Full-platform Detection System and Recognition Method
Through the full-platform detection system, it quickly identifies and adapts to different operating systems, solving the problem of poor cross-platform compatibility of storage devices, achieving convenient data backup and transfer, and improving device interoperability and security.
Patent Information
- Application Number
- CN202510159420.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-02-13
AI Technical Summary
Most existing storage devices only support one or two operating system platforms, resulting in compatibility issues and cannot conveniently backup and transfer data between different platforms, especially poor compatibility of Mac OS and iOS systems.
Provide a full-platform detection system, including USB interface module, analysis and judgment module, dynamic adjustment module, driver adaptation module, data management module and security encryption module. It quickly identifies operating system types through hardware acceleration technology and detailed command library, dynamically adjusts confidence scores, selects the optimal transmission protocol and encryption algorithm to realize cross-platform data transmission.
It realizes comprehensive compatibility across Windows, Android, iOS, Mac OS and Linux systems, improves the universality and convenience of storage devices, ensures data security and interoperability, and is suitable for a variety of application scenarios.
Smart Images

Figure CN119621454B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data detection systems, and particularly to a full-platform detection system and an identification method. Background Art
[0002] With the continuous progress of technology and the diversification of applications, the functions of terminal devices (especially handheld devices) are becoming increasingly powerful. These terminal devices are equipped with different hardware and operating system platforms. The mainstream terminal user operating system platforms in the current market mainly include Windows, Linux, Android, iOS, and Mac OS. As people's needs continue to grow, a person may own multiple terminal devices of different platforms, which has led to a sharp increase in the amount of data stored on the terminal devices. Therefore, the built-in memory of the terminal devices often cannot meet the growing storage needs, and users need to back up or transfer the data of one terminal device to another terminal of a different platform for storage. This requires a USB intelligent storage device to back up or transfer the data;
[0003] However, most of the current storage devices in the market have serious compatibility problems. Many storage devices only support one or two platforms. For example, they only support Windows computers and do not support Mac computers and mobile phone systems, or only support Android mobile phones and do not support iOS mobile phones, etc. Even on the supported platforms, the storage devices may also have large compatibility problems and usually can only be used on specific system versions;
[0004] For example, although some storage devices claim to support Mac OS, due to the differences in the security levels and features of different versions of Mac OS, the management software (APP) of the USB intelligent storage device cannot be normally installed or used, which limits the versatility and convenience of the storage device.
[0005] Therefore, it is necessary to provide a new full-platform detection system and an identification method to solve the above technical problems. Summary of the Invention
[0006] To solve the above technical problems, the present invention provides a full-platform detection system and an identification method.
[0007] The full-platform detection system provided by the present invention includes: a USB interface module, which is used for device power-on initialization and self-check, and is connected to the terminal interfaces of multiple different operating systems for information interaction;
[0008] An analysis and judgment module, which is used for preliminary instruction screening and execution, and judging the type of the operating system according to the instruction operation sequence;
[0009] A dynamic adjustment module, which is used for continuously monitoring the instructions, tracking the quality of the identification decision, and updating the confidence score;
[0010] A driver adaptation module, which is used to prepare driver programs according to the operating system type preliminarily determined by the analysis and judgment module and the confidence score evaluated by the dynamic adjustment module. For high-confidence situations, it loads the most suitable driver and loads the driver program.
[0011] A data management module, which is used to automatically select the most suitable operating system file format.
[0012] A data interaction module, which is used to automatically select the optimal transmission protocol according to the operating system type judged by the analysis and judgment module.
[0013] A security encryption module, which is used to perform multi-factor authentication encryption on important data according to different versions and types of driver programs installed by the driver adaptation module and different transmission protocols adopted by the data interaction module.
[0014] The analysis and judgment module includes an instruction analysis unit and a system discrimination unit. The instruction analysis unit is used to monitor and capture the first SETUP packet, and at the same time parse and judge the execution instruction for the bRequest field of the first SETUP packet. The system discrimination unit is used to, according to the order of instruction names executed by the instruction analysis unit, if the instruction execution order is the same as a specific execution order, send a detection command and receive feedback, otherwise do not send, and then preliminarily judge which operating system's terminal interface the USB interface module is connected to.
