A USB interface control method and device for information security protection

Through authentication and transmission task analysis, the transmission channel capacity of the USB interface is intelligently adjusted, solving the problems of low security and poor resource management of traditional USB interface control devices, and achieving more efficient and secure data transmission.

CN119494127BActive Publication Date: 2025-05-06北京网藤科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510073661.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-06
Estimated Expiration
2045-01-17

AI Technical Summary

Technical Problem

Traditional USB interface control devices have low security problems and cannot intelligently adjust the capacity of the USB transmission channel, resulting in wasted bandwidth resources or system overload.

Method used

By identifying the USB connection status, collecting information of the device to be connected for authentication, analyzing historical and real-time transmission tasks, calculating transmission risk values ​​and adjusting the available capacity of the transmission channel.

Benefits of technology

Improves the security and resource management capabilities of USB interface control, avoids bandwidth resource waste and system overload, and ensures efficient operation of the system and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119494127B_ABST
    Figure CN119494127B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data transmission, and discloses a USB interface control method and device for information security protection, the method comprising: identifying the USB connection state, collecting information of the device to be connected, and performing identity authentication; collecting historical transmission tasks of the device to be connected, extracting historical task indexes, and determining the available capacity of the transmission channel; collecting real-time transmission tasks to determine real-time structure information and real-time content information, determining the transmission risk value, and judging whether to adjust the available capacity of the transmission channel; when it is determined to be adjusted, comparing the collected characteristic index with the historical adjustment plan, and adjusting the available capacity of the transmission channel according to the comparison result; connecting the device to be connected and the workstation with the adjusted available capacity of the transmission channel. The present application strengthens the information security protection capability, and reduces potential safety hazards and failure risks through resource scheduling and risk management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission, and in particular to a USB interface management and control method and device for information security protection. Background Art

[0002] With the rapid development of information technology, USB interface has become an indispensable and important peripheral interface in modern computer systems. Especially in the fields of industrial control, medical equipment, financial payment and data storage, USB interface plays a key role in data transmission and device connection.

[0003] However, traditional USB interface control devices usually need to be connected to a workstation and require the installation of corresponding drivers on the workstation. This method increases the complexity of the system and poses a certain risk of intrusion. For example, these drivers or applications may conflict with other software on the workstation, causing system crashes or instability, affecting the stability and security of the workstation, and thus having a profound impact on the normal operation of the on-site system, which may result in loss of important data or business interruption. In addition, the existing technology cannot intelligently adjust the capacity of the USB transmission channel according to the needs of real-time transmission tasks, resulting in a waste of bandwidth resources or system overload, further affecting system performance and data security.

[0004] Therefore, it is necessary to design a USB interface control method and device for information security protection to solve the problems existing in the current technology. Summary of the invention

[0005] In view of this, the present invention proposes a USB interface management and control method and device for information security protection, aiming to solve the problem of low security existing in the current USB interface management and control technology.

[0006] In one aspect, the present invention provides a USB interface management and control method for information security protection, comprising:

[0007] Identify the USB connection status, collect information of the device to be connected when the USB connection is detected, and perform identity authentication based on the information of the device to be connected;

[0008] When the identity authentication is passed, the historical transmission tasks of the device to be connected are collected, the historical task index of the historical transmission tasks is extracted, and the available capacity of the transmission channel is determined according to the historical task index;

[0009] Collecting the real-time transmission tasks of the device to be connected, analyzing the real-time transmission tasks, determining real-time structure information and real-time content information, determining a transmission risk value according to the real-time structure information and the real-time content information, and judging whether to adjust the available capacity of the transmission channel according to the transmission risk value;

[0010] When it is determined that the available capacity of the transmission channel is to be adjusted, the real-time data volume and the transmission risk value of the real-time transmission task are used as the characteristic index of the real-time transmission task, the characteristic index is compared with the historical adjustment plan, and the adjustment coefficient is determined according to the comparison result to adjust the available capacity of the transmission channel;

[0011] The adjusted available capacity of the transmission channel and the characteristic index are stored, and the device to be connected and the workstation are connected by using the adjusted available capacity of the transmission channel.

[0012] Furthermore, when identity authentication is performed according to the information of the device to be connected, it includes:

[0013] Acquire the information of the device to be connected based on the USB gateway, wherein the information of the device to be connected includes the device type, device ID, manufacturer ID, serial number and firmware version;

[0014] Compare the information of the device to be connected with the whitelist, which includes the authorized device ID, manufacturer ID, device type, serial number and firmware version;

[0015] When the whitelist contains information identical to the information of the device to be connected, it is determined that the identity authentication is passed.

