Safety management method for USB identification and control, medium and equipment
Through the combination of USB security access device and port control module, using OTG technology and whitelist management, the computer security risks caused by the random access of USB devices are solved, the security authentication and control of USB devices are realized, and the spread of viruses and attacks are prevented.
Patent Information
- Application Number
- CN202510683770.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-09-16
AI Technical Summary
Existing technologies cannot effectively regulate the use of USB devices, making computers vulnerable to malicious USB device attacks, virus transmission and data leakage, especially the security risks caused by the random access of BadUSB devices and illegal USB storage devices.
Through the combination of USB security access device and port control module, OTG technology is used to simulate serial port devices and storage ports to perform authentication and whitelist management, intercept illegal USB devices, and only allow authenticated devices to access, thus realizing kernel-level filtering and asymmetric encryption authentication.
Effectively intercept illegal USB devices, ensure only legal devices are connected, prevent virus spread and attacks, maintain user usage habits unchanged, and achieve secure management and control of USB devices.
Smart Images

Figure CN120654279A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of USB management technology, and more particularly to a USB identification and control security management method, medium and device. Background Art
[0002] Over the past decade, information technology has advanced rapidly, with a constant stream of new devices and technologies. However, data connection interfaces have become increasingly monolithic. Previously common interfaces like PS / 2, parallel, and serial ports are becoming increasingly rare, while USB interfaces are becoming increasingly common and widespread. With the evolution of the USB 1.0 specification to USB 3.0 and its integration with FireWire, USB connectivity has gradually unified computer terminal interfaces. USB interfaces serve not only as data transmission interfaces but also as power supplies and function expansion interfaces for some devices. USB flash drives have gradually replaced CDs and floppy disks as the primary device for exchanging data between computers during routine maintenance. Smartphones, wireless network cards, and other devices can not only transfer data to and from computers but can even become network nodes themselves, allowing computers to directly access the internet. While people enjoy the convenience brought by technological advancements, they also pose security risks to the stable operation of their computers. In particular, some "BadUSB" devices, which simulate keyboard keystrokes, have appeared on the market. These devices behave like USB storage devices, but can, upon connection, launch attacks against computers according to pre-programmed programs, making them difficult to detect without prior notice. The careless use of USB storage devices will greatly increase such risks. Even if you do not encounter BadUSB devices, there is a high probability that malicious viruses will be inadvertently introduced through the USB flash drive. Some core data will be taken out of the computer without your knowledge through the USB flash drive. When using the USB interface to charge the mobile phone, the connected computer will be vulnerable to attack or Trojans due to the wireless channel.
[0003] How to effectively regulate the use of USB devices, reduce the random insertion and misuse of USB mobile storage devices, prohibit the use of personal USB devices or external USB storage devices for convenience from being directly connected to production system computers or used directly in operation and maintenance computers; prevent mobile phones, Bluetooth, wireless network cards and other USB devices from being accidentally connected to prohibited networked computers, and provide comprehensive protection for safe production through technical defense methods, is a new topic in the security protection and management of USB devices.
[0004] The industry has introduced numerous practices for USB flash drive security control, but each focuses on a different approach. For example, patent CN 115659430 A focuses on recording the USB port numbers of the mouse and keyboard to prevent a later inserted USB flash drive from reusing the port numbers of the removed mouse and keyboard for data exchange, thereby creating a vulnerability in USB flash drive control. Patent CN 116318967 A focuses on using a network server to securely transfer USB flash drive data, and includes virus detection during the transfer process to ensure the security of the transferred data. One approach prohibits the use of USB flash drives for data exchange; the other involves uploading USB flash drive data to a secure server for transfer before downloading. Both approaches focus on USB flash drive control and fail to address the use of permitted USB authentication keys. Summary of the Invention
[0005] The purpose of the present invention is to provide a USB identification and control security management method, medium and equipment.
[0006] The present invention aims to solve the problems existing in the prior art.
