Domestic substitution-based credential terminal asset management and control method and system

Through dynamic detection and real-time supervision of the trusted terminal asset management system, the problem of low efficiency in trusted terminal asset management has been solved, and effective identification of domestic hardware resources and accurate monitoring of terminal activity and compliance have been achieved, preventing illegal use and improving management efficiency and information accuracy.

CN120765205AInactive Publication Date: 2025-10-10HANGZHOU RONGHUI DATA TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511277264.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2025-10-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing trusted terminal asset management system has difficulty in effectively identifying domestic hardware resources, resulting in inefficient management and an inability to accurately monitor terminal activity and compliance, posing a risk of illegal use of non-trusted operating systems.

Method used

By regularly collecting client information, using asynchronous thread pools to optimize task processing, collecting dynamic behavior data, generating detection reports, setting health indicator tables, real-time monitoring of terminal assets, combining heartbeat mechanisms to ensure communication synchronization, dynamically detecting compliance, activity, and dual-system conditions, and generating a unique device ID for encryption verification.

Benefits of technology

It realizes real-time dynamic management of trusted innovation terminals, prevents asset inconsistencies, strengthens compliance monitoring of trusted innovation terminals, timely warns of violations, improves management efficiency, and ensures the accuracy and consistency of terminal asset information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120765205A_ABST
    Figure CN120765205A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of credential terminal asset management and control, and discloses a domestic substitution-based credential terminal asset management and control method and a domestic substitution-based credential terminal asset management and control system, and the method comprises the following steps: regularly collecting client information according to a client task so as to perfect terminal asset information data; the client task is transmitted to an asynchronous thread pool, the asynchronous thread pool dynamically adjusts and generates optimization measures according to the actual load, and dynamic behavior data in the operation process of the client is collected. According to the invention, real-time dynamic management is realized by detecting client supervision data in real time, the problems of missed management and lack of management caused by inconsistency of actually used terminal assets and account assets are effectively prevented, account information lag is avoided, a compliance product library is established for brand models of complete machines and accessories for credential terminal assets, and the management efficiency is improved. And daily use of a non-compliant credential terminal is prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of credible terminal asset management and control, and specifically to a credible terminal asset management and control method and system based on domestic substitution. Background Art

[0002] In order to safeguard the strategic needs of information security and the needs of advanced industrial upgrading and development, the country has vigorously promoted the innovative application of domestic information technology and carried out in-depth work on replacing trusted innovations across the country. With the continuous advancement of the work of replacing trusted innovations, the replaced trusted innovation assets have gradually increased, and it is necessary to conduct comprehensive monitoring of the operation of all trusted innovation terminals and implement dynamic supervision in accordance with regulatory requirements.

[0003] The existing trusted computing terminal asset management system has difficulty identifying domestic hardware resources. Domestic trusted computing terminal hardware models are diverse, and traditional hardware asset identification methods cannot be effectively adapted, resulting in low efficiency in hardware asset registration, inventory, maintenance, and other management tasks, and prone to inaccurate asset information. There are core functional gaps in the business. Conventional technical solutions do not serve trusted computing replacement businesses and lack management needs to address the trusted computing replacement process. First, there is illegal dual-system monitoring. Due to factors such as imperfect domestic ecological resources and user operating habits, some users still use non-trusted computing operating systems on trusted computing terminals through technical means. Traditional technical solutions have not formed a complete solution to this regulatory need. Second, terminal activity monitoring. Terminal activity is an important indicator of terminal replacement effectiveness. Regulators often need to understand the actual usage of terminal users through terminal operation, such as the use of streaming signing software and network traffic. Third, compliance monitoring. Since trusted computing products have a strict evaluation mechanism, products that have not been professionally evaluated are not included in the trusted computing product system. Traditional technical solutions cannot accurately judge the compliance risks of domestic chip trusted computing terminals and their chips, operating systems, etc., so there are functional gaps in compliance monitoring. Summary of the Invention

[0004] The present invention provides a method and system for managing and controlling the assets of trusted terminal products based on domestic substitution, which has the beneficial effects of real-time supervision and strict detection, and solves the problem of poor supervision and detection effects mentioned in the above background technology.