[0016] Furthermore, extracting the historical task index of the historical transmission task and determining the available capacity of the transmission channel according to the historical task index includes:

[0017] The historical mission index is calculated by the following formula:

[0018]

[0019] Where E represents the historical task index, T represents the total historical transmission time, Tv represents the average transmission time of the historical transmission task, Dv represents the average data volume in the historical transmission task, Rv represents the average transmission rate of the historical transmission task, Rmax represents the maximum rate of the historical transmission task, and a1, a2, and a3 represent weight coefficients;

[0020] The available capacity of the transmission channel is calculated by the following formula:

[0021]

[0022] Among them, C represents the available capacity of the transmission channel, C0 represents the basic capacity of the transmission channel, E represents the historical task index, λ represents the capacity adjustment coefficient, and the value range of λ is (0, 1).

[0023] Further, analyzing the real-time transmission task to determine the real-time structure information and the real-time content information includes:

[0024] The real-time structure information includes data packet size, transmission protocol, data stream type and data packet interval;

[0025] The real-time content information includes data type, sensitivity of data content and timeliness requirements of real-time transmission.

[0026] Further, when determining the transmission risk value according to the real-time structure information and the real-time content information, it includes:

[0027] Acquire the historical transmission tasks, and construct a historical data set according to the historical transmission tasks;

[0028] Sampling the historical data set according to a preset ratio to obtain a training subset and a test subset;

[0029] Acquire a pre-selected neural network model, perform iterative training on the neural network model according to the training subset, and evaluate the iteratively trained neural network model according to the test subset to obtain a data analysis model;

[0030] Inputting the real-time structure information and the real-time content information into the data analysis model to obtain corresponding real-time structure information analysis values ​​and real-time content information analysis values;

[0031] Calculating the transmission risk value according to the real-time structure information analysis value and the real-time content information analysis value;

[0032]

[0033] Among them, F represents the transmission risk value, f1 represents the weight of real-time structure information, N1 represents the real-time structure information analysis value, N2 represents the real-time content information analysis value, and f2 represents the weight of real-time content information.

[0034] Further, judging whether to adjust the available capacity of the transmission channel according to the transmission risk value includes:

[0035] Comparing the transmission risk value with the risk threshold, and determining whether to adjust the available capacity of the transmission channel according to the comparison result;

[0036] When the transmission risk value is greater than the risk threshold, it is determined that the available capacity of the transmission channel is adjusted; when the transmission risk value is less than or equal to the risk threshold, it is determined that the available capacity of the transmission channel is not adjusted.

[0037] Furthermore, comparing the characteristic index with the historical adjustment scheme, and determining the adjustment coefficient according to the comparison result to adjust the available capacity of the transmission channel includes:

[0038] The historical adjustment plan includes a historical characteristic index and a historical adjustment coefficient;

[0039] Calculating the similarity between the characteristic index and each of the historical characteristic indexes, and determining an adjustment coefficient according to the similarity comparison result to adjust the available capacity of the transmission channel;

[0040] When there is data in the historical adjustment scheme whose similarity with the characteristic index is greater than a similarity threshold, adjusting the available capacity of the transmission channel according to the historical adjustment coefficient corresponding to the maximum similarity value;

[0041] When there is no data in the historical adjustment scheme whose similarity with the characteristic index is greater than the similarity threshold, a similarity set is determined and the historical adjustment coefficient corresponding to the maximum similarity value in the similarity set is selected as the initial value, and the initial value is adjusted according to the remaining historical adjustment coefficients in the similarity set to obtain the adjustment coefficient to adjust the available capacity of the transmission channel.

[0042] Further, determining a similarity set and selecting a historical adjustment coefficient corresponding to a maximum similarity value in the similarity set as an initial value, and adjusting the initial value according to the remaining historical adjustment coefficients in the similarity set, includes:

[0043] S1: Initialize K centroids among all the historical feature indices, assign the feature indices to the nearest centroids, and form K clusters;

[0044] S2: Recalculate the centroid of each cluster;

[0045] S3: Repeat S1 and S2 until the centroid no longer changes or the specified number of iterations is reached;

[0046] S4: taking the historical characteristic indexes in the cluster containing the characteristic index as a similarity set, and determining the historical adjustment coefficient corresponding to each historical characteristic index in the similarity set;

[0047] The historical adjustment coefficients in the similarity set that are greater than the median of the historical adjustment coefficients are included in the first data group; the historical adjustment coefficients in the similarity set that are less than the median of the historical leakage positions are included in the second data group; and the initial value is adjusted according to the first data group and the second data group.

[0048] Further, when the initial value is adjusted according to the first data group and the second data group, it includes:

[0049]

[0050] Among them, J represents the adjustment coefficient, J1 represents the average value of the historical adjustment coefficients in the first data group, J0 represents the initial value, J2 represents the average value of the historical adjustment coefficients in the second data group, n1 represents the number of historical adjustment coefficients in the first data group, and n2 represents the number of historical adjustment coefficients in the second data group.

