Mobile terminal management and control method and system based on type-c interface

By integrating the Type-C interface with multiple security authentication and dynamic policy management, it solves the problems of complex deployment, offline loss of control, fragmented processes, and data insecurity in centralized management of mobile terminals, and achieves efficient and secure mobile terminal management and control, which is suitable for mobile terminal sharing and management in government, enterprise, finance, education and other industries.

CN121786866BActive Publication Date: 2026-05-05XIAN PLAIN NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
XIAN PLAIN NETWORK TECH CO LTD
Filing Date
2026-03-05
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Existing technologies for centralized management of mobile terminals suffer from problems such as complex deployment, loss of control offline, fragmented processes, and data insecurity. In particular, the application of the Type-C interface fails to deeply integrate power transmission, data communication, identity authentication, and policy management.

Method used

By integrating Type-C interface capabilities with multiple security authentication and dynamic policy management, a secure, convenient, and efficient mobile terminal management method is constructed. It utilizes RFID card ID and biometric technology for identity binding, enabling automated management and data erasure of mobile terminals, and supporting policy control for offline use.

Benefits of technology

It enables efficient and secure management of mobile terminals, improves user experience and management efficiency, ensures data security, and is suitable for mobile terminal sharing and management scenarios in government, enterprise, finance, education and other industries.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121786866B_ABST
    Figure CN121786866B_ABST
Patent Text Reader

Abstract

This invention belongs to the field of telecommunications technology, specifically relating to a mobile terminal management and control method based on a Type-C interface, comprising the following steps: mobile terminal access, initialization management, mobile terminal borrowing, offline use, and mobile terminal return. When the mobile terminal is accessed, no applications need to be pre-installed; management policies, application installation / uninstallation, and security rule configuration are directly issued via file transfer or protocol commands. When the mobile terminal is used offline, it operates based on a locally pre-built whitelist / blacklist mechanism and an encrypted cache. Upon return, it is automatically and forcibly synchronized to a designated location on the server and then completely cleared from the mobile terminal, effectively ensuring data security. The management system implementing the above management method includes a server, a mobile terminal, and a management device. The management device integrates a main control module, a Type-C physical interface, a USB controller, a data switch circuit, an RFID card scanning module, a network card module, a storage module, and a display and control module.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of telecommunications technology, specifically relating to a mobile terminal management method and system based on a Type-C interface. Background Technology

[0002] With the rapid development of mobile internet technology and the widespread adoption of smart mobile terminals, smartphones, tablets, and other mobile devices have become deeply integrated into various fields such as enterprise offices, education, and public services. In scenarios such as enterprises, schools, libraries, and conference rooms where a large number of mobile terminals need to be centrally managed and shared, how to achieve effective control, secure use, and efficient operation and maintenance of mobile terminals has become a critical technical problem that urgently needs to be solved.

[0003] Currently, centralized management of mobile terminals mainly adopts the following technical solutions, but each has its own limitations:

[0004] 1. A solution combining traditional charging cabinets with independent mobile terminal management software: This solution uses physical charging cabinets to provide centralized charging and storage for mobile terminals, while a separate Mobile Terminal Management (MDM) software system enables remote management of the mobile terminals. The MDM system requires a pre-installed agent application on the mobile terminal to distribute policies, manage applications, and monitor status via network connection. However, this solution has significant drawbacks: charging and management functions are separated, requiring users to perform physical access operations and digital management processes separately; the management process heavily relies on network connection quality and the active cooperation of the mobile terminal; the overall operation process is cumbersome, resulting in a poor user experience and low management efficiency.

[0005] 2. Pure software-based management solutions based on wireless networks: Some solutions attempt to remotely manage online mobile terminals via Wi-Fi or cellular networks. While this method achieves contactless management, its technical limitations are more pronounced: once a mobile terminal leaves the network environment, it immediately enters a management blind spot, unable to execute security policies or reclaim business data; for temporary users or external mobile terminals, they are required to first access a specific network and complete a complex registration process, resulting in excessively high access barriers; more importantly, this solution struggles to achieve accurate correspondence between the physical and digital identities of mobile terminals, leading to security risks such as mis-issuance of policies and mobile terminal impersonation.

[0006] 3. Charging management cabinets with basic data synchronization capabilities: A few high-end charging management cabinets provide basic data synchronization capabilities via wired interfaces such as USB while offering charging functionality. However, these solutions lack sophisticated identity authentication mechanisms and differentiated policy management functions. Their main problems are: inability to reliably authenticate mobile terminals and users; inability to dynamically configure differentiated application policies based on different usage scenarios and user roles; and difficulty in ensuring the complete erasure of user data after the mobile terminal is returned, posing a potential risk of privacy leaks.

[0007] At the same time, Type-C interface technology has developed rapidly and become increasingly popular. The Type-C interface integrates multiple technological advantages: it supports the USB PD protocol, which can provide up to 100W of power output to meet the fast charging needs of various mobile terminals; it supports USB 3.1 / 3.2 and Thunderbolt protocols, with a data transfer rate of up to 40Gbps, laying the foundation for large-capacity data exchange; it supports multiple backup modes and can expand video output and other functions; and it has a built-in USB-C Authentication protocol, which provides underlying support for mobile terminal identity authentication.