[0015] Preferably, the dynamic adjustment module includes a monitoring scoring unit and a tracking scoring unit. The monitoring scoring unit is used to listen at any time to key instructions in various new SETUP packets interacted by the USB interface module or key instructions in other interaction processes, and give a basic confidence score to the key instructions processed according to the operating system type judged from the existing data.
[0016] The tracking scoring unit then adds or subtracts the confidence score on the basis of the basic confidence score given by the monitoring scoring unit according to the key instructions processed by the monitoring scoring unit and given a basic confidence score, combined with the same batch or multiple related key instructions and specific control transmission instructions set, so as to generate a comprehensive confidence score, and feedback the comprehensive confidence score to the driver adaptation module.
[0017] The identification method of the full-platform detection system provided by the second aspect of the present invention is applicable to the described full-platform detection system, and is characterized in that it includes the following steps:
[0018] S1. Device insertion, inserting the USB interface module into the terminal interface of the operating system.
[0019] S2. Power-on self-test. The USB interface module activates the hardware circuit and checks the power status.
[0020] S3. Screening and parsing. Use the instruction analysis unit to monitor and capture the first SETUP packet, and parse the bRequest field in the SETUP packet. At this time, utilize the hardware acceleration technology to speed up the parsing process, and quickly identify the characteristic instructions with the help of the detailed command library.
[0021] S4. Judgment and execution. Judge whether the key instruction parsed from the bRequest field is a specific key instruction. If so, execute it immediately; otherwise, temporarily store it for subsequent instruction analysis, and record the timestamp of the instruction for subsequent confidence scoring.
[0022] S5. Sequential judgment. Use the system discrimination unit to compare the execution sequence of the key instructions in the judgment and execution according to step S4 with the preset special sequence. If they are the same, send a detection command and wait for a reply, and then preliminarily judge the operating system type. Otherwise, continue to listen for new instructions.
[0023] S6. Scoring judgment. For each key instruction, first, the monitoring and scoring unit gives a basic confidence score, and then adjusts the comprehensive confidence score according to the tracking and scoring unit in combination with the key instructions of the same batch or multiple correlations and the specifically set control transfer instructions.
[0024] S7. Driver installation. Use the driver adaptation module to prepare the most suitable driver program according to the initially determined operating system type and the comprehensive confidence score. For high-confidence situations, directly load the driver, and utilize the memory mapping technology to accelerate the loading process, but strict signature verification and other necessary security checks must be completed before this.
[0025] S8. Select file format. Use the data management module to reselect the file format according to the operating system type, implement the intelligent caching strategy, preload the commonly used files into the cache area in advance, and preferentially convert the commonly used files in the cache area into the selected format, and the remaining internal files are converted in sequence.
[0026] S9. Select transmission protocol. Use the data management module to automatically select the optimal transmission protocol according to the operating system type, sign the protocol, and implement the intelligent retransmission strategy to ensure data integrity, and introduce a higher-level error correction code ECC and the content-based verification method.
[0027] S10. Data encryption. Select the encryption algorithm that conforms to the characteristics of the target operating system according to the characteristics of different operating systems, and set multi-factor authentication and fine-grained permission management to implement end-to-end encryption of sensitive data.
[0028] Preferably, the specific operation steps for screening and parsing in step S3 are as follows:
[0029] S301. Start listening. Once a new device is detected and inserted, immediately start listening for data packets on the USB bus. At this time, the hardware accelerator starts working, filtering out irrelevant traffic and focusing on capturing the first SETUP packet from the host.
[0030] S302. Capture the SETUP packet. When a data frame that meets the expected format is received, immediately save it completely.
[0031] S303. Preliminary parsing. Utilize the auxiliary functions provided by the hardware accelerator to quickly extract the key elements in the SETUP packet, especially the value of the bRequest field, because it directly specifies the specific operation type.
[0032] S304. Search for matching items. According to the extracted bRequest value, search for the corresponding entry in the command library. If a complete match is found, a conclusion can be directly drawn; otherwise, proceed to the next step of in-depth analysis and comparison.
[0033] S305. In-depth analysis. For those commands that do not directly hit but have a certain similarity, further check other relevant fields and make a judgment in combination with the context information.
[0034] S306. Record the timestamp. Append a timestamp to each successfully parsed command, which is very important for subsequent confidence scoring because there may be subtle time interval differences between different operating systems.
[0035] S307. Output and send. Once the operating system type is confirmed, generate a brief report listing the parsing methods used and the basis, and send this report to the analysis and judgment module.