[0051] Compared with the prior art, the beneficial effects of the present invention are: by introducing identity authentication, historical task analysis and real-time transmission monitoring, the security and resource management capabilities of USB interface management are improved. Unlike traditional identity authentication and bandwidth management methods, the legitimacy of device connection is ensured by comprehensively considering device information and transmission history, dynamically evaluating transmission risks based on the structure and content of real-time transmission tasks, and intelligently adjusting the available capacity of the transmission channel. The risks of bandwidth resource waste and system overload are avoided, ensuring the efficient operation of the system and data security. By comparing real-time task characteristics with historical adjustment plans, flexible responses can be made under changing workloads, thereby improving the safety, stability and adaptability of USB interfaces. Information security protection capabilities are strengthened, system performance is optimized through resource scheduling and risk management, and potential safety hazards and failure risks are reduced.

[0052] On the other hand, the present application also provides a USB interface control device for information security protection, which is used to apply the above-mentioned USB interface control method for information security protection, including:

[0053] USB interface, used to connect the device to be connected;

[0054] A network port, used to connect the device to be connected with the workstation;

[0055] A control device is connected to the USB interface and the network port,

[0056] The control device is used to identify the USB connection status, collect information of the device to be connected when the USB connection is detected, and perform identity authentication based on the information of the device to be connected;

[0057] When the identity authentication is passed, the historical transmission tasks of the device to be connected are collected, the historical task index of the historical transmission tasks is extracted, and the available capacity of the transmission channel is determined according to the historical task index;

[0058] Collecting the real-time transmission tasks of the device to be connected, analyzing the real-time transmission tasks, determining real-time structure information and real-time content information, determining a transmission risk value according to the real-time structure information and the real-time content information, and judging whether to adjust the available capacity of the transmission channel according to the transmission risk value;

[0059] When it is determined that the available capacity of the transmission channel is to be adjusted, the real-time data volume and the transmission risk value of the real-time transmission task are used as the characteristic index of the real-time transmission task, the characteristic index is compared with the historical adjustment plan, and the adjustment coefficient is determined according to the comparison result to adjust the available capacity of the transmission channel;

[0060] The adjusted available capacity of the transmission channel and the characteristic index are stored, and the device to be connected and the workstation are connected by using the adjusted available capacity of the transmission channel.

[0061] It is understandable that the above-mentioned USB interface control method and device for information security protection have the same beneficial effects and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0063] Figure 1 A flowchart of a USB interface management and control method for information security protection provided by an embodiment of the present invention;

[0064] Figure 2 A schematic diagram of a USB interface control device for information security protection provided by an embodiment of the present invention.

[0065] Among them, 100, USB interface management and control device; 110, USB interface; 120, network port; 130, control device. DETAILED DESCRIPTION

[0066] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art. It should be noted that, in the absence of conflict, the embodiments of the present invention and the features described in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0067] In some embodiments of the present application, see Figure 1 As shown, a USB interface management and control method for information security protection includes:

[0068] S100: Identify the USB connection status, collect information of the device to be connected when the USB connection is detected, and perform identity authentication based on the information of the device to be connected.

[0069] S200: When the identity authentication is passed, the historical transmission tasks of the device to be connected are collected, the historical task index of the historical transmission tasks is extracted, and the available capacity of the transmission channel is determined according to the historical task index.

[0070] S300: Collect real-time transmission tasks of the device to be connected, analyze the real-time transmission tasks, determine real-time structure information and real-time content information, determine a transmission risk value according to the real-time structure information and the real-time content information, and determine whether to adjust the available capacity of the transmission channel according to the transmission risk value.

[0071] S400: When it is determined to adjust the available capacity of the transmission channel, the real-time data volume and the transmission risk value of the real-time transmission task are used as the characteristic index of the real-time transmission task, and the characteristic index is compared with the historical adjustment plan. The adjustment coefficient is determined according to the comparison result to adjust the available capacity of the transmission channel.

[0072] S500: storing the adjusted available capacity of the transmission channel and the characteristic index, and connecting the device to be connected and the workstation using the adjusted available capacity of the transmission channel.