[0008] However, existing technologies for the Type-C interface are mostly limited to basic charging and data transmission functions. In the current field of centralized management of mobile terminals, it has failed to deeply integrate its complete protocol stack capabilities with the needs of mobile terminal management and control, and lacks systematic and innovative solutions to organically integrate core elements such as power transmission, data communication, identity authentication and policy management. Summary of the Invention

[0009] The technical problem to be solved by this invention is to overcome the shortcomings of the prior art and provide a mobile terminal management and control method based on the Type-C interface. By integrating Type-C interface capabilities with multiple security authentication and dynamic policy management, a centralized management and control method for mobile terminals that integrates security, convenience, efficiency and intelligence is constructed. This method effectively overcomes the defects of the prior art, such as complex deployment, offline loss of control, process fragmentation and data insecurity. It is suitable for mobile terminal sharing and management scenarios in government, enterprise, finance, education, medical and other industries with high requirements for mobile terminal and data security.

[0010] Another technical problem to be solved by the present invention is to provide a mobile terminal management system based on a Type-C interface for implementing the above-mentioned management method.

[0011] The technical solution adopted to solve the above technical problems is: a mobile terminal management and control method based on the Type-C interface, characterized by including the following steps:

[0012] Step 1: Mobile Terminal Access: The mobile terminal connects to the management device via a Type-C port. The management device negotiates standard charging with the connected mobile terminal to charge it. Simultaneously, the management device detects the mobile terminal connection event and initiates initial communication with the mobile terminal through a custom message or by utilizing a specific identifier from the USB enumeration process. The RFID card ID is obtained through RFID card scanning. The management device authenticates the mobile terminal based on the specific identifier and the RFID card ID. If authentication fails, an unauthorized mobile terminal is prompted to register and bind. The administrator then selects and binds the RFID card ID of the unauthorized mobile terminal. The user selects whether to select and bind the RFID card ID of the mobile terminal through the management device's touch interface. If no binding is selected, charging only occurs; if binding is selected, the administrator is contacted for authorization. If authentication is successful, the management device, without pre-installing an app, sends a simulated network login portal page or a special configuration description file to the mobile terminal via file synchronization, establishing a trust relationship between the mobile terminal and the management device.

[0013] Step 2, Initialization Management: This includes initialization of mobile terminal management, application management, and personnel management.

[0014] Step 3, Mobile Terminal Borrowing: The user initiates a request for a mobile terminal borrowing selection interface from the server through the identity authentication module on the control device. The control device sends the authentication information to the server for identity verification. If the verification is successful, it returns true and sends the mobile terminal borrowing selection interface to the control device. If the verification fails, it returns false. When the control device receives the verification information as true, it displays the mobile terminal borrowing selection interface, and the user selects the mobile terminal to borrow on the touch interface of the control device. When the received verification information is false, the user is prompted to bind fingerprint or facial information.

[0015] Step 4, Offline Use: The borrowed mobile terminal displays an application list based on the system whitelist / blacklist and the purpose of borrowing. When the user clicks to open the application, they are prompted to enter their username and password for identity verification. If the verification is successful, they will enter the corresponding interactive interface and establish an encrypted working cache area to record the user's operation records and logs.

[0016] Step 5, Mobile Terminal Return: This includes identity authentication, selection of mobile terminal to be returned, scanning of mobile terminal, status update, data synchronization, and data clearing.

[0017] The RFID card ID selection and binding method of this invention is as follows: The administrator requests the mobile terminal binding selection interface from the server through the management device. The server first performs identity authentication. After successful authentication, the server sends the mobile terminal binding selection interface to the management device. The administrator enters the mobile terminal hardware serial number and the scanned RFID card ID on the touch interface of the management device and submits it to the server. The server then binds the mobile terminal RFID card.

[0018] The mobile terminal management initialization of the present invention is as follows: the administrator binds the hardware serial number of the existing mobile terminal with the RFID card ID through the server;

[0019] The application management initialization process is as follows: the administrator sets up an application whitelist and blacklist, uploads applications to be installed, and configures the application data update policy through the server.

[0020] The personnel management initialization process is as follows: the administrator imports the user's basic information on the server, including at least the username, password, and unit; binds the user's fingerprint and facial information on the server for the control device to perform fingerprint or facial recognition; and sets the binding relationship between the application and the personnel on the server.

[0021] The mobile terminal borrowing selection interface of this invention includes meeting mode, exam mode, learning and practice mode, and work mode. Each mode requires requesting user permission verification from the server. If the verification is successful, it returns true; otherwise, it returns false. The control device judges the returned verification information. When the returned verification information is true, it initiates a data update request. When the returned verification information is false, it prompts insufficient permissions. When the server receives the data update request, it sends an update data packet according to the update strategy selected by the user. The control device receives the update data packet and sends it to the mobile terminal to be borrowed. After the mobile terminal data is updated, the lock of the corresponding mobile terminal is unlocked so that the user can borrow it. After the borrowing occurs, the control device feeds back the borrower and borrowing date information to the server. The server updates the mobile terminal information and updates the mobile terminal monitoring interface according to the borrowing information.

[0022] The identity authentication method of this invention is as follows: fingerprint information or facial information is collected by a control device. The control device transmits the collected authentication information to the server for identity authentication. If the authentication is successful, the control device is fed back a verification result of true and a borrowing list. If the authentication fails, the control device is fed back a verification result of false. When the feedback result is false, the control device prompts the user to register.

[0023] The mobile terminal return selection is as follows: when the server returns a result of true, the control device displays a mobile terminal return selection interface, the user selects one of the borrowing lists to perform the return operation, the control device opens the corresponding slot lock, and the user puts the mobile terminal into the corresponding slot.

