System and method for remotely accessing overseas CRM by using public cloud, and storage medium

By reviewing requirements, selecting a suitable public cloud service provider, creating a virtual private network, and configuring security group rules and SSL/TLS encryption, the data transmission problems caused by cross-border network paths were resolved, ensuring system security and compliance, and improving user experience and system stability.

CN120956437APending Publication Date: 2025-11-14CHINA NAT BUILDING MATERIALS TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411667076.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-20
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

Existing systems, methods, and storage media for remotely accessing overseas CRMs via public clouds suffer from slow data transmission speeds and long response times due to long cross-border network paths, impacting user experience; data faces higher security risks during transmission; differences in data protection and privacy regulations across different countries and regions may lead to legal compliance issues; and version differences or interface incompatibility between existing enterprise systems and public cloud platforms may affect the stable operation of the system.

Method used

The requirements review unit ensures that project requirements comply with laws and regulations, selects a suitable public cloud service provider, creates a virtual private network, configures security group rules and SSL/TLS encryption, and conducts testing and verification to ensure the security and stability of the system.

Benefits of technology

It achieves encryption and compliance of data transmission, ensures system security and stability, prevents data leakage, meets the legal and regulatory requirements of different countries and regions, and reduces additional development and testing work.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956437A_ABST
    Figure CN120956437A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of cloud computing, in particular to a system and method for remotely accessing an overseas CRM by utilizing a public cloud and a storage medium. The system comprises a demand review unit which is used for ensuring that project demands meet business targets and laws and regulations through a demand analysis module and a compliance review module; the selection creation unit selects a public cloud service provider based on the project demand of the signal demand review unit, and creates a virtual private network; the security management unit starts SSL / TLS encryption and configures a virtual private network by configuring a security group rule based on the public cloud service provider selected by the selection creation unit, and is used for ensuring the security of remote access and the confidentiality of data transmission; the test verification unit tests the normal operation of the remote access function based on the security management unit, verifies the security and integrity of data transmission, and is used for ensuring the stability and reliability of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cloud computing technology, specifically to a system, method, and storage medium for remotely accessing overseas CRM systems using a public cloud. Background Technology

[0002] The system, methods, and storage media for remotely accessing overseas CRM systems via public cloud involve a series of advanced technologies and security measures, aiming to provide enterprises with an efficient and secure remote access solution. This system primarily relies on the rich resources and services provided by public cloud platforms, such as Virtual Private Cloud (VPC), Elastic Compute Service (ECS), and Object Storage Service (OSS). By constructing an isolated and secure network environment, employees located in different geographical locations can securely access CRM systems deployed overseas via the internet. Specifically, the method first establishes a VPC on the public cloud to simulate the enterprise's private network environment. Then, it restricts network traffic by setting security group rules and network ACLs to ensure that only authorized users and devices can access the CRM system. Simultaneously, encryption protocols such as SSL / TLS are used to encrypt the data transmission process to prevent the leakage of sensitive information. Furthermore, the API gateway service provided by the public cloud can be used to expose secure API interfaces, facilitating developers to call the functions of the CRM system. Regarding data storage, suitable storage media can be selected according to the characteristics and needs of the CRM system, such as using a relational database (RDS) to store structured customer data or using object storage (OSS) to store unstructured files. Throughout the process, it is also necessary to comply with relevant laws and regulations, implement strict data protection and privacy policies, and ensure the security and compliance of user data. In summary, this system and methodology combine the power of cloud computing, best practices in cybersecurity, and flexible data management strategies to provide an ideal remote access solution for globally operating enterprises.

[0003] Existing systems, methods, and storage media for remotely accessing overseas CRM systems via public clouds suffer from several drawbacks. Long cross-border network paths can lead to slow data transmission speeds and long response times, impacting user experience. Data transmission also faces higher security risks, requiring stricter encryption measures to protect sensitive information. Furthermore, different countries and regions have varying data protection and privacy regulations, necessitating that businesses ensure their operations comply with local laws and regulations to avoid fines or even business disruptions. Technical compatibility is also a significant issue, particularly when version differences or interface incompatibilities exist between the company's existing system and the public cloud platform, potentially requiring additional development and testing to ensure stable system operation. Therefore, this paper proposes a system, method, and storage media for remotely accessing overseas CRM systems via public clouds. Summary of the Invention