[0005] The present invention provides the following technical solution: a method for managing and controlling credible terminal assets based on domestic substitution, comprising the following steps:

[0006] Collect client information regularly according to client tasks to improve terminal asset information data;

[0007] Transferring the client task to an asynchronous thread pool, wherein the asynchronous thread pool dynamically adjusts and generates optimization measures according to the actual load;

[0008] Collect dynamic behavior data during client operation;

[0009] Aggregate terminal asset information data and dynamic behavior data to generate client supervision data;

[0010] Analyze whether there is any illegal behavior in the client supervision data by dynamically detecting the client supervision data, and generate a detection report;

[0011] Set up a health indicator table and use the test report to determine the health of the client;

[0012] Set a health threshold and issue an abnormal warning if the health indicator threshold is lower than the threshold;

[0013] The terminal asset information data and the dynamic behavior data are combined to dynamically monitor the client assets.

[0014] As an optional solution of the terminal asset management method based on domestic substitution of the present invention, wherein: the server establishes a periodic sending of the client task list according to the heartbeat mechanism;

[0015] The client collects client supervision data according to the client task list;

[0016] The client periodically sends heartbeat packets to the server, and the server returns a heartbeat response with a task list to ensure that the communication between the two parties is synchronized.

[0017] As an optional solution of the method for managing and controlling the terminal assets of a trust-based innovation company based on domestic substitution described in the present invention, wherein: the client task list is disassembled into multiple client task queues;

[0018] Set task queue thresholds;

[0019] When the client task queue does not reach the threshold, the task data is processed normally;

[0020] When the client task queue has reached the threshold, the server directly returns a response to inform the client that the task has not been processed and does not update the last execution time of the task to ensure that the task will be re-issued at the next heartbeat.

[0021] As an optional solution of the method for managing and controlling terminal assets based on domestic substitution described in the present invention, wherein: the client supervision data also includes compliance data, activity data, and dual-system data;

[0022] The compliance data includes the client's operating system and basic software and hardware parameters, and the compliance of the compliance data is verified through the dynamic detection;

[0023] The activity data includes the frequency of client usage;

[0024] The dual-system data includes physical machine data and virtual machine data, and whether it is a dual system is determined through the dynamic detection;

[0025] The compliance data, activity data, and dual-system data are used to determine the health of the client according to the health index table.

[0026] As an optional solution of the terminal asset management method based on domestic substitution described in the present invention, wherein: detecting physical machine data, the physical machine data including Linux system information, Windows system information, UEFI boot items and GRUB configuration;

[0027] Detecting virtual machine data, including VirtualBox virtual machines, VMware virtual machines, and Phyvirt virtual environments;

[0028] Determine whether it is a dual system according to the physical machine data and the virtual machine data, and if it is a dual system, deduct the health level in the health index table.

[0029] As an optional solution of the method for managing and controlling terminal assets based on domestic substitution described in the present invention, it includes: reading a script, and obtaining the basic software and hardware parameters and the dynamic behavior data according to the reading script;

[0030] The basic software and hardware parameters include machine model information data, CPU information data, operating system information data, memory information data, hard disk information data, network information and application installation data;

[0031] The dynamic behavior data includes power on / off record data, operation status monitoring data, mobile storage device plug-in / out record data, print task record data, application operation status record data and local cache data.

[0032] As an optional solution to the method of asset management of trusted terminal based on domestic substitution described in the present invention, the client information also includes the registered name, contact information, unit, and device location coordinates, and the client information is added to the client supervision data.

[0033] As an optional solution of the terminal asset management method based on domestic substitution described in the present invention, wherein: the terminal asset supervision information is improved by the client supervision data;

[0034] The client's historical data is matched in real time according to the collected client supervision data, and the client is detected and abnormal warnings are issued through the health index table.

[0035] As an optional solution of the terminal asset management method based on domestic substitution described in the present invention, wherein: the client generates a unique device ID and performs AES encryption in combination with the current timestamp and key;

[0036] The server decrypts the key and verifies the legitimacy of the device and time.