[0024] The mobile terminal scanning process is as follows: The control device checks whether it can obtain the hardware serial number. If it cannot obtain the serial number, it prompts the user to connect via USB and checks again after connection. If the hardware serial number can be obtained, it determines whether the mobile terminal is to be returned. If the mobile terminal is determined to be to be returned, it scans the RFID card ID of the mobile terminal through the RFID card scanning module and sends the information of the mobile terminal to the server. If the mobile terminal is determined not to be returned, it prompts whether the mobile terminal should continue to be returned.

[0025] If the user selects "No" on the screen prompting whether to continue returning a mobile terminal that is not yet to be returned, it is determined that the user will not continue returning the current mobile terminal, and the user will be prompted whether to change the mobile terminal. If the user selects "Yes" on the screen prompting whether to continue returning a mobile terminal that is not yet to be returned, it is determined that the user will continue returning the current mobile terminal, and the RFID card ID of the mobile terminal will be scanned by the RFID card scanning module, and the information of the mobile terminal will be sent to the server.

[0026] If the user selects "Yes" when prompted to change the mobile terminal, it is determined that the mobile terminal has been changed, and the control device will re-enter the mobile terminal scanning process after the user changes the mobile terminal; if the user selects "No" when prompted to change the mobile terminal, it is determined that the mobile terminal will not be changed, and the return will be indicated as failed, ending the process.

[0027] When the server receives the mobile terminal return information, it determines whether it is registered based on the hardware serial number. If it is not registered, it is determined to be an illegal mobile terminal, and the user is prompted on the control device to contact the administrator if the illegal mobile terminal is not registered. If it is determined that the hardware serial number is registered but the RFID card ID is empty, the server records the mobile terminal abnormality log and sends a return success message. If the RFID card ID does not match the hardware serial number, the server records the mobile terminal abnormality log and sends a return success message.

[0028] The status update is as follows: after the mobile terminal is successfully returned, the on-site status of the mobile terminal and the mobile terminal status monitoring page are updated.

[0029] The data synchronization is as follows: the control device collects the business data of the returned mobile terminal into the cache area, packages it and uploads it to the server, and the server performs a global update on the data according to the synchronization strategy;

[0030] The data clearing process involves clearing the data and uninstalling applications from the returned mobile terminal after the data synchronization of the control device is completed.

[0031] A mobile terminal management and control system based on a Type-C interface includes a server, at least one management and control device, and at least one mobile terminal. The server and the management and control device communicate via a wired network, and the management and control device and the mobile terminal communicate via a Type-C physical interface.

[0032] The mobile terminal can receive policy files from the control device, manage blacklists, whitelists, and application lists, create encrypted temporary working cache areas, and upload data in the area or receive data clearing under the command of the control device.

[0033] The server is used to implement functions such as management log query, permission authentication, synchronization strategy formulation, data storage, data version control, application management, personnel management, and mobile terminal monitoring.

[0034] The control device includes a main control module, a Type-C physical interface, a USB controller, a data switch circuit, an RFID card scanning module, a network card module, a storage module, and a display and control module. The mobile terminal connects to the control device via the Type-C physical interface. The main control module uses the RFID card scanning module to obtain the RFID card ID and the USB controller to obtain the mobile terminal's hardware serial number. Combined with the mobile terminal registration information from the server, it controls the data switch circuit to selectively establish a data communication link with the connected mobile terminal. Management policies are then issued or data is transmitted through this link. The network card module is used for wired network connection between the control device and the server. The storage module is used for data transmission and caching during data synchronization. The display and control module provides interface display and human-computer interaction functions.

[0035] The control device of the present invention also includes a cabinet with several mobile terminal placement slots and a cabinet control module; the cabinet control module executes the commands issued by the main control module to control the opening of the corresponding placement slots and realizes linkage with the borrowing and returning operations of the mobile terminals.

[0036] The control device of the present invention is also equipped with an identity authentication module, which is used to realize the identity verification of users.

[0037] The identity authentication module of this invention includes a face recognition module and a fingerprint recognition module.

[0038] Compared with the prior art, the present invention has the following advantages:

[0039] 1. This invention combines the power transmission and high-speed data communication capabilities of the Type-C interface with radio frequency identification, biometric identification, and electronic lock control. Users only need to complete one identity authentication and selection operation to automatically complete the physical unlocking, policy configuration, and data pre-installation of the mobile terminal. When returning the device, it automatically completes data recovery, security erasure, and status reset. This invention overcomes the shortcomings of the existing technology that separates physical retrieval and digital management, and greatly improves management efficiency and user borrowing and returning experience.

[0040] 2. This invention utilizes a Type-C data link, eliminating the need for pre-installed applications when mobile terminals connect. Control policies, application installation / uninstallation, and security rule configuration are directly implemented via file transfer or protocol commands. When the mobile terminal is used offline, it operates based on a locally pre-configured whitelist / blacklist mechanism and encrypted cache. This avoids the tedious work of manually installing and configuring management clients on each mobile terminal, achieving zero-contact initialization and significantly reducing operation and deployment costs. Even when the mobile terminal has no network connection, its executable application scope and data storage behavior are still strictly controlled by pre-issued policies, effectively preventing unauthorized use and data leakage risks in offline states, filling the control blind spots of traditional networked MDM solutions.