[0004] The purpose of this invention is to provide a system, method, and storage medium for remotely accessing overseas CRM systems via public cloud. This addresses the issues raised in the background section, such as: long cross-border network paths in existing systems, methods, and storage media for remotely accessing overseas CRM systems via public cloud can lead to slow data transmission speeds and long response times, impacting user experience; higher security risks during data transmission necessitate stricter encryption measures to protect sensitive information; and the different data protection and privacy regulations in different countries and regions require enterprises to ensure their operations comply with local laws and regulations to avoid fines or even business interruption. Furthermore, technology compatibility is a significant issue, especially when there are version differences or interface incompatibilities between the enterprise's existing system and the public cloud platform, potentially requiring additional development and testing to ensure stable system operation.

[0005] To achieve the above objectives, on the one hand, the present invention aims to provide a system for remotely accessing overseas CRM using a public cloud, including a requirements review unit. The requirements review unit uses a requirements analysis module and a compliance review module to ensure that project requirements meet both business objectives and legal and regulatory requirements.

[0006] The selection and creation unit, based on the project requirements of the signal requirements review unit, selects a public cloud service provider and creates a virtual private network;

[0007] The security management unit, based on the public cloud service provider selected by the selection and creation unit, ensures the security of remote access and the confidentiality of data transmission by configuring security group rules, enabling SSL / TLS encryption, and configuring virtual private networks.

[0008] The test and verification unit tests the normal operation of the remote access function based on the security management unit, verifies the security and integrity of data transmission, and is used to ensure the stability and reliability of the system.

[0009] As a further improvement to this technical solution, the requirement review unit includes a requirement analysis module and a compliance review module;

[0010] The requirements analysis module is used to determine the CRM system functions to be accessed, data sensitivity, and access frequency.

[0011] The compliance review module is used to ensure that operations comply with the laws and regulations of the country and region where the operation is located and the target country and region.

[0012] As a further improvement to this technical solution, the selection and creation unit selects a public cloud service provider and creates a virtual private network based on the project requirements of the signal requirement review unit. The specific steps for selecting a public cloud service provider and creating a virtual private network are as follows:

[0013] S3.1. Based on project requirements, evaluate the service characteristics of different cloud service providers;

[0014] These service characteristics include security, stability, cost-effectiveness, and geographic location.

[0015] S3.2 Select a public cloud service provider that meets the project requirements;

[0016] S3.3 Design a virtual private network architecture suitable for project requirements.

[0017] S3.4. Build a virtual private network on the selected cloud platform to ensure the security and isolation of the network environment.

[0018] As a further improvement to this technical solution, the specific steps in S3.4 for building a virtual private network on the selected cloud platform are as follows:

[0019] S3.41. Log in to the selected public cloud service platform;

[0020] S3.42. Enter the Virtual Private Network (VPN) management interface and create a VPN;

[0021] S3.43. Create multiple subnets within a virtual private network;

[0022] S3.44. Allocate a CIDR block for each subnet to ensure that the IP address ranges between subnets do not overlap;

[0023] S3.45. Associate a routing table with each subnet and add routing rules to ensure that the communication paths between subnets and between subnets and external networks are correct.

[0024] S3.46. Create a network ACL, define rules for allowing and denying inbound and outbound traffic, associate a network ACL with each subnet, and configure rules to ensure that authorized traffic can enter and leave the subnet;

[0025] S3.47. Check if the configuration of the Virtual Private Network, subnet, routing table, and network ACL is correct;

[0026] S3.48 Record detailed configuration information for virtual private networks, subnets, routing tables, and network ACLs;

[0027] S3.49. Complete the setup of the virtual private network.

