which are the reference values. M′ represents the number of connection time points.

[0083] In one specific embodiment, k3 can specifically take the value 0.5. and The specific value can be extracted from the network connection specification of the target device. For example, The value can be 5Mbps. The value can be 10dBm, and the network connection specifications are provided by the target device manufacturer.

[0084] Please see Figure 3 As shown, the control trigger analysis module is used to confirm the control device and the control information of the control device.

[0085] Specifically, the control equipment is identified, including: extracting the hardware risk index and access risk index of each target device.

[0086] If the hardware risk index or access risk index of a target device is greater than 0, the target device is marked as a controlled device.

[0087] Specifically, confirm the control information of the controlled equipment, including: E1, analyze the control risk level of the controlled equipment, and match it with the control risk level corresponding to each set adjustment ratio to obtain the matching adjustment ratio k. a .

[0088] It should be added that the risk level corresponding to each adjustment ratio can be obtained through comprehensive analysis based on the risk control standards of the target equipment or on the historical operating experience and simulation experience of the target equipment. The risk control standards can be obtained from the manufacturer of the target equipment.

[0089] E2. Extract the cumulative access duration from the access information, denoted as T0. Simultaneously, extract the access duration and access count of each background application, denoted as T0 respectively. d and F d d represents the background application number, d = 1, 2, ..., x, and the analysis focuses on the feasibility of shutting down each background application.

[0090] E3. Count the number of background applications with a shutdown feasibility score greater than 0, and compare it with the total number of applications to obtain the shutdown feasibility score k. h .

[0091] E4. Let X0 be the number of background applications. If k a ≥k h ,Will The number of background programs closed is multiplied by 1. This is the floor symbol.

[0092] E5. Sort the background applications in descending order of their feasibility of being shut down, and take the top X1 background applications as the shutdown programs. Treat the shutdown command and each shutdown program as control information.

[0093] E6, if k a <k h ,Will The number of background applications to be closed is multiplied by 2, and the background applications ranked first C2 are used as the closed applications.

[0094] E7, will As a compression adjustment factor Extract the settings of the control device from the settings information: memory compression ratio p0, data transmission compression ratio p1, memory compression ratio threshold p′, and data transmission compression ratio threshold p″.

[0095] E8, will As an adjustment to the memory compression ratio p m ,Will As an adjustment of the data transmission compression ratio p w This will close the command, shut down each running program, and p m and p w As control information.

[0096] It's worth noting that when the hardware risk index is greater than 0, it indicates that the memory usage ratio, hardware temperature interference ratio, or battery consumption ratio exceeds their reference values, or that the battery consumption ratio is lower than their corresponding reference values. When these parameters are exceeded, releasing background applications can alleviate operational pressure, thereby reducing heat generation and slowing down battery degradation. Conversely, when the access risk index is greater than 0, it indicates that the program risk weight or risk program ratio is greater than the corresponding reference value. Closing unnecessary background applications can reduce network traffic consumption, decrease the number of simultaneously online devices, and lower the probability of network conflicts. Therefore, when there are background applications that can be closed, closing them should be the first priority. When the number of closable applications is insufficient to meet management needs, adjusting compression strategies can further alleviate operational and network pressure.

[0097] Furthermore, the analysis of the control risk level of the control equipment in step E1 includes: denoting the hardware risk index and access risk index of the control equipment as λ0 and γ0, respectively.

[0098] The risk level of the statistically controlled equipment is denoted as FX. e is a natural constant, and g0 and g1 are the weights of hardware risk and access risk, respectively.

[0099] It should be added that the specific formula for the control risk level of the controlled equipment is set with reference to a variant of the ReLU function and the exponential regression function. The purpose is to ensure the singularity of the analysis of the hardware risk index and the access risk index when comprehensively considering the hardware risk index and the access risk index, that is, to ensure that they are not affected by each other's values.

[0100] It should also be noted that hardware risk measures the risk caused by hardware failure, high temperature or other physical problems, while access risk measures network or other access-related risks. When hardware risks exist, they may lead to serious consequences, including data loss, business interruption and service unavailability. Therefore, hardware risks can lead to access risks, but access risks do not directly lead to hardware risks. Therefore, the weight of hardware risk is set to be greater than that of access risk, i.e., g0 > g1. For example, g0 can be 0.55 and g1 can be 0.45.

[0101] Furthermore, step E2 analyzes the feasibility of shutting down each background application, including: extracting the risk weight of each background application's settings from the database, denoted as ψ. d .

[0102] Calculate the feasibility δ of shutting down each background application. d , y0 and y1 are set ratios, where y0, y1 ∈ (0, 1).

[0103] It should be added that the feasibility of shutting down each background application is also set with reference to the exponential regression function, and rounding down ensures that the final result is 0 when the variable value is less than 0, i.e., infeasible, thus maintaining the consistency of the result trend. d -η0、T d -y0*T0 and F d -y1*max(F d If one of the three items is greater than or equal to 0, the overall value is greater than or equal to 1. Subtracting 1 removes the critical state that equals 0, so as to ensure the validity of the closure feasibility analysis results as much as possible, thereby ensuring the feasibility and reliability of the subsequent closure operation program selection.