[0036] Preferably, the specific operation steps for judgment and execution in step S4 are as follows:
[0037] S401. Receive and judge the instruction. Receive the brief report sent from step S307, extract the parsed SETUP packet information from the brief report, especially the value of the bRequest field in it, and compare it with the preset key instruction features to determine whether there is a match.
[0038] S402. Execute the instruction. If the key instruction features match the preset instruction features, directly execute the key instruction, such as "Set Address" or "Get Device Descriptor". Conversely, if it is not a key instruction, temporarily store it in a queue for further analysis.
[0039] S403. Sequential feedback: After completing the execution of the instruction in step S402, send the running order of the key instruction to the system discrimination unit, inform that the current instruction has been properly processed, and prepare to receive the next instruction or continue to execute the next step.
[0040] Preferably, the specific operation steps of the sequential judgment in step S5 are as follows:
[0041] S501. Receive the running order: Receive the running order of the key instruction sent by the instruction analysis unit.
[0042] S502. Judge the order: Determine whether it is consistent with the preset special order. For example, if the "SetAddress" operation is executed first and then the "Get Device Descriptor" operation is executed, it is determined to be the iOS system and the Mac OS system; otherwise, it is a non-iOS system and a non-Mac OS system.
[0043] S503. Send a detection command: If the order judged in step S502 is consistent with the predetermined special order, send a detection command and wait for a reply, and then further judge the iOS system and the Mac OS system.
[0044] Preferably, the specific operation steps of the scoring judgment in step S6 are as follows:
[0045] S601. Dynamic adjustment and confirmation: Continuously monitor each new instruction according to the monitoring scoring unit.
[0046] S602. Judge the instruction source: Judge whether each new instruction is a SETUP packet or other key instructions. If so, analyze the bRequest feature; otherwise, continue to monitor.
[0047] S603. Basic scoring: Based on the analyzed bRequest feature, perform a basic confidence scoring according to whether the new key instruction itself can corroborate the operating system type determined by the sequential judgment in the existing step S5.
[0048] S604. Dynamic scoring: Use the tracking scoring unit to perform plus or minus confidence scoring on the instruction given the basic confidence scoring, in conjunction with the same batch or multiple associated key instructions and specific control transfer instructions set, to generate a comprehensive confidence scoring on the basis of the basic confidence scoring given by the monitoring scoring unit, and feedback the comprehensive confidence scoring to the driver adaptation module.
[0049] Preferably, the specific operation steps of the driver installation in step S7 are as follows:
[0050] S701. Receive the confidence score, and receive the comprehensive confidence score sent by the tracking scoring unit;
[0051] S702. Make a comprehensive judgment. Based on the basic type judged by the analysis and judgment module and the comprehensive confidence score sent by the tracking scoring unit, comprehensively judge the type of the operating system;
[0052] S703. Install the driver. According to the type of the operating system obtained by the comprehensive judgment in step S702, install the corresponding matching driver according to the type of the operating system, and at the same time use the memory mapping technology to accelerate the loading process.
[0053] Preferably, the specific operation steps of step S8 for selecting the file format are as follows:
[0054] S801. Select the file format. Use the data management module to re-select the file format according to the type of the operating system obtained by the comprehensive judgment in step S702, such as NTFS file format or exFAT file format or HFS+ file format;
[0055] S802. Reload the files. Implement an intelligent caching strategy for the files stored internally, pre-load the commonly used files into the buffer area, and preferentially convert the commonly used files in the buffer area according to the re-selected file format for standby, and the remaining internal files are converted in sequence.
[0056] Preferably, the specific operation steps of step S9 for selecting the transmission protocol are as follows:
[0057] S901. Identify the type of the operating system. According to the type of the currently running operating system and its version number and other information obtained by the comprehensive judgment in step S702, evaluate the most commonly used transmission protocol in this operating system environment;
[0058] S902. Automatically select the transmission protocol. Use the data interaction module to find the best transmission protocol configuration scheme suitable for the current environment to maintain the optimal performance;
[0059] S903. Sign the agreement. The communication parties complete the process of generating and exchanging security keys, clarify the service quality commitments of both parties regarding data transmission rate, delay, packet loss rate, etc., and provide a solution basis for possible problems;
[0060] S904. Introduce an advanced verification method. Add additional redundant information in the data packaging stage so that even if part of the data is lost, the original content can be restored through calculation. Before the data is sent, use the strong hash function SHA-256 to calculate the digest value of the data to be transmitted, and send it to the receiving party together with the data. After the receiving end receives the data, recalculate the hash value independently to confirm that the data transmission is correct.
