Implementation method for managing workload of mobile test terminal by using zero trust

Through the zero-trust management solution, the trust evaluation and data statistics of mobile test terminal devices are solved, and the problems of confusion in device management and difficult to monitor workload are achieved, and clear workload statistics and efficient terminal management are achieved.

CN120448261APending Publication Date: 2025-08-08UNIV OF SCI & TECH BEIJING
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510509378.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

Currently, there are problems such as confusing management of mobile test terminal equipment, unregulated use and frequency, uncountable workloads, and difficult to monitor the workload of test staff.

Method used

Using a zero-trust management solution, the mobile test terminal logs into the test software, uses a trusted gateway and an intelligent management platform to perform trust evaluation and data statistics, record the login time, logout time, access process and test duration, and display it in the workload visual interface.

Benefits of technology

It realizes clear statistics on the workload of test equipment and personnel, improves the ease of use of equipment and the efficiency of full life cycle management, supports intuitive performance evaluation and resource allocation, and improves terminal security and work efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120448261A_ABST
    Figure CN120448261A_ABST
Patent Text Reader

Abstract

The invention provides an implementation method for managing workload of a mobile test terminal by using zero trust, and relates to the technical field of network security. The method comprises the following steps: a mobile test terminal logs in to-be-tested software of test equipment through logging in a test account; sending a service test request of to-be-tested software to the trusted gateway, and sending the service test request to the trusted intelligent management platform by the trusted gateway; a trust evaluation engine of the trusted intelligent management platform performs trust evaluation on the data of the test equipment and the test account through the zero-trust management server to obtain an evaluation result; transmitting the evaluation result to an access control engine, sending an allowing instruction to a trusted gateway, and allowing the mobile test terminal to establish a connection with the service system; the data statistics and analysis engine records the login time, the exit time, the access process and the test duration; and transmitting the data to a workload visual interface for display, thereby completing the test. According to the invention, the working efficiency of the mobile terminal equipment can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method and system for implementing zero-trust management of mobile test terminal workloads. Background Art

[0002] The core concept of zero-trust networking is "never trust, always verify." Traditional network security architectures are based on network perimeter protection. When building a network security system, enterprises first divide the network into different security zones, such as the extranet, intranet, and DMZ. Firewalls, WAFs, and IPS network security defense devices are deployed at the network perimeter to provide layered protection, reshaping the enterprise's business security perimeter. Zero trust reevaluates and revisits traditional perimeter security architecture thinking and offers new recommendations for security architecture: By default, no person, device, system, or application inside or outside the enterprise network is trusted. Instead, the trust foundation for access control is rebuilt based on strict authentication and authorization. This authorization and trust are non-static, relying on authentication and access control capabilities typically provided by identity and access management systems. Modern identity management technology is the technical foundation of zero-trust security. Currently, the concept of zero trust is being applied to workload tracking of mobile terminal devices used in testing in the internet industry. This aims to address current issues such as the chaotic management of mobile testing terminals such as mobile phones, tablets, and POS terminals, the lack of unified records of device usage and frequency, the inability to measure device workloads, and the difficulty in monitoring tester workloads. Summary of the Invention

[0003] In order to solve the existing problems of the concept of zero trust in the workload tracking of mobile terminal devices used for testing in the Internet industry, and to solve the technical problems of the current chaotic management of mobile test terminal devices such as mobile phones, Pads and POS machines, the lack of unified records of the purpose and frequency of device use, the inability to count device workloads, and the difficulty in monitoring the workload of test staff, the embodiment of the present invention provides a method and system for using zero trust to manage the workload of mobile test terminals. The technical solution is as follows:

[0004] In one aspect, a method for implementing zero-trust management of mobile test terminal workloads is provided. The method is implemented by an implementation device for implementing zero-trust management of mobile test terminal workloads, and the method includes:

[0005] S1. The mobile test terminal logs in to the software to be tested on the test device through the test account. The probe software on the test device sends the service test request of the software to be tested to the trusted gateway. The trusted gateway sends the service test request to the trusted intelligent management platform.

[0006] S2. The trust assessment engine of the trusted intelligent management platform performs a trust assessment on the test device data and test account through the zero trust management server to obtain the assessment results. The assessment results are transmitted to the access control engine of the trusted intelligent management platform, which sends a permission instruction to the trusted gateway to allow the mobile test terminal to establish a connection with the business system.

[0007] S3. The data statistics and analysis engine of the trusted intelligent management platform records the login time, logout time, access process and test duration through the zero-trust management server; the login time, logout time, access process and test duration are transmitted to the workload visualization interface of the trusted intelligent management platform for display to complete the test.

