Mobile device supervision and management method, system, electronic device and storage medium
By monitoring the GPS and Bluetooth status of mobile devices, combined with hierarchical warning and network caching technology, the problem of insufficient location information acquisition in dynamic environments in remote supervision solutions is solved, and full-dimensional dynamic monitoring and efficient supervision management of mobile devices are achieved.
Patent Information
- Application Number
- CN202510829030.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-06-20
AI Technical Summary
Existing remote supervision solutions are unable to obtain the specific location information of mobile personnel in real time and cannot adapt to dynamic working environments, resulting in poor supervision effects, insufficient utilization of mobile devices, and poor flexibility and real-time performance.
Obtain location information through the GPS module of the mobile device, monitor the application running time and Bluetooth status, generate supervision reports, and issue graded warnings based on preset graded warning rules. Combined with network status detection, local encrypted caching and breakpoint resumption are implemented, and monitoring strategies are dynamically adjusted.
It realizes full-dimensional dynamic monitoring of mobile devices, improves the real-time and accuracy of supervision and management, reduces the risk of data loss, adapts to different work scenarios, and improves the accuracy of early warning and equipment risk rating.
Smart Images

Figure CN120343505B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of device supervision and management, and in particular to a method, system, electronic device and storage medium for supervising and managing a mobile device. Background Art
[0002] With the rapid development of communication technology and mobile internet, remote monitoring and management have become important means for businesses and organizations to improve efficiency and reduce costs. Existing remote monitoring solutions often rely on fixed devices or dedicated hardware, underutilizing mobile devices and exhibiting poor flexibility and real-time performance. This significantly limits the scope and effectiveness of remote management.
[0003] Existing remote supervision solutions are limited by geographical location and cannot obtain detailed information such as the specific location of mobile personnel in real time. They cannot use dynamic working environments, which affects the supervision effect and needs to be improved. Summary of the Invention
[0004] In order to provide a supervision and management method suitable for a dynamic working environment and improve the supervision and management effect, the present application provides a mobile device supervision and management method, system, electronic device and storage medium.
[0005] In the first aspect, the invention objectives of this application are achieved by adopting the following technical solutions:
[0006] Mobile device supervision and management methods, including:
[0007] Collect device location information of mobile devices and monitor the applications used by users and their running time to obtain application usage data;
[0008] Detect the Bluetooth status of mobile devices, record Bluetooth activation status and duration of continuous communication;
[0009] Uploading the device location information, the application usage data, and the Bluetooth communication data to the server of the supervision and management system for integrated analysis to generate a supervision report containing real-time location tracks, a list of high-frequency applications, and Bluetooth interaction records;
[0010] Based on the preset graded warning rules, graded warnings are issued for abnormal behaviors in the supervision report.
[0011] By adopting the above technical solution, the device location information can be obtained through the GPS module of the mobile device. By real-time collection of GPS location information, application operation data and Bluetooth communication status, full-dimensional dynamic monitoring of the mobile device is achieved, which solves the technical problem that traditional fixed monitoring equipment is limited by geographical fences and cannot track mobile scenes. This application integrates three types of data: location trajectory, high-frequency application list, and Bluetooth interaction record. Through server-side spatiotemporal correlation analysis, it can identify abnormal behavior patterns (such as high-frequency use of social software + abnormal location stay during non-working hours), and can provide graded warnings for abnormal behaviors in supervision reports in real time through preset graded warning rules. Graded warning refers to the use of multi-level warnings to distinguish and warn different risk levels to improve the accuracy of warnings. Therefore, this application provides a supervision and management method suitable for dynamic working environments, thereby improving the supervision and management effect.
[0012] In a preferred embodiment of the present application, the method further includes:
[0013] Set up a network status detection module on the mobile device to monitor the network connection status in real time;
[0014] When a network interruption or transmission delay exceeding a threshold is detected, the local encrypted cache is activated to store the device location information, application usage data, and Bluetooth communication data to be uploaded in a local storage area according to a preset data format;
[0015] After detecting network recovery, the data retransmission process is triggered, and the cached data is uploaded in the order of priority of real-time location data, application usage records, and Bluetooth communication records.
[0016] By adopting the above technical solution, the network connection status is monitored in real time, and the local encrypted cache is automatically enabled when the network is interrupted or high latency occurs, ensuring that key data such as device location information and application usage data are not lost, thereby ensuring data integrity; this application adopts local storage and breakpoint resumption mechanism to avoid data transmission failures due to network fluctuations and reduce redundant requests for cloud data synchronization.
[0017] In a preferred embodiment of the present application, the method further includes:
[0018] Acquire monitoring data information identifying an operating state of a mobile device, and determine hierarchical device state information based on the monitoring data information, the hierarchical device state information including core operating state information, auxiliary operating state information, and low-frequency operating state information;
[0019] Triggering a monitoring instruction based on the hierarchical device status information to obtain device feedback data, the device feedback data including core risk data indicating the frequency of abnormal device behavior, auxiliary risk data indicating application installation and uninstallation dynamics, and potential risk data indicating device geographic location deviation;
[0020] Obtaining device risk rating information based on the device feedback data;
[0021] Based on the device risk rating information, a regulatory label marking instruction is triggered.