[0028] As a further improvement to this technical solution, the security management unit, based on the public cloud service provider selected by the selection and creation unit, configures security group rules, enables SSL / TLS encryption, and configures a virtual private network to ensure the security of remote access and the confidentiality of data transmission. The specific steps for configuring security group rules, enabling SSL / TLS encryption, and configuring a virtual private network are as follows:

[0029] S5.1 Log in to the selected public cloud service platform, enter the security group management interface, and create a security group;

[0030] S5.2 Add inbound rules to define the traffic allowed into the security group;

[0031] S5.3 Add outbound rules to define the traffic allowed to originate from the security group;

[0032] S5.4 Obtain an SSL / TLS certificate and enable SSL / TLS encryption;

[0033] S5.4. Create and configure a virtual private network gateway on the cloud service platform;

[0034] S5.6 Install and configure the virtual private network client on the local device;

[0035] S5.7 Configure routing on the cloud platform and local devices to ensure that traffic is transmitted through virtual private network tunnels.

[0036] As a further improvement to this technical solution, the specific steps in S5.4 for obtaining the SSL / TLS certificate and enabling SSL / TLS encryption are as follows:

[0037] S5.41. Install an SSL / TLS certificate on the CRM system;

[0038] S5.42. Configure the web server to use the HTTPS protocol;

[0039] S5.43. Edit the web server's configuration file and enable SSL / TLS support;

[0040] S5.44. Configure the web server to ensure that all HTTP requests are redirected to HTTPS.

[0041] As a further improvement to this technical solution, the test verification unit tests the normal operation of the remote access function based on the security management unit, and verifies the security and integrity of data transmission to ensure system stability and reliability. The specific steps for testing the normal operation of the remote access function and verifying the security and integrity of data transmission are as follows:

[0042] S7.1 Ensure that security settings are configured in the test environment;

[0043] Security settings include security group rules, SSL / TLS encryption, and virtual private networks;

[0044] S7.2. Using different devices and network environments, try to connect to the CRM system via remote access.

[0045] S7.3 Test the access permissions of different users to ensure that authorized users have access to specific functions and data;

[0046] S7.4 Test whether the security settings are complete;

[0047] S7.5. Use the performance testing tool JMete to simulate a large number of concurrent users accessing the CRM system;

[0048] S7.6. Conduct long-term stress tests to ensure that the system remains stable during long-term operation.

[0049] As a further improvement to this technical solution, the specific steps for testing whether the security settings are complete in S7.4 are as follows:

[0050] S7.41. Use a browser to test the HTTPS connection to ensure that data transmission is encrypted;

[0051] S7.42. Use SSL scanning tools to detect weaknesses in SSL / TLS configurations;

[0052] S7.43. Attempt to access the CRM system from different IP addresses and devices to verify the validity of the security group rules;

[0053] S7.44. Connect from a local device to resources on the cloud platform via a virtual private network to verify the stability and speed of the connection.

[0054] On the other hand, the present invention provides a method for remotely accessing an overseas CRM using a public cloud, used in any of the above-described systems for remotely accessing an overseas CRM using a public cloud, comprising the following steps:

[0055] S9.1. The requirements analysis module and compliance review module are used to ensure that project requirements meet both business objectives and legal and regulatory requirements.

[0056] S9.2. Based on project requirements, select a public cloud service provider and create a virtual private network;

[0057] S9.3. By configuring security group rules, enabling SSL / TLS encryption, and configuring virtual private networks, the security of remote access and the confidentiality of data transmission can be ensured.

[0058] S9.4 Test the normal operation of the remote access function and verify the security and integrity of data transmission to ensure system stability and reliability.

[0059] On the other hand, the present invention provides a computer-readable storage device storing a computer program that, when executed by a processor, implements the steps of the method described in any one of the above-described embodiments.

[0060] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0061] 1. A system, method, and storage medium for remotely accessing overseas CRM systems using a public cloud. The system ensures the project's legality and compliance by checking whether the project requirements meet the legal and regulatory requirements of the host country or region, as well as the target country or region, particularly regarding data protection and personal privacy. Based on the project requirements, a suitable public cloud service provider is selected, and a virtual private network (VPN) is created to provide a foundation for subsequent security management and testing.