[0008] Optionally, the mobile test terminal is an access subject, including: test equipment and test account information;

[0009] The probe software is a terminal software; the probe software is installed on a mobile phone or a Pad mobile terminal; the probe software includes an authentication initiation and network proxy function module and a self-protection module;

[0010] The trusted gateway is used to provide network policies for SSL certificate offloading and mobile test terminals;

[0011] The trusted intelligent management platform includes: a trust assessment engine, an access control engine, a data statistics and analysis engine, and a workload visualization interface;

[0012] The zero-trust management server is used to provide system management and certificate management functions of the zero-trust architecture;

[0013] Among them, the business system is used in the business testing process. The test traffic reaches the business system after passing through the zero-trust architecture, and the feedback is processed by the business system to complete the functional testing of the business system.

[0014] Optionally, the initiating authentication and network proxy function module is used to encrypt the service test request of the software to be tested and send it to the trusted gateway, and decrypt the request packet and response packet of the service test;

[0015] The self-protection module includes: virus detection and killing function, risk warning function and scanning function; the self-protection module is used to update the virus database from time to time, detect viruses and remove viruses.

[0016] Optionally, the trust assessment engine is used to perform risk analysis on specific network requests, perform trust assessment and value assessment on the device data and test account of the accessed object, and issue access policies through the access control engine.

[0017] Optionally, the access control engine is configured to receive the evaluation result of the trust evaluation engine and to interact with the trusted gateway by dynamically adjusting the access rights of the mobile test terminal;

[0018] The data statistics and analysis engine is used to record the access process, test duration and exit time of devices and personnel, and to statistically analyze the test duration of a single device and tester in a specified period;

[0019] The workload visualization interface is used to uniformly visualize the test behavior data generated by the data statistics and analysis engine, so that management personnel can adjust resources as needed.

[0020] On the other hand, a system for implementing the use of zero trust to manage mobile test terminal workloads is provided. The system is applied to the method for implementing the use of zero trust to manage mobile test terminal workloads. The system includes:

[0021] The mobile test terminal is used to log in to the software to be tested on the test device by logging in to the test account;

[0022] The probe software is used to send the service test request of the software to be tested to the trusted gateway according to the probe software on the test device;

[0023] The trusted gateway is used to send the service test request to the trusted intelligent management platform;

[0024] The trusted intelligent management platform is used to transmit the evaluation results to the access control engine of the trusted intelligent management platform, send an authorization instruction to the trusted gateway, and allow the mobile test terminal to establish a connection with the business system; transmit the login time, logout time, access process and test duration to the workload visualization interface of the trusted intelligent management platform for display, and complete the test;

[0025] The zero trust management server is used to record login time, logout time, access process and test duration through the zero trust management server;

[0026] The business system is used to transmit the evaluation results to the access control engine of the trusted intelligent management platform, send an authorization instruction to the trusted gateway, and allow the mobile test terminal to establish a connection with the business system.

[0027] Optionally, the mobile test terminal is an access subject, including: test equipment and test account information;

[0028] The probe software is a terminal software; the probe software is installed on a mobile phone or a Pad mobile terminal; the probe software includes an authentication initiation and network proxy function module and a self-protection module;

[0029] Wherein, the trusted gateway is used to provide SSL certificate offloading and mobile terminal network policy;

[0030] The trusted intelligent management platform includes: a trust assessment engine, an access control engine, a data statistics and analysis engine, and a workload visualization interface;

[0031] The zero-trust management server is used to provide system management and certificate management functions of the zero-trust architecture;

[0032] Among them, the business system is used in the business testing process. The test traffic reaches the business system after passing through the zero-trust architecture, and the feedback is processed by the business system to complete the functional testing of the business system.

[0033] Optionally, the initiating authentication and network proxy function module is used to encrypt the service test request of the software to be tested and send it to the trusted gateway, and decrypt the request packet and response packet of the service test;

[0034] The self-protection module includes: virus detection and killing function, risk warning function and scanning function; the self-protection module is used to update the virus database from time to time, detect viruses and remove viruses.

[0035] Optionally, the trust assessment engine is used to perform risk analysis on specific network requests, perform trust assessment and value assessment on the device data and test account of the accessed object, and issue access policies through the access control engine.

