A USB peripheral file secure transfer system
By connecting USB peripheral client devices to the file security transfer device via network, the problem of traditional USB peripheral devices requiring operation in a computer room is solved, providing a secure file transfer and management solution on the office desk, improving work convenience and security.
Patent Information
- Application Number
- CN202310249766.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-15
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2043-03-15
AI Technical Summary
Traditional USB peripheral file transfer devices are large and noisy, requiring operation in a computer room, which is inconvenient for the workplace, and lacks a centralized management and secure transmission system.
It enables secure transfer of USB storage media by connecting a USB peripheral client device to a secure file transfer device via network. It supports ID password or certificate authentication and includes modules such as file transfer, virus protection, and user permission management. It can be operated on a desktop.
It enables secure file management and transfer on the office desktop, reducing the need for computer room operations and improving the security and convenience of file transfer.
Smart Images

Figure CN116318967B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of network security and secure file transfer, and more particularly to a method for securely transferring files via a USB peripheral client device. This application also relates to the implementation of a USB peripheral secure file transfer system. Background Technology
[0002] In the intranets of many government agencies and enterprises, for information security reasons, in addition to isolating the internal and external networks, it is generally required to disable the use of computer USB ports and restrict employees from plugging in USB storage devices such as USB flash drives and external hard drives at will, in order to prevent virus infection and leakage of important data, so as to protect the information security and trade secrets of the organization.
[0003] Government agencies and enterprises need a system that can centrally, securely, and efficiently manage USB external storage media and securely transfer files to regulate the use of USB external storage devices and protect the security of internal networks.
[0004] Traditional USB peripheral file transfer devices are typically placed in computer rooms because of their large chassis and the noise generated by the fans during operation. This requires employees to go to the computer room to plug and unplug USB external media, which causes great inconvenience to some organizations. Summary of the Invention
[0005] The purpose of this invention is to overcome the deficiencies in the prior art and provide a secure file transfer method for USB peripherals. This application also relates to the implementation of a secure file transfer system for USB peripherals.
[0006] This application provides a method for securely transferring files between USB peripherals, including:
[0007] This system facilitates the transfer of files from USB storage media by connecting a USB peripheral client device to a secure USB file transfer device via a network. Users add the configuration information of their USB peripheral client device to the secure USB file transfer device system, then place the USB peripheral client device on their desk. Once the USB peripheral client device connects to the secure USB file transfer device via the network, users can simply plug and unplug the USB storage media from the USB peripheral client device itself; there is no need to go to a server room to do so. The USB peripheral client device is added to the secure USB file transfer system using an ID password or certificate authentication method. When adding the USB peripheral client device to the system, the user must also enter the USB peripheral client device's serial number and device name. Each USB peripheral client device has its own independent system, and users can access and operate the device by entering a username and password.
[0008] This application also provides a USB peripheral file secure transfer system, which includes: a file transfer module, a user and permission management module, a virus protection module, a USB peripheral management module, a file management module, a transfer management configuration module, a disk mapping configuration module, and a network configuration module;
[0009] The file transfer module includes a USB peripheral area, a virus quarantine area, a file transfer area, and a disk mapping area.
[0010] The USB peripheral area is used to display file information in USB storage media devices. This area also has the function of uploading local files to the USB peripheral area or downloading files from the USB peripheral area to the local machine, as well as the function of transferring files from the USB peripheral area to the destination server via transfer or disk mapping.
[0011] The virus quarantine area is used to manage virus files detected and eliminated by the system. Administrators have the authority to delete or restore virus files.
[0012] The file transfer area is used to display file transfer information achieved through file transfer.
[0013] The disk mapping area is used to display file transfer information implemented through disk mapping.
[0014] The user and permission management module is used to manage system users and control user permissions. The administrator has the highest system privileges, can use the configuration of all system modules, and can manage and control the system usage permissions of other users (including but not limited to permission control for file upload and download, file deletion, and whether password can be changed). The administrator has file operation permissions in the virus quarantine area, configuration permissions for the file management module, and can configure the blacklist and whitelist of users logging into the system.
[0015] The virus protection module is used to detect and kill file viruses, configure virus detection methods (it can perform virus detection on the peripheral device immediately when the USB peripheral device is plugged in, or it can perform virus detection on a single file before transferring the file), configure virus handling strategies (when a virus file is detected, it can directly isolate the virus file, delete the virus file, or only prompt the virus information), compressed file handling strategies (it can choose to ignore the scanning and detection of compressed files), and offline or online virus database update function.
[0016] The USB peripheral management module is used to manage USB peripherals, including but not limited to configuring USB access policies (allowing all USB peripherals to connect or only allowing whitelisted devices to connect); adding / editing USB peripheral clients (authenticating via ID password or certificate).
[0017] The file management module is used to configure which types of files can be uploaded and downloaded. This module has, but is not limited to, file deep detection function (to prevent file extension spoofing), MD5 verification function, and file deep learning function (it can upload files of file types that do not exist in the system and then learn the file types).
