USB multi-port device access encryption authentication method and system
By combining the main control MCU and AES encryption algorithm with analog signal switches, accurate identification and dynamic control of USB devices can be achieved, solving the problem that traditional USB docking stations are easily bypassed and improving the security protection capabilities of terminal devices.
Patent Information
- Application Number
- CN202511274016.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-10-31
AI Technical Summary
Traditional USB docking stations lack hardware-level security protection capabilities, making them vulnerable to being bypassed by unauthorized USB devices, leading to risks of network attacks and data breaches. Existing software protection methods are easily circumvented and lack physical isolation.
The system uses a main control MCU to read the device descriptor and combines it with the AES encryption algorithm for identity authentication. It also uses analog signal switches to achieve physical switching of USB signals and integrates a plug-in/plug-out detection module and a USB expansion hub to achieve accurate identification and dynamic control of USB device types.
It enhances the security of USB devices, avoids the problem of software control being easily tampered with, and has higher security and irreplaceability, making it suitable for the security management of terminal devices in complex network environments.
Smart Images

Figure CN120880773A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data encryption technology, specifically a method and system for encrypting and authenticating access to USB multi-port devices. Background Technology
[0002] As the network connectivity of terminal devices increases, the network environment they operate in becomes more complex, and security threats become increasingly prominent, especially the risks introduced through USB interfaces. For example, attackers may use unauthorized USB storage devices to bypass system access controls, implant malicious code, or steal sensitive data, making it a significant entry point for cyberattacks. Traditional USB docking stations typically lack any identification or authentication mechanisms; any peripheral device compliant with the USB standard can be connected and used, lacking basic access security capabilities.
[0003] To ensure the operational security of terminal devices, there is an urgent need for a USB docking station with security authentication and intelligent control capabilities. This station can identify and determine the permissions of connected devices at the hardware level, effectively reject unauthorized devices from accessing the site, prevent potential network attacks and data leakage risks, and provide a reliable physical security layer for industrial control and critical terminal equipment.
[0004] Existing security protection methods primarily rely on packet forwarding and data routing. One approach involves monitoring packet forwarding at the driver level. This method uses algorithms to monitor USB device packets and cuts off communication when anomalies are detected. This approach uses software filtering to impact the communication speed of USB devices. Another method is software-based USB device type control, which monitors USB devices through a system whitelist to prevent unauthorized access. However, this method is easily circumvented in practice: firstly, the software-based whitelist mechanism can be bypassed by users by modifying system policies or registry configurations, making its effectiveness questionable; secondly, the effectiveness of the whitelist depends on periodic synchronization with the server. If devices are offline for extended periods or whitelist updates are delayed, authorization delays or false blocking can occur, impacting user experience and the timeliness of security management.
[0005] In summary, traditional USB docking stations primarily rely on software-based security measures, lacking essential hardware protection capabilities. Furthermore, current hardware protection levels only address the isolation of USB device types and provide precise isolation and protection for certain storage devices, which is insufficient to meet the security management requirements of USB devices. Summary of the Invention
[0006] The purpose of this invention is to provide a USB multi-port device access encryption authentication method and system, which can accurately identify USB device types and dynamically control access. Compared with existing USB security management methods that rely on operating system policies, software blacklists and whitelists, or traditional manual switching methods, this invention technically reads the device descriptor through the main control MCU and combines it with the AES encryption algorithm to achieve identity authentication. This can effectively identify high-risk device types such as wireless network cards and storage devices, thereby achieving classified access or blocking control, greatly improving the system's security protection capabilities for USB peripherals. At the same time, it innovatively adopts an analog signal switch to realize the physical switching of USB signals between the main control MCU and the host, avoiding the problem of traditional software control being easily tampered with or bypassed, and possessing higher security and irreplaceability.
