Equipment management method and system

By receiving management task requests and using the configuration information of the target external device for data interaction, the problem of needing to develop docking applications when accessing devices in the existing technology is solved, and the convenience and scalability of device management are achieved.

CN120602323APending Publication Date: 2025-09-05SANGFOR TECH INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510786798.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In the existing technology, each time a new external device is connected, a new docking application needs to be developed and configured, resulting in weak scalability and low convenience of device access.

Method used

By receiving management task requests, using the device configuration information of the target external device for data interaction, obtaining the execution results of the device management task and feeding them back to the business end, it avoids configuring specific docking applications for each external device.

Benefits of technology

It realizes unified scheduling and management of multiple external devices, improving the convenience and scalability of device access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602323A_ABST
    Figure CN120602323A_ABST
Patent Text Reader

Abstract

The invention provides a device management method and system, and the method comprises the steps: receiving a management task request for executing a device management task from a business end, the management task request carrying a target device identifier of a target external device, and the target external device being any one of a plurality of external devices; performing data interaction with the target external device according to device configuration information of the target external device to obtain an execution result of the device management task, the device configuration information of the target external device being obtained based on the target device identifier; and feeding back an execution result of the equipment management task to the service end. Based on the scheme, the service end can uniformly schedule and manage a plurality of external devices by initiating the management task request, and does not need to configure corresponding docking applications for the external devices in advance, so that the convenience and expandability of accessing the external devices to the service end are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of device management, and in particular to a device management method and system. Background Art

[0002] With the popularization of big data integrated application services, enterprises often connect a large number of devices to the same business system, which centrally dispatches and manages various external devices.

[0003] In related technologies, when an external device is connected to a business system, because there are differences between the external device and the business system in terms of interface calls, processing logic, data formats, etc., it is necessary to develop a specific docking application for the external device and configure it on the external device so that the external device and the business system can adapt to each other in the above aspects.

[0004] Obviously, in the above access solution, each time a new external device is connected, a new docking application needs to be developed and configured. Therefore, this access solution has the problems of weak scalability and low convenience in accessing external devices. Summary of the Invention

[0005] In view of this, the present application provides a device management method and system to provide a device management solution with greater scalability and higher convenience.

[0006] To achieve the above objectives, this application provides the following technical solutions:

[0007] A first aspect of the present application provides a device management method, comprising:

[0008] receiving a management task request for executing a device management task from a service end, wherein the management task request carries a target device identifier of a target external device, wherein the target external device is any device among a plurality of external devices;

[0009] performing data interaction with the target external device according to the device configuration information of the target external device to obtain an execution result of the device management task, wherein the device configuration information of the target external device is obtained based on the target device identifier;

[0010] Feedback the execution result of the device management task to the service end.

[0011] Optionally, a method for obtaining the device configuration information of the target external device includes at least one of the following:

[0012] According to the target device identifier, obtaining the device configuration information carried in the management task request, and registering the obtained device configuration information in the storage module;

[0013] According to the target device identifier, the device configuration information of the target external device that is pre-registered is read from the storage module.

[0014] Optionally, also include:

[0015] In response to the management task request, generating a task identifier corresponding to the device management task;

[0016] Feedback of the execution result of the device management task to the service end includes:

[0017] According to the task identifier, the execution result of the device management task is fed back to the service end.

[0018] Optionally, the performing data interaction with the target external device according to the device configuration information of the target external device to obtain the execution result of the device management task includes:

[0019] Sending a data pull instruction to the target external device according to the device configuration information of the target external device;

[0020] Target data fed back by the target external device in response to the data pull instruction is received as an execution result of the device management task.

[0021] Optionally, the target data includes:

[0022] target log data generated by the operation of the target external device;

[0023] Alternatively, the target asset data of the target external device, wherein the target asset data represents device assets belonging to the target external device.

[0024] Optionally, also include:

[0025] The target data is stored in a storage module:

[0026] The step of performing data interaction with the target external device according to the device configuration information of the target external device to obtain the execution result of the device management task includes:

[0027] In a case where the management task request does not match the data stored in the storage module, performing data interaction with the target external device according to the device configuration information of the target external device to obtain an execution result of the device management task;

[0028] The method further comprises:

[0029] In a case where the management task request matches the data stored in the storage module, the data matching the management task request is obtained from the storage module as the execution result of the device management task.

[0030] Optionally, the performing data interaction with the target external device according to the device configuration information of the target external device to obtain the execution result of the device management task includes:

[0031] Sending a linkage instruction to the target external device according to the device configuration information of the target external device, wherein the linkage instruction is used to trigger the target external device to perform a linkage operation according to the linkage parameters;

[0032] The linkage operation result fed back by the target external device is received as the execution result of the device management task.

[0033] Optionally, also include:

[0034] detecting a linkage state of the target external device, wherein the linkage state indicates whether the target external device is capable of processing the linkage instruction;

[0035] When the linkage state of the target external device is normal, executing the step of sending the linkage instruction to the target external device;

[0036] When the linkage state of the target external device is abnormal, a linkage abnormality prompt is fed back to the service end.

[0037] Optionally, the linkage parameters are obtained in the following manner:

[0038] Extracting the linkage parameters carried in the management task request;

[0039] Alternatively, the linkage parameter corresponding to the target device identifier is read from a storage module.

[0040] A second aspect of the present application provides a device management system, comprising:

[0041] An interface module is configured to receive a management task request for executing a device management task from a service end, wherein the management task request carries a target device identifier of a target external device, and the target external device is any device among a plurality of external devices;

[0042] Task modules for:

[0043] performing data interaction with the target external device according to the device configuration information of the target external device to obtain an execution result of the device management task, wherein the device configuration information of the target external device is obtained based on the target device identifier;

[0044] Feedback the execution result of the device management task to the service end.

[0045] The beneficial effect of this solution is that when the business end needs to perform a device management task for a target external device, this solution can respond to the management task request of the business end, and perform data exchange with the target external device based on the device configuration information of the target external device. Through this data interaction, the corresponding device management task is completed and the execution result of the task is obtained. Therefore, this solution does not need to configure corresponding docking applications for multiple external devices, and can support the business end to uniformly schedule and manage multiple external devices by initiating management task requests, thereby improving the convenience and scalability of connecting external devices to the business end. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.