[0036] Optionally, the access control engine is configured to receive the evaluation result of the trust evaluation engine and to interact with the trusted gateway by dynamically adjusting the access rights of the mobile test terminal;

[0037] The data statistics and analysis engine is used to record the access process, test duration and exit time of devices and personnel, and to statistically analyze the test duration of a single device and tester in a specified period;

[0038] The workload visualization interface is used to uniformly visualize the test behavior data generated by the data statistics and analysis engine, so that management personnel can adjust resources as needed.

[0039] On the other hand, a device for implementing the use of zero trust to manage the workload of mobile test terminals is provided. The device for implementing the use of zero trust to manage the workload of mobile test terminals includes: a processor; a memory, wherein computer-readable instructions are stored on the memory, and when the computer-readable instructions are executed by the processor, any one of the above-mentioned methods for implementing the use of zero trust to manage the workload of mobile test terminals is calculated.

[0040] On the other hand, a computer-readable storage medium is provided, in which at least one instruction is stored. The at least one instruction is loaded and executed by a processor to implement any one of the above-mentioned methods for implementing zero-trust management of mobile test terminal workloads.

[0041] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:

[0042] In an embodiment of the present invention, the mobile test terminal first logs in to the software to be tested of the test device by logging in to the test account; according to the probe software on the test device, the business test request of the software to be tested is sent to the trusted gateway, and the trusted gateway sends the business test request to the trusted intelligent management platform; secondly, the trust assessment engine of the trusted intelligent management platform performs a trust assessment on the data and test account of the test device through the zero trust management server to obtain the assessment result; the assessment result is transmitted to the access control engine of the trusted intelligent management platform, and an permission instruction is sent to the trusted gateway to allow the mobile test terminal and the business system to establish a connection; finally, the data statistics and analysis engine of the trusted intelligent management platform records the login time, logout time, access process and test duration through the zero trust management server; the login time, logout time, access process and test duration are transmitted to the workload visualization interface of the trusted intelligent management platform for display to complete the test.

[0043] The embodiment of the present invention uses testers and mobile terminal devices as access subjects, and business services, interfaces, functions or business data as access objects, and performs access data and fine-grained identity authentication of the subject through a trusted intelligent management platform to count business test workloads; by adopting a zero-trust solution, each client and server establish an independent and dedicated encrypted business channel, so that a single business person and a single test device have a one-to-one correspondence in each time period, and the statistical relationship is clear; for workload statistics of test equipment, the usability of the test equipment can be improved, and the maximum use effect of the test equipment in the whole life cycle management process can be achieved; by using the embodiment of the present invention for workload statistics of testers, managers can intuitively quantify the work of testers based on the statistical data of the test work, and can associate performance mechanisms, or can assign work to specific testers based on the statistical data of the test work. The embodiment of the present invention can improve the work efficiency of mobile terminal devices, provide solutions for enterprises to save costs, track terminal device loads and improve terminal security, and refine business personnel management strategies. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0045] Figure 1 This is a structural diagram of a zero-trust solution application network architecture provided by an embodiment of the present invention;

[0046] Figure 2 This is a flow chart of a method for implementing zero-trust management of mobile test terminal workloads provided by an embodiment of the present invention;

[0047] Figure 3 This is a schematic diagram of a zero-trust management framework for mobile test terminals provided by an embodiment of the present invention;

[0048] Figure 4 This is a schematic diagram of a workload visualization interface data set provided by an embodiment of the present invention;

[0049] Figure 5 This is a flowchart provided by an embodiment of the present invention for visually displaying specific workloads after an access subject initiates access to a trusted intelligent management platform for data statistical analysis;

[0050] Figure 6 This is a block diagram of a system for implementing zero-trust management of mobile test terminal workloads, provided by an embodiment of the present invention;

[0051] Figure 7 This is a structural diagram of an implementation device for managing mobile test terminal workloads using zero trust, as provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0052] The technical solution of the present invention is described below in conjunction with the accompanying drawings.

[0053] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as an "exemplary" in the present invention should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner. Furthermore, in the embodiments of the present invention, "and / or" can mean both or either of the two.

[0054] In the embodiments of the present invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, when the distinction is not emphasized, the meanings they convey are the same. The terms "of," "corresponding," and "corresponding" may sometimes be used interchangeably. It should be noted that, when the distinction is not emphasized, the meanings they convey are the same.

[0055] In the embodiments of the present invention, sometimes a subscript such as W1 may be written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are the same.

