A component system, terminal device and dual operating system isolation method

Through the hardware-level dual operating system isolation method, the control unit controls the opening or closing of the network card and memory, solving the problem of low security of the software-level isolation method, realizing high-security network isolation, and ensuring the security of user privacy data.

CN113111393BActive Publication Date: 2025-08-08HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010033936.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-01-13
Publication Date
2025-08-08
Estimated Expiration
2040-01-13

AI Technical Summary

Technical Problem

In the prior art, the software-level dual operating system isolation method has low security and cannot effectively prevent hackers from obtaining information in both networks by tampering with access rights.

Method used

The hardware-level dual operating system isolation method is adopted to control the opening or closing of the network card and memory through the control unit. Only one network and operating system are allowed to be in the on state and the other network and operating system are in the off state at the same time, realizing physical isolation.

Benefits of technology

Improves security between different networks and operating systems, prevents hackers from invading information from another network, and ensures the security of user privacy data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113111393B_ABST
    Figure CN113111393B_ABST
Patent Text Reader

Abstract

The present application provides a component system, a terminal device, and a dual operating system isolation method, which relates to the field of terminal technology and is used to improve the security of different network data in the terminal device. The component system includes: a control unit, a processing unit, a first network card, a second network card, a first memory, and a second memory; the control unit is used to control the opening or closing of the first network card, the first memory, the second network card, and the second memory, so that the component system performs one of the following settings: the first setting is to open the first network card and the first memory and close the second network card and the second memory, and the second setting is to open the second network card and the second memory and close the first network card and the first memory; the processing unit is used to access the first memory through the network corresponding to the first network card under the first setting, or to access the second memory through the network corresponding to the second network card under the second setting. The component system can be a terminal device such as a computer, a laptop computer, and a tablet computer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of terminal technology, and in particular to a component system, a terminal device, and a dual operating system isolation method. Background Art

[0002] With the continued development of the internet, people are increasingly demanding higher security for network information. To protect secure information from hackers or viruses, dual-network isolation technology has emerged. Dual-network isolation securely isolates internal and external networks, preventing external networks from intruding through network connections and preventing internal network information from leaking to external networks. Computers supporting dual-network isolation typically have dual operating systems, one for each network—for example, one operating system for the local area network and another for the wide area network. Using the operating system corresponding to each network, the two networks are isolated.

[0003] The prior art provides a software-based dual-operating system isolation method. In this method, a computer is equipped with two network cards and two operating systems, which run simultaneously. Each operating system is bound to a corresponding network card, and the software on each operating system can access the network corresponding to the network card bound to that operating system. However, this software-based dual-operating system isolation method has low security. Summary of the Invention

[0004] The present application provides a component system, terminal device and dual operating system isolation method, which solves the problem of low security when the same device is connected to different networks in the prior art.

[0005] To achieve the above objectives, this application adopts the following technical solutions:

[0006] In a first aspect, a component system is provided, including: a control unit, a processing unit, a first network card, a second network card, a first memory, and a second memory; wherein the control unit is used to control the opening or closing of the first network card, the first memory, the second network card, and the second memory, so that the component system performs one of the following settings: the first setting is to open the first network card and the first memory and close the second network card and the second memory, and the second setting is to open the second network card and the second memory and close the first network card and the first memory; the processing unit is used to receive a first opening instruction of the first network card and the first memory based on the first setting, and access the first memory through the network corresponding to the first network card, or receive a second opening instruction of the second network card and the second memory based on the second setting, and access the second memory through the network corresponding to the second network card.

[0007] In the above technical solution, only one network of the component system is open at the same time, and the other network is closed. The processing unit can only access the data of the open network, but cannot access the data of the closed network, thereby realizing the physical isolation between different networks and different operating systems in the same component system. Compared with the existing technology in which both networks and both operating systems are in the open state, the security of data in different networks is greatly improved.

[0008] In a possible implementation of the first aspect, the control unit includes: a controller, and a first switch, a second switch, a third switch, and a fourth switch connected between the power supply and the first network card, the first memory, the second network card, and the second memory; the controller is also used to: control the first switch and the second switch to be closed, and the third switch and the fourth switch to be disconnected, so as to control the first network card and the first memory to be turned on, and the second network card and the second memory to be turned off; or, control the first switch and the second switch to be disconnected, and the third switch and the fourth switch to be closed, so as to control the second network card and the second memory to be turned on, and the first network card and the first memory to be turned off. In the above possible implementation, the control unit includes a controller and multiple switches. The controller can realize power supply to different network cards and different memories by controlling the closing or disconnection of different switches, thereby realizing control of turning on or off different network cards and different memories. This implementation has the advantages of simple operation, easy implementation, and low cost.

[0009] In one possible implementation of the first aspect, the power supply includes an off-state power supply and an on-state power supply, the first switch and the third switch are specifically connected to the off-state power supply, and the second switch and the fourth switch are specifically connected to the on-state power supply. In this possible implementation, the controller can control the off-state power supply and the on-state power supply via different switches to power different network cards and different memories in the on-state and off-state, respectively.

[0010] In a possible implementation of the first aspect, the control unit further includes: a first control module, a second control module, and a third control module, and the controller includes a first interface, a second interface, and a third interface; wherein the first interface is connected to the control end of the first switch and the input end of the first control module, the first interface and the second interface are respectively connected to the first input end and the second input end of the second control module, the output end of the second control module is connected to the control end of the second switch, the output end of the first control module is connected to the control end of the third switch, the output end of the first control module and the third interface are respectively connected to the first input end and the second input end of the third control module, and the output end of the third control module is connected to the control end of the fourth switch. In the above possible implementation, the control function of the control unit is realized by the controller and multiple control modules, so that the controller can control different network cards and different memories through fewer interfaces, thereby saving controller resources.

[0011] In a possible implementation of the first aspect, the first control module includes a NOT gate, the second control module includes an AND gate, and the third control module includes an AND gate. In the above possible implementation, the different control modules provided have advantages such as simple operation, easy implementation, and low cost.

[0012] In one possible implementation of the first aspect, the second network card is a PCIe network card, and the component system is provided with a PCIe slot for inserting the PCIe network card. In this possible implementation, inserting the PCIe network card as the second network card through the PCIe slot can improve the performance of the component system.

