Composite intrusion detection device and method
By using a composite intrusion detection device, uninterrupted power supply is achieved through power supply circuits and redundant diode switching. Combined with intrusion detection circuits and main control circuits, the problem of uninterrupted intrusion detection at the hardware level is solved, realizing all-time security monitoring of the chassis and recording of intrusion information.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- INSPUR SUZHOU INTELLIGENT TECH CO LTD
- Filing Date
- 2023-06-19
- Publication Date
- 2026-07-31
AI Technical Summary
Existing hardware-level intrusion detection devices cannot provide uninterrupted security 24 hours a day when the server is powered on and off, and cannot record the number of intrusions and the time of occurrence.
A composite intrusion detection device was designed, which uses a power supply circuit combined with a battery power supply module and a motherboard power supply module. Uninterrupted power supply is achieved through redundant diode switching. Combined with the intrusion detection circuit and the main control circuit, it records intrusion information and performs alarm processing.
It enables 24/7 uninterrupted intrusion monitoring of the chassis, ensuring the security of the server when it is powered on and off, and can completely record intrusion information, which is convenient for subsequent tracing of intrusion events.
Smart Images

Figure CN116827618B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of intrusion detection technology, and in particular to a composite intrusion detection device and method. Background Technology
[0002] With the development of the information society, cybersecurity is becoming increasingly important, posing a significant concern for both national security and socio-economic development. In the server domain, software-level intrusion detection employs various methods, including collecting information from network port data streams, checking user permissions, inspecting abnormal processes, and examining unusual files. Software-level intrusion detection analyzes and responds based on security policies, and its functionality is relatively sophisticated.
[0003] Hardware-level intrusion detection typically involves opening the chassis to prevent information theft from internal interfaces or hard drive theft. Current hardware-level intrusion detection technologies are mainly divided into two categories: online detection and offline detection. Online detection can only detect intrusions while the server is powered on and records the number and time of occurrences. It cannot perform intrusion detection when the server is not powered on, thus failing to provide 24 / 7 uninterrupted security. Offline detection, powered by a battery, can detect chassis intrusions 24 / 7, triggering real-time alarms such as buzzers. However, it cannot record the number of intrusions or their corresponding times, making it difficult to trace and pinpoint the time of the intrusion later.
[0004] Therefore, there is an urgent need for a composite intrusion detection device and method that is unaffected by the power-on / off state of the server and provides uninterrupted security to solve the above-mentioned technical problems. Summary of the Invention
[0005] Therefore, it is necessary to provide a composite intrusion detection device to address the aforementioned technical problems and enable uninterrupted intrusion monitoring of the chassis.
[0006] In a first aspect, this application provides a composite intrusion detection device, the device comprising:
[0007] The power supply circuit includes a battery power supply module and a motherboard power supply module. The power supply circuit is connected to the intrusion detection circuit and the main control circuit respectively, and is used to supply power to the intrusion detection circuit and the main control circuit.
[0008] The intrusion detection circuit includes a connector, a first redundant diode, and a second redundant diode. One end of the first redundant diode and the second redundant diode are connected to the connector, and the other end of the first redundant diode and the second redundant diode are connected to the power supply circuit. By switching the conduction of the first redundant diode and the second redundant diode, it is determined whether the power supply is a battery power supply module or a motherboard power supply module powered by the connector.
[0009] When the intrusion detection circuit is connected to the intrusion cable, the intrusion detection circuit determines the intrusion signal based on the connector being connected to the intrusion cable;
[0010] The main control circuit is used to determine and store the intrusion detection result based on the intrusion signal, and to perform alarm processing.
[0011] In some embodiments, the intrusion detection circuit further includes a first sub-circuit, the first sub-circuit including a first resistor and a second resistor, the connector including at least a first pin, a second pin and a third pin, wherein the first redundant diode includes a first sub-diode and a second sub-diode;
[0012] The first pin is connected to the cathode of the first sub-diode, the anode of the first sub-diode is connected to one end of the first resistor, and the other end of the first resistor is connected to the battery power supply module of the power supply circuit.
[0013] The first pin is connected to the cathode of the second sub-diode, the anode of the second sub-diode is connected to one end of the second resistor, and the other end of the second resistor is connected to the mainboard power supply module of the power supply circuit.