[0018] The ferry management configuration module is used to manage ferry channels. It can add multiple file ferry channels and configure the transmission method, pipeline priority, destination server IP and transmission path.
[0019] The disk mapping configuration module is used for file transfer channel management in a file mapping manner. It can add multiple mapping channels and configure the destination server and mapping folder name.
[0020] The network configuration module includes, but is not limited to, interface management configuration, route management configuration, DNS server configuration, and advanced option configuration;
[0021] The interface management configuration is used to manage the interface's working mode, IP address, and subnet mask.
[0022] The routing management configuration is used to manage interface routes;
[0023] The advanced options configuration allows you to configure the timeout for TCP, UDP, or ICMP sessions, enable or disable features such as SYN Cookie attack prevention, source IP spoofing attack prevention, and Ping of Death attack prevention, enable or disable remote logging (requires adding the remote log server IP), and disable access via HTTP or Telnet.
[0024] In summary, system administrators can configure the above modules according to their own needs, and other users can use this USB peripheral file security transfer system to upload, download, and delete files. Attached Figure Description
[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below.
[0026] Figure 1 This is an application scenario diagram of the USB peripheral file secure transfer method in this application;
[0027] Figure 2 This is a diagram illustrating the specific implementation steps of the USB peripheral file secure transfer method in this application;
[0028] Figure 3 This is a schematic diagram of the modules of the USB peripheral file security transfer system in this application;
[0029] Figure 4 This is a flowchart illustrating the use of the USB peripheral file security transfer system in this application; Detailed Implementation
[0030] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0031] The USB peripheral file secure transfer method and USB peripheral file secure transfer system provided in this invention application can be applied to, for example... Figure 1 The office scene shown.
[0032] Figure 1 This illustration shows a local area network (LAN) of a department within an enterprise or institution. If different departments within an organization belong to different LANs, then USB peripheral file transfer devices can be connected to each department's LAN.
[0033] Figure 1After the department shown has deployed the USB peripheral file security transfer device, one end is connected to the destination server.
[0034] Then according to Figure 2 The implementation steps of the USB peripheral file secure transfer method are shown in the diagram. S201 Deploy the USB peripheral file secure transfer device and log in to the USB peripheral file secure transfer system.
[0035] S202 adds relevant configuration information of USB peripheral client devices to the USB peripheral file security transfer system.
[0036] The S203 deploys USB peripheral client devices and connects them to the USB peripheral file security transfer device via a network.
[0037] S204 uses a USB peripheral client device to plug and unplug USB storage media and accesses the USB storage media within the USB peripheral file transfer system to perform the required file transfer operations.
[0038] The following section will provide a detailed introduction to the USB peripheral file security transfer system.
[0039] Specifically, the system login system of this invention has three user modes: first, administrator mode, which has the highest privileges for configuring and managing the system; second, auditor mode, which can view audit log records, including user operation data, system parameters, file transfer records, virus scan records, and other system error information; and third, ordinary user mode, which has the lowest privileges and can only perform operations such as uploading and downloading files according to the configuration made by the administrator.
[0040] like Figure 3 As shown, the administrator with the highest privileges logs into the system first;
[0041] like Figure 3 As shown, after logging into the system, the administrator can view the configuration interfaces of each module in the system. The modules are: file transfer module S300, user and permission management module S301, virus protection module S302, USB peripheral management module S303, file management module S304, ferry management configuration module S305, disk mapping configuration module S306, and network configuration module S307.
[0042] The file transfer module S300 includes a USB peripheral area, a virus quarantine area, a file transfer area, and a disk mapping area, which are used to display the contents of each file.
[0043] The USB peripheral area is used to display the file content in the USB peripheral device. At the same time, this area has the function of uploading local files to the USB peripheral area or downloading files from the USB peripheral area to the local machine, as well as the function of transferring files from the USB peripheral area to the destination server through a transfer method or disk mapping.
[0044] The virus quarantine area is used to manage virus files detected and eliminated by the system. Administrators have the authority to delete or restore virus files.
[0045] The file transfer area is used to display file transfer information implemented via file transfer.
[0046] The disk mapping area is used to display file transfer information implemented through disk mapping.
[0047] The user and permission management module S301 is used to manage system users and control user permissions. The administrator has the highest system privileges, can use the configuration of all system modules, and can manage and control the system usage permissions of other users (including but not limited to permission control for file upload and download, file deletion, and whether password can be changed). The administrator has file operation permissions in the virus quarantine area, configuration permissions for the file management module, and can configure the blacklist and whitelist of users logging into the system.
[0048] The virus protection module S302 is used to detect and kill file viruses, configure virus detection methods (it can immediately detect viruses on the peripheral when a USB peripheral is plugged in, or it can detect viruses on a single file before transferring files), configure virus handling strategies (when a virus file is detected, it can directly isolate the virus file, delete the virus file, or only prompt the virus information), compressed file handling strategies (it can choose to ignore the scanning and detection of compressed files), and offline or online virus database update function.