[0007] Compared with the prior art, the technical solution of the present invention and its beneficial effects are as follows:
[0008] A method for secure management of USB identification and control includes: after a USB secure access device is powered on and started, simulating a serial port device through the OTG technology and waiting for the USB port control module installed on the target computer to connect and authenticate; after the USB port control module authentication times out, the USB secure access device simulates a read-only USB disk of a storage port control module program installation disk through the OTG technology and installs the USB port control module; after the USB port control module is installed, a kernel-level USB device filtering module filters out non-authenticated USB devices, so that the target computer cannot directly use the connected storage-type and non-storage-type USB devices; the USB port control module completes the authentication with the USB secure access device, and the USB secure access device closes the mapped control module installation disk read-only USB storage device. The device starts to detect whether the U disk device inserted into the USB security access device is in the U disk white list of the USB security access device. When the corresponding U disk device is in the U disk white list, the U disk device inserted into the USB security access device is mapped to the target computer through the OTG technology; the USB subsystem of the target computer system identifies the mapped USB device, and the system notifies the registered USB filter driver that a new device has arrived. The kernel-level USB device filtering module of the USB port management module detects whether the physical attribute information of the corresponding device matches the authenticated USB security access device information. After the detection is passed, the device is allowed to be further processed and the USB device is allowed to be used; when the detection of the physical attribute information of the device fails, the USB device directly connected to the target computer is used to intercept the USB device.
[0009] As a further improvement, the present invention further includes: after the user has completed normal use of the USB storage device mapped by the USB security access device, the user can eject the device through the system or directly unplug the USB disk from the USB security access device.
[0010] As a further improvement, it also includes: when there is a special need to use a non-storage USB device on the target computer, and the USB device that needs to be authenticated will not bring risks to the target computer, the USB port management and control module is used to authenticate the type, vendor number, product number, and device description physical information of the USB device. The USB device that passes the authentication is a whitelist USB device and can be directly connected to the target computer for use. When the USB port management and control module identifies the physical information of the USB device, it directly releases the USB device that has completed the authentication for use.
[0011] As a further improvement, the USB port control module completes the authentication with the USB security access device, including: the serial port authentication process between the USB security access device and the USB port control module is: S1, the serial port mapping module of the USB security access device is started; S2, the serial port mapping module creates a virtual USB ACM serial port device; S3, the serial port mapping module maps the serial port device through OTG; S4, the serial port mapping module waits for the serial port communication connection of the authentication application data; S5, the target computer USB port control module is started, and the authentication application data is written to the connected serial port device, and the data is processed by asymmetric encryption; S6, the USB port control module waits for the serial port communication connection of the authentication result data; S7, the serial port mapping module reads the authentication application data and submits it to the device authentication module for verification; S8, the device authentication module fails to verify the authentication application data, and goes to step S4 to wait; S9, the device authentication module successfully verifies the authentication application data, and passes The serial port mapping module writes the authentication result data, and the data is processed by asymmetric encryption; S10, the USB port control module reads the authentication result data and submits it to the port authentication module for verification; S11, the port authentication module fails to verify the authentication result data, and notifies the USB port control module to go to step S5 to re-enter the authentication application data; S12, the port authentication module successfully verifies the authentication result data, and notifies the USB port control module to release the above-mentioned authenticated USB security access device; S13, the USB port control module completes the USB security access device authentication; S14, the USB security access device completes the authentication process.
[0012] As a further improvement, the USB port control module control process is also included: the first step is to start the kernel-level USB device filtering module to monitor the access of the USB device in the computer system; the second step is to connect the USB device to the target computer; the third step is that the operating system forwards the USB information to the USB device subsystem according to the device interface type; the fourth step is that the operating system sequentially inquires whether to perform additional operations on the device instance based on the registered USB filtering module; the fifth step is that the USB port control device filtering module identifies the type of the corresponding USB device, the vendor number VID, the product number PID, and the device serial number of the device physical information; the sixth step is to detect the identified USB storage device information and the device information of the USB security access device authenticated by the USB port control module. The system checks the information of the identified non-storage USB device and the whitelist device information authenticated by the USB device filtering module, and jumps to step nine; in step seven, the detected non-storage USB device information is consistent with the whitelist device information authenticated by the USB device filtering module, and jumps to step nine; in step eight, the currently inserted USB device is prohibited from use, the USB device filtering module intercepts the current device operation, and returns to the system that the device is intercepted and cannot be used, the system no longer processes the device upload message, and the device cannot be used; in step nine, the USB device filtering module completes the operation query of the USB device instance, and returns to the system that the device status is normal and allowed to be used; in step ten, the user operates the mapped U disk or whitelist USB device normally; in step eleven, the user completes the use, removes the device from the USB security access device, or removes the USB device from the target computer.