[0041] 3. This invention binds the mobile terminal's hardware serial number, physical RFID card ID, and user biometrics on the server side, performing multiple cross-verifications at each stage of borrowing, use, and return. By binding the hardware serial number and RFID card ID as dual physical identifiers, it ensures that the mobile terminal retrieved from the cabinet strictly corresponds to the digital assets in the management system, effectively preventing unauthorized replacement or misplacement of the mobile terminal. Dynamically binding user identity, specific mobile terminal, usage scenario, and corresponding permissions ensures the accuracy of policy issuance and the clarity of data ownership. Logs containing the mobile terminal ID, user ID, and time are maintained at each stage of access, binding, borrowing, and return, providing complete evidence for security auditing and accountability.

[0042] 4. This invention supports defining independent modes for different usage purposes. Each mode includes specific application whitelists / blacklists, data synchronization policies, and security rules. Policies are dynamically issued when borrowing data and automatically trigger data synchronization and deletion upon return. A single system can meet the differentiated management needs of various mobile application scenarios within an organization, such as meetings, training, and examinations, improving mobile terminal utilization and management flexibility. User data is confined to an encrypted cache area while offline and is automatically and forcibly synchronized to a designated location on the server upon return, and then completely deleted from the mobile terminal. This ensures that business data is not stored on the ground and leaves no residue, effectively preventing the leakage of sensitive information on shared mobile terminals and achieving full lifecycle security management of data from generation and temporary storage to archiving and cleanup. Attached Figure Description

[0043] Figure 1 This is a flowchart of the present invention.

[0044] Figure 2 yes Figure 1 A flowchart for the return of China Mobile terminals.

[0045] Figure 3 This is a schematic diagram of the control system of the present invention.

[0046] Figure 4This is a schematic diagram of the control device of the present invention. Detailed Implementation

[0047] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments, but the present invention is not limited to these embodiments.

[0048] Example 1

[0049] exist Figure 1 The present invention relates to a mobile terminal management and control method based on a Type-C interface, comprising the following steps:

[0050] Step 1, Mobile Terminal Access: The mobile terminal connects to the management device via the Type-C port. The management device negotiates standard charging with the connected mobile terminal and charges it. At the same time, the management device detects the mobile terminal connection event and initiates initial communication with the mobile terminal through a custom message or by using a specific identifier from the USB enumeration process. The management device's RFID card scanning module starts RFID scanning and scans the RFID card attached to the back of the mobile terminal to obtain the RFID card ID. The management device then authenticates the mobile terminal based on the specific identifier and the RFID ID.

[0051] If authentication fails, a message will appear prompting the administrator to register and bind the illegally accessed mobile terminal. If the operator is an administrator, the RFID card ID of the illegally accessed mobile terminal will be selected for binding. If the operator is a user, the user can select whether to select and bind the RFID card ID of the mobile terminal through the touch interface of the control device. If no binding is selected, charging will only proceed. If binding is selected, the user must contact the administrator for authorization. Specifically, the RFID card ID binding process is as follows: The administrator requests the mobile terminal binding selection interface from the server through the control device. The server first performs identity authentication. After successful authentication, the server sends the mobile terminal binding selection interface to the control device. The administrator enters the hardware serial number of the mobile terminal to be bound and the scanned RFID card ID on the touch interface of the control device and submits it to the server to complete the binding. The server performs the RFID card binding of the mobile terminal. Only the administrator has binding authority in this step. Users need to contact the administrator for authorization when binding their own mobile terminals.

[0052] If authentication is successful, the control device does not need to pre-install an app. It sends a simulated network login portal page or a special configuration description file to the mobile terminal through the file synchronization function, and the mobile terminal establishes a trust relationship with the control device.

[0053] Taking the conference mode as an example, the control device establishes a USB data connection with the mobile terminal and uses the MTP / PTP file transfer function to push a simulated Wi-Fi authentication portal page file to the mobile terminal's download directory. When the user opens this file on the mobile terminal, the page prompts that the mobile terminal has been authorized to access the control network and guides the user to click to confirm, thereby establishing initial trust.

[0054] Step 2, Initialization Management: This includes initialization of mobile terminal management, application management, and personnel management.

[0055] The mobile terminal management initialization described above is as follows: the administrator binds the hardware serial number of the existing mobile terminal with the RFID card ID through the server.

[0056] The application management initialization described above involves the administrator setting up an application whitelist and blacklist, uploading applications to be installed, and configuring application data update policies via the server.

[0057] The above personnel management initialization is as follows: the administrator imports the user's basic information on the server, including at least the username, password, and unit; binds the user's fingerprint and facial information on the server for the control device to perform fingerprint or facial recognition; and sets the binding relationship between the application and the personnel on the server.

[0058] Step 3, Mobile Terminal Borrowing: The user initiates a request for a mobile terminal borrowing selection interface from the server via the authentication module. The control device sends authentication information to the server for identity verification. If the verification is successful, the server returns true and sends the mobile terminal borrowing selection interface to the control device; if the verification fails, the server returns false. When the control device receives true verification information, it displays the mobile terminal borrowing selection interface. The user selects the mobile terminal to borrow on the control device's touch interface. The control device initializes the selected mobile terminal. The server sends the whitelist of applications to be bound and the applications to be added to the blacklist to the control device. After receiving the application whitelist, the control device performs application installation, upgrade, and whitelist update operations on the selected mobile terminal. After receiving the application blacklist, it performs application uninstallation and blacklist update operations on the selected mobile terminal. After the mobile terminal initialization is complete, the control device unlocks the lock of the corresponding mobile terminal storage location. After the user takes out the mobile terminal and closes the lock, the system will prompt the user that the borrowing is complete and send borrowing information to the server.