[0061] Compared with the related technologies, the all-platform detection system and recognition method provided by the present invention have the following beneficial effects:
[0062] 1. By using the technology of the present invention, a USB intelligent storage device will be able to be fully compatible with Windows, Android, iOS, Mac OS and Linux systems. Whether it is iOS and Mac OS in the Apple ecosystem or Windows, Android and Linux in the non-Apple ecosystem, it can easily handle them. It breaks the boundaries between terminals and operating systems, allows users to freely shuttle between different devices, makes data secure storage and transfer convenient, improves the versatility and convenience of storage devices. This all-platform detection system not only simplifies the user's operation steps, but also greatly improves the interoperability and security between devices and different operating systems, is applicable to a wide range of application scenarios, and thus meets the user's needs for backing up and transferring data between different platforms.
[0063] 2. The dynamic adjustment module can monitor and optimize the confidence score in real time, flexibly adjust the decision-making strategy according to the actual situation. Even when the network conditions change or an unknown operating system type is encountered, the system can quickly respond to ensure the best operation performance. At the same time, this adaptive feature also helps the system to continuously learn and improve to better cope with new challenges that may arise in the future. In addition, by integrating hardware acceleration technology and a detailed command library, this solution can significantly accelerate the speed of instruction parsing while maintaining extremely high accuracy. This not only reduces the possibility of misjudgment, but also enables the device to respond to requests from different operating systems in the first time, thus providing a smooth and fast service response. Especially when facing a large number of concurrent requests, it can efficiently and accurately process data requests.
[0064] 3. This solution introduces strict signature verification mechanisms, memory mapping technologies and advanced encryption algorithms, such as multi-factor authentication and fine-grained permission management and other measures. These means work together to build a solid security barrier, effectively preventing unauthorized access and potential data leakage risks, and providing a more secure and reliable usage environment for users. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] Figure 1 It is the flowchart block diagram of the overall modules and units of the all-platform detection system provided by the present invention;
[0066] Figure 2 It is the overall flowchart block diagram of the all-platform detection system and recognition method provided by the present invention;
[0067] Figure 3 It is the specific operation step flowchart block diagram of step S3 screening and parsing provided by the present invention;
[0068] Figure 4 It is a flow block diagram of the specific operation steps for the judgment execution in step S4 provided by the present invention;
[0069] Figure 5 It is a flow block diagram of the specific operation steps for the sequential judgment in step S5 provided by the present invention;
[0070] Figure 6 It is a flow block diagram of the specific operation steps for the scoring judgment in step S6 provided by the present invention;
[0071] Figure 7 It is a flow block diagram of the specific operation steps for the driver installation in step S7 provided by the present invention;
[0072] Figure 8 It is a flow block diagram of the specific operation steps for the file format selection in step S8 provided by the present invention;
[0073] Figure 9 It is a flow block diagram of the specific operation steps for the transmission protocol selection in step S9 provided by the present invention;
[0074] Figure 10 It is a structure block diagram of the analysis and judgment module provided by the present invention;
[0075] Figure 11 It is a structure block diagram of the dynamic adjustment module provided by the present invention. Specific Embodiments
[0076] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0077] Please refer to Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 , Figure 6 , Figure 7 , Figure 8 , Figure 9 , Figure 10 and Figure 11 , where Figure 1 is a flow block diagram of each module and unit of the overall full-platform detection system provided by the present invention; Figure 2 is a flow block diagram of the overall process of the full-platform detection system and recognition method provided by the present invention; Figure 3 is a flow block diagram of the specific operation steps for the screening and parsing in step S3 provided by the present invention; Figure 4 is a flow block diagram of the specific operation steps for the judgment execution in step S4 provided by the present invention; Figure 5 is a flow block diagram of the specific operation steps for the sequential judgment in step S5 provided by the present invention; Figure 6It is the flowchart block diagram of the specific operation steps for the score judgment in step S6 provided by the present invention; Figure 7 It is the flowchart block diagram of the specific operation steps for the driver installation in step S7 provided by the present invention; Figure 8 It is the flowchart block diagram of the specific operation steps for the file format selection in step S8 provided by the present invention; Figure 9 It is the flowchart block diagram of the specific operation steps for the transmission protocol selection in step S9 provided by the present invention; Figure 10 It is the structural block diagram of the analysis and judgment module provided by the present invention; Figure 11 It is the structural block diagram of the dynamic adjustment module provided by the present invention.