[0056] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0057] The embodiment of the present invention provides a method for implementing the use of zero trust to manage the workload of mobile test terminals. The method can be implemented by an implementation device for implementing the use of zero trust to manage the workload of mobile test terminals. The implementation device for implementing the use of zero trust to manage the workload of mobile test terminals can be a terminal or a server. Figure 1 The zero trust solution shown in the figure is implemented using the network architecture; Figure 2 The flowchart of the implementation method of using zero trust to manage mobile test terminal workload is shown. The processing flow of this method may include the following steps:

[0058] S1. The mobile test terminal logs in to the software to be tested on the test device by logging in to the test account; the probe software on the test device sends the service test request of the software to be tested to the trusted gateway, and the trusted gateway sends the service test request to the trusted intelligent management platform.

[0059] Optionally, the mobile test terminal is the access subject, including: test equipment and test account information;

[0060] Among them, the mobile test terminal is the input unit of the business test link; among them, the test equipment is initially recorded and securely set by the equipment management department, and the designated software that can download the required test version is deployed, as well as the probe software to initiate authentication and self-protection.

[0061] Among them, the test account information is the login management test account information.

[0062] The probe software is terminal software; the probe software is installed on mobile phones and Pad mobile terminals; the probe software includes authentication initiation and network proxy function modules and self-protection modules;

[0063] Optionally, an authentication and network proxy function module is initiated to encrypt the service test request of the software to be tested and send it to the trusted gateway, and decrypt the request packet and response packet of the service test;

[0064] Among them, the request packet and response packet of the business test are decrypted, that is, certificate encryption and certificate decryption.

[0065] Among them, the self-protection module includes: virus detection and killing function, risk warning function and scanning function; the self-protection module is used to update the virus database from time to time, detect viruses and clear viruses.

[0066] Among them, the trusted gateway is used to provide SSL certificate offloading and network policies for mobile test terminals;

[0067] In a feasible implementation, after the mobile test terminal initiates a business test request, the trusted gateway sends the request content to the trusted intelligent management platform for authentication. If the authentication is successful, an access connection is established with the business system; if the authentication fails, the connection with the business system is blocked.

[0068] Among them, such as Figure 3 The figure shows a schematic diagram of a zero-trust management framework for mobile test terminals provided by an embodiment of the present invention; the zero-trust management framework for mobile test terminals includes: an access subject, a trusted intelligent management platform, and an access object; wherein the access subject is the test device and test account information; the access object can be one of an application, APP, interface, and business function.

[0069] Among them, the trusted intelligent management platform includes: trust assessment engine, access control engine, data statistics and analysis engine and workload visualization interface;

[0070] Optionally, a trust assessment engine is used to perform risk analysis on specific network requests, perform trust assessment and numerical assessment on the device data and test account of the accessed object, and issue access policies through the access control engine.

[0071] In one feasible implementation, the trust assessment scoring rule uses a risk-aware model based on a machine learning algorithm to comprehensively score the requested customer information, device information, and operational behavior. If the score reaches a preset safety threshold, access is permitted; otherwise, access is denied. In this embodiment of the present invention, all access requests are permitted only if they meet the safety threshold.

[0072] Optionally, an access control engine is configured to receive the evaluation result of the trust evaluation engine and to interact with the trusted gateway by dynamically adjusting the access rights of the mobile test terminal;

[0073] For example, if an illegal user uses a mobile test device, its access to the server will be dynamically restricted.

[0074] Among them, when the access control engine allows access, the trusted gateway allows access to the business system and establishes a connection.

[0075] The data statistics and analysis engine is used to record the access process, test duration, and exit time of devices and personnel, and to statistically analyze the test duration of a single device and tester in a specified period.

[0076] Among them, the workload visualization interface is used to uniformly visualize the test behavior data collected and analyzed by the data statistics and analysis engine, so that managers can adjust resources as needed.

[0077] Among them, the zero trust management server is used to provide system management and certificate management functions of the zero trust architecture;

[0078] Among them, the business system is used in the business testing process. The test traffic reaches the business system after passing through the zero-trust architecture, and the feedback is processed by the business system to complete the functional testing of the business system.

[0079] S2. The trust assessment engine of the trusted intelligent management platform conducts a trust assessment on the data and test account of the test device through the zero trust management server to obtain the assessment results; the assessment results are transmitted to the access control engine of the trusted intelligent management platform, and an authorization instruction is sent to the trusted gateway to allow the mobile test terminal and the business system to establish a connection.

[0080] S3. The data statistics and analysis engine of the trusted intelligent management platform records the login time, logout time, access process and test duration through the zero-trust management server; the login time, logout time, access process and test duration are transmitted to the workload visualization interface of the trusted intelligent management platform for display to complete the test.