[0062] 2. A system, method, and storage medium for remotely accessing overseas CRM systems via public cloud. By configuring security group rules, enabling SSL / TLS encryption, and configuring a virtual private network, the security of remote access and the confidentiality of data transmission are ensured, preventing data leakage and unauthorized access. Comprehensive testing and verification ensure the system functions correctly, is secure and reliable, performs stably, and provides a good user experience, providing confidence and assurance for the system's final launch and use. Attached Figure Description

[0063] Figure 1 This is an overall flowchart of the present invention;

[0064] The meanings of the labels in the diagram are as follows:

[0065] 1. Requirements Review Unit; 2. Selection and Creation Unit; 3. Security Management Unit; 4. Testing and Verification Unit. Detailed Implementation

[0066] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0067] Example 1:

[0068] Please see Figure 1As shown, a system for remotely accessing overseas CRM using a public cloud is provided, including a requirements review unit 1. The requirements review unit 1 uses a requirements analysis module and a compliance review module to ensure that project requirements meet both business objectives and legal and regulatory requirements.

[0069] In this example, requirement review unit 1 includes a requirement analysis module and a compliance review module;

[0070] The requirements analysis module is used to determine the CRM system functions to be accessed, data sensitivity, and access frequency.

[0071] The compliance review module is used to ensure that operations comply with the laws and regulations of the country and region where the operation is located and the target country and region.

[0072] Specifically, the requirements analysis module clarifies the functions, data sensitivity, and access frequency of the CRM system to be accessed, ensuring clear and specific project requirements. The compliance review module ensures that operations comply with the laws and regulations of the current and target countries and regions, guaranteeing the project's legality and security. This provides a solid foundation for subsequent selection, creation, security management, and testing, ensuring the smooth implementation of the entire project and the system's stability and reliability.

[0073] The system for remotely accessing overseas CRM using a public cloud also includes a selection and creation unit 2, which selects a public cloud service provider and creates a virtual private network based on the project requirements of the signal requirements review unit 1.

[0074] In this example, if we select to create Unit 2 based on the project requirements of Unit 1 for signal requirement review, choose a public cloud service provider, and create a virtual private network, the specific steps for selecting a public cloud service provider and creating a virtual private network are as follows:

[0075] S3.1. Based on project requirements, evaluate the service characteristics of different cloud service providers;

[0076] These service characteristics include security, stability, cost-effectiveness, and geographic location.

[0077] S3.2 Select a public cloud service provider that meets the project requirements;

[0078] S3.3 Design a virtual private network architecture suitable for project requirements.

[0079] Specifically, a Virtual Private Network (VPN) is a network technology that creates a secure, encrypted connection over a public network (usually the internet), allowing users to transmit data as securely as if they were on a private network. The main purpose of a VPN is to protect the privacy and integrity of data, preventing it from being stolen or tampered with during transmission.

[0080] A virtual private network architecture includes clients, servers, tunnels, and network devices;

[0081] S3.4. Build a virtual private network on the selected cloud platform to ensure the security and isolation of the network environment.

[0082] In this example, the specific steps for building a virtual private network on the selected cloud platform are as follows:

[0083] S3.41. Log in to the selected public cloud service platform;

[0084] S3.42. Enter the Virtual Private Network (VPN) management interface and create a VPN;

[0085] S3.43. Create multiple subnets within a virtual private network;

[0086] S3.44. Allocate a CIDR block for each subnet to ensure that the IP address ranges between subnets do not overlap;

[0087] S3.45. Associate a routing table with each subnet and add routing rules to ensure that the communication paths between subnets and between subnets and external networks are correct.

[0088] S3.46. Create a network ACL, define rules for allowing and denying inbound and outbound traffic, associate a network ACL with each subnet, and configure rules to ensure that authorized traffic can enter and leave the subnet;

[0089] Specifically, a Network Access Control List (ACL) is a security mechanism that controls traffic entering and leaving a subnet at the network level. In a Network ACL, rules for allowing and denying inbound and outbound traffic can be defined, thereby controlling traffic within the subnet. A Network ACL is similar to a firewall, but it performs traffic control at the subnet level rather than the instance level.

[0090] S3.47. Check if the configuration of the Virtual Private Network, subnet, routing table, and network ACL is correct;

[0091] S3.48 Record detailed configuration information for virtual private networks, subnets, routing tables, and network ACLs;

[0092] S3.49. Complete the setup of the virtual private network.