[0059] Taking the meeting mode as an example, the administrator selects and binds applications to the meeting mode to a whitelist, such as office software WPS, meeting software Tencent Meeting, and an internal browser, while blacklisting game applications. The server sends a data package containing the whitelisted application installation packages, configuration policy files, and the blacklist list to the control device. The control device automatically and silently installs or updates the whitelisted applications on the mobile terminal SN123456 via a USB data link, uninstalls the blacklisted applications, and writes the whitelist policy into the mobile terminal's control configuration file, restricting users to running only the whitelisted applications.

[0060] If the received verification message is false, the user is prompted to bind their fingerprint or facial information.

[0061] Furthermore, the mobile terminal borrowing selection interface includes meeting mode, exam mode, study / practice mode, and work mode. Each mode requires requesting user permission verification from the server. If the verification is successful, it returns true; otherwise, it returns false. The control device judges the returned verification information. When the verification information is true, it initiates a data update request. When the verification information is false, it prompts insufficient permissions. When the server receives the data update request, it sends an update data packet according to the update strategy selected by the user. The control device receives the update data packet and sends it to the mobile terminal to be borrowed. After the mobile terminal data is updated, the lock of the corresponding mobile terminal is unlocked for the user to borrow. After the borrowing occurs, the control device feeds back the borrower and borrowing date information to the server. The server updates the mobile terminal information and updates the mobile terminal monitoring interface according to the borrowing information.

[0062] Taking the meeting mode as an example, before the meeting begins, user A arrives at the control device to borrow a device. He first presses his registered fingerprint on the device's authentication module. The control device sends the fingerprint information to the server for verification. Upon successful verification, the server simultaneously returns a list of mobile terminals that user A is authorized to borrow. The control device screen displays a mobile terminal borrowing selection interface, which includes the borrowable mobile terminal SN123456 and its corresponding meeting mode option. User A selects SN123456 and the meeting mode on the touch interface and clicks confirm. The server receives the request, verifies that user A has meeting mode permissions, and then sends a mobile terminal initialization command and a final data update package for the meeting mode, such as the latest meeting materials, to the control device. Upon receiving the mobile terminal initialization command, the control device performs the initialization operation. After completion, it synchronizes the received data packet to the designated directory of mobile terminal SN123456 via a Type-C data connection. After synchronization, the control device's main control module sends a command to the cabinet control module to unlock the physical slot lock containing the mobile terminal. When User A retrieves the mobile terminal, the control device uploads information such as borrower: User A, borrowing time: 2026-01-27 09:00, mobile terminal: SN123456, mode: conference mode to the server. The server then updates the monitoring status of the mobile terminal to "borrowed".

[0063] Step 4, Offline Use: The borrowed mobile terminal displays an application list based on the system's whitelist / blacklist and the purpose of borrowing. When the user clicks to open the application, they are prompted to enter their username and password for identity verification. If the verification is successful, they enter the corresponding interactive interface and establish an encrypted working cache area to record the user's operation records and logs.

[0064] Taking the meeting mode as an example, when user A uses the mobile terminal during a meeting, he finds that only three application icons are displayed on the desktop: WPS, Tencent Meeting, and the internal browser. When he clicks to open Tencent Meeting, the application first pops up an authentication window, requiring him to enter a unified meeting system account and password. After user A enters the information and passes the authentication, he can enter the meeting normally. During the meeting, he uses WPS to view documents and make annotations. All these operation logs and annotation files are temporarily saved in an encrypted cache area on the mobile terminal.

[0065] Step 5, Return the mobile device: (e.g.) Figure 2 As shown, mobile terminal return also includes identity authentication, mobile terminal selection, mobile terminal scanning, status update, data synchronization, and data clearing.

[0066] The above identity authentication is as follows: the control device collects fingerprint information or facial information, and the control device transmits the collected authentication information to the server for identity authentication. If the authentication is successful, the control device is fed back a verification result of true and a borrowing list. If the authentication fails, the control device is fed back a verification result of false. When the feedback result is false, the control device prompts the user to register.

[0067] The above mobile terminal return selection is as follows: when the server returns a result of true, the control device displays the mobile terminal return selection interface, the user selects one of the borrowing lists to perform the return operation, the control device opens the corresponding slot lock, and the user puts the mobile terminal into the corresponding slot;

[0068] The mobile terminal scanning process is as follows: the hardware serial number of the mobile terminal is obtained through the USB controller. The control device checks whether the hardware serial number can be obtained. If it cannot be obtained, the user is prompted to connect via USB. After connection, the device checks again. If the hardware serial number can be obtained, it determines whether the mobile terminal is to be returned. If the mobile terminal is determined to be to be returned, the RFID card ID of the mobile terminal is scanned through the RFID card scanning module, and the information of the mobile terminal is sent to the server. If the mobile terminal is determined not to be returned, the user is prompted whether to continue returning the mobile terminal.

[0069] If the user selects "No" on the screen prompting whether to continue returning a mobile terminal that is not yet to be returned, it is determined that the user will not continue returning the current mobile terminal, and the user will be prompted whether to change the mobile terminal. If the user selects "Yes" on the screen prompting whether to continue returning a mobile terminal that is not yet to be returned, it is determined that the user will continue returning the current mobile terminal, and the RFID card ID of the mobile terminal will be scanned by the RFID card scanning module, and the information of the mobile terminal will be sent to the server.

[0070] If the user selects "Yes" when prompted to change the mobile terminal, it is determined that the mobile terminal has been changed, and the control device will re-enter the mobile terminal scanning process after the user changes the mobile terminal; if the user selects "No" when prompted to change the mobile terminal, it is determined that the mobile terminal will not be changed, and the return will be indicated as failed, ending the process.