[0013] In one possible implementation of the first aspect, the control unit further includes: a fifth switch connected between the power-on power supply and the PCIe slot; and the controller is further configured to control the fifth switch to close when controlling the second network card to be turned on, so that the power-on power supply supplies power to the PCIe slot. In this possible implementation, the controller can control power supply to the PCIe slot by closing or opening the fifth switch.

[0014] In one possible implementation of the first aspect, the control unit further includes a fourth control module, wherein a first input end of the fourth control module is configured to receive a power-on status indication, a second input end of the fourth control module is connected to an output end of the first control module, and an output end of the fourth control module is connected to a control end of a fifth switch. In this possible implementation, the controller can control the closing or opening of the fifth switch based on the power-on status indication, thereby improving the accuracy of controlling the opening or closing of the second network interface card.

[0015] In a possible implementation of the first aspect, the fourth control module includes an AND gate. In the above possible implementation, the provided fourth control module has the advantages of simple operation, easy implementation, and low cost.

[0016] In one possible implementation of the first aspect, the component system further includes: other PCIe devices in addition to the PCIe network card, and the PCIe slot is further configured to insert other PCIe devices, such as a sound card or a graphics card. In this possible implementation, the PCIe slot is further configured to insert other PCIe devices, thereby improving the compatibility of the component system.

[0017] In a possible implementation of the first aspect, the control unit further includes: a fifth control module, a sixth control module, and a seventh control module; the fourth control module further includes a third input end for receiving a detection signal, wherein the detection signal is used to indicate that a PCIe network card or other PCIe device is inserted into the PCIe slot; the first input end of the fifth control module is connected to the output end of the first control module, the second input end of the fifth control module is used to receive the detection signal, and the output end of the fifth control module is connected to the third switch and the first input end of the third control module; the first input end of the sixth control module is used to receive the detection signal, and the second input end of the sixth control module is connected to the output end of the fourth control module; the first input end of the seventh control module is connected to the output end of the sixth control module, the second input end of the seventh control module is used to receive a power-on status indication, and the output end of the seventh control module is connected to the control end of the fifth switch. In the above possible implementation, the controller realizes turning on or off the second network card through multiple control modules, which can improve the controller's accurate control of the second network card.

[0018] In one possible implementation of the first aspect, the fifth control module includes a NOT gate and an OR gate, wherein one input of the OR gate and the input of the NOT gate serve as the first input and second output of the fifth control module, respectively, the output of the OR gate serves as the output of the fifth control module, and the output of the NOT gate is connected to the other input of the OR gate. The sixth control module includes a NOT gate and an OR gate, wherein the input of the NOT gate and one input of the OR gate serve as the first input and second output of the sixth control module, respectively, the output of the OR gate serves as the output of the sixth control module, and the output of the NOT gate is connected to the other input of the OR gate. The seventh control module includes an AND gate. In the above possible implementations, the multiple control modules provided have the advantages of simple operation, ease of implementation, and low cost.

[0019] In a second aspect, a terminal device is provided, which includes the component system provided by the first aspect or any possible implementation of the first aspect.

[0020] In a possible implementation of the second aspect, the terminal device includes a personal computer, a tablet computer, a laptop computer, a PDA, etc.

[0021] In a third aspect, a dual operating system isolation method is provided, which is applied to a component system provided by the first aspect or any possible implementation of the first aspect, wherein the component system includes a control system, a basic input and output system BIOS, a first operating system bound to a first network card and a first memory, and a second operating system bound to a second network card and a second memory, the method including: the control system controls the power-on of a default network card and a default memory, the default network card and the default memory being the first network card and the first memory, or the second network card and the second memory respectively; the control system starts the BIOS; the BIOS starts the default operating system, the default operating system being the operating system bound to the default network card and the default memory.

[0022] In a possible implementation manner of the third aspect, after the control system starts the BIOS, the method further includes: the BIOS obtaining default indication information from the control system, where the default indication information is used for a default operating system.

[0023] In a possible implementation of the third aspect, before the BIOS starts the default operating system, the method further includes: the BIOS controls the display of operating system option information, where the operating system option information is used to instruct the user to select a target operating system from the first operating system and the second operating system; and the BIOS receives the target operating system selected by the user.

[0024] In a possible implementation of the third aspect, the method further includes: if the target operating system is inconsistent with the default operating system, the BIOS changes the default network card and the default memory; and the BIOS restarts the terminal device.

[0025] In a possible implementation of the third aspect, the BIOS starts a default operating system, including: when the default network card and the default memory are the first network card and the first memory respectively, the BIOS starts the first operating system; when the default network card and the default memory are the second network card and the second memory respectively, the BIOS starts the second operating system.

[0026] In a possible implementation of the third aspect, after the BIOS starts the default operating system, the method further includes: the default operating system receives an operating system switching indication triggered by a user, and changes the default network card and default memory according to the operating system switching indication; and the default operating system restarts the terminal device.

[0027] It can be understood that any of the terminal devices and dual operating system isolation methods provided above include the component systems provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding component systems provided above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1A schematic diagram of the structure of a component system provided in an embodiment of the present application;

[0029] Figure 2 A schematic diagram of the structure of another component system provided in an embodiment of the present application;

[0030] Figure 3 A schematic structural diagram of another component system provided in an embodiment of the present application;

[0031] Figure 4 A schematic diagram of the connection relationship between a motherboard and a PCIe network card provided in an embodiment of the present application;

[0032] Figure 5 A schematic diagram of another connection relationship between a motherboard and a PCIe network card provided in an embodiment of the present application;

[0033] Figure 6 A schematic diagram of the connection relationship of another component system provided in an embodiment of the present application;

[0034] Figure 7 A schematic diagram of the connection relationship of another component system provided in an embodiment of the present application;

[0035] Figure 8 A software architecture diagram of a component system provided in an embodiment of the present application;

[0036] Figure 9 A schematic diagram of a dual operating system isolation method provided in an embodiment of the present application;

[0037] Figure 10 An interface diagram of a component system provided in an embodiment of the present application;

[0038] Figure 11 An interface diagram of another component system provided in an embodiment of the present application;

[0039] Figure 12 A flowchart of another operating system isolation method provided in an embodiment of the present application. DETAILED DESCRIPTION

[0040] In this application, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple. In addition, the embodiments of the present application use words such as "first" and "second" to distinguish objects with similar names, functions or effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order.