[0073] Specifically, the connection status of the USB device is identified in S100. Once a device is detected to be connected through the USB interface, relevant information of the device (such as device type, manufacturer ID, serial number, etc.) is collected. This information will be used for device identity authentication to ensure that only legitimate devices can access the system. After the identity authentication is passed in S200, the historical transmission tasks of the device are analyzed. These historical task information are used to extract the "historical task index". The historical task index comprehensively considers the past data transmission of the device (such as data volume, transmission time, transmission rate, etc.). By analyzing the historical task index, the device's demand for the transmission channel is estimated, and the available capacity of the transmission channel that should be allocated when the device is connected to the system is determined accordingly. The relevant information of the device's current (real-time) transmission task is analyzed in S300. Including real-time structure information (such as data packet size, protocol type, etc.) and real-time content information (such as data type, sensitivity, timeliness requirements, etc.). Calculate the transmission risk value. The transmission risk value is obtained by analyzing the real-time structure information and content information, and measures the risk of the real-time transmission task. According to the calculated transmission risk value, it is determined whether the available capacity of the transmission channel needs to be adjusted to ensure the security and stability of data transmission. In S400, when the transmission risk value exceeds the preset threshold, it is determined that the capacity of the transmission channel needs to be adjusted. At this time, the characteristic index of the real-time transmission task (including the real-time data volume and the transmission risk value) is extracted and compared with the historical adjustment plan. By comparing similar historical adjustment plans, the adjustment coefficient is determined to dynamically adjust the available capacity of the transmission channel to ensure the stability and security of the transmission task. In S500, the adjusted available capacity and characteristic index of the transmission channel will be stored in the system for reference for future transmission tasks. The device and workstation are connected with the adjusted available capacity to ensure efficiency and security during data transmission.

[0074] It is understandable that by combining identity authentication, historical task analysis and real-time transmission monitoring, not only can the legitimacy of device connection be ensured, but also the bandwidth requirements of the transmission channel can be evaluated and adjusted in real time to avoid system crashes or data loss due to insufficient or overloaded bandwidth. At the same time, real-time task analysis and risk assessment can provide tailored bandwidth scheduling strategies for each data transmission task, and can respond to complex usage scenarios more flexibly. In addition, through dynamic monitoring and comparison of historical tasks, the resource allocation of the transmission channel can be continuously optimized, improving overall security, efficiency and stability. It is conducive to solving bandwidth waste, system instability and potential safety hazards in traditional USB interface management and control methods.

[0075] In some embodiments of the present application, when identity authentication is performed based on the information of the device to be connected, it includes: obtaining the information of the device to be connected based on the USB gateway, and the information of the device to be connected includes the device type, device ID, manufacturer ID, serial number and firmware version. Compare the information of the device to be connected with the white list, and the white list includes the authorized device ID, manufacturer ID, device type, serial number and firmware version. When the white list contains the same information as the information of the device to be connected, it is determined that the identity authentication is passed.

[0076] Specifically, by storing the authorized device information in the system in advance and verifying its legitimacy through comparison when the device is connected, it ensures that only authenticated devices can pass identity authentication, preventing the access of illegal devices, thereby improving security. After the device is connected, the basic information of the device to be connected is automatically collected, including device ID, manufacturer ID, device type, serial number and firmware version. The whitelist is a database that stores authorized device information. Authentication can only be passed when all the information of the device to be connected completely matches the device information stored in the whitelist. When the device information matches the whitelist, it means that the device is authorized and will be allowed to continue to connect and perform subsequent operations. If the match fails, the device will be blocked from connecting to avoid intrusion by illegal devices.

[0077] It is understandable that by introducing device information collection and whitelist comparison mechanisms, identity authentication of USB devices is achieved, and security protection capabilities are improved. Unlike the traditional simple device access method, identity authentication based on device information can ensure that only authorized devices can access the system, preventing unauthorized devices from entering, thereby avoiding potential security threats. The whitelist comparison mechanism can also check the access devices in real time to ensure that the legitimacy is verified every time the device is connected, reducing data leakage, virus transmission, and information tampering that may be caused by malicious device access. The verification process is completed automatically, reducing the need for manual intervention.

[0078] In some embodiments of the present application, extracting a historical task index of a historical transmission task and determining the available capacity of a transmission channel according to the historical task index includes:

[0079] The historical mission index is calculated by the following formula:

[0080]

[0081] Among them, E represents the historical task index, T represents the total historical transmission time, Tv represents the average transmission time of the historical transmission task, Dv represents the average value of the data volume in the historical transmission task, Rv represents the average transmission rate of the historical transmission task, Rmax represents the maximum rate of the historical transmission task, and a1, a2, and a3 represent weight coefficients.

[0082] The available capacity of the transmission channel is calculated by the following formula:

[0083]

[0084] Among them, C represents the available capacity of the transmission channel, C0 represents the basic capacity of the transmission channel, E represents the historical task index, λ represents the capacity adjustment coefficient, and the value range of λ is (0, 1).

[0085] It is understandable that the specific values ​​of a1, a2, and a3 can be adjusted according to the actual task requirements. For ease of calculation, a1+a2+a3=1 is preferred. Through historical task index calculation, intelligent decisions are made based on the actual historical performance of the device. Compared with static capacity allocation, dynamic adjustment makes the use of resources more efficient and avoids over-allocation of bandwidth or insufficient resources. By reasonably adjusting the capacity of the transmission channel, the real-time transmission needs of the device can be better met, reducing the risk of bandwidth waste or device overload, thereby improving data transmission efficiency and stability. By adjusting the capacity adjustment coefficient, the range of capacity adjustment can be flexibly controlled according to different needs.