[0037] The present invention also provides an application of a terminal asset management and control system based on domestic substitution, including:

[0038] A collection module that periodically sends a task list, collects client information based on the task list, and collects dynamic behavior data in real time through the collection module;

[0039] an optimization module, the optimization module being used to decompose the task list and adjust the task list according to the asynchronous task thread pool;

[0040] A supervision module, which is used to detect compliance data, activity data, and dual-system data, and to establish a health index table, and to supervise the client through the health index table;

[0041] Abnormal alarm: when the health index table is lower than the health threshold, an abnormal alarm is issued.

[0042] The present invention has the following beneficial effects:

[0043] 1. This method and system for managing and controlling credible terminal assets based on domestic substitution can achieve real-time dynamic management through real-time detection of client supervision data, effectively preventing the inconsistency between actual terminal assets and book assets, the existence of omissions and lack of management, and the lag of book information. In addition, for credible terminal assets, a compliant product library is established for the brand models of complete machines and accessories to prevent the daily use of non-compliant credible terminals.

[0044] 2. This method and system for asset management of trusted and innovative terminals based on domestic substitution strengthens the supervision needs of trusted and innovative terminals in the fields of party and government, state-owned enterprises, key industries, etc., especially closely monitoring the illegal installation of non-trusted and innovative operating systems on trusted and innovative terminals. Once discovered, an immediate warning will be issued. The system automatically collects and updates data for changes in users and configuration information, and retains historical data. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 Schematic diagram of the process steps of the present invention.

[0046] Figure 2 Schematic diagram of the system architecture flow of the present invention.

[0047] Figure 3 This is a schematic diagram of the collection and supervision process of the present invention.

[0048] Figure 4 The terminal supervision process of the present application is shown in the figure. DETAILED DESCRIPTION

[0049] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the protection scope of the present application.

[0050] Embodiment 1

[0051] Please refer to Figures 1-4 One of the methods is a domestic substitute-based Xingcheng terminal asset management method, which comprises the following steps:

[0052] Collecting client information according to the client task timing to improve the terminal asset information data;

[0053] Transmitting the client task to an asynchronous thread pool, and dynamically adjusting the asynchronous thread pool according to the actual load and generating optimization measures;

[0054] Collecting dynamic behavior data in the running process of the client;

[0055] Summarizing the terminal asset information data and the dynamic behavior data to generate client supervision data;

[0056] Analyzing whether the client supervision data contains illegal behavior by dynamically detecting the client supervision data, and generating a detection report;

[0057] Setting a health degree index table to determine the health degree of the client through the detection report;

[0058] Setting a health degree threshold, and issuing an abnormal warning when the health degree is lower than the health degree threshold;

[0059] Dynamically supervising the client asset by combining the terminal asset information data and the dynamic behavior data.

[0060] The server sends a client task, and the server collects its own client supervision data by executing the client task to assist in improving the terminal asset information data;

[0061] When the client task is too much, the asynchronous thread pool is used for processing to reduce the synchronous blocking time of the request and improve the interface response speed;

[0062] The asynchronous thread pool is dynamically adjusted according to the actual load of the task, including adjusting the core number, the maximum thread number and the queue size of the thread pool;

[0063] Specifically, thread pool parameter optimization includes:

[0064] Number of core threads: set to twice the number of system cores to improve the utilization of multi-core CPUs;

[0065] Maximum number of threads: set to 4 times the number of core threads to support high concurrent processing;

[0066] Queue capacity: Set a reasonable queue size based on task processing latency and request traffic estimates;

[0067] Through the above design, the task data reporting mechanism can effectively guarantee service stability in high-concurrency scenarios, avoid request queue congestion, and ensure the integrity and consistency of task execution.

[0068] The client information includes terminal type, device brand, model, CPU chip brand, CPU chip model, operating system brand, operating system version, memory brand, memory capacity, hard disk brand, hard disk capacity, IP address, and MAC address.

[0069] Among them, dynamic behavior data includes power on / off record data, operation status monitoring data, mobile storage device plug-in and unplug record data, print task record data, application operation status record data and local cache data;

[0070] Aggregate client information and dynamic behavior data into client monitoring data. Dynamic detection and analysis of client monitoring data can be used to determine whether there are any violations, such as inconsistent brands and models of chips, memory, disks, and graphics cards compared to those originally installed, dual-boot systems, no antivirus software detected, incomplete user information, low CPU usage, low memory usage, and high disk usage.