[0081] In a feasible implementation, the data required in the mobile device business testing process and the load statistics process include: a test account information set and a workload visualization interface data set; wherein the test account information set includes: an account ID and the login authentication information corresponding to each ID; wherein the login authentication information includes: an initial password, a dynamic password token, and the fingerprint or iris of the corresponding tester; wherein, when logging in, one or more methods can be used for login authentication according to different scenarios.

[0082] Among them, the workload visualization interface data set is available through the trusted intelligent management platform, so managers can intuitively view the test records of all test equipment and testers, and can also query the test records of designated equipment and designated personnel in a targeted manner. Figure 4 Shown is a schematic diagram of a workload visualization interface data set provided by an embodiment of the present invention.

[0083] In a feasible implementation, Figure 5 The flowchart shown is provided in an embodiment of the present invention, in which an access subject initiates access to a trusted intelligent management platform and then performs data statistical analysis to visualize the specific workload. In this flowchart, a tester obtains his or her own test account information set through a management department. The test account is strongly associated with the tester, with one test account corresponding to one tester and one tester corresponding to multiple test accounts. The management department registers the test account, tester, and test equipment on the trusted intelligent management platform. The tester logs in to the software to be tested on the test equipment through the test account. The identity authentication request packet includes: the device data of the access subject and the test account, that is, the real-time data and identity authentication information of the probe software on the device. The device data includes the device's own protection results, device age, and detailed device storage data. When the authentication is passed, the access control engine in the trusted intelligent management platform issues an authorization instruction to the trusted gateway, allowing the mobile test terminal to establish a connection with the business system. When the tester actively clicks to exit on the software product or automatically exits due to a timeout, the connection is disconnected. The trusted intelligent management platform records the disconnection time in real time and retains the data of this connection. The data statistics and analysis engine supplements the test record entries of the device and the person.

[0084] In one feasible implementation, a bank or internet company's app testing department purchases several mobile terminals for testing, allowing testers to perform various functional and verification tests. However, the management of these terminals is often relatively simple. Using this application can more efficiently manage devices, maximize utilization, and reduce resource waste.

[0085] In an embodiment of the present invention, the mobile test terminal first logs in to the software to be tested of the test device by logging in to the test account; according to the probe software on the test device, the business test request of the software to be tested is sent to the trusted gateway, and the trusted gateway sends the business test request to the trusted intelligent management platform; secondly, the trust assessment engine of the trusted intelligent management platform performs a trust assessment on the data and test account of the test device through the zero trust management server to obtain the assessment result; the assessment result is transmitted to the access control engine of the trusted intelligent management platform, and an permission instruction is sent to the trusted gateway to allow the mobile test terminal and the business system to establish a connection; finally, the data statistics and analysis engine of the trusted intelligent management platform records the login time, logout time, access process and test duration through the zero trust management server; the login time, logout time, access process and test duration are transmitted to the workload visualization interface of the trusted intelligent management platform for display to complete the test.

[0086] The embodiment of the present invention uses testers and mobile terminal devices as access subjects, and business services, interfaces, functions or business data as access objects, and performs access data and fine-grained identity authentication of the subject through a trusted intelligent management platform to count business test workloads; by adopting a zero-trust solution, each client and server establish an independent and dedicated encrypted business channel, so that a single business person and a single test device have a one-to-one correspondence in each time period, and the statistical relationship is clear; for workload statistics of test equipment, the usability of the test equipment can be improved, and the maximum use effect of the test equipment in the whole life cycle management process can be achieved; by using the embodiment of the present invention for workload statistics of testers, managers can intuitively quantify the work of testers based on the statistical data of the test work, and can associate performance mechanisms, or can assign work to specific testers based on the statistical data of the test work. The embodiment of the present invention can improve the work efficiency of mobile terminal devices, provide solutions for enterprises to save costs, track terminal device loads and improve terminal security, and refine business personnel management strategies.