[0007] The technical solution of the present invention is as follows: This method describes an encrypted authentication approach for connecting USB multi-port devices. The USB multi-port device includes a host interface and a USB interface, and includes the following steps: S1: When a USB device is first inserted into a USB interface, the insertion / removal detection module (500) first detects a change in current and sends an interrupt signal to the main control MCU unit (200). The main control MCU unit (200) responds to the interrupt and controls the analog signal switching unit (300) to connect to the main control MCU unit (200) by default. The main control MCU unit (200) starts the USB Host function and identifies the type of USB device through device descriptor reading, interface identification, etc. If it is determined to be a low-risk device, the main control MCU unit (200) directly allows it to pass. If it is identified as a mass storage device, the main control MCU unit (200) enters the authentication stage, accesses the encrypted authentication file in the mass storage device, performs AES encryption authentication operation, and uses the AES key for decryption comparison. If the authentication fails or it is identified as a high-risk device, it is prohibited from connecting to the host, the signal is kept cut off, and the host is not reported. S2: If the main control MCU unit (200) passes the authentication, the main control MCU unit (200) controls the analog switch to conduct the USB device signal to the USB expansion unit (400), and the USB expansion unit (400) reports the USB device signal to the host interface unit (600); the host recognizes the USB device and loads the driver to complete the USB device access; S3: If the USB device is unplugged, the plug-in / unplug detection unit (500) detects that the current is disconnected. The main control MCU unit (200) performs shutdown, disconnection and recording operations. The main control MCU unit (200) immediately closes the USB interface channel and clears the connection status to prepare for subsequent detection and authentication.
[0008] Furthermore, the low-risk devices refer to mice and keyboards; the high-capacity storage devices refer to USB flash drives; and the high-risk devices refer to wireless network cards.
[0009] Furthermore, the host interface is used to connect to a host, and the USB interface is used to insert USB devices.
[0010] The USB multi-port device access encryption authentication system is characterized by comprising a power supply module (100), a main control MCU unit (200), an analog signal switching unit (300), a USB expansion unit (400), a plug-in / plug-out detection unit (500), and a host interface unit (600). The main control MCU unit (200) is connected to the analog signal switching unit (300), the USB expansion unit (400), the plug-in / plug-out detection unit (500), and the host interface unit (600) respectively, for the purpose of realizing signal control and status management. in: The power supply module (100) is used to provide a stable power supply to each unit of the system; The main control MCU unit (200) includes an MCU, which is used to identify the type of inserted USB device, perform encryption authentication judgment, and control signal on / off; after authenticating a legitimate USB device, it controls the analog signal switching unit (300) to switch signals, thereby enabling authorized access of the USB device; The analog signal switching unit (300) is used to switch the USB signal path between the USB device and the main control MCU unit (200) or between the USB expansion unit (400) to realize dynamic control and physical isolation of the USB signal; The USB expansion unit (400) includes a USB Hub chip for receiving the USB device signal switched by the analog signal switching unit (300) and outputting the signal to the host interface unit (600). The host interface unit (600) is used to connect to the host's USB interface, transmit the certified USB device signal to the host system, and securely connect the certified USB device to the terminal host system.
[0011] The insertion / removal detection unit (500) is equipped with a set of current detection modules for each USB interface, which are used to detect the insertion / removal status of the USB device and transmit the detection results to the main control MCU unit (200) to trigger the authentication, release or disconnection process; The power supply module (100) uses a switching power supply and a step-down module.
[0012] Furthermore, the main control MCU unit (200) is the core control unit of this system, including an MCU, preferably an STM32F103 or higher performance microcontroller, with USB Host interface, level control, AES encryption and decryption, and external interrupt response function modules; the system runs identification firmware and authentication algorithm, and achieves fast response through interrupt mechanism in conjunction with plug-in detection unit (500); the MCU has multiple sets of authentication keys pre-stored to verify the signature information of legitimate USB devices, and decryption and comparison are performed through AES-128 or AES-256 algorithm. Only USB devices that pass the verification are allowed to communicate with the host.
[0013] Furthermore, the analog signal switching unit (300) adopts high-speed bidirectional analog switch chips such as FSUSB74 and ADG7xx series, which have low on-resistance and fast switching characteristics to meet the full-speed / high-speed signal transmission requirements of USB 2.0. The D+ and D− signals of each USB port in the system are split into two by the analog signal switching unit (300), one leading to the main control MCU unit (200) and the other leading to the USB expansion unit 400. The main control MCU unit (200) determines the conduction direction through the control signal to achieve precise control of the communication path of the USB device.
[0014] Furthermore, the USB expansion unit (400) connects to the analog signal switching paths of each analog signal switching unit (300) through multiple downlink ports, and manages the signals from multiple UCB devices to be certified in a unified manner. The USB expansion unit (400) connects to the host interface unit (600) through the uplink port, and realizes multi-port unified transmission to the host.
[0015] Furthermore, the USB Hub chip includes enumeration logic, a power-on initialization mechanism, and configurable VID / PID information for establishing a valid communication connection with the host interface unit (600).