[0014] In some embodiments, the intrusion detection circuit further includes a second sub-circuit, the second sub-circuit including a third resistor and a fourth resistor, wherein the second redundant diode includes a third sub-diode and a fourth sub-diode;
[0015] The second pin is connected to the cathode of the third sub-diode, the anode of the third sub-diode is connected to one end of the third resistor, and the other end of the third resistor is connected to the battery power supply module of the power supply circuit.
[0016] The second pin is connected to the cathode of the fourth sub-diode, the anode of the fourth sub-diode is connected to one end of the fourth resistor, and the other end of the fourth resistor is connected to the mainboard power supply module of the power supply circuit.
[0017] In some embodiments, when the intrusion detection circuit is connected to an intrusion cable, the third pin is connected to the first pin via the intrusion cable.
[0018] The signal output from the first pin is an in-place signal, used to indicate whether an intrusion cable is installed.
[0019] In some embodiments, when the intrusion detection circuit is connected to an intrusion cable, one end of the switch of the intrusion cable is connected to the second pin, and the other end of the switch of the intrusion cable is connected to the third pin.
[0020] The signal output from the second pin is an intrusion signal, used to indicate the intrusion detection result. If the switch is pressed, the second pin outputs a high-level intrusion signal to indicate that the chassis has not been intruded. If the switch is released, the second pin outputs a low-level intrusion signal to indicate that the chassis has been intruded.
[0021] In some embodiments, a transient voltage suppression diode is also connected to the second pin;
[0022] The intrusion detection circuit also includes a fifth resistor, one end of which is connected to the third pin connection, and the other end of which is grounded.
[0023] In some embodiments, the main control circuit includes a microprocessor unit, an internal storage unit, and a baseboard management controller;
[0024] The microprocessor unit is used to determine the intrusion detection result based on the intrusion signal generated by the intrusion detection circuit. The intrusion detection result includes whether the chassis has been intruded or not.
[0025] The internal storage unit is used to store the corresponding intrusion information in response to the intrusion detection result of the chassis being intruded, wherein the intrusion information includes the intrusion time and the number of intrusions;
[0026] The baseboard management controller is used to read the intrusion information and perform alarm processing based on the intrusion information.
[0027] Secondly, this application provides a composite intrusion detection method, the method comprising:
[0028] The main control circuit determines whether the intrusion cable is installed based on the presence signal emitted from the first pin inside the connector;
[0029] After the intrusion cable is installed, the main control circuit determines the intrusion detection result based on the intrusion signal emitted by the second pin in the connector. The intrusion detection result includes whether the chassis has been intruded or not.
[0030] In response to the intrusion detection result of the chassis being breached, the main control circuit records and stores the intrusion information to the internal storage unit within the main control circuit, and performs alarm processing.
[0031] In some embodiments, the method further includes:
[0032] When the intrusion cable is not installed, the microcontroller unit in the main control circuit reports the presence signal to the baseboard management controller in the main control circuit;
[0033] The baseboard management controller responds to the presence signal and generates a prompt to alert the user to check the installation status of the intrusion cable.
[0034] In some embodiments, the main control circuit records and stores intrusion information to an internal storage unit within the main control circuit, and triggers an alarm, including:
[0035] When the server is online, the baseboard management controller reads the intrusion information in the internal storage unit and displays an alarm on the console.
[0036] When the server goes offline, the baseboard management controller reads the intrusion information in the internal storage unit and displays an alarm on the console when the server is powered on again.
[0037] Thirdly, this application provides an electronic device, the electronic device comprising:
[0038] One or more processors;
[0039] and a memory associated with the one or more processors, the memory storing program instructions that, when read and executed by the one or more processors, perform the following operations:
[0040] The main control circuit determines whether the intrusion cable is installed based on the presence signal emitted from the first pin inside the connector;
[0041] After the intrusion cable is installed, the main control circuit determines the intrusion detection result based on the intrusion signal emitted by the second pin in the connector. The intrusion detection result includes whether the chassis has been intruded or not.
[0042] In response to the intrusion detection result that the chassis has not been breached, the main control circuit records and stores the intrusion information to the internal storage unit within the main control circuit, and performs alarm processing.