[0093] Specifically, by logging into the selected public cloud service platform and creating and configuring VPCs and their subnets, routing tables, and network ACLs, network traffic can be effectively managed, ensuring that only authorized traffic can enter and leave the subnets, while guaranteeing the correct communication paths between subnets. This process provides a solid foundation for the secure operation of the system, preventing unauthorized access and data leakage, and ensuring the stability and reliability of remote access functions.

[0094] The system for remotely accessing overseas CRM using a public cloud also includes a security management unit 3. The security management unit 3, based on the public cloud service provider selected by the selection creation unit 2, configures security group rules, enables SSL / TLS encryption, and configures a virtual private network to ensure the security of remote access and the confidentiality of data transmission.

[0095] In this example, Security Management Unit 3, based on the public cloud service provider selected by Selection and Creation Unit 2, configures security group rules, enables SSL / TLS encryption, and configures a Virtual Private Network (VPN) to ensure the security of remote access and the confidentiality of data transmission. The specific steps for configuring security group rules, enabling SSL / TLS encryption, and configuring a VPN are as follows:

[0096] S5.1 Log in to the selected public cloud service platform, enter the security group management interface, and create a security group;

[0097] S5.2 Add inbound rules to define the traffic allowed into the security group;

[0098] Specifically, the entry rules are as follows:

[0099] For example, allowing access to specific ports (such as HTTP 80, HTTPS 443, SSH 22, etc.) from devices with specific IP addresses or IP ranges.

[0100] You can set the protocol type (TCP, UDP, ICMP, etc.), port number or port range, source IP address or security group.

[0101] S5.3 Add outbound rules to define the traffic allowed to originate from the security group;

[0102] Specifically, the exit rules are as follows:

[0103] By default, most cloud service providers allow all outbound traffic, but can impose restrictions as needed.

[0104] For example, only allow access to specific external services or IP addresses.

[0105] S5.4 Obtain an SSL / TLS certificate and enable SSL / TLS encryption;

[0106] In this example, the specific steps to obtain an SSL / TLS certificate and enable SSL / TLS encryption are as follows:

[0107] S5.41. Install an SSL / TLS certificate on the CRM system;

[0108] S5.42. Configure the web server to use the HTTPS protocol;

[0109] S5.43. Edit the web server's configuration file and enable SSL / TLS support;

[0110] Specifically, the process of editing the web server's configuration file to enable SSL / TLS support is as follows:

[0111] In Nginx, edit the nginx.conf file and add the following configuration:

[0112]

[0113] S5.44 Configure the web server to ensure that HTTP requests are redirected to HTTPS.

[0114] Specifically, the process of configuring a web server to ensure that all HTTP requests are redirected to HTTPS is as follows:

[0115] In Nginx, add the following configuration:

[0116]

[0117] Specifically, by installing SSL / TLS certificates on the CRM system and configuring the web server to use the HTTPS protocol, communication between the client and server can be encrypted, preventing data from being stolen or tampered with during transmission. Furthermore, by configuring the web server to redirect all HTTP requests to HTTPS, users are ensured to always access the CRM system through a secure connection, further enhancing system security. This process provides robust security for remote access functions, ensuring the integrity and privacy of user data.

[0118] S5.5. Create and configure a virtual private network gateway on the cloud service platform;

[0119] Specifically, virtual private network gateway types include IPSec, Open Virtual Private Network, or PPTP;

[0120] In AWS, create a customer gateway and a virtual private gateway, and establish a connection.

[0121] Configure the public IP address and pre-shared key of the customer gateway.

[0122] S5.6 Install and configure the virtual private network client on the local device;

[0123] Specifically, use the Open Virtual Private Network client to import the configuration file and connect to the virtual private network on the cloud platform.

[0124] Configure the client's connection parameters, such as server address, username, and password.

[0125] S5.7 Configure routing on the cloud platform and local devices to ensure that traffic is transmitted through virtual private network tunnels;

[0126] Specifically, in AWS, you configure routing tables to direct traffic from a specific subnet to a Virtual Private Network (VPN) connection.

[0127] Ensure that the routing table of the local device also contains the correct routing entries.

[0128] The system for remotely accessing overseas CRMs using a public cloud also includes a test and verification unit 4. The test and verification unit 4 tests the normal operation of the remote access function based on the security management unit 3, verifies the security and integrity of data transmission, and ensures the stability and reliability of the system.