[0016] Furthermore, the host interface unit (600) is the only interface module for the system to connect to the host. Structurally, it includes a standard Type-A female connector, an EMI anti-interference filter, a TVS electrostatic protection device, and is connected to the host's USB interface. The host cannot actively identify uncertified devices. The entire certification process is completed under the control of the main control MCU unit (200) and the USB expansion unit (400), thereby preventing users from bypassing the system mechanism to forcibly connect peripherals.
[0017] Furthermore, the insertion / removal detection unit (500) includes multiple current detection modules. Each USB port is equipped with a set of current detection modules, which are composed of current sampling amplifiers such as INA199 combined with low-resistance detection resistors. When the device is connected, the current fluctuation triggers an interrupt signal to the main control MCU unit (200), and the main control MCU unit (200) starts the USB device identification process. When the device is disconnected, the current drops and triggers an interrupt again. The main control MCU unit (200) locates the unplugged port according to the interrupt source and performs the channel shutdown and status reset operations.
[0018] The USB multi-port device described in this invention is essentially an intermediate device that needs to connect to a host via a host interface. It provides multiple USB ports for connecting peripherals (including USB storage devices, USB HID devices, printers, etc.). Compared to traditional USB hubs, this invention adds an encryption authentication mechanism. Before a peripheral device is connected to the host, it must undergo the authentication process of this intermediate device, ensuring that only authorized USB peripherals can be recognized and used by the host.
[0019] This system integrates a USB expansion hub and a plug-in / plug-out detection module, supports multi-port device access, automatic polling, and status interruption response, and is suitable for complex terminal access scenarios.
[0020] This invention is constructed using general-purpose electronic components. The overall system design is simple, the control logic is clear, and the manufacturing cost is lower than that of similar isolated control hardware devices, making it suitable for large-scale deployment.
[0021] This invention helps to strengthen the compliance management of USB devices in intranet environments, reduce human intervention, and improve the efficiency of system security operation. It is applicable to industries with strict requirements for USB access, such as government offices, power dispatching, and industrial control sites, and has good practical value and promotion prospects.
[0022] This invention does not rely on operating system permissions or user behavior, requires no software installation, and completes identification, authentication, and control operations entirely through hardware. It is unbreakable, highly adaptable, and highly stable. Compared to existing USB protection technologies, this invention effectively solves the problems of traditional whitelist strategies being easily bypassed, requiring operating system authorization, and lacking physical isolation.
[0023] This system is highly scalable, supporting the addition of more USB ports, upgrading authentication algorithms such as RSA and ECC, logging and remote communication management modules, and policy adjustments through firmware upgrades to meet access control requirements in different scenarios.
[0024] The system design of this invention can effectively enhance the proactive defense capability of terminal devices against USB access, avoiding data leakage or system paralysis caused by malicious peripherals, USB flash drive viruses, etc. At the same time, the system is low in cost, easy to mass-produce and deploy, and has broad application value. Attached Figure Description
[0025] Figure 1 This is a flowchart of the encryption authentication process for USB multi-port device access in this invention.
[0026] Figure 2 This is a connection control relationship diagram for the present invention. Detailed Implementation
[0027] See Figure 1 , Figure 2 .
[0028] Example 1 A method for encrypting and authenticating USB multi-port device connections. A USB multi-port device includes a host interface and a USB interface. The host interface is used to connect to a host, and the USB interface is used to insert the USB device. The method includes the following steps: S1: When a USB device is first inserted into the USB interface, the insertion / removal detection module 500 first detects a change in current and sends an interrupt signal to the main control MCU unit 200. The main control MCU unit 200 responds to the interrupt, controls the analog signal switching unit 300 to connect to the main control MCU unit 200 by default, and the main control MCU unit 200 starts the USB Host function, identifying the type of USB device through device descriptor reading, interface identification, etc. If it is determined to be a low-risk device, the main control MCU unit 200 directly allows it to pass; if it is identified as a mass storage device, the main control MCU unit 200 enters the authentication stage, accesses the encrypted authentication file in the mass storage device, performs AES encryption authentication operation, and uses the AES key for decryption comparison; if authentication fails or it is identified as a high-risk device, it is prohibited from connecting to the host, the signal is kept cut off, and the host is not reported; low-risk devices refer to mice and keyboards; mass storage devices refer to USB flash drives; and high-risk devices refer to wireless network cards.