[0104] It should also be added that, for ease of analysis, y0 can be 0.3 and y1 can be 0.5.

[0105] This invention, through risk analysis and feasibility analysis of shutting down background applications, confirms control information, effectively combines the specific operation types of mobile communication terminals, and achieves targeted control, thereby improving the reliability and effectiveness of mobile communication terminal security and further reducing the risk of enterprise information leakage.

[0106] The database is used to store the normal temperature range of each hardware component of the target device, the reference battery consumption curve under each initial battery capacity, the risk permission set, and the risk weight settings corresponding to each application.

[0107] The device management and control execution terminal is used to configure and adjust the managed devices based on the management and control information of the managed devices.

[0108] This invention effectively solves the problem of fixed resource configuration by monitoring operational information, performing control trigger judgments, and confirming control devices and control information when the judgment result is yes. It fully considers the actual usage of mobile terminals, realizes dynamic adjustment of control strategies, thereby reducing unnecessary resource consumption, ensuring the efficiency and security of mobile communication terminal use, and improving the control effect of mobile communication terminals.

[0109] The above content is merely an example and illustration of the concept of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described, or use similar methods to replace them, as long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, and all such modifications and additions should fall within the protection scope of the present invention.

Claims

1. A one-stop management and control platform based on an Internet mobile communication terminal, characterized in that, include: The device information integration module is used to import the setting information of each mobile communication terminal currently installed by the enterprise, build a setting information set, and treat each mobile communication terminal as a target device. The equipment operation monitoring module is used to monitor the current operating information of each target device; The control trigger judgment module is used to determine whether the control of the target device has been triggered based on the current operating information. If so, the control trigger analysis module is started; otherwise, the process is returned to the device operation monitoring module. The control trigger analysis module is used to confirm the controlled devices and their control information. The identification and control of the device includes: extracting the hardware risk index and access risk index of each target device; if the hardware risk index or access risk index of a target device is greater than 0, the target device is marked as a control device. The database is used to store the normal temperature range of each hardware component of the target device, the reference battery consumption curve under each initial battery capacity, the risk permission set, and the risk weight settings corresponding to each application. The equipment management and control execution terminal is used to configure and adjust the managed equipment based on the management and control information of the managed equipment; The extraction of hardware risk indices for each target device includes: extracting the current memory usage ratio from the device hardware information; extracting the monitored temperature of each hardware component at each cumulative operating time point from the device hardware information to confirm the hardware temperature interference ratio; extracting the rated battery capacity and the remaining battery capacity at each current cumulative operating time point from the device hardware information, and subtracting the two to obtain the battery consumption amount at each current cumulative operating time; extracting the remaining battery capacity at the starting operating time point from the remaining battery capacity at each current cumulative operating time point as the target starting battery capacity; constructing an actual battery consumption curve, denoted as curve A, with the cumulative operating time point as the horizontal axis and the battery consumption amount as the vertical axis; extracting a reference battery consumption curve under the target starting battery capacity from the database, denoted as curve B; comparing curve A and curve B to obtain the length of the overlapping curve, and recording the ratio of the length of the overlapping curve to the length of curve A as the battery consumption matching ratio; The confirmation of the hardware temperature interference ratio includes: extracting the normal temperature range of each hardware component corresponding to the target device from the database; counting the cumulative number of operating time points where the monitored temperature is not within the normal temperature range as the number of temperature interference time points, and comparing it with the cumulative number of operating time points, recording the ratio as the deviation temperature duration ratio; counting the number of hardware components whose deviation temperature duration ratio is greater than a set reference deviation temperature duration ratio as the number of deviation components, and comparing it with the total number of hardware components to obtain the deviation component number ratio. The maximum value is selected from the temperature deviation ratios of each hardware component and used as the first temperature deviation ratio. The average of the deviation temperature duration ratios of each deviation component is calculated to obtain the second deviation temperature duration ratio. ;set up , and The weights are calculated by weighted summation to obtain the hardware temperature interference ratio.

2. The one-stop management and control platform based on an Internet mobile communication terminal as described in claim 1, characterized in that: The determination of whether the target device control is triggered includes: The running status is extracted from the current running information, where the running status is either off or on. If all target devices are in a "shutdown" state, this will not be considered a judgment result. Otherwise, device hardware information, connection information, and access information are extracted from the current operating information. The hardware risk index and access risk index of each target device are analyzed and denoted as follows: and , Indicates the target device number. ; Target devices with a hardware risk index greater than 0 are defined as condition 1, and target devices with an access risk index greater than 0 are defined as condition 2. If neither condition 1 nor condition 2 is true, it will be considered as the judgment result; otherwise, it will be considered as the judgment result.