[0047] Figure 1 This is a flow chart of a device management method disclosed in an embodiment of the present application;

[0048] Figure 2 A schematic diagram of the structure of a device management system disclosed in an embodiment of the present application;

[0049] Figure 3 A data interaction diagram of a device management method disclosed in an embodiment of the present application. DETAILED DESCRIPTION

[0050] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0051] In this application, the terms "comprises," "comprising," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0052] Furthermore, in this document, relational terms such as first and second, etc. are used merely to distinguish one entity or operation from another entity or operation, but do not necessarily require or imply any actual relationship or order between these entities or operations.

[0053] To facilitate understanding of the technical solution of this application, some terms that may be involved in this application are first explained.

[0054] A Security Operations Platform (SOP) is an integrated technology framework designed to help organizations monitor, detect, and respond to cybersecurity threats. It integrates various security tools and data sources to provide real-time security situational awareness and incident response capabilities. This platform typically includes security information and event management (SIEM), threat intelligence, automated response, and analytics capabilities, helping security teams improve efficiency, quickly identify and respond to potential security incidents, and ultimately protect an organization's digital assets and information security.

[0055] The Security Detection Platform is an integrated system for identifying, assessing, and managing security risks within information systems. It leverages automated tools and technologies to conduct real-time monitoring and vulnerability scanning of networks, applications, and devices, ensuring compliance with security standards and policies. The platform generates security reports and provides risk analysis, helping enterprises promptly identify and remediate security risks and enhance overall security protection capabilities. Through centralized management and intelligent analysis, the Security Detection Platform provides organizations with effective security assurance, mitigating the risk of potential cyberattacks and data breaches.

[0056] The Extended Detection and Response (XDR) platform integrates SIEM log access, a security detection engine, a security operations module, and coordinated response. It generates security alerts based on secondary analysis of access logs. Based on the security capabilities of reported security devices, it further identifies potential threats and collaborates with response devices to complete the detection and response loop. This brings semi-automated operational capabilities to network security within the covered environment, saving manpower while improving the quality of network security. XDR is generally considered a mainstream product implementation of security operations platforms and security detection platforms.

[0057] An Application Programming Interface (API) is a set of predefined functions that allows applications and developers to access a set of routines based on a piece of software or hardware without having to access the source code or understand the details of the internal workings.

[0058] Security Information and Event Management (SIEM), also known as data governance, is used to access various external raw logs and output logs in a unified standard format defined within the platform. Organizations with network security requirements typically purchase security devices from multiple vendors and categories, making it difficult for security operations personnel to frequently access each device to view the monitored security logs and analyze the security incidents they detect. SIEM relies on accessing logs from various devices onto the same platform to build a centralized operating environment for customers, saving manpower and improving network security operation efficiency.

[0059] A Security Operations Center (SOC) is a department dedicated to enterprise information security. Its primary responsibility is to monitor, detect, and respond to security incidents within enterprise networks and systems. An SOC is typically comprised of a team of professional security analysts and engineers who use a variety of security tools and technologies to protect an enterprise's information assets, including real-time monitoring of network traffic, analysis of security logs, and detection of malware and cyberattacks. SIEMs tend to be technical solutions for data collection, analysis, and storage of security data from diverse sources, while SOCs tend to be centralized teams and facilities for monitoring, detecting, and responding to security incidents. As a tool for data collection and analysis, SIEMs provide the SOC with the necessary information support, while the SOC uses this information for real-time monitoring and response. The effective combination of the two can significantly enhance an organization's security capabilities.

[0060] Attack Surface Management (ASM) aims to identify, assess, and reduce an organization's potential attack surface. The attack surface refers to all possible entry points that attackers could exploit, including networks, applications, devices, and users. By continuously monitoring and analyzing these entry points, ASM helps enterprises identify security vulnerabilities, misconfigurations, and unauthorized assets, thereby strengthening their overall security posture.

[0061] A Web Application Firewall (WAF) is a security tool specifically designed to protect web applications. It monitors and filters HTTP traffic to prevent various network attacks, such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF). A WAF is an integral part of modern web application security architecture, effectively preventing various network attacks and safeguarding user data and corporate assets.

[0062] Software as a Service (SAAS) is a model for delivering software applications over the internet. Users do not need to install and maintain the software locally, but instead access and use these applications over the internet. SAAS is typically hosted by a third-party service provider, and users subscribe and pay for use on demand. This model reduces enterprise IT costs, simplifies software management and updates, and offers greater flexibility and scalability.

[0063] Security Orchestration, Automation and Response (SOAR) is a key concept in cybersecurity, standing for Security Orchestration, Automation and Response. SOAR's primary purpose is to improve security team efficiency and responsiveness by integrating and automating security tools and processes. SOAR platforms typically combine multiple security technologies, such as SIEM (Security Information and Event Management), firewalls, and intrusion detection systems, to centrally manage security incidents.

[0064] A pod is the smallest deployable unit in Kubernetes, representing a collection of one or more containers that share storage, networking, and a common runtime environment. Containers within a pod are typically closely related and work together, sharing the same IP address and port. A pod can be considered a logical host, responsible for managing the container lifecycle, scheduling, and scaling. Kubernetes uses pods to orchestrate and manage containers, ensuring high availability and scalability of applications.

[0065] In service authentication, a token is a digital credential used for identity verification and authorization. It's typically generated by an authentication server and contains the user's identity and permissions. Tokens can take the form of JWT (JSON Web Token) or OAuth tokens, and are typically issued after a user logs in. Users carry this token in subsequent requests to verify their identity and gain access rights. Tokens typically have a limited validity period, requiring reauthentication upon expiration, enhancing system security and flexibility.

[0066] HyperText Transfer Protocol (HTTP) is a protocol used to transfer data over the Internet. The HTTP protocol defines the format of requests and responses, allowing users to access web pages and other resources through URLs (Uniform Resource Locators).