[0029] S2: If the main control MCU unit 200 passes the authentication, the main control MCU unit 200 controls the analog switch to conduct the USB device signal to the USB expansion unit 400, and the USB expansion unit 400 reports the USB device signal to the host interface unit 600; the host recognizes the USB device and loads the driver to complete the USB device access; S3: If the USB device is unplugged, the plug-in / unplug detection unit 500 detects the current disconnection, and the main control MCU unit 200 performs shutdown, disconnection and recording operations. The main control MCU unit 200 immediately shuts down the USB interface channel and clears the connection status to prepare for subsequent testing and authentication.
[0030] Example 2 The USB multi-port device access encryption authentication system includes a power supply module 100, a main control MCU unit 200, an analog signal switching unit 300, a USB expansion unit 400, a plug-in / plug-out detection unit 500, and a host interface unit 600. The main control MCU unit 200 is connected to the analog signal switching unit 300, the USB expansion unit 400, the plug-in / plug-out detection unit 500, and the host interface unit 600 respectively, and is used to realize signal control and status management. in: The power supply module 100 is used to provide a stable power supply to each unit of the system; The main control MCU unit 200 includes an MCU, which is used to identify the type of inserted USB device, perform encryption authentication, and control signal on / off. After authenticating a legitimate USB device, it controls the analog signal switching unit 300 to switch signals, thereby enabling authorized access of the USB device. The analog signal switching unit 300 is used to switch the USB signal path between the USB device and the main control MCU unit 200 or between the USB expansion unit 400, so as to realize the dynamic control and physical isolation of the USB signal. The USB expansion unit 400 includes a USB Hub chip, which is used to receive the USB device signal switched by the analog signal switching unit 300 and output the signal to the host interface unit 600. The host interface unit 600 is used to connect to the host's USB interface, transmit the certified USB device signal to the host system, and securely connect the certified USB device to the terminal host system.
[0031] The insertion / removal detection unit 500 is equipped with a set of current detection modules for each USB interface, which are used to detect the insertion / removal status of the USB device and transmit the detection results to the main control MCU unit 200 to trigger the authentication, release or disconnection process. The main control MCU unit 200 is the core control unit of this system, including an MCU, preferably an STM32F103 or higher performance microcontroller, with USB Host interface, level control, AES encryption and decryption, and external interrupt response modules; the system runs identification firmware and authentication algorithm, and achieves fast response through interrupt mechanism in conjunction with the plug-in detection unit 500; the MCU has multiple sets of authentication keys pre-stored to verify the signature information of legitimate USB devices, and decryption and comparison are performed through AES-128 or AES-256 algorithm. Only USB devices that pass the verification are allowed to communicate with the host.
[0032] The main control MCU unit 200 has a built-in polling mechanism to periodically detect the insertion status of USB devices under the simulated switching path and initiate device enumeration and descriptor reading operations.
[0033] The main control MCU unit 200 executes the following control strategies for different types of USB devices: If it is an HID type device, directly control the analog signal switching unit 300 to switch the signal path to the USB expansion unit 400; If it is a storage device, then an encryption authentication process will be executed; If it is a wireless network card, keep the signal disconnected. The analog signal switching unit 300 uses high-speed bidirectional analog switch chips such as FSUSB74 and ADG7xx series, which have low on-resistance and fast switching characteristics to meet the full-speed / high-speed signal transmission requirements of USB 2.0. In the system, the D+ and D− signals of each USB port are split into two by the analog signal switching unit 300, one leading to the main control MCU unit 200 and the other leading to the USB expansion unit 400. The main control MCU unit 200 determines the conduction direction through control signals to achieve precise control of the communication path of USB devices.
[0034] The analog signal switching unit 300 adopts a multi-channel analog switch structure, and the signal path of each USB device interface can be switched between the main control MCU unit 200 and the USB expansion unit 400.
[0035] The USB expansion unit 400 connects to the analog signal switching paths of each analog signal switching unit 300 through multiple downlink ports, and manages the signals from multiple UCB devices to be certified in a unified manner. The USB expansion unit 400 connects to the host interface unit 600 through the uplink port, and realizes multi-port unified transmission to the host.
[0036] The USB expansion unit 400 is used to receive signals from certified USB devices and forward them to the host interface unit 600 through the built-in USB Hub chip. The USB Hub chip includes enumeration logic, a power-on initialization mechanism, and configurable VID / PID information for establishing a valid communication connection with the host interface unit 600.
[0037] The host interface unit 600 is the only interface module for the system to connect to the host. Structurally, it includes a standard Type-A female connector, an EMI anti-interference filter, a TVS electrostatic protection device, and connects to the host's USB interface. The host cannot actively identify uncertified devices. The entire certification process is completed under the control of the main control MCU unit 200 and the USB expansion unit 400, thereby preventing users from bypassing the system mechanism to forcibly connect peripherals.