[0041] Before introducing the embodiments of the present application, the software-level dual operating system isolation and the physical-level dual operating system isolation involved in the present application are first explained.

[0042] Software-level dual-operating system isolation refers to the isolation between two operating systems by configuring the permissions or access rights of different software running on the hardware unit. After isolation, both operating systems are in operation, and the network card bound to each operating system is also in operation, but one operating system cannot access the software running on the other operating system, the information managed by it, or the network provided by the bound network card.

[0043] Physical-level dual operating system isolation refers to the isolation between two dual operating systems achieved directly by configuring different hardware units. After isolation, the two operating systems are not in running state at the same time. At the same time, only one operating system and the network card bound to it are running, and the other operating system and the network card bound to it are shut down. Therefore, the running operating system can only access the network provided by the bound network card.

[0044] Currently, most terminal devices can be installed with two operating systems and two network cards. Each operating system is bound to a corresponding network card. These two network cards can provide two different networks, and each operating system can access the network provided by the bound network card. For example, the two operating systems include operating system 1 and operating system 2. The two network cards bound to the two operating systems are network card 1 and network card 2. Network card 1 provides a wide area network (WAN) and network card 2 provides a local area network (LAN). In this case, the user can access the WAN using operating system 1 and the local area network using operating system 2.

[0045] To ensure the security of information on both networks and prevent hackers and other unauthorized individuals from accessing information on one network through the other, dual operating system isolation is required. Dual operating system isolation means that a user can only access one network at a time through one operating system, rather than accessing both networks simultaneously.

[0046] In the software-level dual operating system isolation solution provided in the prior art, two network cards and two operating systems are running at the same time, but a user can only log in to one operating system at a time and access the network corresponding to the network card bound to the operating system through the software on the operating system. This software-level dual operating system isolation method is implemented through access permission configuration at the software level, that is, different network access permissions are configured for different operating systems, but the two network cards are not isolated in terms of hardware. For example, the two network cards and two operating systems are running at the same time. In this case, when hackers and other illegal elements invade, they can obtain information in the two networks at the same time by tampering with the access permissions, thus resulting in a low security problem.

[0047] Based on this, the embodiment of the present application provides a technical solution for isolating dual operating systems, which is based on hardware-level isolation and can also be called physical isolation. Specifically, for two operating systems and two network cards, only one operating system and the network card bound to the operating system are turned on or running at the same time, and the other operating system and the network card bound to the operating system are turned off. There will not be a situation where two network cards and two operating systems are turned on or running at the same time. In this case, since the other operating system and the network card are turned off, even if hackers and other illegal elements invade, they cannot turn on the other operating system and the network card by means of tampering with access rights, and thus cannot obtain information in another network. Therefore, the technical solution provided by the present application is highly secure. The technical solution provided by the embodiment of the present application is described in detail below.

[0048] Figure 1 This is a schematic diagram of the structure of a component system provided in an embodiment of the present application. The component system includes: a control unit 11, a processing unit 12, a first network card 13, a second network card 14, a first memory 15, and a second memory 16. The control unit 11 is connected to the first network card 13, the second network card 14, the first memory 15, and the second memory 16 via control signal lines, and the processing unit 12 is connected to the first network card 13, the second network card 14, the first memory 15, and the second memory 16 via a bus.

[0049] The first network card 13 can be used to enable the first network, and the first memory 15 can be used to store data on the first network. The second network card 14 can be used to enable the second network, and the second memory 16 can be used to store data on the second network. The control unit 11 can be used to control the enabling or disabling of the first network card 13, the first memory 15, the second network card 14, and the second memory 16, so that the component system performs one of the following settings: a first setting in which the first network card 13 and the first memory 15 are enabled and the second network card 14 and the second memory 16 are disabled; a second setting in which the second network card 14 and the second memory 16 are enabled and the first network card 13 and the first memory 15 are disabled. The processing unit 12 can be used to receive a first enabling instruction for the first network card 13 and the first memory 15 based on the first setting, and access the first network through the first network card 13 and the first memory 15, or to receive a second enabling instruction for the second network card 14 and the second memory 16 based on the second setting, and access the second network through the second network card 14 and the second memory 16.

[0050] In the embodiment of the present application, only one network of the component system is open at a time, while the other network is closed. The processing unit 12 can only access data on the open network, but cannot access data on the closed network. This achieves physical isolation between different networks and different operating systems within the component system. Compared to the prior art where both networks and both operating systems are open, the security of data in different networks is greatly improved. For example, if the first network is a wide area network (WAN) and the second network is a local area network (LAN), the data in the LAN typically includes user privacy data. In this way, when the WAN is open and the LAN is closed, the security of user privacy data can be guaranteed even if hackers or other illegal personnel invade.

[0051] Further, such as Figure 2 As shown, the component system may further include a first switch SW1, a second switch SW2, a third switch SW3, and a fourth switch SW4. The first switch SW1 is connected between the power supply and the first network card 13, the second switch SW2 is connected between the power supply and the first storage 15, the third switch SW3 is connected between the power supply and the second network card 14, and the fourth switch SW4 is located between the power supply and the second storage 16. The power supply includes an off-state power supply and an on-state power supply. The first switch SW1 and the third switch SW3 are specifically connected to the off-state power supply, and the second switch SW2 and the fourth switch SW4 are specifically connected to the on-state power supply.

[0052] The control unit 11 can be used to control the opening or closing of the first switch SW1, the second switch SW2, the third switch SW3, and the fourth switch SW4. The control unit 11 can connect or disconnect the power supply in the power-off state S5 to supply power to the first network card 13 by controlling the first switch SW1, connect or disconnect the power supply in the power-off state S5 to supply power to the second network card 14 by controlling the third switch SW3, connect or disconnect the power supply in the power-on state S0 to supply power to the first memory 15 by controlling the second switch SW2, and connect or disconnect the power supply in the power-on state S0 to supply power to the second memory 16 by controlling the fourth switch SW4.

[0053] It should be noted that S0 represents the power-on state of the component system, and S5 represents the power-down state of the component system. When the component system is in the power-on state S0, both the power supply in the power-down state S5 and the power supply in the power-up state S0 are in operation. When the component system is in the power-down state S5, the power supply in the power-down state S5 is in operation, and the power supply in the power-up state S0 is inoperative. The operating voltage of both the power supply in the power-down state S5 and the power supply in the power-up state S0 can be 3.3V. Figure 2 In the figure, the power supply of S5 in the shutdown state is represented as +3V3_S5, and the power supply of S0 in the startup state is represented as +3V3_S0.