[0022] By adopting the above technical solution, the device operating status is divided into three levels: core, auxiliary, and low-frequency, which reduces the consumption of redundant monitoring resources and concentrates resources to handle high-risk conditions (such as core operation abnormalities). This application avoids misjudgment of a single indicator through comprehensive analysis of multi-dimensional risk data (abnormal behavior frequency, application installation dynamics, and geographic location offset), thereby improving the accuracy of device risk rating. At the same time, by triggering graded regulatory labels based on risk data, high-risk devices can be quickly located and targeted control measures can be implemented.
[0023] In a preferred embodiment of the present application, the step of obtaining monitoring data information identifying the operating status of a mobile device and determining hierarchical device status information based on the monitoring data information includes:
[0024] Obtain basic device information, including device model, system version, and hardware configuration parameters;
[0025] Obtain the monitoring data information associated with the basic information of the device, the monitoring data information including device CPU occupancy, memory usage, network traffic data and application startup log;
[0026] Generate a device operation feature model based on the device basic information, the monitoring data information and a preset abnormal behavior feature library;
[0027] According to the device operation characteristic model, corresponding hierarchical device status information is matched from a preset hierarchical database.
[0028] By adopting the above technical solution, combining basic device information (model, system version) with real-time monitoring data (CPU occupancy, memory usage), a dynamic device operation feature model is constructed to improve the accuracy of status classification; by matching the device status with a preset abnormal behavior feature library, potential risks (such as abnormal CPU occupancy caused by malicious applications running in the background) can be discovered in advance. This application is based on the joint analysis of historical data and real-time data to achieve dynamic updates of device status classification and adapt to changes in device performance in different usage scenarios.
[0029] In a preferred example of the present application, triggering a supervision instruction based on the hierarchical device status information to obtain device feedback data specifically includes:
[0030] The core operation status information, auxiliary operation status information and low-frequency operation status information are respectively associated with different monitoring strategy weights;
[0031] Dynamically adjust monitoring strategy weights based on the hierarchical device status information to trigger hierarchical supervision instructions;
[0032] The hierarchical supervision instructions are used to collect device operation logs, application permission call records and geo-fence data to generate device feedback data.
[0033] By adopting the above technical solutions, differentiated monitoring strategy weights are assigned to different device states (such as assigning higher monitoring frequency to core states) to achieve precise resource allocation; multi-source information such as operation logs, permission call records, and geographic fence data are collected through hierarchical supervision instructions to cover the key risk dimensions of device operation; this application combines multi-dimensional data (such as high-frequency permission calls + abnormal geographic location offsets) for comprehensive analysis to enhance the ability to identify hidden risks (such as certain software activities).
[0034] In a preferred example of the present application, obtaining device risk rating information based on the device feedback data specifically includes:
[0035] Calculating a core risk coefficient of the device based on the frequency of abnormal behaviors in the core risk data;
[0036] Generate an application compliance score based on the application installation and uninstallation dynamics in the auxiliary risk data and in combination with the application whitelist library;
[0037] Calculate the location deviation based on the geographic location offset distance in the potential risk data and the preset geographic fence rules;
[0038] Based on the core risk factor, application compliance score and location deviation, device risk rating information is comprehensively generated.
[0039] By adopting the above technical solution, the core risk coefficient (frequency of abnormal behavior), application compliance score (installation and uninstallation dynamics) and location deviation (geo-fence rules) are independently calculated to achieve multi-dimensional quantification of risks and avoid misjudgment of single indicators; combined with differentiated weight distribution of different risk types (core / auxiliary / potential), the scenario adaptability of risk rating is improved; this application generates equipment risk rating through a comprehensive scoring mechanism, providing an objective basis for subsequent disposal and reducing the cost of manual intervention.
[0040] In a preferred embodiment of the present application, after triggering the regulatory label marking instruction based on the device risk rating information, the application further includes:
[0041] According to the equipment risk rating information, a corresponding disposal plan is matched from a preset regulatory policy library;
[0042] If the device risk rating exceeds a preset threshold, a hierarchical control instruction is triggered, which may include limiting device performance, disabling non-essential permissions, or isolating high-risk applications;
[0043] After the hierarchical control instructions are executed, the monitoring data collection instructions are re-triggered to verify the effectiveness of risk treatment and update the regulatory label status.
[0044] By adopting the above technical solutions, targeted management and control can be achieved by matching preset disposal plans according to risk ratings (such as limiting performance for core risks and isolating applications for auxiliary risks); through the "triggering disposal, verifying effectiveness and updating labels" process, a dynamic closed loop of risk management is formed to avoid the failure of static strategies; hierarchical control instructions (such as only limiting the performance of high-risk devices) reduce interference with normal devices and balance security and user experience.