[0043] The beneficial effects achieved by this application are as follows:
[0044] This application provides a composite intrusion detection device, including a power supply circuit, an intrusion detection circuit, and a main control circuit. The power supply circuit includes a battery power supply module and a motherboard power supply module, which are connected to the intrusion detection circuit and the main control circuit respectively, for supplying power to the intrusion detection circuit and the main control circuit. The intrusion detection circuit includes a connector, a first redundant diode, and a second redundant diode, wherein one end of the first redundant diode and the second redundant diode is connected to the connector, and the conduction of the first redundant diode and the second redundant diode is switched to determine whether to supply power to the battery power supply module or the motherboard power supply module. When an intrusion cable is connected to the intrusion detection circuit, the intrusion detection circuit is connected to the intrusion cable based on the connector and uses the connector to determine the intrusion signal. The main control circuit is used to determine and store the intrusion detection result based on the intrusion signal, and to perform alarm processing. By integrating two power supply modules in the power supply circuit to supply power to the intrusion detection circuit and the main control circuit, and automatically switching between the battery and the server motherboard that provide power when the server is powered on and off, uninterrupted 24-hour intrusion monitoring of the chassis is achieved.
[0045] Furthermore, redundant diodes are provided for the first and second pins of the connector in the intrusion detection circuit. The first and second pins are powered independently, which increases the security of the composite intrusion detection device. At the same time, the power supply of the first and second pins can be achieved by switching the conduction of the redundant diodes. When the server is powered on, the first and second pins are powered by the server motherboard, and when the server is offline, the first and second pins are powered by the battery.
[0046] Furthermore, since the second pin is connected to the switch of the intrusion cable when the intrusion cable is connected to the intrusion detection circuit, a transient voltage suppression diode is added to avoid the problem of electrostatic breakdown of the microcontroller pins that may be connected to the subsequent stage.
[0047] Furthermore, when the server is offline, the intrusion information can be stored in the storage unit within the main control circuit. When the server is powered on again, the intrusion information in the storage unit can be read, achieving a complete record of the intrusion information of the chassis. This avoids the data loss problem caused by the inability to record intrusion information due to server offline, and further facilitates staff to trace intrusion events later. Attached Figure Description
[0048] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort, wherein:
[0049] Figure 1 This is a schematic diagram of the composite intrusion detection device provided in the embodiments of this application;
[0050] Figure 2 This is a schematic diagram of the intrusion detection circuit provided in an embodiment of this application;
[0051] Figure 3 This is a schematic diagram of a composite intrusion detection method provided in an embodiment of this application;
[0052] Figure 4 This is a flowchart of another composite intrusion detection method provided in the embodiments of this application;
[0053] Figure 5 This is a structural diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0054] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0055] It should be understood that, in the description of this application, unless the context explicitly requires it, the words "comprising," "including," and similar terms throughout the specification and claims should be interpreted as encompassing rather than being exclusive or exhaustive; that is, meaning "including but not limited to."
[0056] It should also be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0057] It should be noted that the terms "S1," "S2," etc., are used only for descriptive purposes and do not specifically refer to the order or sequence, nor are they intended to limit this application. They are merely for the convenience of describing the method of this application and should not be construed as indicating the sequential order of the steps. Furthermore, the technical solutions of the various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. When the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed in this application.
[0058] Example 1
[0059] This application provides a composite intrusion detection device, specifically, as shown in the embodiments below. Figure 1 The schematic diagram of the device shown indicates that the composite intrusion detection device specifically includes a power supply circuit 101, an intrusion detection circuit 102, and a main control circuit 103.
[0060] Specifically, the power supply circuit 101 includes a battery power supply module (not shown in the figure) and a motherboard power supply module (not shown in the figure). The power supply circuit 101 is connected to both the intrusion detection circuit 102 and the main control circuit 103 to provide power to these circuits. Typically, the power supply circuit uses either the battery power supply module or the motherboard power supply module. When the server is online, it usually powers the motherboard power supply module. When the server is offline and cannot be powered (i.e., the motherboard power supply module is not working properly), it switches to the battery power supply module. Specifically, the battery power supply module can be a battery, powered through the P3V_VBAT output of the battery. Alternatively, a rechargeable battery can be used to reduce battery replacements. The motherboard power supply module is powered through the P3V3_STBY output of the VR (voltage regulator) on the server motherboard. By configuring the power supply circuit as described above, 24-hour uninterrupted intrusion detection of the chassis can be ensured. Furthermore, by switching between the battery and the server motherboard for power supply, battery wear is effectively reduced, and battery life is increased.