[0071] Among them, the health index table is:

[0072]

[0073] The total score is 100 points and divided into three levels, defining red, yellow and green management;

[0074] Green code: >80 points;

[0075] Yellow code: 70 points to 80 points;

[0076] Red code: <70 points;

[0077] When the code is red, an alarm is issued to the client, prompting the client to adjust the client;

[0078] By real-time detection of client supervision data for real-time dynamic management, we can effectively prevent the inconsistency between actual terminal assets and book assets, the existence of omissions and lack of management, and avoid the lag of book information. For the trusted terminal assets, we will establish a compliant product library for the brand and model of the whole machine and accessories to prevent the daily use of non-compliant trusted terminals, strengthen the supervision of trusted terminals in the party and government, state-owned enterprises, key industries and other fields, and especially closely monitor the illegal installation of non-trusted operating systems (dual systems) on trusted terminals. Once discovered, we will issue an immediate warning. For changes in users and configuration information, the system will automatically collect and update and retain historical data.

[0079] The server establishes a periodic task list for sending to the client based on the heartbeat mechanism;

[0080] The client collects client supervision data according to the client task list;

[0081] The client periodically sends heartbeat packets to the server, and the server returns a heartbeat response with a task list to ensure that both parties are in sync.

[0082] The client initiates a heartbeat request, the server sends a task execution list, the client executes the task and requests the interface to submit the corresponding results, and the server receives the result data and puts it into the asynchronous thread pool for processing;

[0083] Through the periodic client task list, execute relevant commands to obtain basic information, and obtain the CPU utilization, memory utilization, and disk utilization information of the current detection device through calculation and interception.

[0084] Split the client task list into multiple client task queues;

[0085] Set task queue thresholds;

[0086] When the client task queue does not reach the threshold, the task data is processed normally;

[0087] When the client task queue reaches the threshold, the server directly returns a response to inform the client that the task has not been processed and does not update the last execution time of the task to ensure that the task will be re-issued in the next heartbeat;

[0088] Client supervision data also includes compliance data, activity data, and dual-system data;

[0089] Compliance data includes the client's operating system and basic software and hardware parameters, and the compliance of the compliance data is verified through dynamic detection.

[0090] Activity data includes client usage frequency;

[0091] Dual system data includes physical machine data and virtual machine data, and whether it is a dual system is determined by dynamic detection;

[0092] Compliance data, activity data, and dual system data determine the health of the client according to the health index table;

[0093] Activity data is a dynamic indicator that is calculated and updated in real time, reflecting the real use of Xingcheng computers. From the unit or global perspective, it reflects the activity rate, i.e. the number of active terminals / access terminal number. From the individual perspective, it is divided into three states:

[0094] Inactive: no use in the past 30 days;

[0095] Active - qualified: no use in the past 15 days;

[0096] Low activity: no use in the past 7 days;

[0097] Active: normal use within the past 7 days;

[0098] Detect physical machine data, including Linux system information, Windows system information, UEFI boot items and GRUB configuration;

[0099] Detect virtual machine data, including VirtualBox virtual machine, VMware virtual machine and Phyvirt virtual environment;

[0100] Determine whether it is a dual system according to the physical machine data and virtual machine data, and deduct the health index in the health index table when it is a dual system;

[0101] The detection results are executed in the following steps:

[0102] Partition feature detection uses `fdisk-l` to obtain the disk partition list, judges whether there is an NTFS / FAT32 file system, and detects whether it contains multiple Windows typical files (such as `bootmgr`, `Windows / System32`, etc.), and determines that there is a Windows system when the number threshold is met.

[0103] Virtualization environment detection checks whether there is Phyvirt, VirtualBox, VMware and other virtualization software and its default installation directory in the system, and further identifies whether there is a configuration or system file with the word `windows`.

[0104] It includes reading scripts to obtain basic hardware and software parameters and dynamic behavior data according to the reading scripts;

[0105] Basic software and hardware parameters include machine model information, CPU information, operating system information, memory information, hard disk information, network information, and application installation data;

[0106] Dynamic behavior data includes power on / off record data, operation status monitoring data, mobile storage device plug-in and unplug record data, print task record data, application operation status record data and local cache data.

[0107] Reading the basic software and hardware parameters of the terminal by reading the script includes the following execution steps:

[0108] System model information: Execute the `sudodmidecode -tsystem` command to extract hardware identification information such as system manufacturer and product name.