[0013] According to a second aspect of the present invention, a storage medium is provided, wherein the storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the USB identification and control security management method described in any one of claims 1 to 5 are implemented.
[0014] The third aspect of the present invention provides an electronic device, which includes at least a memory and a processor, wherein a computer program is stored on the memory, and the processor implements the steps of the USB identification and control security management method when executing the computer program on the memory.
[0015] The beneficial effects of the present invention are:
[0016] The present invention intercepts all USB storage devices except those mapped by a USB security access device on a target computer through a USB port control module; the USB port control module communicates with the USB security access device through a serial port to implement device authentication based on an asymmetric encryption system, ensuring that only legitimate access devices can be connected to the target computer for use; the USB security access device maps only the USB storage device to composite USB devices including ergonomic devices and storage devices, thereby preventing potential malicious hardware or programmable hardware such as USB flash drive logic bombs from attacking the target computer; the USB security access device implements whitelist access control based on physical attributes such as USB device type, vendor number, product number, and device serial number, ensuring that only authenticated USB devices can ultimately access the target computer.
[0017] The patent of this invention utilizes a variety of USB control technologies to solve the problems of target computers being easily infected with viruses, easily attacked by USB flash drive logic bombs, and having internal files stored arbitrarily due to the private use, cross-use, and arbitrary use of USB storage devices; it also solves the security problems of internal and external network connectivity and internal data theft caused by USB interface smart phones, wireless network cards, Bluetooth and other devices being mistakenly connected to the target computer.
[0018] The present invention maps a USB storage device to a target computer by directly connecting it to a USB security access device OTG, without changing the user's usage habits. When a user operates the mapped USB flash drive, he or she is actually operating the USB flash drive connected to the USB security access device. By using a kernel-level USB filter driver, incomplete interception of the USB device can be avoided, and unknown viruses or Trojans can be prevented from entering the target computer through the interaction of the USB device. By using a USB storage device whitelist mechanism, the USB flash drive devices that can be used by the user are limited, so as to avoid random insertion and misuse, and the spread of malicious code between different systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 This is a schematic diagram of the steps of a USB identification and control security management method provided by an embodiment of the present invention.
[0020] Figure 2 This is a schematic diagram of a USB security access device and a USB port management and control module provided by an embodiment of the present invention.
[0021] Figure 3 This is a flow chart of a USB security management method for identification and control provided by an embodiment of the present invention.
[0022] Figure 4 This is a schematic diagram of the serial port authentication process of the USB security access device and the USB port management and control module provided by an embodiment of the present invention.
[0023] Figure 5This is a schematic diagram of the control process of the USB port management and control module provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0024] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the invention claimed for protection, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0025] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.
[0026] Reference Figures 1 to 5 As shown,
[0027] A method for secure management of USB identification and control includes: after a USB secure access device is powered on and started, simulating a serial port device through the OTG technology and waiting for the USB port control module installed on the target computer to connect and authenticate; after the USB port control module authentication times out, the USB secure access device simulates a read-only USB disk of a storage port control module program installation disk through the OTG technology and installs the USB port control module; after the USB port control module is installed, a kernel-level USB device filtering module filters out non-authenticated USB devices, so that the target computer cannot directly use the connected storage-type and non-storage-type USB devices; the USB port control module completes the authentication with the USB secure access device, and the USB secure access device closes the mapped control module installation disk read-only USB storage device. The device starts to detect whether the U disk device inserted into the USB security access device is in the U disk white list of the USB security access device. When the corresponding U disk device is in the U disk white list, the U disk device inserted into the USB security access device is mapped to the target computer through the OTG technology; the USB subsystem of the target computer system identifies the mapped USB device, and the system notifies the registered USB filter driver that a new device has arrived. The kernel-level USB device filtering module of the USB port management module detects whether the physical attribute information of the corresponding device matches the authenticated USB security access device information. After the detection is passed, the device is allowed to be further processed and the USB device is allowed to be used; when the detection of the physical attribute information of the device fails, the USB device directly connected to the target computer is used to intercept the USB device.