[0067] Remote Procedure Call (RPC) is a computer communication protocol that allows programs to execute procedures or functions on different computers. Through RPC, clients can call services located on servers just like calling local functions, hiding the complexities of network communication. RPC typically uses a specific serialization format (such as JSON, XML, or Protocol Buffers) to transmit data and relies on network protocols (such as HTTP and TCP) for communication.

[0068] This application embodiment provides a device management method, see Figure 1 , is a flowchart of the method, which may include the following steps.

[0069] S101, receiving a management task request for executing a device management task from a service end, wherein the management task request carries a target device identifier of a target external device, and the target external device is any device among multiple external devices.

[0070] The method provided in this embodiment can be Figure 2 The interface modules and task modules shown are executed.

[0071] The business end may include any one or more modules that need to manage external devices, for example, Figure 2 The data governance, security orchestration and automated response, attack surface management and work order modules can also include other modules without limitation.

[0072] The interface module can expose one or more APIs to the business end. When any module on the business end needs to perform device management tasks, such as obtaining relevant data of external devices or triggering external devices to perform related operations, it can send management task requests to the interface module by calling these APIs. The interface module receives management task requests from the business end through the API.

[0073] When calling the API, the target device ID can be passed into the interface module as an input parameter of the API. A management task request can carry one or more target device IDs. Figure 2 For example, the external devices managed by the business end include external device 1, external device 2 and external device 3, and each external device corresponds to a unique device identifier, for example, external device 1, external device 2 and external device 3 correspond to device identifiers 1, 2 and 3 respectively; the target device identifier can include 1, indicating that the target external device is external device 1, and can also include 1 and 2, indicating that the target external device includes external device 1 and external device 2.

[0074] S102 : performing data interaction with the target external device according to the device configuration information of the target external device to obtain the execution result of the device management task, wherein the device configuration information of the target external device is obtained based on the target device identifier.

[0075] Step S102 can be performed by Figure 2 The task modules shown are executed.

[0076] After receiving the management task request, the interface module can respond to the management task request by sending the corresponding device management task to the task module, triggering the task module to execute step S102 to process the device management task. The device management task issued by the interface module can also carry the target device identifier, allowing the task module to exchange data with the corresponding target external device based on the target device identifier.

[0077] Optional, such as Figure 2 As shown, after obtaining the device management task, the task module can obtain the application code corresponding to the obtained device management task from the storage module and execute the application code, thereby establishing a communication connection with the target external device and performing data exchange.

[0078] Device configuration information may include information related to the corresponding external device and required for data exchange with the external device. For example, the device configuration information may include protocol information, which identifies the communication protocol applicable to the external device. Based on this protocol information, the task module can communicate with the target external device according to the corresponding communication protocol. The device configuration information may also include credential information, which the task module can use to log in to the target external device and obtain data from or send instructions to the target external device after login. Exemplarily, the credential information may be the aforementioned signaling token.

[0079] The data interaction with the target external device may include obtaining data related to the device management task from the target external device, and may also include sending an instruction corresponding to the device management task to the target external device so that the target external device performs a corresponding operation.

[0080] S103: Feedback the execution result of the device management task to the service end.

[0081] Step S103 can be performed by Figure 2 When the task module shown is executed, if the task module obtains data from the target external device, the obtained data can be fed back to the business end as the execution result. When the task module sends an instruction to the target external device to trigger the target external device to perform a specific operation, the execution result may include the operation result after the target external device performs the operation, such as operation success or operation failure.

[0082] The task module can feed back the execution results to the interface module, and then the interface module feeds back the execution results to the business end.

[0083] In some embodiments, the interface module and the task module may be implemented using application as a service technology. In this case, the interface module may be equivalent to a device management service, and the task module may be equivalent to a task management service.

[0084] The beneficial effect of this embodiment is that when the business end needs to perform a device management task for the target external device, this solution can respond to the management task request of the business end, and exchange data with the target external device based on the device configuration information of the target external device. Through this data interaction, the corresponding device management task is completed and the execution result of the task is obtained. Therefore, this solution does not need to configure corresponding docking applications for multiple external devices, and can support the business end to uniformly schedule and manage multiple external devices by initiating management task requests, thereby improving the convenience and scalability of connecting external devices to the business end.

[0085] Optionally, in order to distinguish different types of device management tasks, the interface module can provide multiple interfaces corresponding to different types of tasks, such as Figure 2 The data pull interface for data pull tasks, the asset synchronization interface for asset synchronization and asset query tasks, and the linkage interface for linkage tasks are shown. Accordingly, the business end can send different management task requests to the interface module's interface to trigger the task module to execute the corresponding device management task through the interface module.

[0086] The device management request that triggers the data pulling task may carry the target device identifier and may indicate the target data that needs to be pulled.

[0087] The device management request that triggers the asset synchronization task and asset query task can carry the target device identifier.

[0088] The linkage task request that triggers the linkage task may carry linkage parameters and a target device identifier, and may indicate the linkage operation that needs to be performed on the target external device.

[0089] When the service end needs to perform any type of device management task, it can call the interface corresponding to the type, thereby sending a management task request for performing the task of the type to the interface module.

[0090] The task module may include multiple modules corresponding to different types of device management tasks, such as Figure 2After the data pulling task module, asset synchronization task module, linkage task module, and interface module shown receive any type of management task request, they can issue device management tasks to the task modules of the corresponding types, and the task modules of the corresponding types will interact with the target external devices for data.

[0091] For example, when receiving a management task request of the data pull type, the interface module sends the device management task to the data pull task module; when receiving a management task request of the asset synchronization type, the interface module sends the device management task to the asset synchronization task module; when receiving a management task request of the linkage type, the interface module sends the device management task to the linkage task module.

[0092] The data pulling task module is used to pull relevant data about the device operation, such as log data, from the target external device to complete the data collection task.

[0093] The asset synchronization task is used to synchronize the asset data of the target external device to ensure the consistency of the device's asset data in the system.

[0094] Linkage tasks are used to process linkage tasks that issue linkage instructions to devices to ensure that linkage operations between devices can proceed smoothly.

[0095] The interface module can send device management tasks to the task module in various ways, such as sending device management tasks through RPC instructions.