[0045] In the second aspect, the invention objective of this application is achieved by adopting the following technical solutions:
[0046] Mobile device supervision and management system, the system includes a mobile device terminal and a system server;
[0047] The mobile device includes:
[0048] A location information collection module is used to collect device location information of mobile devices;
[0049] Application monitoring module, used to monitor the applications used by users and their running time, and generate application usage data;
[0050] Bluetooth status detection module, used to detect the Bluetooth status of the mobile device and record the Bluetooth activation status and continuous communication duration;
[0051] A data uploading module, configured to upload the device location information, the application usage data, and the Bluetooth communication data to the system server;
[0052] The system server is used to integrate and analyze the received device location information, application usage data and Bluetooth communication data to generate a supervision report, which includes real-time location trajectory, high-frequency application list and Bluetooth interaction record; based on preset graded warning rules, it identifies abnormal behavior in the supervision report and issues corresponding graded warnings.
[0053] In a third aspect, the invention objective of this application is achieved by adopting the following technical solutions:
[0054] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the mobile device supervision and management method are implemented.
[0055] Fourthly, the invention objectives of this application are achieved by adopting the following technical solutions:
[0056] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the mobile device supervision and management method.
[0057] In summary, this application includes at least one of the following beneficial technical effects:
[0058] 1. Based on preset graded warning rules, abnormal behaviors in supervision reports are identified and graded warnings are implemented, allowing the system to take appropriate measures based on the risk level. This application effectively improves the automation level of mobile device supervision, the depth of data analysis, and the efficiency of warning response. It is suitable for various application scenarios that require compliance supervision of mobile terminal behavior, such as enterprise security management, judicial supervision, and education management.
[0059] 2. Set different monitoring strategy weights based on different levels of device operating status information (core, auxiliary, and low-frequency), and dynamically adjust the supervision strategy to achieve intelligent hierarchical supervision of device behavior. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 This is a flow chart of a method for supervising and managing a mobile device in one embodiment of the present application;
[0061] Figure 2 This is another flow chart of a method for supervising and managing a mobile device in one embodiment of the present application;
[0062] Figure 3 It is a schematic diagram of a device in one embodiment of the present application. DETAILED DESCRIPTION
[0063] The present application is further described in detail below with reference to the accompanying drawings.
[0064] In one embodiment, if Figure 1 As shown, the present application discloses a method for supervising and managing a mobile device, which specifically includes the following steps:
[0065] S1: Collect the device location information of the mobile device, monitor the applications used by the user and their running time, and obtain application usage data.
[0066] In this embodiment, device location information refers to the geographic coordinates (latitude and longitude), positioning timestamp and positioning accuracy data of the mobile device obtained through GPS, base station positioning (LBS), Wi-Fi positioning and other technologies; application usage data includes application name, application package name, foreground running time, background startup times, screen lighting time and other records.
[0067] Specifically, the mobile terminal integrates the location service SDK, sets the positioning frequency (e.g., every 5 minutes) and positioning mode (e.g., high-precision / power-saving mode). The positioning data is desensitized (e.g., deblurring coordinates to several decimal places) and encrypted via HTTPS before being transmitted to the server. Application usage monitoring involves deploying an application monitoring module on the mobile terminal and periodically (e.g., every hour) pulling application usage records through the system API.
[0068] S2: Detect the Bluetooth status of the mobile device and record the Bluetooth activation status and continuous communication duration.
[0069] In this embodiment, the Bluetooth status includes Bluetooth on (paired / unpaired), off, connected device list, and communication active status. The continuous communication duration refers to the cumulative time from the establishment to the disconnection of the Bluetooth device connection.
[0070] Specifically, when Bluetooth is turned on, the turn-on timestamp is recorded and the list of paired devices (such as Bluetooth headsets and smart bracelets) is scanned. When the Bluetooth device is successfully connected, the timer is started to record the active communication time; if data transmission (such as file transfer or audio streaming) is detected, the continuous communication duration is updated.
[0071] S3: Upload device location information, application usage data, and Bluetooth communication data to the server of the supervision and management system for integrated analysis to generate a supervision report containing real-time location tracks, high-frequency application lists, and Bluetooth interaction records.
[0072] In this example, the monitoring report includes a structured data file containing real-time location traces, a list of frequently used applications, and Bluetooth interaction records. Integrated analysis correlates multi-source data and identifies unusual patterns (e.g., sudden changes in device location, application usage timeouts, etc.).
[0073] Specifically, the server analyzes real-time location trajectories, connecting location points into a trajectory map using a GIS (Geographic Information System) engine. This allows detection of unusual trajectory deviations (e.g., crossing 100 kilometers within an hour). It also analyzes a mobile device's frequently used application list, such as counting the top five applications by daily usage time and marking applications with excessive usage (e.g., gaming apps used for over three hours). It also queries mobile device Bluetooth interaction records to analyze Bluetooth device connection frequency and identify unusual behavior (e.g., frequent connections to unfamiliar devices during off-hours).
[0074] S4: Provide graded warnings for abnormal behaviors in supervision reports based on preset graded warning rules.
[0075] In this embodiment, the hierarchical warning rules are based on the severity of abnormal behavior, and are divided into warning levels (e.g., low risk, medium risk, high risk) and defined trigger conditions. Warning triggers can be notified to administrators or users via email, SMS, or system pop-up windows.