[0078] In the specific implementation process, as Figures 1 - 11 shown, the full-platform detection system and recognition method provided by the present invention include a USB interface module, which is used for device power-on initialization and self-check, and is connected to the terminal interfaces of multiple different operating systems for information interaction;
[0079] An analysis and judgment module, which is used for preliminary instruction screening and execution, and judging the type of operating system according to the instruction operation sequence;
[0080] A dynamic adjustment module, which is used for continuously monitoring instructions, tracking the quality of recognition decisions, and updating the confidence score;
[0081] A driver adaptation module, which is used for preparing the driver program according to the type of operating system initially determined by the analysis and judgment module and the confidence score evaluated by the dynamic adjustment module, and loading the most suitable driver for high-confidence situations;
[0082] A data management module, which is used for automatically selecting the most suitable operating system file format;
[0083] A data interaction module, which is used for automatically selecting the optimal transmission protocol according to the type of operating system judged by the analysis and judgment module;
[0084] A security encryption module, which is used for multi-factor authentication encryption of important data according to the different versions and types of driver programs installed by the driver adaptation module and the different transmission protocols adopted by the data interaction module;
[0085] It should be noted that the security encryption module is a crucial component in the system, aiming to ensure the integrity and confidentiality of important data during transmission. It enhances security by combining multiple authentication factors, not only relying on traditional password verification methods but also introducing additional security layers such as biometrics and hardware tokens. This multi-factor authentication (MFA) mechanism requires users to provide at least two different types of credentials to prove their identity, thus greatly improving the security and reliability of the account. Multi-factor authentication encryption refers to using multiple independent and complementary authentication means to protect the key or sensitive information while performing data encryption. This method can not only prevent unauthorized access but also effectively resist attacks against a single authentication method;
[0086] The analysis and judgment module includes an instruction analysis unit and a system discrimination unit. The instruction analysis unit is used to listen for and capture the first SETUP packet, and at the same time parse and judge the execution instruction for the bRequest field of the first SETUP packet. The system discrimination unit is used to send a detection command and receive feedback according to the order of the instruction names executed by the instruction analysis unit. If the instruction execution order is the same as a specific execution order, otherwise it does not send, and then preliminarily judge which operating system's terminal interface the USB interface module is connected to.
[0087] The dynamic adjustment module includes a monitoring scoring unit and a tracking scoring unit. The monitoring scoring unit is used to listen at any time for the key instructions in various new SETUP packets interacted by the USB interface module or the key instructions in other interaction processes, and give a basic confidence score to the key instructions processed according to the type of operating system judged from the existing data;
[0088] The tracking scoring unit then adds or subtracts the confidence score based on the key instructions processed by the monitoring scoring unit and given a basic confidence score, combined with the key instructions of the same batch or multiple related key instructions and the control transfer instructions set specifically, to generate a comprehensive confidence score, and feedback the comprehensive confidence score to the driver adaptation module.