[0054] Accordingly, in Figure 2 In the example, the control unit 11 can be specifically used to: control the first switch SW1 and the second switch SW2 to be closed or opened, so as to control the first network card 13 and the first storage 15 to be turned on or off at the same time; and control the third switch SW3 and the fourth switch SW4 to be closed or opened, so as to control the second network card 14 and the second storage 16 to be turned on or off at the same time. When the control unit 11 controls the first switch SW1 and the second switch SW2 to be closed, the third switch SW3 and the fourth switch SW4 can be controlled to be opened; when the control unit 11 controls the third switch SW3 and the fourth switch SW4 to be closed, the first switch SW1 and the second switch SW2 can be controlled to be opened. In this way, the control unit 11 can control the first network card 13 and the second network card 14 not to be turned on at the same time, and the first storage 15 and the second storage 16 not to be turned on at the same time, thereby achieving physical isolation between different networks.

[0055] Optionally, the control unit 11 may include a controller and a peripheral circuit. The controller may include an embedded controller (EC), a complex programmable logic device (CPLD), or a field-programmable gate array (FPGA). The peripheral circuit may include multiple control modules, each of which may include one or more logic gate circuits, which may be AND gates, OR gates, NOT gates, or any combination thereof. Figure 3 、 Figure 5 and Figure 6 The logic gate circuits included in the peripheral circuit shown in the figure are merely exemplary and do not limit the embodiments of the present application.

[0056] The processing unit 12 may include a processor, which may include a central processing unit (CPU), a system on chip (SOC), a digital signal processor (DSP), or an FPGA.

[0057] The first memory 15 and the second memory 16 may include a solid-state drive (SSD), a hard disk drive (HDD), a flash memory, or an embedded Multi Media Card (EMMC) memory.

[0058] Any of the first switch SW1, the second switch SW2, the third switch SW3, and the fourth switch SW4 may include an analog switch (load switch) or a mechanical switch (mechanical switching device). An analog switch may refer to a switching device that uses the controllable conductivity of a semiconductor to connect and disconnect the current in a circuit, such as a switching circuit designed based on a diode, a transistor, or a field-effect transistor. A mechanical switch may refer to a switching device that closes and opens one or more circuits by the action of separable contacts, such as a contactor or a relay. When the switch is a common switch such as a mechanical switch, the switch may include a closed state and an open state (also referred to as an unclosed state or an open state); when the switch is an analog switch, the switch may include an on state and an off state, where the on state may correspond to the closed state of a common switch, and the off state may correspond to the open state of a common switch.

[0059] In one possible implementation, Figure 3 As shown, the control unit 11 includes a controller 111, a first NOT gate 112, a first AND gate 113, and a second AND gate 114. The controller 111 is provided with a first interface, a second interface, and a third interface. Optionally, the first interface, the second interface, and the third interface can be general purpose input / output (GPIO) interfaces. Figure 3 In the description, the processing unit 12 includes the processor 12 as an example.

[0060] The controller 111 is connected to the input of the first NOT gate 112, the control terminal of the first switch SW1, and one input of the first AND gate 113 via a first interface, to the other input of the first AND gate 113 via a second interface, and to one input of the second AND gate 114 via a third interface. The output of the first NOT gate 112 is connected to the control terminal of the third switch SW3 and the other input of the second AND gate 114. The output of the first AND gate 113 is connected to the control terminal of the second switch SW2. The output of the second AND gate 114 is connected to the control terminal of the fourth switch SW4. The first switch SW1 can be used to connect or disconnect the power supply in the power-on state S5 to the first network card 13, and the second switch SW2 can be used to connect or disconnect the power supply in the power-on state S0 to the first memory 15. The third switch SW3 can be used to connect or disconnect the power supply in the power-on state S5 to the second network card 14, and the fourth switch SW4 can be used to connect or disconnect the power supply in the power-on state S0 to the second memory 16. Figure 3 In the following example, the power supply of S0 in the power-on state is +3V3_S0, and the power supply of S5 in the power-off state is +3V3_S5.

[0061] Specifically, the control unit 11 controls the first network card 13 and the first memory 15 to be turned on at the same time, and controls the second network card 14 and the second memory 16 to be turned off at the same time. Specifically, the controller 111 outputs a high level through the first interface and outputs a high level through the second interface, so that the high level output by the first interface can control the first switch SW1 to be closed, so that the power supply in the shutdown state S5 supplies power to the first network card 13. At the same time, the high level output by the first interface and the high level output by the second interface are outputted at a high level after passing through the first AND gate 113. The high level can control the second switch SW2 to be closed, so that the power supply in the power-on state S0 supplies power to the first memory 15. In addition, the high level output by the first interface is converted to a low level after passing through the first NOT gate 112. The low level can control the third switch SW3 to be opened, so as to cut off the power supply in the power-on state S5 to the second network card 14. At the same time, the low level still outputs a low level after passing through the second AND gate 114. The output low level can control the fourth switch SW4 to be opened, so as to cut off the power supply in the power-on state S0 to the second memory 16.

[0062] The control unit 11 controls the second network card 14 and the second memory 16 to be turned on simultaneously, and controls the first network card 13 and the first memory 15 to be turned off simultaneously. Specifically, the control unit 111 may include: the controller 111 outputs a low level through the first interface and a high level through the third interface, so that the low level output by the first interface is converted to a high level after passing through the first NOT gate 112. The high level can control the third switch SW3 to be closed, so that the power supply in the shutdown state S5 supplies power to the second network card 14. At the same time, the high level and the high level output by the third interface are converted to a high level after passing through the second AND gate 114. The output high level can control the fourth switch SW4 to be closed, so that the power supply in the power-on state S0 supplies power to the second memory 16; in addition, the low level output by the first interface can control the first switch SW1 to be opened, so as to cut off the power supply in the power-on state S5 to the first network card 13. At the same time, the low level output by the first interface still outputs a low level after passing through the first AND gate 113. The output low level can control the second switch SW2 to be opened, so as to cut off the power supply in the power-on state S0 to the first memory 15.