[0096] The task module can obtain the device configuration information of the target external device in a variety of ways. For example, the task module can obtain the device configuration information of the target external device in any of the following ways:

[0097] Acquisition method 1: obtain the device configuration information carried in the management task request according to the target device identifier, and register the obtained device configuration information in the storage module;

[0098] The second acquisition method is to read the device configuration information of the pre-registered target external device from the storage module according to the target device identifier.

[0099] In the case where the target external device is an external device newly connected to the service end, the corresponding device configuration information can be obtained through acquisition method 1. In this acquisition method, the device configuration information of the newly connected external device can be manually configured in the service end. When the service end needs to perform a device management task for the external device, the service end sends a management task request carrying the device identification and device configuration information of the external device to the interface module. After receiving the management task request, the interface module can determine that the storage module does not have the device configuration information of the target external device based on the target device identification carried therein, and then parse the management task request to obtain the device configuration information carried therein, and register the read device configuration information in the storage module for use when performing tasks for the device again in the future.

[0100] In this embodiment, the storage module may include a database for persistently storing data, and may also include a real-time runtime cache for temporarily caching data and supporting fast read and write operations by the interface module and task module. Registering device configuration information with the storage module is equivalent to writing the target device identifier and device configuration information carried in the management task request to the database and the real-time runtime cache.

[0101] In addition to storing the device configuration information of the target external device, the real-time operation cache can also store at least one of the intermediate data generated during the execution of any device management task and the execution result of the device management task to support subsequent operations and queries.

[0102] The data stored in the real-time running cache can be updated and cleaned regularly, or updated and cleaned when the amount of stored data reaches a certain threshold. The updating and cleaning methods can be referred to related technologies and will not be described in detail here.

[0103] If the target external device is not a newly connected external device to the service end, the corresponding device configuration information can be obtained through acquisition method 2. In this acquisition method, the interface module can query the corresponding device configuration information in the storage module according to the target device identifier, and use the queried device configuration information as the device configuration information of the target external device.

[0104] Exemplarily, the management task request carries the target device identifier 1 , and the interface module queries and reads the device configuration information of the external device 1 corresponding to the target device identifier 1 from the storage module according to the target device identifier 1 .

[0105] By obtaining device configuration information in the above manner, on the one hand, when a new external device is connected to the business end, the device configuration information of the new external device can be obtained in a timely manner through the management task request, ensuring that the corresponding device management task can be executed normally. On the other hand, by storing and querying the device configuration information of the connected external device, the execution efficiency of the device management task for the existing external device can be improved, and there is no need to parse the device configuration information from the management task request every time the device management task is executed.

[0106] In some optional embodiments, after obtaining the management task request, the following steps may be further performed:

[0107] In response to the management task request, generating a task identifier corresponding to the device management task;

[0108] Correspondingly, the execution results of the device management task are fed back to the business end, which may include:

[0109] Feedback the execution results of the device management task to the business end based on the task identifier.

[0110] The task identifier can be generated by the interface module. Each management task request corresponds to a unique task identifier. The interface module can generate the task identifier based on various information, such as the timestamp of the management task request, the identifier of the business end sending the management task request, and the corresponding task type. Alternatively, the interface module can generate a random string as the task identifier while ensuring uniqueness.

[0111] After generating a task identifier, the interface module can feed it back to the service end, allowing the service end to establish a correspondence between the task identifier and the issued management task request. In this case, when feeding back an execution result based on the task identifier, the interface module can feed both the task identifier and the execution result back to the service end. Upon receiving this, the service end can determine, based on the task identifier, which previously issued management task request the execution result corresponds to, thereby correctly processing the execution result.

[0112] After generating a task identifier, the interface module can locally store the task identifier corresponding to the management task request and simultaneously record the network address (e.g., IP address) of the service end that sent the management task request. In this case, when feedback is provided based on the task identifier, the interface module can query the corresponding network address based on the task identifier and provide feedback to that network address, ensuring that the execution result is accurately provided to the service end.

[0113] After generating the task identifier, the interface module can send the device management task and the corresponding task identifier to the task module, and save the task identifier locally. Therefore, after the task module obtains the execution result, it can feedback the execution result to the interface in the interface module responsible for sending the device management task (such as the asset synchronization interface) according to the task identifier, thereby feeding back the execution result through the interface.

[0114] Optionally, the interface module may also apply the above-mentioned several modes of processing task identifiers simultaneously.

[0115] The advantage of generating a task identifier and feeding back the execution results based on the task identifier is that the task module may execute multiple device management tasks at the same time. The task identifier helps to distinguish the execution results of multiple device management tasks executed simultaneously by the task module, so that the business end can correctly receive and process the execution results of the device management tasks.

[0116] Optionally, data is exchanged with the target external device based on the device configuration information of the target external device to obtain the execution result of the device management task, including:

[0117] Sending a data pull instruction to the target external device according to the device configuration information of the target external device;

[0118] The target data fed back by the target external device in response to the data pull instruction is received as the execution result of the device management task.

[0119] When receiving a data pull task or an asset synchronization task, the task module may send a data pull instruction to the target external device. Depending on the task, the target data to be pulled by the data pull instruction may be different.

[0120] When a data pulling task is received, the data pulling instruction sent can be used to pull target log data from the target external device. The log data of any external device can represent the operations performed by the external device and the status of the device in the past period of time. The target data fed back by the target external device can be the target log data generated by the operation of the target external device.

[0121] When an asset synchronization task is received, the data pull instruction sent can be used to pull target asset data from the target external device. Correspondingly, the target data fed back by the target external device can be the target asset data of the target external device. The asset data of any external device can represent the device assets belonging to the external device, such as how many graphics processors the external device has, how big the hard disk is, the models of the graphics processor and hard disk, etc. Correspondingly, the target asset data can represent the device assets belonging to the target external device.

[0122] The device configuration information may include the protocol information and credential information (such as a token) of the target external device. When sending a data pull instruction, the task module can determine that the target external device is applicable to the HTTP protocol based on the protocol information, and then establish a communication connection with the target external device through the HTTP protocol. Then, the task module sends a data pull instruction to the target external device based on the HTTP protocol. The data pull instruction carries the credential information of the target external device, and the data pull instruction can indicate which target data needs to be pulled.