[0076] Specifically, the preset hierarchical warning rules are defined as follows:
[0077] Low risk: The app is used for more than 8 hours per day (triggering a warning).
[0078] Medium risk: The device location deviates by more than 5 kilometers in a single day (triggering an email notification to the administrator).
[0079] High risk: Bluetooth connection to an unknown device and continuous communication for more than 1 hour (triggering a real-time alarm and automatically restricting device permissions).
[0080] The server compares the monitoring report data with the rule base. For example, when it detects that a certain application has been used continuously for more than 8 hours, the system automatically generates a low-level warning information to remind users that there is a risk of using the application for too long. If the geographical location offset of the mobile device is detected to be more than 50,000 meters, the system generates a medium-level warning information to indicate that there may be abnormal location changes. When a high-risk warning is triggered, the server sends a control instruction to the mobile terminal (such as disabling the Bluetooth function) and remotely locks the device through an API call to the enterprise MDM (mobile device management) system.
[0081] Furthermore, a network status detection module is set up on the mobile device to monitor the network connection status in real time; when a network interruption is detected or the transmission delay exceeds a threshold, the local encrypted cache is started, and the device location information, application usage data and Bluetooth communication data to be uploaded are stored in the local storage area according to a preset data format; after the network recovery is detected, the data retransmission process is triggered, and the cached data is uploaded in the priority order of real-time location data, application usage records and Bluetooth communication records.
[0082] In one embodiment, if Figure 2 As shown, the mobile device supervision and management method further includes:
[0083] S10: Acquire monitoring data information identifying the operating status of the mobile device, and determine hierarchical device status information based on the monitoring data information. The hierarchical device status information includes core operating status information, auxiliary operating status information, and low-frequency operating status information.
[0084] In this embodiment, for some networked mobile devices, in order to protect the devices from malware attacks, the present application further provides a technical solution for status assessment and dynamic disposal of mobile devices, and provides a hierarchical supervision and management method for different types of mobile devices. While supervising non-compliance of employee mobile devices, it can also meet the high security requirements of internal supervision of IoT device protection in a high-security mobile office environment. It is suitable for application scenarios where a multinational financial institution requires employees to use mobile devices to process sensitive customer data (such as transaction confirmation and contract signing), and needs to meet the requirements of real-time compliance monitoring (such as preventing data leakage (such as photographing sensitive documents and connecting to unauthorized networks) and dynamic risk defense at the same time. It is suitable for application scenarios with a higher security level.
[0085] In this embodiment, monitoring data includes real-time operational metrics such as device hardware resource usage (CPU utilization, memory usage), system logs (application startup / shutdown records), and network traffic data. Hierarchical device status information includes core operational status, auxiliary operational status, and low-frequency operational status. Core operational status refers to key indicators of basic device functions (e.g., CPU utilization > 80% and low-memory alarms); auxiliary operational status refers to non-core indicators that affect the user experience (e.g., frequent background application startup and abnormal network traffic); and low-frequency operational status refers to when the device is idle or underloaded (e.g., the screen is off and no application activity occurs).
[0086] Specifically, step S10 includes:
[0087] S101: Obtain basic device information, including device model, system version, and hardware configuration parameters.
[0088] In this embodiment, the device model refers to the hardware model of the mobile device; the system version refers to the operating system version number; and the hardware configuration parameters refer to the CPU model, memory capacity, storage space, sensor type, etc.
[0089] S102: Acquire monitoring data information associated with basic device information, including device CPU occupancy, memory usage, network traffic data, and application startup logs.
[0090] In this embodiment, CPU occupancy refers to the percentage of device CPU resource usage (e.g., 85% indicates high load); memory usage refers to the real-time usage of the device's RAM (e.g., 4GB / 8GB); network traffic data refers to the device's network data transmission and reception volume (e.g., uplink / downlink speed, connection IP address); and application startup logs refer to application startup time, runtime, permission call records, etc.
[0091] S103: Generate a device operation feature model based on device basic information, monitoring data information and a preset abnormal behavior feature library.
[0092] In this embodiment, the abnormal behavior feature library contains a dataset of known normal and abnormal device behaviors (e.g., sudden increases in CPU usage, unauthorized application installations). The device operation feature model is a machine learning model trained based on basic device information and monitoring data, used to identify device status. This application uses a random forest classification algorithm to train a device operation feature model capable of identifying device operation status. After inputting training data (including multiple feature values and corresponding device status labels), the model automatically learns and establishes an association between features and device status, which is then used for automatic judgment of the device operation status.
[0093] Specifically, after data preprocessing of the acquired device basic information and monitoring data information, key features are extracted. The key features include static features and dynamic features. Static features refer to device model, system version, and hardware configuration; dynamic features refer to CPU occupancy fluctuation rate, application installation frequency, and suspicious port communication records.
[0094] S104: According to the device operation characteristic model, corresponding hierarchical device status information is matched from a preset hierarchical database.
[0095] In this embodiment, the preset hierarchical database is a preset device status classification rule base, which includes thresholds or feature matching rules for different states (core / auxiliary / low-frequency). The hierarchical device status information includes core operating state, auxiliary operating state, and low-frequency operating state.