[0038] The host interface unit 600 includes a set of USB signal output lines, ESD protection circuitry, and physical connection ports, used to stably output the authenticated device signal to the host.
[0039] The insertion / removal detection unit 500 includes multiple current detection modules. Each USB port is equipped with a set of current detection modules, which are composed of current sampling amplifiers such as INA199 combined with low-resistance detection resistors. When a device is connected, current fluctuations trigger an interrupt signal to the main control MCU unit 200, which then initiates the USB device identification process. When the device is disconnected, the current drops, triggering another interrupt. The main control MCU unit 200 locates the unplugged port based on the interrupt source and performs channel shutdown and status reset operations.
[0040] In practical use, the system of the present invention has the following workflow: 1. When any USB port is connected to a device, the insertion / removal detection module 500 first detects the current change and sends an interrupt signal to the main control MCU unit 200; 2. The main control MCU unit 200 responds to the interrupt and controls the analog signal switching unit 300 to conduct the signal of that port to the main control MCU unit 200; 3. The main control MCU unit 200 starts the USB Host function to identify, enumerate, and determine the type of the device, and read the device descriptor; 4. If identified as a storage device, the main control MCU unit 200 enters the authentication phase, accesses the encrypted authentication file in the USB port access device, and uses the AES key for decryption and comparison; 5. If authentication is successful, the MCU controls the analog switch to switch the signal to the USB expansion unit 400; 6. The USB expansion unit 400 reports the device information to the host interface unit 600 via the USB Hub chip; the host identifies the device and loads the driver to complete the connection. 7. If authentication fails or the device is identified as high-risk, keep the signal cut off and do not report to the host. 8. When the device is unplugged, the current detection module provides feedback on the status, and the MCU performs shutdown, disconnection, and recording operations.
[0041] This system design does not rely on operating system permissions or user behavior, requires no software installation, and completes identification, authentication, and control operations entirely through hardware. It is unbreakable, highly adaptable, and highly stable. Compared to existing USB protection technologies, this invention effectively solves the problems of traditional whitelist strategies being easily bypassed, requiring operating system authorization, and lacking physical isolation.
[0042] It is worth noting that this system is highly scalable, supporting the addition of more USB ports, upgrading authentication algorithms such as RSA and ECC, logging functions and remote communication management modules, and policy adjustments through firmware upgrades to meet the access control needs of different scenarios.
Claims
1. A method for encrypted authentication of USB multi-port device access, wherein the USB multi-port device includes a host interface and multiple USB ports, characterized in that, Includes the following steps: S1: When a USB device is first inserted into a USB interface, the insertion / removal detection module (500) first detects a change in current and sends an interrupt signal to the main control MCU unit (200). The main control MCU unit (200) responds to the interrupt and controls the analog signal switching unit (300) to connect to the main control MCU unit (200) by default. The main control MCU unit (200) starts the USB Host function and identifies the type of USB device through device descriptor reading, interface identification, etc. If it is determined to be a low-risk device, the main control MCU unit (200) directly allows it to pass. If it is identified as a mass storage device, the main control MCU unit (200) enters the authentication stage, accesses the encrypted authentication file in the mass storage device, performs AES encryption authentication operation, and uses the AES key for decryption comparison. If the authentication fails or it is identified as a high-risk device, it is prohibited from connecting to the host, the signal is kept cut off, and the host is not reported. S2: If the main control MCU unit (200) passes the authentication, the main control MCU unit (200) controls the analog switch to conduct the USB device signal to the USB expansion unit (400), and the USB expansion unit (400) reports the USB device signal to the host interface unit (600); the host recognizes the USB device and loads the driver to complete the USB device access; S3: If the USB device is unplugged, the plug-in / unplug detection unit (500) detects that the current is disconnected. The main control MCU unit (200) performs shutdown, disconnection and recording operations. The main control MCU unit (200) immediately closes the USB interface channel and clears the connection status to prepare for subsequent detection and authentication.
2. The USB multi-port device access encryption authentication method according to claim 1, characterized in that, The low-risk devices refer to mice and keyboards; the high-capacity storage devices refer to USB flash drives; and the high-risk devices refer to wireless network cards.
3. The USB multi-port device access encryption authentication method according to claim 1, characterized in that, The host interface is used to connect to the host, and the USB interface is used to insert USB devices.