[0123] After receiving the data pull instruction, the target external device verifies the credentials to verify whether the task module has permission to pull the data. If the verification is successful, the target external device feeds the target data indicated by the data pull instruction back to the task module. After receiving the target data, the task module sends the target data as the execution result to the interface module, which then feeds the execution result back to the business end.

[0124] Through the method of the above embodiment, the device management system can pull the required target data from the target external device according to the needs of the business end and provide it to the business end to meet the data needs of the business end.

[0125] Optionally, after receiving the target data, the task module can also perform the following steps:

[0126] Save the target data in the storage module:

[0127] In the case of saving the target data, data interaction is performed with the target external device according to the device configuration information of the target external device to obtain the execution result of the device management task, which may include:

[0128] In the case that the management task request does not match the data stored in the storage module, data is exchanged with the target external device according to the device configuration information of the target external device to obtain the execution result of the device management task;

[0129] In a case where the management task request matches the data stored in the storage module, the data matching the management task request is obtained from the storage module as the execution result of the device management task.

[0130] The target data may be stored in a database of the storage module. When storing the target data, the task module may store the target data, the type of the target data, the device identifier of the external device providing the target data, and the timestamp of receiving the target data in the database in a corresponding manner.

[0131] Based on this, after the interface module obtains the management task request and issues the device management task to the task module, the task module can determine whether the management task request matches the target data stored in the database.

[0132] If the management task request corresponds to a data pulling task, then the conditions for matching the management task request with the data in the database may include: the device identifier carried by the management task request is consistent with the device identifier of the target data in the database, the type of the target data with the consistent device identifier is log data, and the time interval between the timestamp of the target data and the timestamp of receiving the management task request is less than a certain threshold; if the above conditions are met at the same time, the management task request and the corresponding target data match; if all the data in the database cannot meet the above conditions at the same time, the management task request does not match the target data stored in the database.

[0133] If the management task request corresponds to an asset query task, then the conditions for matching the management task request with the data in the database may include: the device identifier carried by the management task request is consistent with the device identifier of the target data in the database, and the type of the target data with the consistent device identifier belongs to asset data; if the above conditions are met at the same time, the management task request and the corresponding target data match; if all the data in the database cannot meet the above conditions at the same time, the management task request does not match the target data stored in the database.

[0134] The above thresholds can be pre-set as needed and are not limited.

[0135] Through the method of the above embodiment, when the device management system executes data pulling tasks and asset synchronization tasks, it can feed back the data recently pulled from the same external device to the business end, without having to repeatedly pull data from the same external device multiple times in a short period of time, thereby improving the efficiency of feeding back the execution results to the business end and reducing the bandwidth resources occupied by data interaction between the task module and the external device.

[0136] Further optionally, the storage module can serve as a data hub, and the task module can distribute the various data stored in the storage module to different modules in the business end according to the set rules, so that each module can easily share data content and promote collaborative work between modules.

[0137] When the task module distributes data to various modules on the business side, it can also control the data distribution traffic, achieve traffic control of the entire business side, ensure stable and efficient operation of the system, and provide efficient data processing solutions.

[0138] Optionally, data is exchanged with the target external device based on the device configuration information of the target external device to obtain the execution result of the device management task, including:

[0139] Sending a linkage instruction to the target external device according to the device configuration information of the target external device, wherein the linkage instruction is used to trigger the target external device to perform a linkage operation according to the linkage parameters;

[0140] The linkage operation result fed back by the target external device is received as the execution result of the device management task.

[0141] For the method of sending linkage instructions according to device configuration information, please refer to the method of sending data pull instructions according to device configuration information mentioned above, which will not be repeated here.

[0142] The linkage instruction may carry linkage parameters and credential information, and may indicate the linkage operation to be performed by the target external device.

[0143] The linkage operation indicated by the linkage instruction may be to block an IP address, and the linkage parameters may include the IP address to be blocked, such as 168.0.0.1, and the duration of the block, such as 1 hour or 24 hours.

[0144] The linkage operation to be executed can be obtained by the interface module by parsing the linkage task request, and the task module is informed by sending the linkage task to the task module.

[0145] The linkage operation indicated by the linkage instruction can be to limit the traffic of the IP address. The linkage parameters can include the IP address whose traffic needs to be restricted, such as 168.0.0.1; the duration of the traffic restriction, such as 1 hour, 24 hours; and the threshold for restricting traffic, such as limiting it to less than 100MB.

[0146] After receiving the linkage command, the target external device can verify the credential information contained in it. If the verification is successful, it will perform the corresponding linkage operation according to the linkage parameters. In the above example, the target external device can ban the IP address 168.0.0.1 for one hour, or limit the amount of data from the IP address 168.0.0.1 to less than 100MB for the next 24 hours.

[0147] The linkage operation result can indicate whether the target external device successfully executed the corresponding linkage operation. For example, after receiving a linkage instruction to block an IP address, if the target external device successfully blocks the specified IP address, it will feedback a linkage operation result indicating a successful block. If the target external device fails to block the specified IP address, it will feedback a linkage operation result indicating a failed block.

[0148] Through the method of the above embodiment, the device management system can control the external device to perform corresponding linkage operations by sending linkage instructions to the external device, thereby improving the control efficiency of the external device and timely controlling the target external device in some scenarios to avoid irreversible losses. For example, when an external device may be subject to a network attack, the above method can be used to promptly ban the IP address that initiates the attack and block subsequent attack behaviors.

[0149] Optionally, before sending the linkage instruction, the task module may also perform the following steps:

[0150] Detecting the linkage status of the target external device, the linkage status indicates whether the target external device can process the linkage instruction;

[0151] When the linkage state of the target external device is normal, executing the step of sending a linkage instruction to the target external device;

[0152] When the linkage status of the target external device is abnormal, a linkage abnormality prompt is fed back to the business end.

[0153] The linkage status may include the communication connection status between the task module and the target external device, and may also include the device status of the target external device itself;

[0154] When the communication connection status is normal, the task module and the target external device can correctly send and receive data and instructions. When the communication connection status is abnormal, the task module and the target external device cannot correctly send and receive data and instructions.