[0071] When the server receives the mobile terminal return information, it determines whether it is registered based on the hardware serial number. If it is not registered, it is determined to be an illegal mobile terminal, and the user is prompted on the control device to contact the administrator if the illegal mobile terminal is not registered. If it is determined that the hardware serial number is registered but the RFID card ID is empty, the server records the mobile terminal abnormality log and sends a return success message. If the RFID card ID does not match the hardware serial number, the server records the mobile terminal abnormality log and sends a return success message.

[0072] The above status update is as follows: After the mobile terminal is successfully returned, the mobile terminal's location status and the mobile terminal status monitoring page will be updated.

[0073] The above data synchronization is as follows: the control device collects the business data of the returned mobile terminal into the cache area, packages it and uploads it to the server, and the server performs a global update of the data according to the synchronization strategy;

[0074] The above data clearing refers to the process of clearing the data and uninstalling applications from the returned mobile terminal after the data synchronization of the control device is completed.

[0075] Taking the meeting mode as an example, after the meeting, User A returns the mobile terminal. First, he authenticates with his fingerprint on the control device. After successful verification by the server, it returns User A's current borrowing list, including SN123456, to the control device. The control device's touchscreen displays a mobile terminal return selection interface. User A selects SN123456 for return, the lock on the corresponding slot unlocks, and User A places the mobile terminal in and connects it to the Type-C interface. The control device successfully reads the mobile terminal's hardware serial number SN123456 via the USB controller and determines that the mobile terminal is on the return list. Subsequently, the RFID card scanning module reads the RFID card ID on the back of the mobile terminal. The control device sends SN123456 and the RFID card ID to the server. The server checks and finds that the two are bound, indicating a successful match. Next, the control device initiates a data synchronization process: via USB data connection, it compresses and packages all document annotation records, application logs, and other data generated by User A during the meeting within the mobile terminal's buffer area, transmits them temporarily to the control device's storage module, and then uploads them to the server. According to the preset meeting mode synchronization strategy, the server archives this data to user A's personal meeting record directory. After data synchronization is complete, the control device sends a data clearing command to the mobile terminal: clear the business data generated during this borrowing in the buffer area and uninstall a specific plugin temporarily installed during this meeting. Finally, the control device reports the return to the server. The server updates the mobile terminal's status to be available and displays on the monitoring page that the mobile terminal has been returned, and the control device prepares to receive the next borrowing request.

[0076] This embodiment further illustrates the handling method when encountering an abnormal mobile terminal during the return process. Suppose user A returns a mobile terminal, and the control device scans its hardware serial number as SN888999. However, this mobile terminal is not found in user A's borrowed list returned by the server. The control device's touch interface displays: "Mobile terminal SN888999 detected is not your mobile terminal to be returned. Do you want to continue returning it?" User A realizes they may have mistakenly taken a colleague's mobile terminal and selects "No." The screen then prompts: "Do you want to change the mobile terminal?" User A selects "Yes," retrieves mobile terminal SN888999, and replaces it with their borrowed mobile terminal SN123456, placing it in the slot. The control device re-enters the mobile terminal scanning process, successfully identifying SN123456 as the mobile terminal to be returned, and continues to complete the normal return, data synchronization, and clearing process.

[0077] If user A chooses to continue returning mobile terminal SN888999, the corresponding slot will be locked. The returned mobile terminal SN888999 will be scanned for its RFID card, and its information will be sent to the server. When the server receives the mobile terminal return information, if SN888999 is not registered, it will indicate an illegal mobile terminal and request the administrator to contact them. If the hardware serial number SN888999 is already in the server's registration database, but the RFID card ID is empty or does not match the bound hardware serial number, the server will record a mobile terminal anomaly log after receiving the anomaly information reported by the control device: "Mobile terminal SN888999 attempted to be returned by an unbound user; RFID information is abnormal," and will notify the administrator to check. Simultaneously, to avoid blocking the return process, the server will still send a return success command to the control device to complete the mobile terminal recycling, but will mark the mobile terminal's status as abnormal and pending verification in the background.

[0078] like Figure 3 As shown, the mobile terminal management system based on the Type-C interface that implements the above management method includes a server, at least one management device, and at least one mobile terminal. In practice, there can be multiple management devices, and each management device can be equipped with multiple mobile terminals. The server and the management device communicate through a wired network connection, and the management device and the mobile terminal communicate through a Type-C physical interface connection.

[0079] The aforementioned mobile terminal is a tablet computer or mobile phone, etc. This terminal can receive policy files issued by the control device and restrict the installation and operation of applications accordingly, i.e., a whitelist / blacklist mechanism. It can create an encrypted temporary working cache area and can upload data in this area or accept data clearing under the instruction of the control device.

[0080] The aforementioned servers are deployed in the data center to implement functions such as management log querying, access authentication, synchronization policy formulation, data storage, data version control, application management, personnel management, and mobile terminal monitoring. The servers have a database to store the hardware serial numbers of all mobile terminals, bound RFID card IDs, bound personnel information, application whitelists / blacklists, various policy modes, synchronized user data, operation logs, etc. A web management interface is provided for administrators to perform comprehensive management of mobile terminals, personnel, applications, and policies.