[0087] Figure 6 This is a block diagram of a system for implementing a zero-trust management system for mobile test terminal workloads according to an exemplary embodiment. The system is used to implement a method for implementing a zero-trust management system for mobile test terminal workloads. Figure 6 The system includes a mobile test terminal 610, probe software 620, a trusted gateway 630, a trusted intelligent management platform 640, a zero-trust management server 650, and a business system 660. Among them:

[0088] The mobile test terminal 610 is used to log in to the software to be tested on the test device by logging in to the test account;

[0089] The probe software 620 is used to send the service test request of the software to be tested to the trusted gateway according to the probe software on the test device;

[0090] The trusted gateway 630 is used to send the service test request to the trusted intelligent management platform;

[0091] The trusted intelligent management platform 640 is used to transmit the evaluation results to the access control engine of the trusted intelligent management platform, send an authorization instruction to the trusted gateway, and allow the mobile test terminal to establish a connection with the business system; transmit the login time, logout time, access process and test duration to the workload visualization interface of the trusted intelligent management platform for display, and complete the test;

[0092] The zero trust management server 650 is used to record login time, logout time, access process and test duration through the zero trust management server;

[0093] The business system 660 is used to transmit the evaluation results to the access control engine of the trusted intelligent management platform, and send an authorization instruction to the trusted gateway to allow the mobile test terminal to establish a connection with the business system.

[0094] Optionally, the mobile test terminal is an access subject, including: test equipment and test account information;

[0095] The probe software is a terminal software; the probe software is installed on a mobile phone or a Pad mobile terminal; the probe software includes an authentication initiation and network proxy function module and a self-protection module;

[0096] Wherein, the trusted gateway is used to provide SSL certificate offloading and mobile terminal network policy;

[0097] The trusted intelligent management platform includes: a trust assessment engine, an access control engine, a data statistics and analysis engine, and a workload visualization interface;

[0098] The zero-trust management server is used to provide system management and certificate management functions of the zero-trust architecture;

[0099] Among them, the business system is used in the business testing process. The test traffic reaches the business system after passing through the zero-trust architecture, and the feedback is processed by the business system to complete the functional testing of the business system.

[0100] Optionally, the initiating authentication and network proxy function module is used to encrypt the service test request of the software to be tested and send it to the trusted gateway, and decrypt the request packet and response packet of the service test;

[0101] The self-protection module includes: virus detection and killing function, risk warning function and scanning function; the self-protection module is used to update the virus database from time to time, detect viruses and remove viruses.

[0102] Optionally, the trust assessment engine is used to perform risk analysis on specific network requests, perform trust assessment and value assessment on the device data and test account of the accessed object, and issue access policies through the access control engine.

[0103] Optionally, the access control engine is configured to receive the evaluation result of the trust evaluation engine and to interact with the trusted gateway by dynamically adjusting the access rights of the mobile test terminal;

[0104] The data statistics and analysis engine is used to record the access process, test duration and exit time of devices and personnel, and to statistically analyze the test duration of a single device and tester in a specified period;

[0105] The workload visualization interface is used to uniformly visualize the test behavior data generated by the data statistics and analysis engine, so that management personnel can adjust resources as needed.

[0106] In an embodiment of the present invention, the mobile test terminal first logs in to the software to be tested of the test device by logging in to the test account; according to the probe software on the test device, the business test request of the software to be tested is sent to the trusted gateway, and the trusted gateway sends the business test request to the trusted intelligent management platform; secondly, the trust assessment engine of the trusted intelligent management platform performs a trust assessment on the data and test account of the test device through the zero trust management server to obtain the assessment result; the assessment result is transmitted to the access control engine of the trusted intelligent management platform, and an permission instruction is sent to the trusted gateway to allow the mobile test terminal and the business system to establish a connection; finally, the data statistics and analysis engine of the trusted intelligent management platform records the login time, logout time, access process and test duration through the zero trust management server; the login time, logout time, access process and test duration are transmitted to the workload visualization interface of the trusted intelligent management platform for display to complete the test.

[0107] The embodiment of the present invention uses testers and mobile terminal devices as access subjects, and business services, interfaces, functions or business data as access objects, and performs access data and fine-grained identity authentication of the subject through a trusted intelligent management platform to count business test workloads; by adopting a zero-trust solution, each client and server establish an independent and dedicated encrypted business channel, so that a single business person and a single test device have a one-to-one correspondence in each time period, and the statistical relationship is clear; for workload statistics of test equipment, the usability of the test equipment can be improved, and the maximum use effect of the test equipment in the whole life cycle management process can be achieved; by using the embodiment of the present invention for workload statistics of testers, managers can intuitively quantify the work of testers based on the statistical data of the test work, and can associate performance mechanisms, or can assign work to specific testers based on the statistical data of the test work. The embodiment of the present invention can improve the work efficiency of mobile terminal devices, provide solutions for enterprises to save costs, track terminal device loads and improve terminal security, and refine business personnel management strategies.

[0108] Figure 7 This is a schematic diagram of a device for implementing a zero-trust management mobile test terminal workload according to an embodiment of the present invention. Figure 7 As shown, the implementation equipment for using zero trust to manage mobile test terminal workloads can include the above Figure 6 The system for implementing the management of mobile test terminal workload using zero trust is shown. Optionally, the device 710 for implementing the management of mobile test terminal workload using zero trust may include a first processor 2001.