[0061] Specifically, the intrusion detection circuit 102 includes at least a connector J1, a first redundant diode D1, and a second redundant diode D2. One end of the first redundant diode D1 and the second redundant diode D2 are connected to the connector J1, and the other end of the first redundant diode D1 and the second redundant diode D2 are connected to the power supply circuit 101, so that the connector J1 is powered by the current output from the battery power supply module and the motherboard power supply module. When an intrusion cable is connected to the intrusion detection circuit 102, the intrusion detection circuit 102 connects to the intrusion switch cable based on the connector J1 and uses the connector J1 to determine the intrusion signal.
[0062] Specifically, such as Figure 2The diagram shows an intrusion detection circuit. The circuit also includes a first sub-circuit and a second sub-circuit. The first sub-circuit includes a first resistor R1 and a second resistor R2. The second sub-circuit includes a third resistor R3 and a fourth resistor R4. Connector J1 includes at least a first pin, a second pin, and a third pin. The first redundant diode D1 includes a first sub-diode d1 and a second sub-diode d2. The second redundant diode D2 includes a third sub-diode d3 and a fourth sub-diode d4. The first sub-circuit supplies power to the first pin of connector J1, and the second sub-circuit supplies power to the second pin of connector J1. Furthermore, the intrusion detection circuit includes a fifth resistor R5, one end of which is connected to the third pin of connector J1, and the other end is grounded.
[0063] In this circuit, the first pin of connector J1 is connected to the cathode of the first sub-diode d1, the anode of the first sub-diode d1 is connected to one end of the first resistor R1, and the other end of the first resistor R1 is connected to the battery power supply module of the power supply circuit 101, so as to use the current output by the battery power supply module to power the first pin; the first pin is connected to the cathode of the second sub-diode d2, the anode of the second sub-diode d2 is connected to one end of the second resistor R2, and the other end of the second resistor R2 is connected to the motherboard power supply module of the power supply circuit, so as to use the current output by the motherboard power supply module to power the first pin. The first pin of connector J1 is connected to the output P3V_VBAT of the battery power supply module and the output P3V3_STBY of the motherboard power supply module through the first sub-circuit (first resistor R1 and second resistor R2), respectively, so as to enable the first pin to be powered by either the battery power supply module or the motherboard power supply module. In particular, by switching the first sub-diode d1 and the second sub-diode d2 in the first redundant diode D1 to conduct, the motherboard power supply module is used to power the first pin when the server is online, and the battery power supply module is used to power the first pin when the server is offline. When the server is online, the motherboard power supply module provides a voltage of 3.3V, which is greater than the 3V provided by the battery power supply module. At this time, the second sub-diode d2 is conducting and the voltage at the cathode of the second sub-diode is about 3.1V. The first sub-diode d1 is not conducting, so the motherboard power supply module is used to supply power to the first pin. When the server is offline, only the P3V_VBAT output by the battery power supply module is powered. Therefore, the first sub-diode d1 is conducting and the second sub-diode d2 is not conducting. At this time, the battery power supply module is used to supply power to the first pin.
[0064] The second pin of connector J1 is connected to the cathode of the third sub-diode d3. The anode of the third sub-diode d3 is connected to one end of the third resistor R3. The other end of the third resistor R3 is connected to the battery power supply module of the power supply circuit 101, so as to use the output of the battery power supply module to power the second pin of connector J1. The second pin is also connected to the cathode of the fourth sub-diode d4. The anode of the fourth sub-diode d4 is connected to one end of the fourth resistor R4. The other end of the fourth resistor R4 is connected to the motherboard power supply module of the power supply circuit 101, so as to use the output of the motherboard power supply module to power the second pin of connector J1. The second pin is connected via a second sub-circuit (third resistor R3 and fourth resistor R4) to the output P3V_VBAT of the battery power supply module and the output P3V3_STBY of the motherboard power supply module, respectively. This allows either the battery power supply module or the motherboard power supply module to power the second pin. By switching the conduction of the first sub-diode d1 and the second sub-diode d2 within the second redundant diode D1, the motherboard power supply module is used to power the second pin when the server is online, and the battery power supply module is used when the server is offline. When the server is online, since the voltage provided by the motherboard power supply module is 3.3V, which is greater than the 3V provided by the battery power supply module, the fourth sub-diode d4 is conducting and the voltage at the cathode of the second sub-diode is approximately 3.1V. The third sub-diode d3 is not conducting, and the motherboard power supply module powers the second pin. When the server is offline, only the P3V_VBAT output from the battery power supply module is powered, so the third sub-diode d3 is conducting and the fourth sub-diode d4 is not conducting, and the battery power supply module provides power.