[0081] like Figure 4As shown, the control device in this embodiment is a physical cabinet that integrates a main control module, a Type-C physical interface, a USB controller, a data switch circuit, an RFID card scanning module, a network card module, a storage module, and a display and control module. The mobile terminal connects to the control device via the Type-C physical interface. The main control module uses the RFID card scanning module to obtain the RFID card ID and the USB controller to obtain the mobile terminal's hardware serial number. Combined with the mobile terminal registration information from the server, it controls the data switch circuit to selectively establish a data communication link with the connected mobile terminal. Management policies are then issued or data is transmitted through this link. Specifically, all Type-C interfaces are connected to the USB controller via the data switch circuit. The main control module can control the on / off state of the switches via a program, thus selectively establishing data communication with a specific mobile terminal or simply charging it. The network card module is used for wired network connection between the control device and the server. The storage module is used for data transmission and caching during data synchronization. The display and control module provides the interface display and human-computer interaction functions.

[0082] The control device also includes a cabinet control module and an identity authentication module. The cabinet control module controls the electromagnetic lock of each storage slot, executes commands issued by the main control module to open the corresponding storage slot, and is linked with the borrowing and returning operations of the mobile terminal. The identity authentication module is used to verify the user's identity, including a facial recognition module and a fingerprint recognition module.

[0083] The working principle of this invention is as follows:

[0084] The mobile terminal is placed in the slot of the control device and automatically connects to the Type-C interface. Administrators register mobile terminal information, bind users, and formulate policies on the server side. When a user borrows a device, they complete identity authentication and select the mobile terminal through the authentication module and the control device's touchscreen. The server verifies permissions and sends policies and data to the control device, which then injects them into the target mobile terminal via the corresponding Type-C data link and unlocks it. Users work offline using the mobile terminal, with all data temporarily stored in a local cache. When returning the device, the user is re-authenticated and placed back in the mobile terminal. The control device automatically recognizes the mobile terminal, retrieves the cached data to the server via the Type-C data link, clears the mobile terminal, and finally updates its status. The entire process requires no additional app installation or complex settings on the mobile terminal, achieving secure and convenient centralized mobile terminal management.

Claims

1. A mobile terminal management and control method based on a Type-C interface, characterized in that: Includes the following steps: Step 1: Mobile Terminal Access: The mobile terminal connects to the management device via the Type-C port. The management device negotiates standard charging with the connected mobile terminal to charge it. Simultaneously, the management device detects the mobile terminal connection event and initiates initial communication with the mobile terminal through a custom message or by using a specific identifier from the USB enumeration process. The RFID card ID is obtained through RFID card scanning. The management device authenticates the mobile terminal based on the specific identifier and the RFID card ID. If authentication fails, it prompts an unauthorized mobile terminal access request for registration and binding. The administrator then selects and binds the RFID card ID of the unauthorized mobile terminal. The user selects whether to select and bind the RFID card ID of the mobile terminal through the touch interface of the management device. If no binding is selected, charging will only proceed. If binding is selected, the user will contact the administrator for authorization. If authentication is successful, the control device does not need to pre-install an App. It sends a simulated network login portal page or a special configuration description file to the mobile terminal through the file synchronization function, and the mobile terminal establishes a trust relationship with the control device. The RFID card ID selection and binding process is as follows: The administrator requests the mobile terminal binding selection interface from the server through the management device. The server first performs identity authentication. After successful authentication, the server sends the mobile terminal binding selection interface to the management device. The administrator enters the mobile terminal hardware serial number and the scanned RFID card ID on the touch interface of the management device and submits it to the server. The server then binds the mobile terminal RFID card. Step 2, Initialization Management: This includes initialization of mobile terminal management, application management, and personnel management. Step 3, Mobile Terminal Borrowing: The user initiates a request for a mobile terminal borrowing selection interface from the server through the identity authentication module on the control device. The control device sends the authentication information to the server for identity verification. If the verification is successful, it returns true and sends the mobile terminal borrowing selection interface to the control device. If the verification fails, it returns false. When the control device receives the verification information as true, it displays the mobile terminal borrowing selection interface, and the user selects the mobile terminal to borrow on the touch interface of the control device. When the received verification information is false, the user is prompted to bind fingerprint or facial information. Step 4, Offline Use: The borrowed mobile terminal displays an application list based on the system whitelist / blacklist and the purpose of borrowing. When the user clicks to open the application, they are prompted to enter their username and password for identity verification. If the verification is successful, they will enter the corresponding interactive interface and establish an encrypted working cache area to record the user's operation records and logs. Step 5, Mobile Terminal Return: This includes identity authentication, selection of mobile terminal to be returned, scanning of mobile terminal, status update, data synchronization, and data clearing.

2. The mobile terminal management and control method based on the Type-C interface according to claim 1, characterized in that, The mobile terminal management initialization is as follows: the administrator binds the hardware serial number of the existing mobile terminal with the RFID card ID through the server; The application management initialization process is as follows: the administrator sets up an application whitelist and blacklist, uploads applications to be installed, and configures the application data update policy through the server. The personnel management initialization process is as follows: the administrator imports the user's basic information on the server, including at least the username, password, and unit; binds the user's fingerprint and facial information on the server for the control device to perform fingerprint or facial recognition; and sets the binding relationship between the application and the personnel on the server.