[0096] Specifically, the trigger conditions for the core running state are: CPU usage > 90% for 5 seconds or memory usage > 90% for 10 seconds; the trigger conditions for the auxiliary running state are the number of application installations per day > 3 times or unknown applications are started in the background; the trigger conditions for the low-frequency running state are that the device is stationary and there is no application activity for more than 30 minutes.
[0097] S20: Triggering a supervision instruction based on the hierarchical device status information to obtain device feedback data, which includes core risk data indicating the frequency of abnormal device behavior, auxiliary risk data of application installation and uninstallation dynamics, and potential risk data of device geographic location offset.
[0098] In this embodiment, core risk data refers to abnormal behavior of the device's core functions (such as high-frequency abnormal process startup and abuse of sensitive permissions); auxiliary risk data refers to application installation / uninstallation dynamics (such as high-risk application installation and unofficial application sources); potential risk data refers to the device's geographic location offset (such as exceeding the preset geographic fence range).
[0099] Specifically, step S20 includes:
[0100] S201: Core operation status information, auxiliary operation status information, and low-frequency operation status information are associated with different monitoring strategy weights respectively.
[0101] In this embodiment, monitoring policy weights refer to the priority or resource allocation ratio of different status information when triggering monitoring instructions. The weighting rule is as follows: core status is associated with high weight (for example, CPU monitoring frequency is set to once per second), auxiliary status is associated with medium weight (for example, application installation monitoring frequency is set to once per minute), and low-frequency status is associated with low weight (for example, only recording device inactivity without active monitoring).
[0102] Specifically, the weight allocation model is trained through a state classification model (such as the random forest algorithm): the state characteristics of the device and the corresponding weight values are input as training samples, so that the model can automatically learn and establish the relationship between the state characteristics and the monitoring weights, thereby realizing dynamic adjustment of the device supervision strategy.
[0103] S202: Dynamically adjust the monitoring strategy weight according to the hierarchical device status information and trigger the hierarchical supervision instruction.
[0104] In this embodiment, hierarchical monitoring instructions are monitoring tasks dynamically generated based on the device status (such as high-frequency acquisition, regular acquisition, and silent monitoring). The mobile terminal obtains the device status in real time through the system API.
[0105] Specifically, the weight adjustment strategies include:
[0106] ① Core status trigger sub-policy: If the CPU usage is greater than 90%, the monitoring weight is increased to the highest level (for example, collecting the process list every 500ms);
[0107] ② Auxiliary state trigger sub-strategy: If a non-whitelisted application is detected, temporarily increase the monitoring frequency of application permission calls;
[0108] ③ Low-frequency state trigger sub-strategy: If the device remains stationary for more than 1 hour, reduce the monitoring frequency to once per hour.
[0109] For example, the instruction triggering situation is (taking the Android system as an example): deploying a dynamic monitoring policy adjustment mechanism in the Android system, automatically switching different monitoring modes according to the real-time operating status of the device (such as CPU usage, application installation behavior), thereby achieving an adaptive balance between resource utilization and supervision needs.
[0110] S203: Collect device operation logs, application permission call records and geo-fence data through hierarchical supervision instructions to generate device feedback data.
[0111] In this embodiment, the device operation log refers to the user's operation record on the device (such as the number of unlocks, application installation / uninstallation events); the application permission call record refers to the log of the application requesting sensitive permissions (such as camera and microphone calls); and the geo-fence data refers to the distance between the device and the preset safety area and the length of time it stays there.
[0112] Specifically, in the Android system, AccessibilityService monitors sensitive permission requests (requiring user authorization) and obtains permission call records. Geofence data is calculated by combining the mobile terminal's GPS and the connected base station's positioning to determine the distance to the fence: GPS positioning obtains the mobile device's geographic location, determines the latest geographic location, and then calculates the actual distance between this latest geographic location and the set geofence center point. It also calculates the time interval since the mobile device entered the geofence area, and records the actual distance and duration information in the geofence log for subsequent analysis.
[0113] S30: Obtain device risk rating information based on device feedback data.
[0114] In this embodiment, the risk rating information refers to the severity of core risks, auxiliary risks, and potential risks calculated by weight, and divided into "low risk", "medium risk" and "high risk" levels.
[0115] Specifically, step S30 includes:
[0116] S301: Calculate the core risk coefficient of the device based on the frequency of abnormal behaviors in the core risk data.
[0117] In this embodiment, the abnormal behavior frequency refers to the number of times the abnormal behavior occurs in a unit of time (such as the duration of the CPU usage > 90%).
[0118] Specifically, the original collected data is first normalized: for example, the original data is mapped to a unified dimension (such as percentage or times / hour). For example, the CPU usage is normalized to:
[0119] ,in, To normalize to CPU usage value; The current CPU usage value of the device; This is the reference value of the device's maximum CPU processing capability.
[0120] The risk factor is calculated as follows:
[0121] The core risk factor is calculated based on the preset weights and thresholds. The risk score calculation formula is:
[0122] in, 、 、 is the preset weight coefficient; memory is the memory usage; The number of times abnormal behavior occurs; The value range is 0-100.