[0065] Furthermore, when the intrusion cable is connected to the intrusion detection circuit 102, the first and third pins of connector J1 are directly connected via the intrusion cable. The first pin outputs an in-place signal, which is low, indicating that the device supports intrusion detection. If the intrusion cable is not connected to the intrusion detection circuit 102, as mentioned above, since the first pin is connected to the first and second resistors, it outputs a high-level in-place signal due to the pull-up resistor, indicating that the device does not support intrusion detection. When the intrusion cable is correctly installed, the second pin is connected to one end of the switch on the intrusion cable, and the other end of the switch is connected to the third pin. When the chassis cover is closed and the switch is pressed, the second pin is left floating, and the potential is high through the pull-up resistors (third resistor R3 and fourth resistor R4), indicating that the chassis has not been intruded upon. When the chassis cover is opened, the switch pops up and connects to ground, so the second pin outputs a low-level intrusion signal, indicating that the chassis is in an intrusion state. It should be noted that when no cable is installed, the presence signal output by the first pin is high, and the intrusion signal output by the second pin is high by default. At this time, the main control circuit directly generates a prompt based on the uploaded presence signal to remind the user to install or check the cable. After the intrusion cable is installed normally, the intrusion signal is detected again to determine whether the chassis is in an intrusion state.
[0066] In some embodiments, to protect the safety of connector J1, a transient voltage suppression diode D3 is also connected to the second pin of connector J1 to avoid the problem that the microcontroller pins connected to the subsequent stage may be electrostatically damaged due to the second pin being connected to the switch of the intrusion cable.
[0067] Specifically, the main control circuit 103 includes a microprocessor unit (MCU), an internal storage unit, and a baseboard management controller (BMC). Specifically, the main control circuit 103 uses the microprocessor unit to determine the intrusion signal; if the intrusion signal is high, the intrusion detection result is determined to be that the chassis has not been intruded; if the intrusion signal is low, the intrusion detection result is determined to be that the chassis has been intruded. This can be implemented using a low-power, small-size MCU, such as STMicroelectronics' STM32C011 series MCU; this application does not limit this. The main control circuit stores the intrusion time and number of intrusions when the microprocessor unit determines that the chassis has been intruded based on the intrusion signal through the internal storage unit. The baseboard management controller obtains intrusion information through the I2C channel. The intrusion time is generated by an RTC (Real-Time Clock) integrated within the main control circuit. Furthermore, as mentioned above, the main control circuit 103 is connected to the power supply circuit 101, enabling power supply via battery output when the server is offline and via the server motherboard's VR output when the server is online, with switching via redundant diodes. When the server is online, the baseboard management controller can actively read the intrusion time and count stored in the internal storage unit via the I2C channel and display an alarm on the console (BMCweb). When the server is offline, the intrusion time and count are stored in the microcontroller's internal storage unit. When the server is powered on again, the baseboard management controller actively reads the intrusion time and count recorded during offline operation and displays an alarm on the console. It is understandable that if a buzzer is connected to the main control circuit, the buzzer can also be controlled to alarm for intrusions.
[0068] Example 2
[0069] Corresponding to the composite intrusion detection device disclosed in Embodiment 1 above, this application also provides a composite intrusion detection method, such as... Figure 3 The schematic diagram illustrates the steps for detecting and issuing alarms regarding intrusion into the chassis using the method disclosed in this application within a composite intrusion detection device:
[0070] Step S1: Check if the intrusion cable is installed.