[0089] The identification method of the full-platform detection system provided in the second aspect of the present invention is applicable to the described full-platform detection system, and includes the following steps:
[0090] S1. Device insertion, insert the USB interface module into the terminal interface of the operating system;
[0091] S2. Power-on self-check, the USB interface module activates the hardware circuit and checks the power status;
[0092] S3. Screening and parsing: Use the instruction analysis unit to monitor and capture the first SETUP packet, and parse the bRequest field in the SETUP packet. At this time, utilize hardware acceleration technology to speed up the parsing process, and quickly identify characteristic instructions with the help of a detailed command library;
[0093] S4. Judgment and execution: Judge whether the key instruction parsed from the bRequest field is a specific key instruction. If so, execute it immediately; otherwise, temporarily store it for subsequent instruction analysis, and record the timestamp of the instruction for subsequent confidence scoring;
[0094] S5. Sequence judgment: Use the system discrimination unit to compare the execution sequence of the key instructions in the judgment and execution of step S4 with the preset special sequence. If they are the same, send a detection command and wait for a reply, and then preliminarily judge the operating system type; otherwise, continue to monitor new instructions;
[0095] S6. Scoring judgment: For each key instruction, first, the monitoring and scoring unit gives a basic confidence score, and then adjusts the comprehensive confidence score according to the tracking and scoring unit in combination with the same batch or multiple related key instructions and specific control transfer instructions;
[0096] S7. Driver installation: Use the driver adaptation module to prepare the most suitable driver program according to the preliminarily determined operating system type and comprehensive confidence score. For high-confidence cases, directly load the driver, and utilize memory mapping technology to accelerate the loading process, but strict signature verification and other necessary security checks must be completed before this;
[0097] S8. Select file format: Use the data management module to reselect the file format according to the operating system type, implement an intelligent caching strategy, preload common files into the cache area, and preferentially convert the common files in the cache area into the selected format, and the remaining internal files are converted in sequence;
[0098] S9. Select transmission protocol: Use the data management module to automatically select the optimal transmission protocol according to the operating system type, sign the protocol, and implement an intelligent retransmission strategy to ensure data integrity, and introduce a higher-level error correction code ECC and content-based verification methods;
[0099] S10. Data encryption: Select an encryption algorithm that conforms to the characteristics of the target operating system according to the characteristics of different operating systems, and set multi-factor authentication and fine-grained permission management to implement end-to-end encryption of sensitive data.
[0100] The specific operation steps of step S3 screening and parsing are as follows:
[0101] S301. Start listening. Once a new device is detected and inserted, immediately start listening for data packets on the USB bus. At this time, the hardware accelerator starts working, filtering out irrelevant traffic and focusing on capturing the first SETUP packet from the host.
[0102] S302. Capture the SETUP packet. When a data frame that meets the expected format is received, immediately save it in its entirety.
[0103] S303. Preliminary parsing. Utilize the auxiliary functions provided by the hardware accelerator to quickly extract the key elements in the SETUP packet, especially the value of the bRequest field, because it directly specifies the specific operation type.
[0104] S304. Find matching items. According to the extracted bRequest value, search for the corresponding entry in the command library. If a perfect match is found, a conclusion can be directly drawn; otherwise, proceed to the next step of in-depth analysis and comparison.
[0105] S305. In-depth analysis. For those commands that do not directly hit but have a certain similarity, further check other relevant fields and make a judgment in combination with the context information.
[0106] S306. Record the timestamp. Append a timestamp to each successfully parsed command, which is very important for subsequent confidence scoring because there may be subtle time interval differences between different operating systems.
[0107] S307. Output and send. Once the operating system type is confirmed, generate a brief report listing the parsing methods used and the basis, and send this report to the analysis and judgment module.
[0108] The specific operation steps for step S4 judgment are as follows:
[0109] S401. Receive and judge the instruction. Receive the brief report sent from step S307, extract the parsed SETUP packet information from the brief report, especially the value of the bRequest field in it, and compare it with the preset key instruction features to determine whether there is a match.
[0110] S402. Execute the instruction. If the key instruction features match the preset instruction features, directly execute the key instruction, such as "Set Address" or "Get Device Descriptor". Conversely, if it is not a key instruction, temporarily store it in a queue for further analysis.
[0111] S403. Sequential feedback: After completing the execution of the instruction in step S402, send the running order of the key instruction to the system discrimination unit, inform that the current instruction has been properly processed, and prepare to receive the next instruction or continue to execute the next step.
[0112] The specific operation steps of the sequential judgment in step S5 are as follows:
[0113] S501. Receive the running order: Receive the running order of the system key instruction sent by the instruction analysis unit;
[0114] S502. Judge the order: Whether it is consistent with the preset special order. For example, if the "SetAddress" operation is executed first and then the "Get Device Descriptor" operation is executed, it is determined to be the iOS system and the Mac OS system; otherwise, it is a non-iOS system and a non-Mac OS system.
[0115] It should be noted that the USB enumeration process on the Apple operating systems iOS and Mac OS is different from that on non-Apple operating systems such as Windows, Android, and Linux. On the Apple operating systems, the "Set Address" operation is executed first and then the "Get Device Descriptor" operation, while on non-Apple operating systems, the "GetDevice Descriptor" operation is executed first and then the "Set Address" operation. By detecting the execution order of these operations, the USB intelligent storage device can determine whether it is inserted into an Apple terminal device or a non-Apple terminal device. Since the usage methods and processes of the USB intelligent storage device for non-Apple terminal devices are relatively consistent, there is no need for additional system platform identification, and the USB intelligent storage device can directly communicate and transfer data with non-Apple terminal devices. Therefore, it is only necessary to judge whether it is the Apple operating systems iOS and Mac OS.