[0109] Optionally, the implementation device 710 for managing mobile test terminal workload using zero trust may also include a memory 2002 and a transceiver 2003 .

[0110] The first processor 2001, the memory 2002 and the transceiver 2003 may be connected via a communication bus.

[0111] The following combination Figure 7 The following describes in detail the components of the device 710 for implementing zero-trust management of mobile test terminal workloads:

[0112] The first processor 2001 is the control center of the device 710 for implementing zero-trust management of mobile test terminal workloads. It can be a single processor or a collective term for multiple processing elements. For example, the first processor 2001 can be one or more central processing units (CPUs), application-specific integrated circuits (ASICs), or one or more integrated circuits configured to implement embodiments of the present invention, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0113] Optionally, the first processor 2001 can execute various functions of the implementation device 710 for managing the workload of the mobile test terminal using zero trust by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.

[0114] In a specific implementation, as an embodiment, the first processor 2001 may include one or more CPUs, such as Figure 7 CPU0 and CPU1 are shown in FIG.

[0115] In a specific implementation, as an embodiment, the implementation device 710 for managing the workload of a mobile test terminal using zero trust may also include multiple processors, such as Figure 7 1 and 2. The first processor 2001 and the second processor 2004 are shown in FIG. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0116] The memory 2002 is used to store the software program for executing the solution of the present invention, and is controlled by the first processor 2001 for execution. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0117] Optionally, the memory 2002 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2002 may be integrated with the first processor 2001 or exist independently, and through the interface circuit ( Figure 7 (not shown) is coupled to the first processor 2001, which is not specifically limited in this embodiment of the present invention.

[0118] The transceiver 2003 is used to communicate with a network device or a terminal device.

[0119] Optionally, the transceiver 2003 may include a receiver and a transmitter ( Figure 7 The receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.

[0120] Optionally, the transceiver 2003 may be integrated with the first processor 2001 or may exist independently, and the interface circuit of the implementation device 710 ( Figure 7 (not shown) is coupled to the first processor 2001, which is not specifically limited in this embodiment of the present invention.

[0121] It should be noted that Figure 7 The structure of the implementation device 710 for managing mobile test terminal workloads using zero trust shown in the figure does not constitute a limitation on the router. The actual knowledge structure identification device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0122] In addition, the technical effects of the device 710 for implementing the use of zero trust to manage the workload of mobile test terminals can refer to the technical effects of the method for implementing the use of zero trust to manage the workload of mobile test terminals described in the above method embodiment, and will not be repeated here.

[0123] It should be understood that the first processor 2001 in the embodiment of the present invention may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc.

[0124] It should also be understood that the memory in the embodiments of the present invention may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory may be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0125] The above embodiments can be implemented in whole or in part via software, hardware (e.g., circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product comprises one or more computer instructions or computer programs. When loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are fully or partially performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable system. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired means (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0126] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0127] In this disclosure, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0128] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0129] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0130] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices, systems and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0131] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, systems, and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of the system or unit, which can be electrical, mechanical or other forms.

[0132] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0133] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0134] If the functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or the portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage media include various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical disks.

[0135] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A method for implementing zero-trust management of mobile test terminal workloads, characterized in that: The method for implementing the zero-trust management of mobile test terminal workloads is implemented by the zero-trust solution application architecture for mobile test terminal management; The architecture includes: a mobile test terminal, probe software, a trusted gateway, a trusted intelligent management platform, a zero-trust management server, and a business system; the method includes: S1. The mobile test terminal logs in to the software to be tested on the test device through the test account. The probe software on the test device sends the service test request of the software to be tested to the trusted gateway. The trusted gateway sends the service test request to the trusted intelligent management platform. S2. The trust assessment engine of the trusted intelligent management platform performs a trust assessment on the test device data and test account through the zero trust management server to obtain the assessment results. The assessment results are transmitted to the access control engine of the trusted intelligent management platform, and a permission instruction is sent to the trusted gateway to allow the mobile test terminal to establish a connection with the business system. S3. The data statistics and analysis engine of the trusted intelligent management platform records the login time, logout time, access process and test duration through the zero trust management server; the login time, logout time, access process and test duration are transmitted to the workload visualization interface of the trusted intelligent management platform for display to complete the test.