[0086] In some embodiments of the present application, when analyzing the real-time transmission task and determining the real-time structure information and the real-time content information, the real-time structure information includes the data packet size, transmission protocol, data stream type and data packet interval. The real-time content information includes the data type, the sensitivity of the data content and the timeliness requirement of the real-time transmission.

[0087] In some embodiments of the present application, when determining the transmission risk value according to the real-time structure information and the real-time content information, it includes:

[0088] Obtain historical transmission tasks and build historical data sets based on the historical transmission tasks.

[0089] The historical data set is sampled according to a preset ratio to obtain a training subset and a test subset.

[0090] A pre-selected neural network model is obtained, and the neural network model is iteratively trained according to the training subset, and the iteratively trained neural network model is evaluated according to the test subset to obtain a data analysis model.

[0091] The real-time structure information and the real-time content information are input into the data analysis model to obtain the corresponding real-time structure information analysis value and the real-time content information analysis value.

[0092] The transmission risk value is calculated based on the real-time structure information analysis value and the real-time content information analysis value.

[0093]

[0094] Wherein, F represents the transmission risk value, f1 represents the weight of the real-time structure information, N1 represents the real-time structure information analysis value, N2 represents the real-time content information analysis value, and f2 represents the weight of the real-time content information. Preferably, f1 takes a value of 0.5 and f2 takes a value of 0.5.

[0095] In some embodiments of the present application, when determining whether to adjust the available capacity of the transmission channel according to the transmission risk value, the method includes: comparing the transmission risk value with the risk threshold, and determining whether to adjust the available capacity of the transmission channel according to the comparison result. When the transmission risk value is greater than the risk threshold, it is determined that the available capacity of the transmission channel is adjusted. When the transmission risk value is less than or equal to the risk threshold, it is determined that the available capacity of the transmission channel is not adjusted.

[0096] Specifically, real-time structural information includes:

[0097] Packet size: The number of bytes in each packet, reflecting the amount of payload being transmitted.

[0098] Transmission protocol: The type of protocol used for transmission (such as TCP, UDP, etc.) affects the transmission efficiency of data packets and the stability of the network.

[0099] Data stream type: For example, whether it is video streaming, file transfer, real-time monitoring, etc. Different stream types will affect the real-time and stability of data transmission.

[0100] Packet interval: The time interval between data packets affects the data transmission rate and network load balancing.

[0101] Real-time content information includes:

[0102] Data type: The type of data (such as text, audio, video, etc.). Different types of data have different requirements for transmission channels.

[0103] Sensitivity of data content: If the transmitted data is confidential information or has high security requirements, the transmission process needs to be accelerated to reduce the risk of leakage.

[0104] Timeliness requirements for real-time transmission: Whether data transmission has strict timeliness requirements (such as real-time audio and video transmission) affects the requirements for transmission rate and delay.

[0105] By collecting data of historical transmission tasks, a database including historical analysis values ​​and historical tasks is established.

[0106] Sampling to obtain training subsets and test subsets: According to the preset ratio, sampling is performed from the historical data set to form training subsets and test subsets for training and evaluating the neural network model.

[0107] The pre-selected neural network model is iteratively trained using the training subset.

[0108] Use the test subset to evaluate the trained neural network to ensure the effectiveness and accuracy of the model.

[0109] After training, the neural network model becomes a data analysis model, which is used to predict the risk value of subsequent real-time tasks.

[0110] It is understandable that the risk of the transmission task is comprehensively evaluated by comprehensively analyzing the real-time structural information and the real-time content information. Compared with the traditional single-factor evaluation method, it can better reflect the complexity and demand of the actual transmission task, so as to make more accurate adjustment decisions. Through the learning of historical transmission data by the neural network model, the risk of the current task can be predicted based on the historical performance of the equipment and transmission tasks, and the capacity of the transmission channel can be adjusted in real time. Real-time calculation of the transmission risk value and dynamic adjustment of the available capacity of the transmission channel based on the value can help avoid the problem of insufficient or over-allocation of bandwidth, thereby improving data transmission efficiency and system stability. By adjusting the available capacity when the transmission risk value is too high, network congestion and resource overload can be actively avoided, and the fault tolerance and anti-interference ability of the overall system can be improved, thereby reducing task failures or delays caused by network bottlenecks.

[0111] In some embodiments of the present application, comparing the characteristic index with the historical adjustment scheme, and determining the adjustment coefficient according to the comparison result to adjust the available capacity of the transmission channel includes:

[0112] The historical adjustment plan includes the historical characteristic index and the historical adjustment coefficient.

[0113] The similarity between the characteristic index and each historical characteristic index is calculated, and the adjustment coefficient is determined according to the similarity comparison result to adjust the available capacity of the transmission channel.