[0155] When the device is in a normal state, the target external device can correctly parse and process the received data and instructions. When the device is in an abnormal state, the target external device cannot correctly parse and process the received data and instructions.

[0156] If the communication connection status and device status of the target external device are normal, then its linkage status is normal. At this time, the target external device can correctly receive and process the linkage instructions of the task module. If at least one of the communication connection status and device status of the target external device is abnormal, then its linkage status is abnormal. At this time, the target external device cannot correctly receive and process the linkage instructions.

[0157] The method for detecting the linkage status can be that the task module sends a detection instruction to the target external device. The detection instruction can instruct the target external device to reply with a specific response message. If the task module does not receive feedback from the target external device within a preset time (for example, 20 milliseconds, 100 milliseconds, etc., not limited) after sending the detection instruction, or receives feedback but the feedback message is not the specified response message, then the linkage status is determined to be abnormal. If a response message is received within the preset time, then the linkage status is determined to be normal.

[0158] When the linkage status is abnormal, the task module (specifically, it can be the linkage task module) can feedback the linkage abnormal prompt to the interface module (specifically, it can be the linkage interface), and then the interface module will feedback the linkage abnormal prompt to the business end. The business end can then display the linkage abnormal prompt on a specific display screen, thereby prompting relevant personnel to inspect and maintain the target external equipment.

[0159] Through the method of the above embodiment, the device management system can timely discover external devices in abnormal linkage status, and ensure that the linkage instructions issued by the task module can be correctly executed by the target external device.

[0160] Before the task module issues a linkage instruction, it can first obtain the corresponding linkage parameters. The methods for obtaining the linkage parameters can be any of the following:

[0161] Method 1 for obtaining linkage parameters: extract the linkage parameters carried in the management task request;

[0162] The second method for obtaining linkage parameters is to read the linkage parameters corresponding to the target device identifier from the storage module.

[0163] In the first method of obtaining linkage parameters, the business end can configure the linkage parameters in the management task request. After receiving the management task request, the interface module can add the linkage parameters carried in the request to the issued linkage task. In this way, the task module can obtain the linkage parameters from the received linkage task.

[0164] In the second method of obtaining linkage parameters, the linkage parameters can be manually configured in advance in the database of the storage module, and the configured linkage parameters correspond to the device identifier, that is, one device identifier corresponds to a set of linkage parameters. After the task module obtains the linkage task, it queries the database based on the target device identifier carried in the linkage task to obtain the corresponding linkage parameters.

[0165] Obtaining linkage parameters using the first method allows the service end to easily configure different linkage parameters for each linkage task, allowing the target external device to flexibly execute linkage operations based on different linkage parameters for different scenarios. Obtaining linkage parameters using the second method reduces the amount of data sent by the service end to the interface module, thereby reducing bandwidth usage.

[0166] In some optional embodiments, the task module can also control the calling frequency of each interface in the interface module. For example, a calling number threshold can be set for each interface. If the number of calls of an interface in the most recent unit time exceeds the calling number threshold, the interface can be temporarily prohibited from being called. After a period of time, the interface can be opened again so that it can be called by the business end.

[0167] The above method can control the number of device management tasks that the task module needs to process within a certain period of time, thereby avoiding the task module crashing or low task processing efficiency due to an excessive number of device management tasks.

[0168] To facilitate understanding of the device management method of this embodiment, Figure 3 The example illustrates an application scenario of the device management method.

[0169] After the SIEM on the business side configures the device configuration information for the newly connected target external device, the SIEM executes step 1 and initiates a data pull request with the device configuration information. Correspondingly, the data pull interface of the interface module receives the data pull request. This data pull request is equivalent to the management task request for executing a data pull task in the aforementioned embodiment. Step 1 is equivalent to step S101 in the aforementioned embodiment.

[0170] The interface module parses the device configuration information carried in the data pull request and executes step 2, registering the device configuration information, thereby writing the device configuration information of the target external device into the storage module. In addition, the interface module executes step 3, submitting the data pull task based on the data pull request, which is equivalent to sending the data pull task to the task module.

[0171] After receiving the data pull task, the task module (specifically, the data pull task module) executes step 4, sending a data pull instruction based on the device configuration information. In step 4, the task module determines, based on the device configuration information, that the target external device supports the HTTP protocol. It then establishes a connection with the device via HTTP and sends the data pull instruction to the device.

[0172] After the target external device receives the data pull instruction and verifies the credential information carried therein, it executes step 5 and returns the target data. Thus, the task module obtains the target data provided by the target external device. Steps 2 to 5 are equivalent to step S102 in the aforementioned embodiment, and the target data is equivalent to the execution result obtained by the task module.

[0173] As some examples, the target data may be log data generated by the target external device, for example, data in the following format.

[0174] "{\"timestamp\":1731910317140,\"formatVersion\":1,\"webaclId\":\"arn:vender:wafv2:us-east-1:229568694718:global / webacl / CreatedByCloudFront-3665c169-5f69-4cdb-93f6-e5931c1de7b1 / 91a5224a-7845-4ff4-9b8c-23281d12adbf\",\"termina tingRuleId\":\"Default_Action\",\"terminatingRuleType\":\"REGULAR\",\"action\":\"ALLOW\",\"requestId\":\"PpqER60 CEKbsptnkzWftvXxnK7MtvOt991dl32zzSDWDzcyn8Vj_kQ==\"},\"ja3Fingerprint\":\"479b976148ec2a1a195ae2e15805fefa\"}\n".

[0175] The task module executes step 6, caches the target data, and executes step 7 via the interface module, feeding back the target data based on the task identifier. At this point, the SIEM on the business side obtains the required log data of the target external device. Steps 6 and 7 are equivalent to step S103 in the aforementioned embodiment.

[0176] On the other hand, the ASM on the business side can periodically send asset synchronization requests to the interface module, triggering the interface module to send asset synchronization tasks to the task module. The task module responds to the asset synchronization task, pulls the target asset data of the device from the target external device and stores it in the storage module. The asset synchronization request can be regarded as a management task request for triggering the asset synchronization task.