[0109] CPU information: Use the `lscpu` command to collect processor model, architecture, number of cores, and other information.

[0110] Operating system information: Use the `hostnamectl` command first to obtain basic system information and adapt it to different domestic systems. The UOS system uses the ` / etc / os-version` file to obtain detailed version information, and the Kylin system uses the ` / etc / os-release` file to obtain version information.

[0111] Memory information: Use `sudodmidecode --typememory` command to extract detailed information such as memory slot, capacity, type, etc.

[0112] Hard disk information: Use the `sudofdisk -l` command to obtain the device name, capacity and other information of the physical disk.

[0113] Network information: Use the `ifconfig` command to collect the names, MAC addresses, IP addresses, etc. of all network interfaces.

[0114] Hard disk partition information: Use the `df -h` command to obtain file system mounting information and the usage of each partition.

[0115] Application installation information: Run the `dpkg-query` command to obtain metadata such as the name, version, and architecture of all installed applications in the system, and output them in a specific format for easy structured parsing.

[0116] Reading scripts to read dynamic behavior data includes the following execution steps:

[0117] Collect dynamic behavior data during equipment operation for system operation analysis and risk identification:

[0118] Power on / off log: Use `journalctl --list-boots` to obtain the device boot history and filter based on the last shutdown time to improve processing efficiency.

[0119] Operation status monitoring: Execute `top-b-n3-d1` to obtain key operation indicators such as the current operation load, CPU usage, and memory usage of the device.

[0120] Mobile storage device plug-in and unplug records: By analyzing the ` / var / log / kern.log` log file, extract the plug-in and unplug events of external storage devices such as USB flash drives, and perform incremental filtering based on the last recorded time.

[0121] Print task records: Parse the log files in the ` / var / spool / cups / ` directory to obtain historical print task information, and combine time filtering strategies to reduce unnecessary data scanning.

[0122] Application running status record: Continuously monitor the specified key application process. Get the matching process ID through `ps -ef`, combined with ` / proc / <pid>The / comm file extracts the start time and running time of the file, and realizes targeted data updating;

[0123] It should be particularly pointed out that all basic hardware and software parameters and dynamic behavior data are preferentially written into a local cache file, frequent uploading operations are reduced, system stability is improved, and bandwidth resource occupation is optimized;

[0124] The client information also includes the registered name, contact information, unit, and device location coordinates, and is supplemented into the client supervision data;

[0125] Install the asset management and control client of the national security terminal, and register in real name, the registration information includes name, contact information, unit, and device location, wherein the device location needs to be marked with geographic coordinates according to the address information;

[0126] Generate asset items according to the registration information;

[0127] Combine the terminal configuration information and running information collected by the client to form complete asset information, dynamic running information and safe use information, rely on the health index table to monitor and abnormally alarm the terminal asset;

[0128] Perfect the terminal asset supervision information through the client supervision data;

[0129] According to the collected client supervision data, the historical data of the client are matched in real time, and the client is detected and abnormally alarmed through the health index table;

[0130] The client generates a device unique ID and combines the current timestamp and key for AES encryption;

[0131] The server decrypts the key and verifies the legality of the device and time;

[0132] The client generates a device unique ID and combines the current timestamp and key to generate an api_key through AES encryption, the server decrypts the key and verifies the legality of the device and time, if the time deviation is too large, the calibration time is returned, and the client executes the sudo date command to complete local time synchronization.

[0133] The application also provides a national security terminal asset management and control system based on domestic substitution, comprising:

[0134] The collection module periodically sends a task list, and the collection module collects client information according to the task list, and collects dynamic behavior data in real time through the collection module;

[0135] The optimization module is used for decomposing the task list, and adjusting the task list according to the asynchronous task thread pool;

[0136] The supervision module is used to detect compliance data, activity data, and dual-system data, and to establish a health indicator table to monitor the client through the health indicator table;

[0137] Abnormal alarm: when the health indicator table is lower than the health threshold, an abnormal alarm will be issued.

[0138] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprise," "include," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.