[0114] When there is data in the historical adjustment scheme whose similarity with the characteristic index is greater than the similarity threshold, the available capacity of the transmission channel is adjusted according to the historical adjustment coefficient corresponding to the maximum similarity value.

[0115] When there is no data in the historical adjustment scheme whose similarity with the characteristic index is greater than the similarity threshold, a similarity set is determined and the historical adjustment coefficient corresponding to the maximum similarity value in the similarity set is selected as the initial value. The initial value is adjusted according to the remaining historical adjustment coefficients in the similarity set to obtain the adjustment coefficient to adjust the available capacity of the transmission channel.

[0116] In some embodiments of the present application, determining a similarity set and selecting a historical adjustment coefficient corresponding to the maximum similarity value in the similarity set as an initial value, and adjusting the initial value according to the remaining historical adjustment coefficients in the similarity set includes:

[0117] S1: Initialize K centroids among all historical feature indices, assign feature indices to the nearest centroids, and form K clusters.

[0118] S2: Recalculate the centroid of each cluster.

[0119] S3: Repeat S1 and S2 until the centroid no longer changes or the specified number of iterations is reached.

[0120] S4: taking the historical characteristic indexes in the cluster containing the characteristic index as a similarity set, and determining the historical adjustment coefficient corresponding to each historical characteristic index in the similarity set.

[0121] The historical adjustment coefficients in the similarity set that are greater than the median of the historical adjustment coefficients are included in the first data group. The historical adjustment coefficients in the similarity set that are less than the median of the historical leakage positions are included in the second data group. The initial value is adjusted according to the first data group and the second data group.

[0122] In some embodiments of the present application, when the initial value is adjusted according to the first data group and the second data group, it includes:

[0123]

[0124] Among them, J represents the adjustment coefficient, J1 represents the average value of the historical adjustment coefficients in the first data group, J0 represents the initial value, J2 represents the average value of the historical adjustment coefficients in the second data group, n1 represents the number of historical adjustment coefficients in the first data group, and n2 represents the number of historical adjustment coefficients in the second data group.

[0125] Specifically, the characteristic index of the current task is calculated and compared with the characteristic index of the historical transmission tasks. By calculating the similarity, the similarity between the current task and the historical tasks is evaluated, and the relevance of the historical tasks is identified. If the similarity between the characteristic index of the current task and the characteristic index of a historical task exceeds the preset threshold, it means that the resource demand of the current task is similar to that of the historical task, and the adjustment coefficient of the historical task can be directly referenced. In the absence of directly similar historical tasks, a similar set is formed to obtain an initial adjustment coefficient, and then further adjusted in combination with other adjustment coefficients in the similar set to ensure that resource allocation is as accurate as possible. Through comparison and adjustment, the most suitable available capacity of the transmission channel is intelligently selected for each real-time transmission task. The need for human intervention is reduced, and resource allocation is made more accurate and efficient.

[0126] It is understandable that by calculating the similarity between the real-time feature index and the historical feature index, the similarity between the current task and the historical task can be more accurately judged, and the appropriate adjustment coefficient can be selected accordingly. This embodiment is more flexible than simply relying on rules or fixed values ​​for adjustment, and can adapt to the specific needs of different tasks. By comparing historical data, the capacity of the transmission channel is automatically adjusted, reducing the need for manual intervention and making resource allocation more accurate and intelligent.

[0127] In the above embodiments, the security and resource management capabilities of USB interface management are improved by introducing identity authentication, historical task analysis and real-time transmission monitoring. Unlike traditional identity authentication and bandwidth management methods, the legitimacy of device connection is ensured by comprehensively considering device information and transmission history, dynamically evaluating transmission risks based on the structure and content of real-time transmission tasks, and intelligently adjusting the available capacity of the transmission channel. The risks of bandwidth resource waste and system overload are avoided, ensuring the efficient operation of the system and data security. By comparing real-time task characteristics with historical adjustment plans, flexible responses can be made under changing workloads, improving the safety, stability and adaptability of USB interfaces. Information security protection capabilities are strengthened, system performance is optimized through resource scheduling and risk management, and potential safety hazards and failure risks are reduced.

[0128] In another preferred embodiment based on the above embodiment, refer to Figure 2 As shown, this embodiment provides a USB interface control device 100 for information security protection, which is used to apply the above-mentioned USB interface control method for information security protection, including:

[0129] USB interface 110, used to connect to a device to be connected;

[0130] Network port 120, used to connect the device to be connected with the workstation;

[0131] The control device 130 is connected to the USB interface 110 and the network port 120.