2. The method for implementing zero-trust management of mobile test terminal workload according to claim 1, characterized in that: The mobile test terminal is the access subject, including: test equipment and test account information; The probe software is a terminal software; the probe software is installed on mobile phones and Pad mobile terminals; the probe software includes an authentication and network proxy function module and a self-protection module; The trusted gateway is used to provide network policies for SSL certificate offloading and mobile test terminals; The trusted intelligent management platform includes: a trust assessment engine, an access control engine, a data statistics and analysis engine, and a workload visualization interface; The zero-trust management server is used to provide system management and certificate management functions of the zero-trust architecture; Among them, the business system is used in the business testing process. The test traffic reaches the business system after passing through the zero-trust architecture, and the feedback is processed by the business system to complete the functional testing of the business system.

3. The method for implementing zero-trust management of mobile test terminal workload according to claim 2, characterized in that: The initiating authentication and network proxy function module is used to encrypt the service test request of the software to be tested and send it to the trusted gateway, and decrypt the request packet and response packet of the service test; The self-protection module includes: virus detection and killing function, risk warning function and scanning function; the self-protection module is used to update the virus database from time to time, detect viruses and remove viruses.

4. The method for implementing zero-trust management of mobile test terminal workload according to claim 2, characterized in that: The trust assessment engine is used to perform risk analysis on specific network requests, perform trust assessment and value assessment on the device data and test account of the accessed object, and issue access policies through the access control engine.

5. The method for implementing zero-trust management of mobile test terminal workload according to claim 2, characterized in that: The access control engine is used to receive the evaluation results of the trust evaluation engine and dynamically adjust the access rights of the mobile test terminal to work in conjunction with the trusted gateway; The data statistics and analysis engine is used to record the access process, test duration and exit time of devices and personnel, and to statistically analyze the test duration of a single device and tester in a specified period; The workload visualization interface is used to uniformly visualize the test behavior data generated by the data statistics and analysis engine, so that management personnel can adjust resources as needed.

6. A system for implementing zero-trust management of mobile test terminal workloads, wherein the system is used to implement the method for implementing zero-trust management of mobile test terminal workloads as described in any one of claims 1 to 5, characterized in that: The system comprises: The mobile test terminal is used to log in to the software to be tested on the test device by logging in to the test account; The probe software is used to send the service test request of the software to be tested to the trusted gateway according to the probe software on the test device; The trusted gateway is used to send the service test request to the trusted intelligent management platform; The trusted intelligent management platform is used to transmit the evaluation results to the access control engine of the trusted intelligent management platform, send an authorization instruction to the trusted gateway, and allow the mobile test terminal to establish a connection with the business system; transmit the login time, logout time, access process and test duration to the workload visualization interface of the trusted intelligent management platform for display, and complete the test; The zero trust management server is used to record login time, logout time, access process and test duration through the zero trust management server; The business system is used to transmit the evaluation results to the access control engine of the trusted intelligent management platform, send an authorization instruction to the trusted gateway, and allow the mobile test terminal to establish a connection with the business system.

7. The system for implementing zero-trust management of mobile test terminal workload according to claim 6, characterized in that: The mobile test terminal is the access subject, including: test equipment and test account information; The probe software is a terminal software; the probe software is installed on mobile phones and Pad mobile terminals; the probe software includes an authentication and network proxy function module and a self-protection module; Wherein, the trusted gateway is used to provide SSL certificate offloading and mobile terminal network policy; The trusted intelligent management platform includes: a trust assessment engine, an access control engine, a data statistics and analysis engine, and a workload visualization interface; The zero-trust management server is used to provide system management and certificate management functions of the zero-trust architecture; Among them, the business system is used in the business testing process. The test traffic reaches the business system after passing through the zero-trust architecture, and the feedback is processed by the business system to complete the functional testing of the business system.

8. The method for implementing zero-trust management of mobile test terminal workload according to claim 7, characterized in that: The initiating authentication and network proxy function module is used to encrypt the service test request of the software to be tested and send it to the trusted gateway, and decrypt the request packet and response packet of the service test; The self-protection module includes: virus detection and killing function, risk warning function and scanning function; the self-protection module is used to update the virus database from time to time, detect viruses and remove viruses.

9. A device for implementing zero-trust management of mobile test terminal workloads, characterized in that: The implementation equipment for using zero trust to manage mobile test terminal workloads includes: processor; A memory having computer-readable instructions stored thereon, wherein when the computer-readable instructions are executed by the processor, the method according to any one of claims 1 to 5 is calculated.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program code, which can be called by a processor to execute the method according to any one of claims 1 to 5.