[0071] Specifically, the intrusion detection circuit includes a connector for connecting the intrusion switch cable. The first pin of this connector is the presence signal of the intrusion cable, and the second pin is the intrusion signal. The specific configuration method of the intrusion detection circuit is described in Embodiment 1, and will not be repeated here. The main control circuit determines whether the intrusion cable is successfully installed based on the presence signal received from the first pin of the connector within the intrusion detection circuit. If the presence signal is low, it is determined that the intrusion cable has been successfully installed, indicating that the intrusion detection device supports intrusion detection; if the presence signal is high, it is determined that the intrusion cable is not installed. The specific judgment operation can be performed by the microprocessor unit within the main control circuit. Furthermore, it is understood that when the microprocessor receives a high-level presence signal, it reports the presence signal to the baseboard management controller within the main control circuit. The baseboard management controller, in response to the presence signal reported by the microprocessor, generates a prompt on the control panel to remind the user to install or check the cable.
[0072] Step S2: After the intrusion cable is correctly installed, determine the intrusion detection results to determine whether the chassis has been intruded upon.
[0073] Specifically, the main control circuit determines the intrusion detection result based on the intrusion signal received from the second pin of the connector within the intrusion detection circuit. This intrusion detection result includes whether the chassis has been intruded or not. Specifically, the microprocessor unit within the main control circuit determines the result based on the received intrusion signal. If the received intrusion signal is high, an intrusion detection result indicating the chassis has not been intruded is generated; if the received intrusion signal is low, an intrusion detection result indicating the chassis has been intruded is generated.
[0074] Step S3: In response to the intrusion detection result of the chassis intrusion, record and store the corresponding intrusion information and perform alarm processing.
[0075] Specifically, in response to intrusion detection results of an intrusion into the chassis, the main control circuit stores the intrusion time and number of intrusions using its internal storage unit. When the server is online, the main control circuit actively reads the intrusion information from the internal storage unit via the I2C channel through the baseboard management controller and displays an alarm on the console, showing the specific intrusion time and number of intrusions for easy tracing by staff. When the server is offline, the intrusion information is still stored in the internal storage unit of the main control circuit, but the baseboard management controller cannot directly read it via the I2C channel at this time; after the server is powered on again, the baseboard management controller actively reads the intrusion information recorded in the internal storage unit when offline and displays an alarm on the console.
[0076] It is understood that the composite intrusion detection method provided in this application embodiment can supply power to both the main control circuit and the intrusion detection circuit regardless of whether the server is online or offline. Therefore, in both cases, the main control circuit can detect whether an intrusion has occurred in the chassis. Through the intrusion detection method disclosed in this application embodiment, uninterrupted intrusion monitoring of the chassis can be achieved, regardless of whether the server is online or offline, providing more comprehensive security for the chassis. Furthermore, the time and number of intrusions to the chassis can be completely recorded, without data loss due to server offline, facilitating the location of intrusion events in subsequent work.
[0077] Example 3
[0078] Corresponding to Embodiments 1 and 2 above, this application provides another intrusion detection method, such as... Figure 4 The flowchart shown specifically includes:
[0079] 410. The main control circuit determines whether the intrusion cable is installed based on the presence signal emitted from the first pin inside the connector;
[0080] Preferably, the method further includes:
[0081] 411. When the intrusion cable is not installed, the microcontroller unit in the main control circuit reports the presence signal to the baseboard management controller in the main control circuit.
[0082] 412. The baseboard management controller, in response to the presence signal, generates a prompt to alert the user to check the installation status of the intrusion cable.
[0083] 420. After the intrusion cable is installed, the main control circuit determines the intrusion detection result based on the intrusion signal emitted by the second pin in the connector. The intrusion detection result includes whether the chassis has been intruded or not.
[0084] 430. In response to the intrusion detection result of the chassis being intruded, the main control circuit records and stores the intrusion information to the internal storage unit within the main control circuit, and performs alarm processing.
[0085] Preferably, the main control circuit records and stores intrusion information to an internal storage unit within the main control circuit, and triggers an alarm, including:
[0086] 431. When the server is online, the baseboard management controller reads the intrusion information in the internal storage unit and displays an alarm on the console;
[0087] 432. After the server goes offline, the baseboard management controller reads the intrusion information in the internal storage unit and displays an alarm on the console when the server is powered on again.