[0129] In this example, test verification unit 4 tests the normal operation of the remote access function based on security management unit 3, and verifies the security and integrity of data transmission to ensure system stability and reliability. The specific steps for testing the normal operation of the remote access function and verifying the security and integrity of data transmission are as follows:

[0130] S7.1 Ensure that security settings are configured in the test environment;

[0131] Security settings include security group rules, SSL / TLS encryption, and virtual private networks;

[0132] S7.2. Using different devices and network environments, try to connect to the CRM system via remote access.

[0133] S7.3 Test the access permissions of different users to ensure that authorized users have access to specific functions and data;

[0134] S7.4 Test whether the security settings are complete;

[0135] In this example, the specific steps for testing whether the security settings are complete are as follows:

[0136] S7.41. Use a browser to test the HTTPS connection to ensure that data transmission is encrypted;

[0137] Specifically, the steps to test an HTTPS connection using a browser are as follows:

[0138] Open your browser:

[0139] Open your preferred web browser, such as Google Chrome, Mozilla Firefox, Microsoft Edge, etc.

[0140] Accessing the CRM system:

[0141] Enter the CRM system's URL in your browser's address bar, ensuring that the URL begins with https: / / ;

[0142] Check your browser's address bar:

[0143] Make sure a lock icon is displayed in your browser's address bar, indicating that the connection is secure.

[0144] Click the lock icon to view detailed connection information, including the SSL / TLS protocol version used, encryption algorithm, and certificate information.

[0145] View certificate information:

[0146] In the lock icon details, view the SSL / TLS certificate details, including the certificate issuer, validity period, domain name, etc.

[0147] Verify that the certificate was issued by a trusted Certificate Authority (CA) and is within its validity period.

[0148] Check network requests:

[0149] Use your browser's developer tools (usually you can open them by pressing F12 or right-clicking the page and selecting "Inspect").

[0150] Navigate to the "Network" tab, refresh the page, and observe the status of all network requests.

[0151] Confirm that all requests are made via HTTPS, and there are no HTTP requests.

[0152] Test data transmission:

[0153] Perform operations in the CRM system, such as logging in, submitting forms, and uploading files.

[0154] Monitor your browser's network requests to ensure that all data transmissions are made through encrypted connections.

[0155] Check response time:

[0156] Record the response time of each operation to ensure that encrypted connections do not significantly impact system performance.

[0157] S7.42. Use SSL scanning tools to detect weaknesses in SSL / TLS configurations;

[0158] Specifically, an SSL scanning tool is a specialized tool used to assess the security of a website's or application's SSL / TLS configuration. It helps users discover potential security risks and weaknesses by detecting and analyzing SSL / TLS certificates, encryption algorithms, protocol versions, and configuration vulnerabilities, thereby ensuring the security and confidentiality of data transmission. Commonly used SSL scanning tools include SSLLabs' SSL Test, Qualys' SSL Labs Scanner, and Nmap's SSL plugin. These tools provide detailed reports to help administrators optimize SSL / TLS configurations and improve system security.

[0159] S7.43. Attempt to access the CRM system from different IP addresses and devices to verify the validity of the security group rules;

[0160] S7.44. Connect from a local device to resources on the cloud platform via a virtual private network to verify the stability and speed of the connection.

[0161] Specifically, we test HTTPS connections using a browser to ensure data transmission is encrypted; we use SSL scanning tools to detect weaknesses in SSL / TLS configurations, identify and fix potential security issues; we attempt to access the CRM system from different IP addresses and devices to verify the effectiveness of security group rules, ensuring that only authorized traffic can enter and leave the subnet; and we connect from local devices to resources on the cloud platform via a virtual private network to verify the stability and speed of the connection, ensuring the security and reliability of remote access.

[0162] S7.5. Use the performance testing tool JMete to simulate a large number of concurrent users accessing the CRM system;

[0163] Specifically, JMeter is an open-source performance testing tool developed and maintained by the Apache Software Foundation. It is primarily used for performance testing of web applications, but can also be used to test other types of web applications and services. JMeter supports multiple protocols, including HTTP, HTTPS, FTP, TCP, JDBC, and JMS, and can simulate concurrent access to applications by multiple users, thereby evaluating the application's performance and stability.