[0123] S302: Generate an application compliance score based on the application installation and uninstallation dynamics in the auxiliary risk data and the application whitelist library.
[0124] In this embodiment, application installation and uninstallation dynamics refers to the user's behavior records of installing or uninstalling applications, focusing on non-whitelisted applications; the application whitelist library refers to a pre-defined list of trusted applications (such as enterprise-approved productivity tools).
[0125] Specifically, the proportion of whitelisted applications is calculated and combined with the weighted extreme of installation frequency to obtain the application compliance score: Application compliance score = (number of whitelisted applications / total number of applications) multiplied by 100. If no application is installed on the device, 0 points will be returned directly.
[0126] S303: Calculate the location deviation based on the geographic location offset distance in the potential risk data and the preset geographic fence rules.
[0127] In this embodiment, the geographic location offset distance refers to the straight-line distance between the current location of the device and the center point of the preset geographic fence; the geographic fence rule refers to the defined safety area range (such as a circular area with a radius of 50 meters).
[0128] Specifically, the Haversine formula is applied to calculate the offset distance. The offset distance is the spherical distance between two points. Spherical distance = average radius of the earth (unit: meter) × central angle; the position deviation is the percentage of the offset distance to the fence radius.
[0129] S304: Generate device risk rating information based on the core risk factor, application compliance score, and location deviation.
[0130] In this embodiment, the risk rating information is divided into "low risk", "medium risk" and "high risk" levels based on the comprehensive scoring results of the core risk coefficient, application compliance score and position deviation.
[0131] Specifically, we first define the weight of each indicator (e.g., core risk factor 60%, application compliance score 30%, position deviation 10%), and perform a weighted comprehensive score. The weighted comprehensive score formula is:
[0132] weighted_score = (core risk factor × 0.6) + (application compliance score × 0.3) + (position deviation × 0.1). Set the risk rating classification rules:
[0133] High risk: comprehensive score ≥80.
[0134] Medium risk: 50≤comprehensive score<80.
[0135] Low risk: composite score <50.
[0136] S40: Triggering a regulatory label marking instruction based on the device risk rating information.
[0137] In this embodiment, the regulatory tag refers to metadata that identifies the risk level of the device, which is used for subsequent handling policy matching (such as "limit performance when the risk is high"); specifically, the regulatory tag is generated based on the rating result, and the regulatory tag is written to the device's local database and synchronized to the server's regulatory database; after the high-risk tag is triggered, the server sends control instructions to the device, such as disabling non-essential permissions through the MDM protocol.
[0138] Furthermore, after step S40, the mobile device supervision and management method further includes:
[0139] S401: According to the equipment risk rating information, a corresponding disposal plan is matched from a preset supervision policy library.
[0140] In this embodiment, the regulatory policy library is a preset policy rule library that contains disposal strategies corresponding to different risk levels (such as limiting performance, disabling permissions, and isolating applications); the disposal plan is a standardized operating instruction for a specific risk level (such as high-risk devices need to "disable Bluetooth + limit CPU performance").
[0141] Specifically, the regulatory policy library contains a table of policy rules. For example, the low-risk solution involves logging only; the medium-risk solution involves disabling non-essential permissions (such as Bluetooth and NFC); and the high-risk solution involves limiting CPU performance (reducing the frequency by 20%) and isolating high-risk applications. The policy library is searched based on the device's risk rating (e.g., a comprehensive score of 80 or higher indicates high risk) to identify the corresponding solution.
[0142] S402: If the device risk rating information exceeds a preset threshold, a hierarchical control instruction is triggered, which includes limiting device performance, disabling non-essential permissions, or isolating high-risk applications.
[0143] In this embodiment, the hierarchical control instructions are control commands dynamically generated according to the risk level, which contain specific operation parameters. The instructions are issued through the mobile device management (MDM) protocol or the operating system API. After receiving the instructions, the mobile device calls the system API to perform the operation.
[0144] S403: After the hierarchical control instructions are executed, the monitoring data collection instructions are re-triggered to verify the effectiveness of risk treatment and update the supervision label status.
[0145] In this embodiment, the monitoring data collection instruction is to re-trigger the data collection process of S10-S40 to obtain the latest status data of the equipment; the label status update refers to switching the supervision label from "high risk" to "medium risk" or "released" according to the verification results.
[0146] Specifically, after issuing the hierarchical control instruction, wait for a preset time (such as 30 minutes), re-collect device data, and calculate the risk indicator change rate. The evaluation indicators of the risk indicator change rate include the CPU performance improvement rate and the permission abuse reduction rate. The original data before the device executes the hierarchical control instruction (including the CPU usage before control (before_CPU) and the number / frequency of permission abuse before control (before_permissions)) and the real-time data after the device executes the hierarchical control instruction (including the CPU usage after control (after_CPU) and the number of permission abuse after control (after_permissions)) are obtained. The calculation formula is:
[0147] CPU performance improvement rate = (before_CPU - after_CPU) / before_CPU × 100.
[0148] Permission abuse reduction rate = (before_permissions - after_permissions) / before_permissions × 100.