[0088] Example 4
[0089] Corresponding to all the above embodiments, this application provides an electronic device, including:
[0090] One or more processors; and memory associated with the one or more processors, the memory storing program instructions that, when read and executed by the one or more processors, perform the following operations:
[0091] The main control circuit determines whether the intrusion cable is installed based on the presence signal emitted from the first pin inside the connector;
[0092] After the intrusion cable is installed, the main control circuit determines the intrusion detection result based on the intrusion signal emitted by the second pin in the connector. The intrusion detection result includes whether the chassis has been intruded or not.
[0093] In response to the intrusion detection result of the chassis being breached, the main control circuit records and stores the intrusion information to the internal storage unit within the main control circuit, and performs alarm processing.
[0094] In some implementation scenarios, when the program instructions are read and executed by the one or more processors, they perform the following operations:
[0095] When the intrusion cable is not installed, the microcontroller unit in the main control circuit reports the presence signal to the baseboard management controller in the main control circuit;
[0096] The baseboard management controller responds to the presence signal and generates a prompt to alert the user to check the installation status of the intrusion cable.
[0097] In some implementation scenarios, when the program instructions are read and executed by the one or more processors, they perform the following operations:
[0098] When the server is online, the baseboard management controller reads the intrusion information in the internal storage unit and displays an alarm on the console.
[0099] When the server goes offline, the baseboard management controller reads the intrusion information in the internal storage unit and displays an alarm on the console when the server is powered on again.
[0100] in, Figure 5An exemplary architecture of an electronic device is shown, which may include a processor 510, a video display adapter 511, a disk drive 512, an input / output interface 513, a network interface 514, and a memory 520. The processor 510, video display adapter 511, disk drive 512, input / output interface 513, network interface 514, and memory 520 can communicate with each other via a bus 530.
[0101] The processor 510 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solution provided in this application.
[0102] The memory 520 can be implemented in the form of ROM (Read-Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 520 can store the operating system 521 for controlling the execution of the electronic device 500, and the basic input / output system (BIOS) 522 for controlling the low-level operations of the electronic device 500. Additionally, it can store a web browser 523, a data storage management system 524, and an icon / font processing system 525, etc. The aforementioned icon / font processing system 525 can be the application program that specifically implements the aforementioned steps in this embodiment. In summary, when the technical solution provided in this application is implemented through software or firmware, the relevant program code is stored in the memory 520 and is called and executed by the processor 510.
[0103] Input / output interface 513 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touch screens, microphones, various sensors, etc., and output devices may include displays, speakers, vibrators, indicator lights, etc.
[0104] Network interface 514 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0105] Bus 530 includes a pathway for transmitting information between various components of the device, such as processor 510, video display adapter 511, disk drive 512, input / output interface 513, network interface 514, and memory 520.
[0106] In addition, the electronic device 500 can also obtain information on specific claim conditions from the virtual resource object claim condition information database for use in condition judgment, etc.
[0107] It should be noted that although the above-described device only shows the processor 510, video display adapter 511, disk drive 512, input / output interface 513, network interface 514, memory 520, bus 530, etc., in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the solution of this application, and does not necessarily include all the components shown in the figures.