[0063] Furthermore, when Figure 1 、 Figure 2 or Figure 3 When the various units or devices included in the component system shown are integrated on a mainboard, the first network card 13 and the second network card 14 can both be onboard network cards, that is, the first network card 13 and the second network card 14 can be directly integrated on the mainboard. Alternatively, the first network card can be an onboard network card, and the second network card 14 can be a PCIe network card, that is, the mainboard is provided with a PCIe slot, and the PCIe network card serving as the second network card 14 can be inserted into the mainboard through the PCIe slot.

[0064] Among them, for onboard network cards and PCIe network cards, each network card can include a physical layer PHY and a media access control layer MAC, and the location of the PHY and MAC is irrelevant to the form of the network card. The PHY and MAC of the same network card can be located in the network card at the same time, or only the PHY can be located in the network card and the MAC can be located in the processing unit. Figure 3 Taking the first network card 13 and the second network card 14 shown as an example, the physical layer PHY1 corresponding to the first network card 13 can be located in the first network card 13, and the media access control layer MAC1 corresponding to the first network card 13 can be located in the processing unit 12; the physical layer PHY2 and the media access control layer MAC2 corresponding to the second network card 14 are both located in the second network card 14.

[0065] For example, Figure 4This is a schematic diagram of the connection relationship between the motherboard and the PCIe network card (second network card 14) in a component system provided in an embodiment of the present application. The motherboard is integrated with a control unit 11, a processing unit 12, a first network card 13, a first memory 15, and a second memory 16. Furthermore, the motherboard can also be integrated with a first switch SW1, a second switch SW2, a third switch SW3, and a fourth switch SW4. Figure 4 In the motherboard, the PCIe slot may include a power line, a PCIe bus, and other auxiliary signal lines, etc. Other auxiliary signal lines may include a test data input signal line JTAG_TDI and a test data output signal line JTAG_TDO. JTAG_TDI is connected to the power supply (for example, +3V3) through a resistor, and JTAG_TDO is connected to the ground line through a resistor.

[0066] Among them, inside the PCIe network card, JTAG_TDI is connected to JTAG_TDO. The motherboard can determine whether the PCIe slot is inserted with a PCIe network card by detecting the level of the JTAG_TDO output. Specifically, when the motherboard detects that JTAG_TDO outputs a high level, it can be determined that the PCIe slot is inserted with a PCIe network card; when the motherboard detects that JTAG_TDO outputs a low level, it can be determined that the PCIe slot is inserted with other PCIe devices, for example, other PCIe devices can be graphics cards, or sound cards, etc. For the convenience of description, the signal output by JTAG_TDO can be called a network card detection signal. Figure 4 It is represented as LAN_CARD_DETECT in .

[0067] Optional, such as Figure 5 As shown, the PCIe bus may include: a test reset signal line PCIe_TRST of the PCIe bus, a test mode selection signal line PCIe_TMS of the PCIe bus, a test data output signal line PCIe_TDO of the PCIe bus, a test clock signal line PCIe_TCK of the PCIe bus, and a test data input signal line PCIe_TDI of the PCIe bus. PCIe_TDO and PCIe_TDI can be used as the above-mentioned JTAG_TDO and JTAG_TDI respectively. Figure 5 In the example, PCIe_TRST, PCIe_TDI, and PCIe_TMS are connected to a power line (e.g., +3V3) through resistors, and PCIe_TDO and PCIe_TCK are connected to a ground line through resistors.

[0068] Specifically, when second network interface card 14 is inserted into a PCIe slot, the PCIe slot corresponds to a slot power supply. This slot power supply is derived by dividing the power supply in the power-on state (S0). This slot power supply is only active when the component system is powered on. Within the PCIe card, this divided slot power supply is connected to the card's ISOLATE pin. The card uses the ISOLATE pin to distinguish between powered-on and powered-off states. When the component system is powered on, the card establishes a connection to the PCIe bus. When the component system is powered off, the card disconnects from the PCIe bus. Accordingly, the control unit 11 can further control the supply of this slot power supply.

[0069] For example, combined Figure 3 ,like Figure 6 As shown, the control unit 11 may further include: a third AND gate 115 and a fifth switch SW5. One input end of the third AND gate 115 is connected to the output end of the first NOT gate 112, and the output end of the third AND gate 115 is connected to the control end of the fifth switch SW5. The fifth switch SW5 is used to connect or disconnect the connection between the power supply S0 in the power-on state and the input end of the voltage divider circuit, that is, the fifth switch SW5 is used to connect or disconnect the power supply of the slot ( Figure 6 Another input terminal of the third AND gate 115 is used to receive the system status indication signal IN_S0. For example, when the component system is in the power-on state, the IN_S0 may be at a high level, and when the component system is in the power-off state, the IN_S0 may be at a low level.

[0070] Specifically, when the component system is in the power-on state, and the control unit 11 controls the second network card 14 and the second memory 16 to be turned on at the same time, and controls the first network card 13 and the first memory 15 to be turned off at the same time, it can specifically include: the controller 111 outputs a low level through the first interface and outputs a high level through the third interface, so that the low level output by the first interface is converted to a high level after passing through the first NOT gate 112, and the high level can control the third switch SW3 to be closed, so that the power supply S5 in the shutdown state provides an auxiliary power supply +3.3V_Aux to the PCIe slot corresponding to the second network card 14 (that is, the power supply of the second network card 14 is normal), and at the same time, the high level and the high level corresponding to IN_S0 are outputted at a high level after passing through the third AND gate 115, and the output high level can control the fifth switch SW5 to be closed, so that the slot The power supply is normally supplied, so that the voltage divider signal output by the voltage divider circuit in the second network card 14 can enable the second network card 14 to detect the power-on state S0, and then establish a connection with the PCIe bus; at the same time, after passing through the first NOT gate 112, it is converted into a high level and the high level output by the third interface is outputted as a high level after passing through the second AND gate 114. The output high level can control the fourth switch SW4 to close, so that the power supply in the power-on state S0 supplies power to the second memory 16; in addition, the low level output by the first interface can control the first switch SW1 to be disconnected, so as to cut off the power supply in the power-off state S5 for the first network card 13. At the same time, the low level output by the first interface is still outputted as a low level after passing through the first AND gate 113. The output low level can control the second switch SW2 to be disconnected, so as to cut off the power supply in the power-on state S0 for the first memory 15.

[0071] Optionally, when other PCIe devices are inserted into the PCIe slot on the motherboard, the control unit 11 can control the first network card 13 and other PCIe devices to be turned on at the same time, that is, the control unit 11 can control the shutdown state S5 power supply and the slot power supply to supply power to the first network card 13 and other PCIe devices at the same time.