3. The one-stop management and control platform based on an Internet mobile communication terminal as described in claim 2, characterized in that: By setting weights for memory usage ratio, hardware temperature interference ratio, and battery consumption consistency ratio, a hardware risk index for each target device is calculated using a linear regression function. .

4. The one-stop management and control platform based on an Internet mobile communication terminal as described in claim 2, characterized in that: The analysis of the access risk index of each target device includes: Based on the connection information, network risk factors are set for each target device. ; Extract each access application from the access information, and extract the setting risk weight of each access application from the database. Calculate the average access application risk weight by means of the average risk weight. Extract the background applications from the access information, and similarly analyze them using the same method as the average access application risk weight to obtain the average background application risk weight. Extract the risk permission set from the database, extract the application permission list from the access information, and then extract each application permission involved. Record the application permissions involved in the risk permission set as risk permissions. Extract the number of access applications associated with each risky permission from the application permission list, and filter out the maximum value as the number of risky access applications; The number of accessed applications is counted, and the ratio of the number of risky accessed applications to the total number of accessed applications is calculated as the risky access ratio. Extract the number of background applications associated with each risk permission from the application permission list, and set the risk background application ratio in the same way as the risk access program ratio setting method. The average access procedure risk weight, average background procedure risk weight, risky access procedure ratio, and risky background procedure ratio for each target device are respectively denoted as: , , and ; Calculate the access risk index for each target device. , , To set reference application risk weights, To set a reference risk procedure ratio.

5. A one-stop management and control platform based on an Internet mobile communication terminal as described in claim 4, characterized in that: The setting of network risk factors for each target device includes: Extract the network speed and signal strength at each connection time point from the connection information, and create the network speed sequence and signal strength sequence for each target device; For each target device, the network speed sequence and signal strength sequence are compared one by one with the set reference connection network speed and reference connection signal strength. If the comparison results of each value in the network speed sequence and the signal strength sequence corresponding to a target device are all greater than or equal to 0, then 0 is taken as the network risk factor of the target device; otherwise, the target device is recorded as a deviation device. The number of values ​​less than a certain value in the comparison results of the network speed sequence and the network signal strength sequence corresponding to the statistical deviation device is denoted as follows: and ; Calculate the standard deviation of the network speed and signal strength at each connection time point. Use the results as network speed fluctuation and signal strength fluctuation, respectively, and denot them as follows: and ; Will , , and Importing the Sigmoid function, the network risk factor of the output deviation device is used. This allows us to obtain the network risk factors for each target device. , The value can be 0 or , .

6. The one-stop management and control platform based on an Internet mobile communication terminal as described in claim 4, characterized in that: The control information of the confirmed control device includes: Analyze the control risk level of the controlled equipment and match it with the control risk level corresponding to each set adjustment ratio to obtain the matching adjustment ratio. ; Extract the cumulative access time from the access information and record it as follows: Simultaneously, the access duration and number of accesses for each background application are extracted and recorded as follows: and , Indicates the background application number. Analyze the feasibility of shutting down each background application; The number of background applications with a shutdown feasibility score greater than 0 is counted, and this number is compared to the total number of applications to obtain the shutdown feasibility score. ; The number of background applications is denoted as ,like ,Will As the number of background programs closed , The floor symbol; Sort the background applications in descending order of their feasibility to be shut down, and then... Each background application in the unit acts as a shutdown procedure, and the shutdown command and each shutdown procedure are used as control information; like ,Will As the number of background running programs closed Before sorting Each background application acts as a shutdown program; Will As a compression adjustment factor Extract the memory compression ratio of the control device settings from the settings information set. Set the data transmission compression ratio Memory compression ratio threshold and data transmission compression ratio threshold ; Will As an adjustment to the memory compression ratio ,Will As an adjustment to the data transmission compression ratio This will close the command, shut down each running program, and As control information.

7. A one-stop management and control platform based on an Internet mobile communication terminal as described in claim 6, characterized in that: The risk level of the analysis and control equipment includes: The hardware risk index and access risk index of the control equipment are respectively denoted as: and ; The control risk level of statistically controlled equipment is denoted as... , , It is a natural constant. and These are the weights for hardware risk and access risk, respectively.

8. The one-stop management and control platform based on an Internet mobile communication terminal as described in claim 7, characterized in that: The analysis of the feasibility of shutting down each application in the background includes: Extract the risk weight settings for each backend application from the database, denoted as... ; Statistical analysis of the feasibility of shutting down each background application , , and To set the ratio, .

Citation Information

Patent Citations

  • Mobile terminal management and control method and system

    CN106559258A

  • A mobile terminal security authentication method, management platform, and mobile terminal

    CN109041059B

  • Application program management method and device

    CN115017476A

  • System-in-package equipment operation supervision system based on Internet of Things

    CN117075555A

  • Information communication technology safety monitoring system and monitoring method thereof

    CN117176466A