[0028] It also includes: after the user completes normal use of the USB storage device mapped by the USB security access device, the user can eject the device through the system or directly unplug the USB disk from the USB security access device.
[0029] It also includes: when there is a special need to use a non-storage USB device on the target computer, and the USB device that needs to be authenticated will not bring risks to the target computer, the USB port control module is used to authenticate the type, vendor number, product number, and device description physical information of the USB device. The USB device that passes the authentication is a whitelist USB device and can be directly connected to the target computer for use. When the USB port control module identifies the physical information of the USB device, it directly releases the USB device that has completed the authentication for use.
[0030] The USB port control module completes the authentication with the USB security access device, including: the serial port authentication process between the USB security access device and the USB port control module is as follows: S1, the serial port mapping module of the USB security access device is started; S2, the serial port mapping module creates a virtual USB ACM serial port device; S3, the serial port mapping module maps the serial port device through OTG; S4, the serial port mapping module waits for the serial port communication connection of the authentication application data; S5, the USB port control module of the target computer is started, and the authentication application data is written to the connected serial port device, and the data is processed by asymmetric encryption; S6, the USB port control module waits for the serial port communication connection of the authentication result data; S7, the serial port mapping module reads the authentication application data and submits it to the device authentication module for verification; S8, the device authentication module fails to verify the authentication application data, and goes to step S4 to wait; S9, the device authentication module successfully verifies the authentication application data, and passes The serial port mapping module writes the authentication result data, and the data is processed by asymmetric encryption; S10, the USB port control module reads the authentication result data and submits it to the port authentication module for verification; S11, the port authentication module fails to verify the authentication result data, and notifies the USB port control module to go to step S5 to re-enter the authentication application data; S12, the port authentication module successfully verifies the authentication result data, and notifies the USB port control module to release the above-mentioned authenticated USB security access device; S13, the USB port control module completes the USB security access device authentication; S14, the USB security access device completes the authentication process.
[0031] The control process of the USB port control module is as follows: the first step is to start the kernel-level USB device filtering module to monitor the access of USB devices in the computer system; the second step is to connect the USB device to the target computer; the third step is for the operating system to forward the USB information to the USB device subsystem according to the device interface type; the fourth step is for the operating system to ask the registered USB filtering modules in turn whether to perform additional operations on the device instance; the fifth step is for the USB port control device filtering module to identify the type of the corresponding USB device, the vendor number VID, the product number PID, and the device serial number of the device physical information; the sixth step is to detect the consistency of the identified USB storage device information with the device information of the USB security access device authenticated by the USB port control module. Jump to step nine; step seven, detect the consistency between the identified non-storage USB device information and the whitelist device information authenticated by the USB device filtering module, and jump to step nine if they are consistent; step eight, the currently inserted USB device is prohibited from use, the USB device filtering module intercepts the current device operation, and returns to the system that the device is intercepted and cannot be used, the system no longer processes the device upload message further, and the device cannot be used; step nine, the USB device filtering module completes the operation inquiry of the USB device instance, and returns to the system that the device status is normal and allowed to be used; step ten, the user operates the mapped U disk or whitelist USB device normally; step eleven, the user completes the use, removes the device from the USB security access device or removes the USB device from the target computer.