[0177] The target asset data obtained by the task module will also be fed back to the ASM on the business side through the interface module.

[0178] After obtaining the target data, the SIEM can execute step 8, parsing the target data. During the parsing process, the SIEM can execute step 9, querying the asset data. Specifically, in step 9, the SIEM can send an asset query request to the asset synchronization interface of the interface module. Step 9 is equivalent to step S101 in the aforementioned embodiment, and the asset query request is equivalent to the management task request that triggers the asset query task.

[0179] The asset synchronization module responds to the request and executes step 10 to submit the asset query task to the task module (specifically, the asset synchronization task module). The asset query request is equivalent to a management task request for triggering the asset query task.

[0180] After the task module obtains the asset query task, it executes step 11 to query the target asset data. The query finds that the asset query request matches the asset data stored in the database, that is, the database of the storage module already has the target asset data corresponding to the target external device. Therefore, the target asset data is given to the interface module. The interface module executes step 12 to feedback the target asset data to the SIEM on the business end.

[0181] Steps 10 and 11 are equivalent to:

[0182] In a case where the management task request matches the data stored in the storage module, the data matching the management task request is obtained from the storage module as the execution result of the device management task.

[0183] Step 12 is equivalent to step S103 in the aforementioned embodiment, and the target asset data fed back by the interface module is equivalent to the execution result of the asset query task.

[0184] After receiving the target asset data, the SIEM analyzes the target asset data and the target data, proceeding to step 13 to perform security analysis and trigger the built-in playbook. In step 13, the SIEM enriches the received log data based on the target asset data. Enrichment can be understood as determining which device assets the IP addresses in the log data correspond to and labeling the asset owners to whom these devices and assets belong.

[0185] The enriched log data can be used for security analysis. Suppose the SIEM discovers through security analysis that the protected host (10.0.0.10) of the target external device has been successfully attacked by a high-threat vulnerability exploit. The attack originated from the external IP address 20.20.20.20. The SIEM then triggers a built-in script for handling vulnerability exploit attacks.

[0186] SIEM can have multiple built-in scripts for handling different problems. Each built-in script can include several instructions that can be executed by the business end. After the business end discovers that there is a specific problem with the target external device, it can trigger the corresponding built-in script and handle the problem by executing the instructions therein.

[0187] For example, in the above example, after discovering that the target external device is vulnerable to vulnerability exploitation, the built-in script for handling the problem is triggered to block the attack.

[0188] After the built-in script is triggered, the business-side XDR platform generates a security incident and sends it to the business-side Security Orchestration and Automated Response (SOAR). Based on the preset rules, SOAR executes step 14 to the interface module (specifically, the linkage interface) and initiates a linkage task request. Step 14 is equivalent to step S101 in the previous embodiment.

[0189] The linkage task request can carry linkage parameters, such as the IP address to be blocked (such as 20.20.20.20 above) and the blocking duration (such as permanent blocking), and can be used to indicate the linkage operation to be performed, such as instructing a blocking operation.

[0190] The interface module responds to the linkage task request, executes step 15 to submit the linkage task to the task module (specifically, the linkage task module), and provides the linkage parameters, target device identifier, linkage operation to be executed and other information to the task module.

[0191] Then, the task module executes step 16 and sends a linkage instruction to the target external device based on the above information. The target external device responds to the linkage instruction and executes step 17 and performs a linkage operation, thereby permanently banning the IP address 20.20.20.20.

[0192] Before executing step 16, the task module may first detect the linkage status of the target external device. The detection method is similar to the above embodiment and will not be described in detail.

[0193] When the task module sends a linkage instruction, it can determine whether the target external device is applicable to the XLINK protocol based on the device configuration information of the target external device, establish a connection with the device based on the XLINK protocol, and send the linkage instruction to the device.

[0194] After the ban is successful, the target external device executes step 18 and feedbacks the linkage operation result. The linkage operation result indicates that the corresponding IP address is successfully banned. The task module uses the linkage operation result as the execution result, executes step 19, and feedbacks the execution result. Then the interface module also executes step 19 and gives the execution result to the business end. The business end executes step 20 and displays the execution result, which shows that the IP address 20.20.20.20 has been banned.

[0195] Steps 15 to 18 are equivalent to step S102 of the aforementioned embodiment, and step 19 is equivalent to step S103 of the aforementioned embodiment.

[0196] It can be seen from the above examples that after applying the method of this embodiment, unified management of device configuration information of multiple external devices can be achieved, providing a better customer interaction experience; and the docking cost of SIEM, ASM, SOAR and other modules and external devices on the business side can be reduced; it also has high reusability, and can not only be provided to SIEM, ASM, SOAR and other modules for use in the future, but can also support the interaction between other modules and external devices on the business side.

[0197] A second aspect of the present application provides a device management system, comprising:

[0198] An interface module is configured to receive a management task request for executing a device management task from a service end, wherein the management task request carries a target device identifier of a target external device, and the target external device is any device among multiple external devices;

[0199] Task modules for:

[0200] According to the device configuration information of the target external device, data is exchanged with the target external device to obtain the execution result of the device management task, where the device configuration information of the target external device is obtained based on the target device identifier;

[0201] Feedback the execution results of device management tasks to the business end.

[0202] The task module feeds back the execution result, which means that the task module feeds back the execution result to the interface module, and the interface module feeds back the execution result to the business end.

[0203] Optionally, the task module obtains the device configuration information of the target external device by at least one of the following methods:

[0204] According to the target device identifier, obtain the device configuration information carried in the management task request, and register the obtained device configuration information in the storage module;

[0205] Read the device configuration information of the pre-registered target external device from the storage module according to the target device identifier.

[0206] Optionally, the interface module can also be used for:

[0207] In response to the management task request, generating a task identifier corresponding to the device management task;

[0208] The task module provides feedback to the business end on the execution results of the device management task, including:

[0209] Feedback the execution results of the device management task to the business end based on the task identifier.