[0132] The control device 130 is used to identify the USB connection status, collect the information of the device to be connected when the USB connection is detected, and perform identity authentication according to the information of the device to be connected;

[0133] When the identity authentication is passed, the historical transmission tasks of the device to be connected are collected, the historical task index of the historical transmission tasks is extracted, and the available capacity of the transmission channel is determined according to the historical task index;

[0134] Collect the real-time transmission tasks of the devices to be connected, analyze the real-time transmission tasks, determine the real-time structure information and the real-time content information, determine the transmission risk value according to the real-time structure information and the real-time content information, and determine whether to adjust the available capacity of the transmission channel according to the transmission risk value;

[0135] When it is determined that the available capacity of the transmission channel should be adjusted, the real-time data volume and the transmission risk value of the real-time transmission task are used as the characteristic index of the real-time transmission task, and the characteristic index is compared with the historical adjustment plan. The adjustment coefficient is determined according to the comparison result to adjust the available capacity of the transmission channel;

[0136] The adjusted available capacity of the transmission channel and the characteristic index are stored, and the device to be connected and the workstation are connected by using the adjusted available capacity of the transmission channel.

[0137] It is understandable that the introduction of identity authentication, historical task analysis, and real-time transmission monitoring improves the security and resource management capabilities of USB interface control. Unlike traditional identity authentication and bandwidth management methods, the legitimacy of device connections is ensured by comprehensively considering device information and transmission history, dynamically evaluating transmission risks based on the structure and content of real-time transmission tasks, and intelligently adjusting the available capacity of transmission channels. The risk of bandwidth resource waste and system overload is avoided, ensuring the efficient operation of the system and data security. By comparing real-time task characteristics with historical adjustment plans, flexible responses can be made under changing workloads, improving the safety, stability, and adaptability of USB interfaces. Information security protection capabilities are strengthened, and system performance is optimized through resource scheduling and risk management, reducing potential safety hazards and failure risks.

[0138] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0139] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0140] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0141] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0142] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A USB interface management and control method for information security protection, characterized in that: include: Identify the USB connection status, collect information of the device to be connected when the USB connection is detected, and perform identity authentication based on the information of the device to be connected; When the identity authentication is passed, the historical transmission tasks of the device to be connected are collected, the historical task index of the historical transmission tasks is extracted, and the available capacity of the transmission channel is determined according to the historical task index; Collecting the real-time transmission tasks of the device to be connected, analyzing the real-time transmission tasks, determining real-time structure information and real-time content information, determining a transmission risk value according to the real-time structure information and the real-time content information, and judging whether to adjust the available capacity of the transmission channel according to the transmission risk value; When it is determined that the available capacity of the transmission channel is to be adjusted, the real-time data volume and the transmission risk value of the real-time transmission task are used as the characteristic index of the real-time transmission task, the characteristic index is compared with the historical adjustment plan, and the adjustment coefficient is determined according to the comparison result to adjust the available capacity of the transmission channel; The adjusted available capacity of the transmission channel and the characteristic index are stored, and the device to be connected and the workstation are connected using the adjusted available capacity of the transmission channel; Extracting the historical task index of the historical transmission task and determining the available capacity of the transmission channel according to the historical task index includes: The historical mission index is calculated by the following formula: Where E represents the historical task index, T represents the total historical transmission time, Tv represents the average transmission time of the historical transmission task, Dv represents the average data volume in the historical transmission task, Rv represents the average transmission rate of the historical transmission task, Rmax represents the maximum rate of the historical transmission task, and a1, a2, and a3 represent weight coefficients; The available capacity of the transmission channel is calculated by the following formula: Among them, C represents the available capacity of the transmission channel, C0 represents the basic capacity of the transmission channel, E represents the historical task index, λ represents the capacity adjustment coefficient, and the value range of λ is (0, 1).

2. The USB interface management and control method for information security protection according to claim 1, characterized in that: When identity authentication is performed according to the information of the device to be connected, it includes: Acquire the information of the device to be connected based on the USB gateway, wherein the information of the device to be connected includes the device type, device ID, manufacturer ID, serial number and firmware version; Compare the information of the device to be connected with the whitelist, which includes the authorized device ID, manufacturer ID, device type, serial number and firmware version; When the whitelist contains information identical to the information of the device to be connected, it is determined that the identity authentication is passed.

3. The USB interface management and control method for information security protection according to claim 1, characterized in that: Analyzing the real-time transmission task to determine the real-time structure information and the real-time content information includes: The real-time structure information includes data packet size, transmission protocol, data stream type and data packet interval; The real-time content information includes data type, sensitivity of data content and timeliness requirements of real-time transmission.

4. The USB interface management and control method for information security protection according to claim 3, characterized in that: When determining the transmission risk value according to the real-time structure information and the real-time content information, it includes: Acquire the historical transmission tasks, and construct a historical data set according to the historical transmission tasks; Sampling the historical data set according to a preset ratio to obtain a training subset and a test subset; Acquire a pre-selected neural network model, perform iterative training on the neural network model according to the training subset, and evaluate the iteratively trained neural network model according to the test subset to obtain a data analysis model; Inputting the real-time structure information and the real-time content information into the data analysis model to obtain corresponding real-time structure information analysis values ​​and real-time content information analysis values; Calculating the transmission risk value according to the real-time structure information analysis value and the real-time content information analysis value; Among them, F represents the transmission risk value, f1 represents the weight of real-time structure information, N1 represents the real-time structure information analysis value, N2 represents the real-time content information analysis value, and f2 represents the weight of real-time content information.