[0108] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, a cloud server, or a network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0109] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for system or system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and relevant parts can be referred to the descriptions in the method embodiments. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0110] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A hybrid intrusion detection device, comprising: The device includes a power supply circuit, an intrusion detection circuit, and a main control circuit. The power supply circuit includes a battery power supply module and a motherboard power supply module. The power supply circuit is connected to the intrusion detection circuit and the main control circuit respectively, and is used to supply power to the intrusion detection circuit and the main control circuit. The intrusion detection circuit includes a connector, a first redundant diode, and a second redundant diode. One end of each of the first and second redundant diodes is connected to the connector, and the other end is connected to the power supply circuit. Switching the conduction of the first and second redundant diodes determines whether the circuit powers a battery-powered module or a motherboard-powered module powered by the connector. The intrusion detection circuit also includes a first sub-circuit and a second sub-circuit. The first sub-circuit includes a first resistor and a second resistor. The second sub-circuit includes a third resistor and a fourth resistor. The connector includes at least a first pin, a second pin, and a third pin. The first redundant diode includes a first sub-diode and a second sub-diode. The second redundant diode includes a third sub-diode and a fourth sub-diode. In this circuit, the first pin is connected to the cathode of the first sub-diode, the anode of the first sub-diode is connected to one end of the first resistor, and the other end of the first resistor is connected to the battery power supply module of the power supply circuit; the first pin is connected to the cathode of the second sub-diode, the anode of the second sub-diode is connected to one end of the second resistor, and the other end of the second resistor is connected to the motherboard power supply module of the power supply circuit; the second pin is connected to the cathode of the fourth sub-diode, the anode of the fourth sub-diode is connected to one end of the fourth resistor, and the other end of the fourth resistor is connected to the motherboard power supply module of the power supply circuit; When the server is online, the output voltage of the motherboard power supply module is higher than that of the battery power supply module, corresponding to the conduction of the second and fourth sub-diodes, and the cutoff of the first and third sub-diodes, with the motherboard power supply module supplying power to the first and second pins; when the server is offline, the motherboard power supply module has no output, the first and third sub-diodes are conducted, and the second and fourth sub-diodes are cut off, with the battery power supply module supplying power to the first and second pins. When the intrusion detection circuit is connected to the intrusion cable, the intrusion detection circuit determines the intrusion signal based on the connector being connected to the intrusion cable; The main control circuit is used to determine and store the intrusion detection result based on the intrusion signal, and to perform alarm processing.
2. The apparatus of claim 1, wherein, When the intrusion detection circuit is connected to an intrusion cable, the third pin is connected to the first pin via the intrusion cable; The signal output from the first pin is an in-place signal, used to indicate whether an intrusion cable is installed.
3. The apparatus of claim 2, wherein, When the intrusion detection circuit is connected to the intrusion cable, one end of the switch of the intrusion cable is connected to the second pin, and the other end of the switch of the intrusion cable is connected to the third pin. The signal output from the second pin is an intrusion signal, used to indicate the intrusion detection result. If the switch is pressed, the second pin outputs a high-level intrusion signal to indicate that the chassis has not been intruded. If the switch is released, the second pin outputs a low-level intrusion signal to indicate that the chassis has been intruded.
4. The apparatus of any one of claims 1-3, wherein, A transient voltage suppressor diode is also connected to the second pin; The intrusion detection circuit also includes a fifth resistor, one end of which is connected to the third pin connection, and the other end of which is grounded.
5. The apparatus of any one of claims 1-4, wherein, The main control circuit includes a microprocessor unit, an internal storage unit, and a baseboard management controller. The microprocessor unit is used to determine the intrusion detection result based on the intrusion signal generated by the intrusion detection circuit. The intrusion detection result includes whether the chassis has been intruded or not. The internal storage unit is used to store the corresponding intrusion information in response to the intrusion detection result of the chassis being intruded, wherein the intrusion information includes the intrusion time and the number of intrusions; The baseboard management controller is used to read the intrusion information and perform alarm processing based on the intrusion information.
6. A hybrid intrusion detection method applied to the hybrid intrusion detection device of claim 1, characterized by, The method includes: The main control circuit determines whether the intrusion cable is installed based on the presence signal emitted from the first pin inside the connector; After the intrusion cable is installed, the main control circuit determines the intrusion detection result based on the intrusion signal emitted by the second pin in the connector. The intrusion detection result includes whether the chassis has been intruded or not. In response to the intrusion detection result of the chassis being breached, the main control circuit records and stores the intrusion information to the internal storage unit within the main control circuit, and performs alarm processing.
7. The method of claim 6, wherein, The method further includes: When the intrusion cable is not installed, the microcontroller unit in the main control circuit reports the presence signal to the baseboard management controller in the main control circuit; The baseboard management controller responds to the presence signal and generates a prompt to alert the user to check the installation status of the intrusion cable.
8. The method according to claim 7, characterized in that, The main control circuit records and stores intrusion information in its internal storage unit, and issues an alarm, including: When the server is online, the baseboard management controller reads the intrusion information in the internal storage unit and displays an alarm on the console. When the server goes offline, the baseboard management controller reads the intrusion information in the internal storage unit and displays an alarm on the console when the server is powered on again.