[0072] For example, combined Figure 6 ,like Figure 7As shown, the control unit 11 may further include: a first OR gate 116, a second OR gate 117, a fourth AND gate 118, a second NOT gate 119, and a third NOT gate 120; the third AND gate 115 also includes a third input terminal for receiving a network card detection signal. The input terminal of the second NOT gate 119 is used to receive the network card detection signal, the output terminal of the first NOT gate 112 is connected to one input terminal of the first OR gate 116, the output terminal of the second NOT gate 119 is connected to the other input terminal of the first OR gate 116, and the output terminal of the first OR gate 116 is connected to the control terminal of the third switch SW3. The input terminal of the third NOT gate 120 is used to receive the network card detection signal, the output terminal of the third NOT gate 120 is connected to one input terminal of the second OR gate 117, the other input terminal of the second OR gate 117 is connected to the output terminal of the third AND gate 115, and the output terminal of the second OR gate 117 is connected to one output terminal of the fourth AND gate 118. Another output terminal of the fourth AND gate 118 is used to receive the system status indication signal IN_S0 . The output terminal of the fourth AND gate 118 is connected to the control terminal of the fifth switch SW5 .

[0073] Specifically, when other PCIe devices are inserted into the PCIe slot, the control unit 11 controls the first network card 13 and the other PCIe devices to be turned on at the same time, which may specifically include: the controller 111 outputs a high level through the first interface, the second interface and the third interface, and detects that the network card detection signal LAN_CARD_DETECT is a low level and the system status indication signal IN_S0 is a high level; when the first interface and the second interface output high levels, according to Figure 6 Correlation analysis shows that the power supply of the first network card 13 and the first memory 15 is normal. When the first interface outputs a high level and the network card detection signal is low, the two input terminals of the first OR gate 116 are low and high, respectively. The output terminal of the first OR gate 116 outputs a high level, which controls the closure of the third switch SW3, thereby ensuring normal power supply to the auxiliary power supply +3.3V_Aux of the PCIe slot. At the same time, this high level and the high level output from the third interface pass through the second AND gate 114 to output a high level. The high level output controls the closure of the fourth switch SW4, thereby ensuring normal power supply to the second memory 16. When the network card detection signal is low, the second OR gate 117 outputs a high level. This high level and the high level of the system status indication signal IN_S0 pass through the third AND gate 115 to output a high level. The high level output controls the closure of the fifth switch SW5, thereby ensuring normal power supply to the slot. Therefore, when the PCIe slot is inserted into other PCIe devices, the first network card 13 and other PCIe devices can both function normally, thereby improving the compatibility of the component system.

[0074] Based on this, an embodiment of the present application further provides a terminal device, which includes any possible component system provided above. Optionally, the terminal device can be a personal computer (PC), tablet computer, laptop computer, PDA, etc.

[0075] The above mainly describes the solution provided by this application from the perspective of the various hardware included in the component system or the terminal device. In actual application, based on the hardware architecture included in the above-mentioned terminal device, the various software in the software architecture based on this hardware architecture are also improved accordingly. The following mainly describes the solution provided by this application from the perspective of the software architecture of the terminal device.

[0076] Figure 8 A schematic diagram of the software architecture of a component system or terminal device provided in an embodiment of the present application. The software architecture may include: a control system running on a controller 111, a basic input output system (BIOS) running on a processor 12, a first operating system, and a second operating system. The first operating system is bound to the first network card 13 and the first memory 15, for example, the first network card driver and the first memory driver run on the first operating system; the second operating system is bound to the second network card 14 and the second memory 16, for example, the second network card driver and the second memory driver run on the second operating system. Accordingly, as Figure 9 As shown, the dual operating system isolation method based on the software architecture may include the following steps.

[0077] S201: The control system controls the default network card and the default memory to be powered on, where the default network card and the default memory are respectively the first network card 13 and the first memory 15, or the default network card and the default memory are respectively the second network card 14 and the second memory 16.

[0078] When the control system detects a power-on operation, the control system can determine the default network card and default storage device based on the default indication information and control the power-on of the default network card and default storage device. When the default network card and default storage device are the first network card 13 and the first storage device 15, respectively, the control system controls the power-on of the first network card 13 and the first storage device 15; when the default network card and default storage device are the second network card 14 and the second storage device 16, respectively, the control system controls the power-on of the second network card 14 and the second storage device 16.

[0079] Optionally, the default indication information includes first indication information or second indication information, where the first indication information is used to indicate that the default network card and the default storage are the first network card 13 and the first storage 15, respectively, and the second indication information is used to indicate that the default network card and the default storage are the second network card 14 and the second storage 16, respectively. For example, taking the default indication information as the OS_Select variable as an example, the first indication information is that OS_Select is equal to 1, and the second indication information is that OS_Select is equal to 2. The control system can determine the value of OS_Select. When OS_Select = 1, the control system can control the first network card 13 and the first storage 15 to be powered on; when OS_Select = 2, the control system can control the second network card 14 and the second storage 16 to be powered on.

[0080] In actual applications, the power-on operation may be triggered by the user, for example, the user may trigger the power-on operation by pressing the power button of the terminal device, or by selecting the relevant restart icon in the power menu under the start menu. Figure 10 As shown, the power menu includes icons for shutdown, sleep, restart, and restart and switch to another operating system or network card. The related restart icon can refer to a restart icon and a restart and switch to another operating system or network card icon.

[0081] It should be noted that when the user chooses to restart and switch to another operating system or network card icon, the currently started operating system can change the default network card and default storage when it is started next time. The specific process of changing the default network card and default storage can be found in the relevant description in S206 below, and this embodiment of the application will not be repeated here.

[0082] S202: The control system starts BIOS.

[0083] After the control system controls the first network card 13 and the first memory 15 to be powered on, or controls the second network card 14 and the second memory 16 to be powered on, the control system may start the BIOS.

[0084] S203: BIOS starts the default operating system.

[0085] The BIOS can boot a default operating system based on default indication information, which includes first indication information or second indication information. The first indication information is used to indicate that the default network card and the default memory are the first network card 13 and the first memory 15, respectively, in which case the default operating system is the first operating system. The second indication information is used to indicate that the default network card and the default memory are the second network card 14 and the second memory 16, respectively, in which case the default operating system is the second operating system. Specifically, when the default operating system is the first operating system, the BIOS can boot the first operating system; when the default operating system is the second operating system, the BIOS can boot the second operating system.