[0139] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.< / pid>

Claims

1. A method for managing and controlling terminal assets based on domestic substitution, characterized in that: The following steps are involved: Collect client information regularly according to client tasks to improve terminal asset information data; Transferring the client task to an asynchronous thread pool, wherein the asynchronous thread pool dynamically adjusts and generates optimization measures according to the actual load; Collect dynamic behavior data during client operation; Aggregate terminal asset information data and dynamic behavior data to generate client supervision data; Analyze whether there is any illegal behavior in the client supervision data by dynamically detecting the client supervision data, and generate a detection report; Set up a health indicator table and use the test report to determine the health of the client; Set a health threshold and issue an abnormal warning if the health indicator threshold is lower than the threshold; The terminal asset information data and the dynamic behavior data are combined to dynamically monitor the client assets.

2. The method for managing and controlling terminal assets based on domestic substitution according to claim 1 is characterized in that: The server periodically sends the client task list according to the heartbeat mechanism; The client collects client supervision data according to the client task list; The client periodically sends heartbeat packets to the server, and the server returns a heartbeat response with a task list to ensure that the communication between the two parties is synchronized.

3. The method for managing and controlling terminal assets based on domestic substitution according to claim 2 is characterized in that: Decomposing the client task list into a plurality of client task queues; Set task queue thresholds; When the client task queue does not reach the threshold, the task data is processed normally; When the client task queue has reached the threshold, the server directly returns a response to inform the client that the task has not been processed and does not update the last execution time of the task to ensure that the task will be re-issued at the next heartbeat.

4. The method for managing and controlling credible terminal assets based on domestic substitution according to claim 3 is characterized in that: The client supervision data also includes compliance data, activity data, and dual system data; The compliance data includes the client's operating system and basic software and hardware parameters, and the compliance of the compliance data is verified through the dynamic detection; The activity data includes the frequency of client usage; The dual-system data includes physical machine data and virtual machine data, and whether it is a dual system is determined through the dynamic detection; The compliance data, activity data, and dual-system data are used to determine the health of the client according to the health index table.

5. The method for managing and controlling terminal assets based on domestic substitution according to claim 4 is characterized in that: The method also includes detecting physical machine data, wherein the physical machine data includes Linux system information, Windows system information, UEFI boot items, and GRUB configuration; Detecting virtual machine data, including VirtualBox virtual machines, VMware virtual machines, and Phyvirt virtual environments; Determine whether it is a dual system according to the physical machine data and the virtual machine data, and if it is a dual system, deduct the health level in the health index table.

6. The method for managing and controlling terminal assets based on domestic substitution according to claim 4 is characterized in that: The method further comprises reading a script, and obtaining the basic software and hardware parameters and the dynamic behavior data according to the reading script; The basic software and hardware parameters include machine model information data, CPU information data, operating system information data, memory information data, hard disk information data, network information and application installation data; The dynamic behavior data includes power on / off record data, operation status monitoring data, mobile storage device plug-in / out record data, print task record data, application operation status record data and local cache data.

7. The method for managing and controlling credible terminal assets based on domestic substitution according to claim 6 is characterized in that: The client information also includes the registered name, contact information, work unit, and device location coordinates, and the client information is added to the client supervision data.

8. The method for managing and controlling terminal assets based on domestic substitution according to claim 2 is characterized in that: Improve terminal asset supervision information through the client supervision data; The client's historical data is matched in real time according to the collected client supervision data, and the client is detected and abnormal warnings are issued through the health index table.

9. The method for managing and controlling credible terminal assets based on domestic substitution according to claim 8 is characterized in that: The client generates a unique device ID and performs AES encryption on it in combination with the current timestamp and key; The server decrypts the key and verifies the legitimacy of the device and time.

10. A system for controlling terminal assets based on domestic substitution is applied, characterized in that: include: A collection module that periodically sends a task list, collects client information based on the task list, and collects dynamic behavior data in real time through the collection module; An optimization module, the optimization module being used to decompose the task list and adjust the task list according to the asynchronous task thread pool; A supervision module, which is used to detect compliance data, activity data, and dual-system data, and to establish a health index table, through which the client is supervised; Abnormal alarm: when the health index table is lower than the health threshold, an abnormal alarm is issued.

Citation Information

Patent Citations

  • Data security management and control platform for credential terminal

    CN117201073A

  • Terminal security management system

    CN119996049A