[0032] This patent proposes a security management method for device identification and control that uses a USB security access device and a USB port control module to work together. The USB security access device is responsible for the identification and control mapping of whitelisted USB flash drives, and the USB port control module completes the authentication with the USB security access device and the filtering and control of USB devices. Users can view the USB flash drive inserted into the USB security access device through the target computer connected to the USB security access device. The file data stored on the USB flash drive accessed through the mapping method is consistent with the file data that can be accessed directly on the computer. If the user deletes the files on the mapped USB flash drive, the corresponding files on the actual USB flash drive will also be cleared, and the usage habits of the USB flash drive remain consistent. If the user directly inserts the USB flash drive into the target computer, the USB port control module will identify and intercept the USB flash drive, and it cannot be used directly; that is, the USB flash drive can only be mapped to the target computer through OTG after being detected by the USB security access device.
[0033] The patent of this invention utilizes a variety of USB control technologies to solve the problems of target computers being easily infected with viruses, easily attacked by USB flash drive logic bombs, and having internal files stored arbitrarily due to the private use, cross-use, and arbitrary use of USB storage devices; it also solves the security problems of internal and external network connectivity and internal data theft caused by USB interface smart phones, wireless network cards, Bluetooth and other devices being mistakenly connected to the target computer.
[0034] The USB port security management is completed by adopting interactive authentication between the two major components of USB security access device and USB port management and control module, with the cooperation of OTG serial port mapping module, OTG installation disk mapping module, OTG U disk mapping module, device authentication module, USB device filtering module, port authentication module and other components.
[0035] The USB disk mapping adopts OTG technology. Through this technology, the USB security access device maps the USB storage device plugged into the device to the target computer connected to the device. The USB disk observed in the target computer is consistent with the one plugged into the device, including but not limited to file content, directory structure, disk capacity, remaining space, etc.
[0036] The USB security access device also maps a serial port device for authentication and interaction between the USB security access device and the USB port management and control module.
[0037] After the USB security access device is connected to the target computer, the USB port control module initiates authentication with the device. Once authentication is successful, the USB security access device maps the connected USB drive to the target computer. The USB port control module identifies the USB device and, if authentication is valid, allows the mapped USB drive to be used. When the USB drive is no longer used, it can be removed from the USB security access device, and the mapped USB drive disappears from the target computer.
[0038] Reference Figure 2 As shown, the USB security access device is a device used for identifying, managing and mapping USB storage devices. After serial communication authentication, the storage part of the managed whitelist USB flash drive can be mapped out through OTG technology. Hereinafter referred to as the access device or device. The USB port control module is a program module used for filtering and controlling USB devices, which can intercept non-authenticated USB devices, including but not limited to USB storage devices, smart phones, wireless network cards, Bluetooth devices, etc. After serial communication authentication, the USB storage device mapped by the USB security access device can be released. Hereinafter referred to as the control module.
[0039] According to a second aspect of the present invention, a storage medium is provided, wherein the storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the USB identification and control security management method described in any one of claims 1 to 5 are implemented.
[0040] The third aspect of the present invention provides an electronic device, which includes at least a memory and a processor, wherein a computer program is stored on the memory, and the processor implements the steps of the USB identification and control security management method when executing the computer program on the memory.
[0041] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Those skilled in the art should understand that any modifications and equivalent substitutions that do not depart from the spirit and scope of the present invention should fall within the scope of protection of the claims of the present invention.
Claims
1. A USB identification and control security management method, characterized in that: include: After the USB security access device is powered on and started, it simulates a serial port device through OTG technology and waits for the USB port control module installed on the target computer to connect and authenticate; After waiting for the USB port control module authentication to time out, the USB security access device uses OTG technology to simulate a read-only USB flash drive containing the port control module program installation disk and install the USB port control module. After the USB port control module is installed, the kernel-level USB device filtering module filters out unauthenticated USB devices, preventing the target computer from directly using connected storage and non-storage USB devices. The USB port control module completes authentication with the USB security access device. The USB security access device closes the mapped control module installation disk read-only USB storage device and begins to detect whether the USB flash drive device plugged into the USB security access device is in the USB flash drive whitelist of the USB security access device. If the corresponding USB flash drive device is in the USB flash drive whitelist, the USB flash drive device plugged into the USB security access device is mapped to the target computer through the OTG technology. The USB subsystem of the target computer system identifies the mapped USB device, and the system notifies the registered USB filter driver that a new device has arrived. The kernel-level USB device filter module of the USB port control module detects whether the physical attribute information of the corresponding device matches the authenticated USB security access device information. If the detection passes, the device is allowed to proceed with further processing and the USB device is allowed to be used. If the detection of the device physical attribute information fails, the USB device directly connected to the target computer is blocked from use.