[0164] S7.6. Conduct long-term stress tests to ensure that the system remains stable during long-term operation.

[0165] Specifically, by configuring security group rules, SSL / TLS encryption, and virtual private networks, the security settings of the test environment were ensured to be robust. Remote access functionality was tested using different devices and network environments to verify the access permissions of different users, ensuring that only authorized users could access specific functions and data. Simultaneously, performance testing tools (such as JMeter) were used to simulate a large number of concurrent user accesses and to conduct long-term stress tests, ensuring the system remained stable and reliable under high load and prolonged operation. This process provided solid confidence and assurance for the final deployment and use of the system.

[0166] Example 2:

[0167] The difference between Embodiment 2 and Embodiment 1 is that this embodiment introduces a static mechanical performance acquisition and analysis method used in a system that remotely accesses an overseas CRM via a public cloud.

[0168] A method for remotely accessing an overseas CRM using a public cloud, for use in any of the above-mentioned systems for remotely accessing an overseas CRM using a public cloud, includes the following steps:

[0169] S9.1. The requirements analysis module and compliance review module are used to ensure that project requirements meet both business objectives and legal and regulatory requirements.

[0170] S9.2. Based on project requirements, select a public cloud service provider and create a virtual private network;

[0171] S9.3. By configuring security group rules, enabling SSL / TLS encryption, and configuring virtual private networks, the security of remote access and the confidentiality of data transmission can be ensured.

[0172] S9.4 Test the normal operation of the remote access function and verify the security and integrity of data transmission to ensure system stability and reliability.

[0173] This invention provides a computer-readable storage device, characterized in that: the computer-readable storage device stores a computer program, which, when executed by a processor, implements the steps of the method described in any one of the above-mentioned embodiments.

[0174] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention.

Claims

1. A system for remotely accessing overseas CRM systems using a public cloud, characterized in that: include: The requirement review unit (1) uses the requirement analysis module and the compliance review module to ensure that the project requirements meet both business objectives and legal and regulatory requirements. The selection creation unit (2) selects a public cloud service provider and creates a virtual private network based on the project requirements of the signal requirements review unit (1); Security management unit (3), which, based on the public cloud service provider selected by the selection creation unit (2), configures security group rules, enables SSL / TLS encryption, and configures virtual private networks to ensure the security of remote access and the confidentiality of data transmission; The test verification unit (4) tests the normal operation of the remote access function based on the security management unit (3), verifies the security and integrity of data transmission, and is used to ensure the stability and reliability of the system.

2. The system for remotely accessing overseas CRM using a public cloud as described in claim 1, characterized in that: The requirement review unit (1) includes a requirement analysis module and a compliance review module; The requirements analysis module is used to determine the CRM system functions to be accessed, data sensitivity, and access frequency. The compliance review module is used to ensure that operations comply with the laws and regulations of the country and region where the operation is located and the target country and region.

3. The system for remotely accessing overseas CRM using a public cloud as described in claim 1, characterized in that: The selection and creation unit (2) selects a public cloud service provider and creates a virtual private network based on the project requirements of the signal requirements review unit (1). The specific steps for selecting a public cloud service provider and creating a virtual private network are as follows: S3.

1. Based on project requirements, evaluate the service characteristics of different cloud service providers; These service characteristics include security, stability, cost-effectiveness, and geographic location. S3.2 Select a public cloud service provider that meets the project requirements; S3.3 Design a virtual private network architecture suitable for project requirements. S3.

4. Build a virtual private network on the selected cloud platform to ensure the security and isolation of the network environment.

4. The system for remotely accessing overseas CRM using a public cloud as described in claim 3, characterized in that: In step S3.4, the specific steps for building a virtual private network on the selected cloud platform are as follows: S3.

41. Log in to the selected public cloud service platform; S3.

42. Enter the Virtual Private Network (VPN) management interface and create a VPN; S3.

43. Create multiple subnets within a virtual private network; S3.

44. Allocate a CIDR block for each subnet to ensure that the IP address ranges between subnets do not overlap; S3.

45. Associate a routing table with each subnet and add routing rules to ensure that the communication paths between subnets and between subnets and external networks are correct. S3.