[0086] In one possible implementation, the default indication information may be configured in the BIOS. In another possible implementation, after the control system starts the BIOS, the method further includes S203a: the BIOS obtains the default indication information from the control system.

[0087] In actual application, before the BIOS starts the default operating system, the BIOS can initialize the default network card and the default memory. When the default network card and the default memory are the first network card 13 and the first memory 15 respectively, the BIOS initializes the first network card 13 and the first memory 15; when the default network card and the default memory are the second network card 14 and the second memory 16 respectively, the BIOS initializes the second network card 14 and the second memory 16. When initializing the default network card and the default memory, the BIOS can also initialize peripherals such as the sound card, graphics card or keyboard. Specifically, the BIOS initialization of the first network card 13 and the first memory 15, or initialization of the second network card 14 and the second memory 16 can specifically include: power-on self-test, that is, detecting whether the network card or memory can work normally; configuring basic functions, that is, configuring the basic functions of the network card, such as the PXE boot (starting a computer from the network) function, etc.

[0088] Further, such as Figure 9 As shown, before S203, the method may further include: S204-S206.

[0089] S204: The BIOS determines to display operating system option information, where the displayed operating system option information is used to prompt the user to select a target operating system, where the target operating system is one of the first operating system and the second operating system.

[0090] The BIOS can determine whether to display the operating system option information based on the display selection information; if so, the operating system option information can be directly displayed; if not, the operating system option information can be omitted or displayed after re-determining the display selection information. When the BIOS does not display the operating system option information, the BIOS can directly boot the operating system bound to the default network card and the default storage.

[0091] Optionally, the display selection information includes first selection information or second selection information, where the first selection information indicates whether to display the operating system option information, and the second selection information indicates whether to not display the operating system option information. For example, taking the display selection information as a prompt variable, the first selection information indicates prompt is equal to 1, and the second selection information indicates prompt is equal to 0. The BIOS can determine the value of prompt. When prompt = 1, the BIOS can directly display the operating system option information; when prompt = 0, the BIOS can either not display the operating system option information or assign prompt a value of 1 and then display the operating system option information.

[0092] For example, taking the current user as user1 in User as an example, the operating system option information can be as follows: Figure 11 As shown, the display interface of the terminal device can display "Please select the operating system to start. If you select the first operating system, please enter 1. If you select the second operating system, please enter 2." Therefore, the user can select the first operating system as the target operating system by entering 1, and select the second operating system as the target operating system by entering 2.

[0093] S205: The BIOS determines whether the default operating system is consistent with the target operating system. If consistent, the process proceeds to S203; if not, the process proceeds to S206.

[0094] Among them, BIOS can determine whether the default operating system bound to the default network card and the default memory is consistent with the target operating system. If the default network card and the default memory are the first network card 13 and the first memory 15 respectively, the default operating system is the first operating system. When the target operating system selected by the user is the first operating system, the default operating system is consistent with the target operating system. When the target operating system selected by the user is the second operating system, the default operating system is inconsistent with the target operating system. If the default network card and the default memory are the second network card 14 and the second memory 16 respectively, the default operating system is the second operating system. When the target operating system selected by the user is the first operating system, the default operating system is inconsistent with the target operating system. When the target operating system selected by the user is the second operating system, the default operating system is consistent with the target operating system.

[0095] S206: If they are inconsistent, the BIOS changes the default network card and the default storage and restarts the system. After the restart, the system returns to S201 to continue the execution.

[0096] Among them, the BIOS can change the default network card and the default memory by changing the default indication information. Exemplarily, when the default indication information is the first indication information, the BIOS can change the default indication information to the second indication information, so that the default network card and the default memory can be changed from the first network card 13 and the first memory 15 to the second network card 14 and the second memory 16; when the default indication information is the second indication information, the BIOS can change the default indication information to the first indication information, so that the default network card and the default memory can be changed from the second network card 14 and the second memory 16 to the first network card 13 and the first memory 15. For example, taking the default indication information as the OS_Select variable as an example, the first indication information is OS_Select equal to 1, and the second indication information is OS_Select equal to 2, then the BIOS can change the default network card and the default memory by changing the value of OS_Select, that is, changing the value of OS_Select from 1 to 2, or from 2 to 1.

[0097] Optionally, when changing the default indication information, the BIOS may also change the display selection information. For example, when the display selection information is the first selection information, the BIOS may change the display selection information to the second selection information. This allows the BIOS to not display the operating system option information the next time the terminal device is restarted, and to directly start the operating system bound to the changed default network card and default storage. For example, if the display selection information is the prompt variable, and the first selection information is prompt equal to 1, and the second selection information is prompt equal to 0, the BIOS can change the display selection information by assigning prompt a value of 0.

[0098] It should be noted that after the BIOS changes the default instruction information and the display selection information, the BIOS may also notify the control system of the default instruction information and the display selection information so that the control system and the default instruction information and display selection information known by the BIOS are consistent.

[0099] For ease of understanding, the following takes the default indication information as the OS_Select variable, the display selection information as the prompt variable, and the default network card and the default storage as the first network card 13 and the first storage 15 as an example. Figure 12 The solutions provided in the embodiments of this application are illustrated by examples.

[0100] At boot time, the control system determines whether OS_Select is equal to 1 (OS_Select == 1). If so, it controls the power-on of the first network card 13 and the first storage 15. If not, it controls the power-on of the second network card 14 and the second storage 16. The control system then starts the BIOS. The BIOS obtains OS_Select from the control system, determines whether OS_Select is equal to 1 (OS_Select == 1), and if so, initializes the first network card 13 and the first storage 15. If not, it initializes the second network card 14 and the second storage 16. After initializing the first network card 13 and the first storage 15, it determines whether prompt is equal to 1 (prompt == 1). If not, it sets prompt=1 and then starts the first operating system to terminate. If so, it allows the user to select the target operating system and sets OS_Select according to the target operating system. It further determines whether OS_Select is equal to 1 (OS_Select == 1). If so, it starts the first operating system. If not, it sets prompt=0 and OS_Select=2 and then restarts. Similarly, after initializing the second network card 14 and the second memory 16, determine whether prompt is equal to 1 (prompt == 1). If not (N), set prompt = 1 and start the second operating system to end; if (Y), let the user select the target operating system and set OS_Select according to the target operating system, and further determine whether OS_Select is equal to 2 (OS_Select == 2). If so, start the second operating system; if not (N), set prompt = 0 and OS_Select = 1 and then restart.