[0049] The USB peripheral management module S303 is used to manage USB peripherals, including but not limited to configuring USB access policies (allowing all USB peripherals to connect or only allowing whitelisted devices to connect); adding / editing USB peripheral clients (authenticating via ID password or certificate).
[0050] The file management module S304 is used to configure which types of files can be uploaded and downloaded. This module has, but is not limited to, file deep detection function (to prevent file extension spoofing), MD5 verification function, and file deep learning function (it can upload files of file types that do not exist in the system and then learn the file types).
[0051] The ferry management configuration module S305 is used to manage ferry channels. It can add multiple file ferry channels and configure the transmission method, pipeline priority, destination server IP and transmission path.
[0052] The disk mapping configuration module S306 is used for file transfer channel management in a file mapping manner. It can add multiple mapping channels and configure the destination server and mapping folder name.
[0053] The network configuration module S307 includes, but is not limited to, interface management configuration, route management configuration, DNS server configuration, and advanced option configuration;
[0054] The interface management configuration is used to manage the interface's working mode, IP address, and subnet mask.
[0055] The routing management configuration is used to manage interface routes;
[0056] The advanced options configuration is used to configure the timeout for TCP, UDP, or ICMP sessions, to enable or disable functions such as preventing SYN cookie attacks, preventing source IP spoofing attacks, and preventing Ping of death attacks, to enable or disable the remote logging function (requires adding the remote log server IP), and to prohibit access via HTTP or Telnet.
[0057] like Figure 4 The flowchart shows how the administrator configures the system according to the requirements described in the above modules and saves the configuration. Other users can then log in to the system using their assigned username and password to transfer files.
[0058] according to Figure 4 The flowchart illustrates that after other ordinary users use the system, when they insert a USB external medium into the USB peripheral client, the system will perform USB detection and verification according to the configuration of the USB peripheral management module S303. After the verification is passed and access is allowed, the system will either automatically perform virus detection immediately when the USB external device is inserted, or manually perform virus detection on a single file, depending on the virus protection configuration set by the administrator. If a virus file is detected, the system will directly delete, quarantine, or alert the user according to the configuration of the virus protection module. If no virus is detected, the system will perform file transfer according to the transfer management configuration module S305 or the disk mapping configuration module S306 set by the administrator.
[0059] The above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art can still make modifications or equivalent substitutions to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention are within the protection scope of the claims of the present invention pending approval.
Claims
1. A USB peripheral file secure transfer system, characterized in that, The system includes: a file transfer module, a user and permission management module, a virus protection module, a USB peripheral management module, a file management module, a ferry management configuration module, a disk mapping configuration module, and a network configuration module; The file transfer module includes a USB peripheral area, a virus quarantine area, a file transfer area, and a disk mapping area. The USB peripheral area is used to display the contents of the inserted USB storage medium, and has the functions of uploading local files to the USB peripheral area or downloading files from the USB peripheral area to the local machine, as well as transferring files from the USB peripheral area to the destination server via a transfer method or disk mapping. The virus quarantine area is used to manage virus files detected and eliminated by the system. Administrators have the authority to delete or restore virus files. The file transfer area is used to display file information transferred via file transfer. The disk mapping area is used to display file information implemented in a disk mapping manner; The user and permission management module is used to manage system users and control user permissions; The virus protection module is used to detect and kill file viruses, configure virus detection methods, configure virus handling strategies, compress file handling strategies, and update the virus database offline or online. The USB peripheral management module is used to manage USB peripherals, configure USB access control policies, and add / edit USB peripheral clients. The file management module is used to configure which types of files can be uploaded and downloaded. This module has file deep detection function, MD5 verification function, and file deep learning function. The ferry management configuration module is used to manage ferry channels. It can add multiple file ferry channels and configure the transmission method, channel priority, destination server IP and transmission path. The disk mapping configuration module is used for file transfer channel management in a file mapping manner. It can add multiple mapping channels and configure the destination server and mapping folder name. The network configuration module includes interface management configuration, route management configuration, DNS server configuration, and advanced option configuration; The USB peripheral file secure transfer method executed by the aforementioned USB peripheral file secure transfer system is as follows: Users add the configuration information of their USB peripheral client devices to the USB peripheral file secure transfer system. The USB peripheral client devices are placed on the user's desk. Once connected to the system via network, users can securely transfer files by simply plugging and unplugging the USB storage media on the client device itself, without needing to go to the server room to do so on the system. The USB peripheral client devices are added to the system using ID password or certificate authentication. When adding a USB peripheral client device, the user must also enter its serial number and device name. Each USB peripheral client device has its own independent system, and users can access and operate it by entering a username and password.
Citation Information
Patent Citations
Machine in middle of ferry -boat of magnetic medium information security
CN205621004U