46. Create a network ACL, define rules for allowing and denying inbound and outbound traffic, associate a network ACL with each subnet, and configure rules to ensure that authorized traffic can enter and leave the subnet; S3.

47. Check if the configuration of the Virtual Private Network, subnet, routing table, and network ACL is correct; S3.48 Record detailed configuration information for virtual private networks, subnets, routing tables, and network ACLs; S3.

49. Complete the setup of the virtual private network.

5. The system for remotely accessing overseas CRM using a public cloud as described in claim 1, characterized in that: The security management unit (3), based on the public cloud service provider selected by the selection and creation unit (2), configures security group rules, enables SSL / TLS encryption, and configures a virtual private network to ensure the security of remote access and the confidentiality of data transmission. The specific steps for configuring security group rules, enabling SSL / TLS encryption, and configuring a virtual private network are as follows: S5.1 Log in to the selected public cloud service platform, enter the security group management interface, and create a security group; S5.2 Add inbound rules to define the traffic allowed into the security group; S5.3 Add outbound rules to define the traffic allowed to originate from the security group; S5.4 Obtain an SSL / TLS certificate and enable SSL / TLS encryption; S5.

4. Create and configure a virtual private network gateway on the cloud service platform; S5.6 Install and configure the virtual private network client on the local device; S5.7 Configure routing on the cloud platform and local devices to ensure that traffic is transmitted through virtual private network tunnels.

6. The system for remotely accessing overseas CRM using a public cloud as described in claim 5, characterized in that: In S5.4, the specific steps for obtaining the SSL / TLS certificate and enabling SSL / TLS encryption are as follows: S5.

41. Install an SSL / TLS certificate on the CRM system; S5.

42. Configure the web server to use the HTTPS protocol; S5.

43. Edit the web server's configuration file and enable SSL / TLS support; S5.

44. Configure the web server to ensure that all HTTP requests are redirected to HTTPS.

7. The system for remotely accessing overseas CRM using a public cloud as described in claim 1, characterized in that: The test verification unit (4) tests the normal operation of the remote access function based on the security management unit (3), and verifies the security and integrity of data transmission to ensure the stability and reliability of the system. The specific steps for testing the normal operation of the remote access function and verifying the security and integrity of data transmission are as follows: S7.1 Ensure that security settings are configured in the test environment; Security settings include security group rules, SSL / TLS encryption, and virtual private networks; S7.

2. Using different devices and network environments, try to connect to the CRM system via remote access. S7.3 Test the access permissions of different users to ensure that authorized users have access to specific functions and data; S7.4 Test whether the security settings are complete; S7.

5. Use the performance testing tool JMete to simulate a large number of concurrent users accessing the CRM system; S7.

6. Conduct long-term stress tests to ensure that the system remains stable during long-term operation.

8. The system for remotely accessing overseas CRM using a public cloud as described in claim 7, characterized in that: In S7.4, the specific steps for testing whether the security settings are complete are as follows: S7.

41. Use a browser to test the HTTPS connection to ensure that data transmission is encrypted; S7.

42. Use SSL scanning tools to detect weaknesses in SSL / TLS configurations; S7.

43. Attempt to access the CRM system from different IP addresses and devices to verify the validity of the security group rules; S7.

44. Connect from a local device to resources on the cloud platform via a virtual private network to verify the stability and speed of the connection.

9. A method for remotely accessing an overseas CRM using a public cloud, used in a system for remotely accessing an overseas CRM using a public cloud as described in any one of claims 1-8, characterized in that: Includes the following steps: S9.

1. The requirements analysis module and compliance review module are used to ensure that project requirements meet both business objectives and legal and regulatory requirements. S9.

2. Based on project requirements, select a public cloud service provider and create a virtual private network; S9.

3. By configuring security group rules, enabling SSL / TLS encryption, and configuring virtual private networks, the security of remote access and the confidentiality of data transmission can be ensured. S9.4 Test the normal operation of the remote access function and verify the security and integrity of data transmission to ensure system stability and reliability.

10. A computer-readable storage device, characterized in that: The computer-readable storage device stores a computer program that, when executed by a processor, implements the steps of the method of claim 9.