[0101] In an embodiment of the present application, the control system controls only the power-on of the first network card 13 and the first memory 15, or controls only the power-on of the second network card 14 and the second memory 16 at the same time. Similarly, the BIOS only starts the first operating system bound to the first network card 13 and the first memory 15, or only starts the second operating system bound to the second network card 14 and the second memory 16 at the same time. As a result, only one network is open at the same time, and the other network is closed. The processor can only access data on the open network, but cannot access data on the closed network. This achieves physical isolation between different networks and improves the security of data in different networks. For example, the first network is a wide area network (WAN), and the second network is a local area network (LAN). Typically, the data in the LAN includes user privacy data. In this way, when the WAN is open and the LAN is closed, the security of user privacy data can be guaranteed even if hackers or other illegal personnel invade.

[0102] In the several embodiments provided in this application, it should be understood that the disclosed component systems, terminal devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0103] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0104] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may be physically included separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0105] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to perform some steps of the method described in each embodiment of the present application.

[0106] Finally, it should be noted that the above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A component system, characterized in that: include: A control unit, a processing unit, a first network card, a second network card, a first memory, and a second memory, wherein the control unit includes a controller, and a first switch, a second switch, a third switch, and a fourth switch connected between a power supply and the first network card, the first memory, the second network card, and the second memory; wherein, The control unit is configured to control the first network card, the first memory, the second network card, and the second memory to be turned on or off, so that the component system performs one of the following settings: a first setting in which the first network card and the first memory are turned on and the second network card and the second memory are turned off; and a second setting in which the second network card and the second memory are turned on and the first network card and the first memory are turned off. the processing unit being configured to receive a first enabling instruction for the first network card and the first storage based on the first setting, and access the first storage through the network corresponding to the first network card, or to receive a second enabling instruction for the second network card and the second storage based on the second setting, and access the second storage through the network corresponding to the second network card; The controller is configured to control the first switch and the second switch to be closed, and the third switch and the fourth switch to be opened, so as to control the first network card and the first storage to be turned on, and the second network card and the second storage to be turned off; or Controlling the first switch and the second switch to be disconnected, and the third switch and the fourth switch to be closed, so as to control the second network card and the second storage to be turned on, and the first network card and the first storage to be turned off; The power supply includes an off-state power supply and an on-state power supply, the first switch and the third switch are specifically connected to the off-state power supply, and the second switch and the fourth switch are specifically connected to the on-state power supply; The second network card is a PCIe network card, and the component system is provided with a PCIe slot, and the PCIe slot is used to insert the PCIe network card; The control unit further includes: a fifth switch connected between the power-on state power supply and the PCIe slot; The controller is further configured to control the fifth switch to be closed when controlling the second network card to be turned on, so that the power supply in the power-on state supplies power to the PCIe slot; The controller is further configured to control the fifth switch to close when the first network card is turned on and the PCIe slot is used to insert other PCIe devices except the PCIe network card, so that the power-on state power supply supplies power to the PCIe slot.

2. The component system according to claim 1, characterized in that The control unit further comprises: a first control module, a second control module and a third control module, and the controller comprises a first interface, a second interface and a third interface; The first interface is connected to the control end of the first switch and the input end of the first control module, the first interface and the second interface are connected to the first input end and the second input end of the second control module respectively, the output end of the second control module is connected to the control end of the second switch, the output end of the first control module is connected to the control end of the third switch, the output end of the first control module and the third interface are connected to the first input end and the second input end of the third control module respectively, and the output end of the third control module is connected to the control end of the fourth switch.

3. The component system according to claim 2, characterized in that The first control module includes a NOT gate, the second control module includes an AND gate, and the third control module includes an AND gate.

4. The component system according to claim 1, characterized in that The control unit also includes: a fourth control module, a first input end of the fourth control module is used to receive a power-on status indication, a second input end of the fourth control module is connected to the output end of the first control module, and the output end of the fourth control module is connected to the control end of the fifth switch.

5. The component system according to claim 4, characterized in that The fourth control module includes an AND gate.

6. A terminal device, characterized in that: The terminal device includes the component system according to any one of claims 1-5.

7. The terminal device according to claim 6, characterized in that The terminal devices include personal computers and tablet computers.

8. A dual operating system isolation method, characterized in that: Applied to the component system according to any one of claims 1 to 5, the component system comprising a control system, a basic input / output system (BIOS), a first operating system bound to a first network card and a first storage device, and a second operating system bound to a second network card and a second storage device, the method comprising: The control system controls the default network card and the default memory to be powered on, wherein the default network card and the default memory are respectively the first network card and the first memory, or the second network card and the second memory; The control system starts the BIOS; The BIOS starts a default operating system, where the default operating system is an operating system bound to the default network card and the default memory.

9. The method according to claim 8, characterized in that After the control system starts the BIOS, the method further includes: The BIOS obtains default indication information from the control system, where the default indication information is used for the default operating system.

10. The method according to claim 8 or 9, characterized in that Before the BIOS starts the default operating system, the method further includes: The BIOS controls the display of operating system option information, where the operating system option information is used to instruct the user to select a target operating system from the first operating system and the second operating system; The BIOS receives the target operating system selected by a user.

11. The method according to claim 10, characterized in that The method further comprises: If the target operating system is inconsistent with the default operating system, the BIOS changes the default network card and the default memory; The BIOS restarts the component system.

12. The method according to claim 8 or 9, characterized in that The BIOS starts the default operating system, including: When the default network card and the default memory are respectively the first network card and the first memory, the BIOS starts the first operating system; When the default network card and the default memory are the second network card and the second memory respectively, the BIOS starts the second operating system.

13. The method according to claim 8 or 9, characterized in that After the BIOS starts the default operating system, the method further includes: The default operating system receives an operating system switching instruction triggered by a user, and changes the default network card and the default memory according to the operating system switching instruction; The default operating system restarts the component system.

Citation Information

Patent Citations

  • Safety management system for multiple independent operation platforms

    CN101510240A

  • Integrated network isolating card

    CN2667565Y