3. The mobile terminal management and control method based on the Type-C interface according to claim 1, characterized in that: The mobile terminal borrowing selection interface includes meeting mode, exam mode, study mode, and work mode. Each mode requires requesting user permission verification from the server. If the verification is successful, it returns true; otherwise, it returns false. The control device judges the returned verification information. When the returned verification information is true, it initiates a data update request. When the returned verification information is false, it prompts insufficient permissions. When the server receives a data update request, it sends an update data packet according to the update strategy selected by the user. The control device receives the update data packet and sends it to the mobile terminal to be borrowed. After the mobile terminal data is updated, the lock of the corresponding mobile terminal is unlocked so that the user can borrow it. After a borrowing occurs, the control device sends the borrower and borrowing date information back to the server. The server then updates the mobile terminal information and updates the mobile terminal monitoring interface based on the borrowing information.

4. The mobile terminal management and control method based on the Type-C interface according to claim 1, characterized in that, The identity authentication is as follows: the control device collects fingerprint information or facial information, and the control device transmits the collected authentication information to the server for identity authentication. If the authentication is successful, the control device is fed back a verification result of true and a borrowing list. If the authentication fails, the control device is fed back a verification result of false. When the feedback result is false, the control device prompts the user to register. The mobile terminal return selection is as follows: when the server returns a result of true, the control device displays a mobile terminal return selection interface, the user selects one of the borrowing lists to perform the return operation, the control device opens the corresponding slot lock, and the user puts the mobile terminal into the corresponding slot. The mobile terminal scanning process is as follows: The control device checks whether it can obtain the hardware serial number. If it cannot obtain the serial number, it prompts the user to connect via USB and checks again after connection. If the hardware serial number can be obtained, it determines whether the mobile terminal is to be returned. If the mobile terminal is determined to be to be returned, it scans the RFID card ID of the mobile terminal through the RFID card scanning module and sends the information of the mobile terminal to the server. If the mobile terminal is determined not to be returned, it prompts whether the mobile terminal should continue to be returned. If the user selects "No" on the screen prompting whether to continue returning a mobile terminal that is not yet to be returned, it is determined that the user will not continue returning the current mobile terminal, and the user will be prompted whether to change the mobile terminal. If the user selects "Yes" on the screen prompting whether to continue returning a mobile terminal that is not yet to be returned, it is determined that the user will continue returning the current mobile terminal, and the RFID card ID of the mobile terminal will be scanned by the RFID card scanning module, and the information of the mobile terminal will be sent to the server. When the user selects "yes" on the prompt screen asking whether to change the mobile terminal, it is determined that the mobile terminal has been changed. After the user changes the mobile terminal, the control device will re-enter the mobile terminal scanning process. When the user selects "No" on the screen prompting whether to change the mobile device, it is determined that the user does not want to change the mobile device, and a message indicating return failure is displayed, ending the process. When the server receives the mobile terminal return information, it determines whether it is registered based on the hardware serial number. If it is not registered, it is determined to be an illegal mobile terminal, and the user is prompted on the control device to contact the administrator if the illegal mobile terminal is not registered. If it is determined that the hardware serial number is registered but the RFID card ID is empty, the server records the mobile terminal abnormality log and sends a return success message. If the RFID card ID does not match the hardware serial number, the server records the mobile terminal abnormality log and sends a return success message. The status update is as follows: after the mobile terminal is successfully returned, the on-site status of the mobile terminal and the mobile terminal status monitoring page are updated. The data synchronization is as follows: the control device collects the business data of the returned mobile terminal into the cache area, packages it and uploads it to the server, and the server performs a global update on the data according to the synchronization strategy; The data clearing process involves clearing the data and uninstalling applications from the returned mobile terminal after the data synchronization of the control device is completed.

5. A mobile terminal management system based on a Type-C interface, applied to the mobile terminal management method based on a Type-C interface as described in any one of claims 1 to 4, characterized in that: It includes a server, at least one control device, and at least one mobile terminal. The server and the control device communicate via a wired network, and the control device and the mobile terminal communicate via a Type-C physical interface. The mobile terminal can receive policy files from the control device, manage blacklists, whitelists, and application lists, create encrypted temporary working cache areas, and upload data in the area or receive data clearing under the command of the control device. The server is used to implement functions such as management log query, permission authentication, synchronization strategy formulation, data storage, data version control, application management, personnel management, and mobile terminal monitoring. The control device includes a main control module, a Type-C physical interface, a USB controller, a data switch circuit, an RFID card scanning module, a network card module, a storage module, and a display and control module. The mobile terminal connects to the control device via the Type-C physical interface. The main control module uses the RFID card scanning module to obtain the RFID card ID and the USB controller to obtain the mobile terminal's hardware serial number. Combined with the mobile terminal registration information from the server, it controls the data switch circuit to selectively establish a data communication link with the connected mobile terminal. Management policies are then issued or data is transmitted through this link. The network card module is used for wired network connection between the control device and the server. The storage module is used for data transmission and caching during data synchronization. The display and control module provides interface display and human-computer interaction functions.

6. The mobile terminal management and control system based on the Type-C interface according to claim 5, characterized in that: The control device also includes a cabinet with several mobile terminal placement slots and a cabinet control module; the cabinet control module executes commands issued by the main control module to control the opening of the corresponding placement slots and links with the borrowing and returning operations of the mobile terminals.

7. The mobile terminal management and control system based on the Type-C interface according to claim 5, characterized in that: The control device is also equipped with an identity authentication module, which is used to verify the identity of users.

8. The mobile terminal management and control system based on the Type-C interface according to claim 7, characterized in that: The identity authentication module includes a face recognition module and a fingerprint recognition module.

Citation Information

Patent Citations

  • Equipment management method, equipment management device, server and storage medium

    CN113450520A

  • Secret-related area visitor mobile terminal security control method and system, and medium

    CN121418515A