[0149] The standards for verifying the improvement effect are: CPU performance improvement must exceed 25%, and permission abuse reduction must exceed 35%. Only when the above two conditions are met, the improvement is verified to be successful, otherwise it is judged to be a failure.
[0150] Tag status updates include: if verification passes (e.g., the risk factor decreases by 50%), the tag status is updated to "Mitigated"; if not, the control level is upgraded (e.g., from "Limited Performance" to "Complete Device Lockdown"). This application implements an automated closed-loop risk management process through a "detection, control, verification, and update" process. Dynamically adjusting control intensity (e.g., from "Limited Performance" to "Complete Isolation") based on the real-time status of the device will improve supervision and management effectiveness.
[0151] It should be understood that the serial numbers of the steps in the above embodiments do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0152] In one embodiment, a mobile device supervision and management system is provided. The mobile device supervision and management system corresponds to the mobile device supervision and management method in the above embodiment.
[0153] The mobile device supervision and management system includes the mobile device terminal and the system server; the detailed description of each functional module is as follows:
[0154] Mobile devices include:
[0155] A location information collection module is used to collect device location information of mobile devices;
[0156] Application monitoring module, used to monitor the applications used by users and their running time, and generate application usage data;
[0157] Bluetooth status detection module, used to detect the Bluetooth status of the mobile device and record the Bluetooth activation status and continuous communication duration;
[0158] Data upload module, used to upload device location information, application usage data and Bluetooth communication data to the system server;
[0159] The system server is used to integrate and analyze the received device location information, application usage data and Bluetooth communication data to generate a supervision report, which includes real-time location tracks, high-frequency application lists and Bluetooth interaction records; based on preset graded warning rules, it identifies abnormal behaviors in the supervision report and issues corresponding graded warnings.
[0160] Optionally, the mobile device supervision and management system further includes:
[0161] A data acquisition module is used to obtain monitoring data information that identifies the operating status of the mobile device;
[0162] a state identification module, configured to determine hierarchical device state information based on the monitoring data information, wherein the hierarchical device state information includes core operation state information, auxiliary operation state information, and low-frequency operation state information;
[0163] An instruction triggering module, configured to trigger a supervision instruction based on the hierarchical device status information;
[0164] a feedback collection module, in response to the supervision instruction, collecting device feedback data, the device feedback data including core risk data indicating the frequency of abnormal device behavior, auxiliary risk data indicating application installation and uninstallation dynamics, and potential risk data indicating device geographic location offset;
[0165] a risk assessment module, connected to the feedback collection module, for generating device risk rating information based on the device feedback data;
[0166] A label management module is connected to the risk assessment module and is used to trigger a regulatory label marking instruction based on the device risk rating information.
[0167] For the specific limitations of the mobile device supervision and management system, please refer to the limitations of the mobile device supervision and management method above, which will not be repeated here; the various modules in the above-mentioned mobile device supervision and management system can be implemented in whole or in part through software, hardware and their combination; the above-mentioned modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of the above-mentioned modules.
[0168] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 3 As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store device location information, application usage data and hierarchical warning rules, etc. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a method for supervising and managing mobile devices is implemented.
[0169] In one embodiment, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the following steps are performed:
[0170] S1: Collect the device location information of the mobile device and monitor the applications used by the user and their running time to obtain application usage data;
[0171] S2: Detect the Bluetooth status of the mobile device and record the Bluetooth activation status and duration of continuous communication;
[0172] S3: Upload device location information, application usage data, and Bluetooth communication data to the server of the supervision and management system for integrated analysis to generate a supervision report containing real-time location tracks, a list of high-frequency applications, and Bluetooth interaction records;
[0173] S4: Provide graded warnings for abnormal behaviors in supervision reports based on preset graded warning rules.
[0174] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0175] S1: Collect the device location information of the mobile device and monitor the applications used by the user and their running time to obtain application usage data;
[0176] S2: Detect the Bluetooth status of the mobile device and record the Bluetooth activation status and duration of continuous communication;
[0177] S3: Upload device location information, application usage data, and Bluetooth communication data to the server of the supervision and management system for integrated analysis to generate a supervision report containing real-time location tracks, a list of high-frequency applications, and Bluetooth interaction records;
[0178] S4: Provide graded warnings for abnormal behaviors in supervision reports based on preset graded warning rules.