4. A USB multi-port device access encryption authentication system, characterized in that, It includes a power supply module (100), a main control MCU unit (200), an analog signal switching unit (300), a USB expansion unit (400), a plug-in / plug-out detection unit (500), and a host interface unit (600). The main control MCU unit (200) is connected to the analog signal switching unit (300), the USB expansion unit (400), the plug-in / plug-out detection unit (500), and the host interface unit (600) respectively, and is used to realize signal control and status management. in: The power supply module (100) is used to provide a stable power supply to each unit of the system; The main control MCU unit (200) includes an MCU, which is used to identify the type of inserted USB device, perform encryption authentication judgment, and control signal on / off; after authenticating a legitimate USB device, it controls the analog signal switching unit (300) to switch signals, thereby enabling authorized access of the USB device; The analog signal switching unit (300) is used to switch the USB signal path between the USB device and the main control MCU unit (200) or between the USB expansion unit (400) to realize dynamic control and physical isolation of the USB signal; The USB expansion unit (400) includes a USB Hub chip for receiving the USB device signal switched by the analog signal switching unit (300) and outputting the signal to the host interface unit (600). The host interface unit (600) is used to connect to the host's USB interface, transmit the certified USB device signal to the host system, and securely connect the certified USB device to the terminal host system; The insertion / removal detection unit (500) is equipped with a set of current detection modules for each USB interface, which are used to detect the insertion / removal status of the USB device and transmit the detection results to the main control MCU unit (200) to trigger the authentication, release or disconnection process; The power supply module (100) uses a switching power supply and a step-down module.
5. The USB multi-port device access encryption authentication system according to claim 4, characterized in that, The main control MCU unit (200) is the core control unit of this system, including an MCU. It is preferred to use a microcontroller with performance of STM32F103 or above, and has a USBHost interface, level control, AES encryption and decryption, and external interrupt response function modules. The system runs identification firmware and authentication algorithm, and achieves fast response through interrupt mechanism in conjunction with plug-in / plug-out detection unit (500); the MCU has multiple sets of authentication keys pre-stored to verify the signature information of legitimate USB devices. The keys are decrypted and compared using AES-128 or AES-256 algorithms, and only USB devices that pass the verification are allowed to communicate with the host.
6. The USB multi-port device access encryption authentication system according to claim 4, characterized in that, The analog signal switching unit (300) adopts high-speed bidirectional analog switch chips such as FSUSB74 and ADG7xx series, which have low on-resistance and fast switching characteristics to meet the full-speed / high-speed signal transmission requirements of USB 2.
0. The D+ and D− signals of each USB port in the system are split into two by the analog signal switching unit (300), one leading to the main control MCU unit (200) and the other leading to the USB expansion unit 400. The main control MCU unit (200) determines the conduction direction through the control signal to achieve precise control of the communication path of the USB device.
7. The USB multi-port device access encryption authentication system according to claim 4, characterized in that, The USB expansion unit (400) connects to the analog signal switching paths of each analog signal switching unit (300) through multiple downlink ports, and manages the signals from multiple UCB devices to be certified in a unified manner. The USB expansion unit (400) connects to the host interface unit (600) through the uplink port, and realizes multi-port unified transmission to the host.
8. The USB multi-port device access encryption authentication system according to claim 4, characterized in that, The USB Hub chip has enumeration logic, a power-on initialization mechanism, and configurable VID / PID information for establishing a valid communication connection with the host interface unit (600).
9. The USB multi-port device access encryption authentication system according to claim 4, characterized in that, The host interface unit (600) is the only interface module for the system to connect to the host. Structurally, it includes a standard Type-A female connector, an EMI anti-interference filter, a TVS electrostatic protection device, and a USB interface connected to the host. The host cannot actively identify uncertified devices. The entire certification process is completed under the control of the main control MCU unit (200) and the USB expansion unit (400), thereby preventing users from bypassing the system mechanism to forcibly connect peripherals.
10. The USB multi-port device access encryption and authentication system according to claim 4, characterized in that, The insertion / removal detection unit (500) includes multiple current detection modules. Each USB port is equipped with a set of current detection modules, which are composed of current sampling amplifiers such as INA199 combined with low-resistance detection resistors. When the device is connected, the current fluctuation triggers an interrupt signal to the main control MCU unit (200), and the main control MCU unit (200) starts the USB device identification process. When the device is disconnected, the current drops and triggers an interrupt again. The main control MCU unit (200) locates the unplugged port according to the interrupt source and performs the channel shutdown and status reset operations.
Citation Information
Cited By
A computer interface security control system and method
CN122508644A