5. The USB interface management and control method for information security protection according to claim 4, characterized in that: When judging whether to adjust the available capacity of the transmission channel according to the transmission risk value, it includes: Comparing the transmission risk value with the risk threshold, and determining whether to adjust the available capacity of the transmission channel according to the comparison result; When the transmission risk value is greater than the risk threshold, it is determined that the available capacity of the transmission channel is adjusted; when the transmission risk value is less than or equal to the risk threshold, it is determined that the available capacity of the transmission channel is not adjusted.

6. The USB interface management and control method for information security protection according to claim 1, characterized in that: Comparing the characteristic index with the historical adjustment plan, and determining the adjustment coefficient according to the comparison result to adjust the available capacity of the transmission channel, includes: The historical adjustment plan includes a historical characteristic index and a historical adjustment coefficient; Calculating the similarity between the characteristic index and each of the historical characteristic indexes, and determining an adjustment coefficient according to the similarity comparison result to adjust the available capacity of the transmission channel; When there is data in the historical adjustment scheme whose similarity with the characteristic index is greater than a similarity threshold, adjusting the available capacity of the transmission channel according to the historical adjustment coefficient corresponding to the maximum similarity value; When there is no data in the historical adjustment scheme whose similarity with the characteristic index is greater than the similarity threshold, a similarity set is determined and the historical adjustment coefficient corresponding to the maximum similarity value in the similarity set is selected as the initial value, and the initial value is adjusted according to the remaining historical adjustment coefficients in the similarity set to obtain the adjustment coefficient to adjust the available capacity of the transmission channel.

7. The USB interface management and control method for information security protection according to claim 6, characterized in that: Determining a similarity set and selecting a historical adjustment coefficient corresponding to a maximum similarity value in the similarity set as an initial value, and adjusting the initial value according to the remaining historical adjustment coefficients in the similarity set, including: S1: Initialize K centroids among all the historical feature indices, assign the feature indices to the nearest centroids, and form K clusters; S2: Recalculate the centroid of each cluster; S3: Repeat S1 and S2 until the centroid no longer changes or the specified number of iterations is reached; S4: taking the historical characteristic indexes in the cluster containing the characteristic index as a similarity set, and determining the historical adjustment coefficient corresponding to each historical characteristic index in the similarity set; The historical adjustment coefficients in the similar set that are greater than the median of the historical adjustment coefficients are included in the first data group; the historical adjustment coefficients in the similar set that are less than the median of the historical adjustment coefficients are included in the second data group; and the initial value is adjusted according to the first data group and the second data group.

8. The USB interface management and control method for information security protection according to claim 7, characterized in that: When the initial value is adjusted according to the first data group and the second data group, it includes: Among them, J represents the adjustment coefficient, J1 represents the average value of the historical adjustment coefficients in the first data group, J0 represents the initial value, J2 represents the average value of the historical adjustment coefficients in the second data group, n1 represents the number of historical adjustment coefficients in the first data group, and n2 represents the number of historical adjustment coefficients in the second data group.

9. A USB interface control device for information security protection, used for applying the USB interface control method for information security protection according to any one of claims 1 to 8, characterized in that: include: USB interface, used to connect the device to be connected; A network port, used to connect the device to be connected with the workstation; A control device is connected to the USB interface and the network port, The control device is used to identify the USB connection status, collect information of the device to be connected when the USB connection is detected, and perform identity authentication based on the information of the device to be connected; When the identity authentication is passed, the historical transmission tasks of the device to be connected are collected, the historical task index of the historical transmission tasks is extracted, and the available capacity of the transmission channel is determined according to the historical task index; Collecting the real-time transmission tasks of the device to be connected, analyzing the real-time transmission tasks, determining real-time structure information and real-time content information, determining a transmission risk value according to the real-time structure information and the real-time content information, and judging whether to adjust the available capacity of the transmission channel according to the transmission risk value; When it is determined that the available capacity of the transmission channel is to be adjusted, the real-time data volume and the transmission risk value of the real-time transmission task are used as the characteristic index of the real-time transmission task, the characteristic index is compared with the historical adjustment plan, and the adjustment coefficient is determined according to the comparison result to adjust the available capacity of the transmission channel; The adjusted available capacity of the transmission channel and the characteristic index are stored, and the device to be connected and the workstation are connected by using the adjusted available capacity of the transmission channel.

Citation Information

Patent Citations

  • Performance self-test system and method of engine test equipment

    CN118329452A

  • Solid state disk performance monitoring method and system

    CN118585397A