[0179] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0180] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0181] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, it should be understood by those skilled in the art that the technical solutions described in the aforementioned embodiments may still be modified, or some of the features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
Claims
1. A method for supervising and managing a mobile device, characterized in that: include: Collect device location information of mobile devices and monitor the applications used by users and their running time to obtain application usage data; Detect the Bluetooth status of mobile devices, record Bluetooth activation status and duration of continuous communication; Uploading the device location information, the application usage data, and the Bluetooth communication data to the server of the supervision and management system for integrated analysis to generate a supervision report containing real-time location tracks, a list of high-frequency applications, and Bluetooth interaction records; Provide graded warnings for abnormal behaviors in supervision reports based on preset graded warning rules; The method further comprises: Acquiring monitoring data information identifying the operating status of a mobile device, determining hierarchical device status information based on the monitoring data information, the hierarchical device status information including core operating status information, auxiliary operating status information, and low-frequency operating status information; triggering a supervision instruction based on the hierarchical device status information to obtain device feedback data, the device feedback data including core risk data indicating the frequency of abnormal device behavior, auxiliary risk data indicating application installation and uninstallation dynamics, and potential risk data regarding device geographic location deviation; Obtaining device risk rating information based on the device feedback data; triggering a regulatory label marking instruction based on the device risk rating information; The obtaining of device risk rating information according to the device feedback data specifically includes: Calculating a core risk coefficient of the device based on the frequency of abnormal behaviors in the core risk data; Generate an application compliance score based on the application installation and uninstallation dynamics in the auxiliary risk data and in combination with the application whitelist library; Based on the geographic location offset distance in the potential risk data and the preset geographic fence rules, the location deviation is calculated; based on the core risk factor, application compliance score and location deviation, the device risk rating information is comprehensively generated.
2. The mobile device supervision and management method according to claim 1, characterized in that: The method further comprises: Set up a network status detection module on the mobile device to monitor the network connection status in real time; When a network interruption or transmission delay exceeding a threshold is detected, the local encrypted cache is activated to store the device location information, application usage data, and Bluetooth communication data to be uploaded in a local storage area according to a preset data format; After detecting network recovery, the data retransmission process is triggered, and the cached data is uploaded in the order of priority of real-time location data, application usage records, and Bluetooth communication records.
3. The mobile device supervision and management method according to claim 1, characterized in that: The acquiring of monitoring data information identifying the operating status of the mobile device and determining the graded device status information based on the monitoring data information includes: Obtain basic device information, including device model, system version, and hardware configuration parameters; Obtain the monitoring data information associated with the basic information of the device, the monitoring data information including device CPU occupancy, memory usage, network traffic data and application startup log; Generate a device operation feature model based on the device basic information, the monitoring data information and a preset abnormal behavior feature library; According to the device operation characteristic model, corresponding hierarchical device status information is matched from a preset hierarchical database.
4. The mobile device supervision and management method according to claim 1, characterized in that: The triggering of a supervision instruction based on the hierarchical device status information to obtain device feedback data specifically includes: The core operation status information, auxiliary operation status information and low-frequency operation status information are respectively associated with different monitoring strategy weights; Dynamically adjust monitoring strategy weights based on the hierarchical device status information to trigger hierarchical supervision instructions; The hierarchical supervision instructions are used to collect device operation logs, application permission call records and geo-fence data to generate device feedback data.
5. The mobile device supervision and management method according to claim 1, characterized in that: After triggering a regulatory label marking instruction based on the device risk rating information, the method further includes: According to the equipment risk rating information, a corresponding disposal plan is matched from a preset regulatory policy library; If the device risk rating exceeds a preset threshold, a hierarchical control instruction is triggered, which may include limiting device performance, disabling non-essential permissions, or isolating high-risk applications; After the hierarchical control instructions are executed, the monitoring data collection instructions are re-triggered to verify the effectiveness of risk treatment and update the regulatory label status.
6. A mobile device supervision and management system, characterized in that: The system includes a mobile device and a system server; The mobile device includes: A location information collection module is used to collect device location information of mobile devices; Application monitoring module, used to monitor the applications used by users and their running time, and generate application usage data; A Bluetooth status detection module is used to detect the Bluetooth status of the mobile device and record the Bluetooth activation status and continuous communication duration; a data upload module is used to upload the device location information, the application usage data and the Bluetooth communication data to the system server; The system server is used to integrate and analyze the received device location information, application usage data, and Bluetooth communication data to generate a monitoring report, which includes real-time location tracks, a list of high-frequency applications, and Bluetooth interaction records; identify abnormal behaviors in the monitoring report based on preset graded warning rules and issue corresponding graded warnings; The mobile device supervision and management system is also used to perform the following method: Acquiring monitoring data information identifying the operating status of a mobile device, determining hierarchical device status information based on the monitoring data information, the hierarchical device status information including core operating status information, auxiliary operating status information, and low-frequency operating status information; triggering a supervision instruction based on the hierarchical device status information to obtain device feedback data, the device feedback data including core risk data indicating the frequency of abnormal device behavior, auxiliary risk data indicating application installation and uninstallation dynamics, and potential risk data regarding device geographic location deviation; Obtaining device risk rating information based on the device feedback data; triggering a regulatory label marking instruction based on the device risk rating information; The obtaining of device risk rating information according to the device feedback data specifically includes: Calculating a core risk coefficient of the device based on the frequency of abnormal behaviors in the core risk data; Generate an application compliance score based on the application installation and uninstallation dynamics in the auxiliary risk data and in combination with the application whitelist library; Based on the geographic location offset distance in the potential risk data and the preset geographic fence rules, the location deviation is calculated; based on the core risk factor, application compliance score and location deviation, the device risk rating information is comprehensively generated.
7. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the mobile device supervision and management method according to any one of claims 1 to 5 are implemented.
8. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the mobile device supervision and management method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Remote monitoring and management system for mobile equipment
CN118612261A