[0210] Optionally, the task module exchanges data with the target external device based on the device configuration information of the target external device to obtain the execution result of the device management task, including:

[0211] Sending a data pull instruction to the target external device according to the device configuration information of the target external device;

[0212] The target data fed back by the target external device in response to the data pull instruction is received as the execution result of the device management task.

[0213] Optionally, target data includes:

[0214] Target log data generated by the operation of the target external device;

[0215] Alternatively, the target asset data of the target external device represents the device assets belonging to the target external device.

[0216] Optionally, the task module can also be used to:

[0217] Save the target data in the storage module:

[0218] The task module exchanges data with the target external device based on the device configuration information of the target external device to obtain the execution results of the device management task, including:

[0219] In the case that the management task request does not match the data stored in the storage module, data is exchanged with the target external device according to the device configuration information of the target external device to obtain the execution result of the device management task;

[0220] The task module can also be used to:

[0221] In a case where the management task request matches the data stored in the storage module, the data matching the management task request is obtained from the storage module as the execution result of the device management task.

[0222] Optionally, the task module exchanges data with the target external device based on the device configuration information of the target external device to obtain the execution result of the device management task, including:

[0223] Sending a linkage instruction to the target external device according to the device configuration information of the target external device, wherein the linkage instruction is used to trigger the target external device to perform a linkage operation according to the linkage parameters;

[0224] The linkage operation result fed back by the target external device is received as the execution result of the device management task.

[0225] Optionally, the task module can also be used to:

[0226] Detecting the linkage status of the target external device, the linkage status indicates whether the target external device can process the linkage instruction;

[0227] When the linkage state of the target external device is normal, executing the step of sending a linkage instruction to the target external device;

[0228] When the linkage status of the target external device is abnormal, a linkage abnormality prompt is fed back to the business end.

[0229] Optionally, the task module may obtain linkage parameters in the following ways:

[0230] Extract the linkage parameters carried in the management task request;

[0231] Alternatively, the linkage parameter corresponding to the target device identifier is read from the storage module.

[0232] The task module extracts the linkage parameters carried in the management task request, which means that the interface module parses the management task request to obtain the linkage parameters, and then gives the linkage parameters to the task module in the linkage task, and the task module obtains the linkage parameters from the linkage task.

[0233] The structure of the above device management system and its connection with the business end and external devices can be found in Figure 2 The interface module and task module are not described in detail.

[0234] The working principle of the equipment management system provided in this embodiment can be found in the relevant steps of the equipment management method provided in any embodiment of this application, and will not be repeated here.

[0235] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system or system embodiments, since they are basically similar to method embodiments, the description is relatively simple. For relevant parts, refer to the partial description of the method embodiment. The system and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without expending creative work.

[0236] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0237] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A device management method, characterized in that: include: receiving a management task request for executing a device management task from a service end, wherein the management task request carries a target device identifier of a target external device, wherein the target external device is any device among a plurality of external devices; performing data interaction with the target external device according to the device configuration information of the target external device to obtain an execution result of the device management task, wherein the device configuration information of the target external device is obtained based on the target device identifier; Feedback the execution result of the device management task to the service end.

2. The method according to claim 1, characterized in that The method for obtaining the device configuration information of the target external device includes at least one of the following: According to the target device identifier, obtaining the device configuration information carried in the management task request, and registering the obtained device configuration information in the storage module; According to the target device identifier, the device configuration information of the target external device that is pre-registered is read from the storage module.

3. The method according to claim 1, characterized in that Also includes: In response to the management task request, generating a task identifier corresponding to the device management task; Feedback of the execution result of the device management task to the service end includes: According to the task identifier, the execution result of the device management task is fed back to the service end.

4. The method according to claim 1, wherein The step of performing data interaction with the target external device according to the device configuration information of the target external device to obtain the execution result of the device management task includes: Sending a data pull instruction to the target external device according to the device configuration information of the target external device; Target data fed back by the target external device in response to the data pull instruction is received as an execution result of the device management task.

5. The method according to claim 4, characterized in that The target data includes: target log data generated by the operation of the target external device; Alternatively, the target asset data of the target external device, wherein the target asset data represents device assets belonging to the target external device.

6. The method according to claim 4, characterized in that Also includes: The target data is stored in a storage module: The step of performing data interaction with the target external device according to the device configuration information of the target external device to obtain the execution result of the device management task includes: In a case where the management task request does not match the data stored in the storage module, performing data interaction with the target external device according to the device configuration information of the target external device to obtain an execution result of the device management task; The method further comprises: In a case where the management task request matches the data stored in the storage module, the data matching the management task request is obtained from the storage module as the execution result of the device management task.

7. The method according to claim 1, characterized in that The step of performing data interaction with the target external device according to the device configuration information of the target external device to obtain the execution result of the device management task includes: Sending a linkage instruction to the target external device according to the device configuration information of the target external device, wherein the linkage instruction is used to trigger the target external device to perform a linkage operation according to the linkage parameters; The linkage operation result fed back by the target external device is received as the execution result of the device management task.

8. The method according to claim 7, characterized in that Also includes: detecting a linkage state of the target external device, wherein the linkage state indicates whether the target external device is capable of processing the linkage instruction; When the linkage state of the target external device is normal, executing the step of sending the linkage instruction to the target external device; When the linkage state of the target external device is abnormal, a linkage abnormality prompt is fed back to the service end.

9. The method according to claim 7, characterized in that The linkage parameters are obtained in the following ways: Extracting the linkage parameters carried in the management task request; Alternatively, the linkage parameter corresponding to the target device identifier is read from a storage module.

10. A device management system, characterized in that: include: An interface module is configured to receive a management task request for executing a device management task from a service end, wherein the management task request carries a target device identifier of a target external device, and the target external device is any device among a plurality of external devices; Task modules for: performing data interaction with the target external device according to the device configuration information of the target external device to obtain an execution result of the device management task, wherein the device configuration information of the target external device is obtained based on the target device identifier; Feedback the execution result of the device management task to the service end.

Citation Information

Patent Citations

  • Business management method and device and storage medium

    CN116193299A

  • Multi-cloud resource data processing method and device, equipment and storage medium

    CN116723246A

  • Robot Fleet Management for Value Chain Networks

    US20220187847A1