2. A USB identification and control security management method according to claim 1, characterized in that: Also includes: After the user has completed normal use of the USB storage device mapped through the USB security access device, he can eject the device through the system or directly unplug the USB disk from the USB security access device.
3. A USB identification and control security management method according to claim 1, characterized in that: Also includes: When there is a special need to use a non-storage USB device on the target computer, and the USB device that needs to be authenticated does not bring risks to the target computer, the USB port control module is used to authenticate the type, vendor number, product number, and device description physical information of the USB device. The authenticated USB device is a whitelisted USB device and can be directly connected to the target computer for use. When the USB port control module identifies the physical information of the USB device, it directly releases the USB device that has completed authentication for use.
4. A USB identification and control security management method according to claim 1, characterized in that: The USB port control module completes authentication with the USB security access device, including: The serial port authentication process between the USB security access device and the USB port control module is as follows: S1, the serial port mapping module of the USB security access device is started; S2, the serial port mapping module creates a virtual USB ACM serial port device; S3, the serial port mapping module maps the serial port device through OTG; S4, the serial port mapping module waits for the serial port communication connection of the authentication application data; S5, the target computer's USB port control module starts up and writes authentication application data to the connected serial port device. The data is processed using asymmetric encryption. S6, the USB port control module waits for the authentication result data serial communication connection; S7, the serial port mapping module reads the authentication application data and sends it to the device authentication module for verification; S8, the device authentication module fails to verify the authentication application data, and goes to step S4 to wait; S9, the device authentication module verifies that the authentication application data is successful, notifies the serial port mapping module to write the authentication result data, and the data is processed using an asymmetric encryption method; S10, the USB port control module reads the authentication result data and sends it to the port authentication module for verification; S11, the port authentication module fails to verify the authentication result data, and notifies the USB port control module to go to step S5 to re-enter the authentication application data; S12, the port authentication module verifies that the authentication result data is successful, and notifies the USB port control module to release the authenticated USB security access device; S13, the USB port control module completes the USB security access device authentication; S14, the USB security access device completes the authentication process.
5. A USB identification and control security management method according to claim 1, characterized in that: Also includes: The control process of the USB port control module is as follows: The first step is to start the kernel-level USB device filtering module to monitor the access of USB devices in the computer system; Step 2: Connect the USB device to the target computer; In the third step, the operating system forwards the information to the USB device subsystem based on the device interface type; In the fourth step, the operating system asks the registered USB filter modules in turn whether to perform additional operations on the device instance; Step 5: The USB port control device filtering module identifies the device physical information of the corresponding USB device, including the type, vendor ID (VID), product ID (PID), and device serial number. Step 6: Check if the identified USB storage device information is consistent with the device information of the USB security access device authenticated by the USB port control module, and jump to step 9 if they are consistent; Step 7: Check if the identified non-storage USB device information is consistent with the whitelist device information authenticated by the USB device filtering module, and jump to step 9 if they are consistent; Step 8: The currently inserted USB device is prohibited from use. The USB device filtering module intercepts the current device operation and returns to the system that the device is blocked and cannot be used. The system no longer processes the device upload message and the device cannot be used. In step 9, the USB device filtering module completes the operation query of the USB device instance and returns to the system that the device status is normal and can be used; Step 10: The user operates the mapped USB flash drive or whitelisted USB device normally; In step 11, the user completes use and removes the device from the USB security access device or removes the USB device from the target computer.
6. A storage medium, characterized in that The storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the USB identification and control security management method described in any one of claims 1 to 5 are implemented.
7. An electronic device, characterized in that: The device comprises at least a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program in the memory, the steps of the USB identification and control security management method according to any one of claims 1 to 5 are implemented.