[0116] S503. Send a detection command: If the order judged in step S502 is consistent with the predetermined special order, send a detection command and wait for a reply, and then further judge the iOS system and the Mac OS system;
[0117] It should be noted that for Apple terminal devices, the iOS system and the Mac OS system are further distinguished by the support of communication protocols. For the iOS system, the iAP2 USB communication protocol is supported, while the Mac OS does not support the iAP2 protocol. When the USB intelligent storage device is plugged into the USB port of the Apple terminal device, the USB intelligent storage device sends the Detect detection instruction of iAP2. If the plugged device is an iOS terminal device, a reply message will be received quickly; otherwise, there will be no reply. By this operation, it can be identified whether it is an iOS terminal device or a Mac OS operating system device. This method is applicable to both USB2.0 and below and USB3.0 and above communications.
[0118] The specific operation steps of step S6 scoring judgment are as follows:
[0119] S601. Dynamic adjustment and confirmation. Continuously monitor each new instruction according to the monitoring scoring unit.
[0120] S602. Determine the instruction source. Determine whether each new instruction is a SETUP packet or other key instructions. If so, analyze the bRequest feature; otherwise, continue to monitor.
[0121] S603. Basic scoring. For the analyzed bRequest feature, based on whether the new key instruction itself can corroborate the operating system type determined by the existing step S5 sequence judgment, a basic confidence score is given.
[0122] It should be noted that the basic confidence scoring standard reflects the corroboration strength of the current instruction for a specific operating system type. For example, if the behavior pattern of a certain instruction highly conforms to the expectation of a certain operating system, a higher basic score is given; otherwise, the score is lower. The purpose is to establish a preliminary confidence framework through the individual evaluation of each key instruction as the basis for subsequent comprehensive scoring.
[0123] S604. Dynamic scoring. Use the tracking scoring unit to perform addition or subtraction of confidence scores on the instructions given the basic confidence score, in combination with the same batch or multiple associated key instructions and specific control transfer instructions set, to generate a comprehensive confidence score on the basis of the basic confidence score given by the monitoring scoring unit, and feedback the comprehensive confidence score to the driver adaptation module.
[0124] It should be noted that after the tracking scoring unit takes over the basic confidence score from the monitoring scoring unit, it begins to consider the relationship between this instruction and other instructions in the same batch or multiple related instructions. Here, the "same batch" usually refers to a series of consecutive instructions sent by the same host, and "multiple related" refers to those instructions that are not continuous in time but logically related. Special attention should be paid to some control transfer instructions with special meanings, which can often provide more information about the internal state of the operating system. Based on the above factors, the confidence score is increased or decreased on the original basis to finally form a more comprehensive and accurate comprehensive confidence score. This score will be directly fed back to the driver adaptation module to guide the next action selection and ensure that the final judgment of the operating system type is as accurate as possible.
[0125] The specific operation steps of step S7 for driver installation are as follows:
[0126] S701. Receive the confidence score, and receive the comprehensive confidence score sent by the tracking scoring unit;
[0127] S702. Make a comprehensive judgment, and comprehensively judge the type of the operating system according to the basic type judged by the analysis and judgment module and the comprehensive confidence score sent by the tracking scoring unit;
[0128] S703. Install the driver. According to the type of the operating system obtained by the comprehensive judgment in step S702, install the corresponding matching driver, and at the same time use the memory mapping technology to accelerate the loading process;
[0129] It should be noted that the driver adaptation module is responsible for loading the prepared driver program into the operating system, and this process varies depending on the operating system:
[0130] For example: Windows, use the standard driver installation API (such as SetupAPI) to register the driver service. If it is a user-mode driver, it can be directly loaded by the application by calling the relevant interface. For kernel-mode drivers, usually the computer needs to be restarted to make the changes take effect;
[0131] For example: Linux, compile it into a dynamically loadable module (.ko file), and then use the insmod or modprobe command to insert it into the kernel space. The kernel module can be statically compiled into the kernel through macro definitions and automatically loaded at system startup to ensure the correct loading order because some basic modules need to be loaded before other modules.
[0132] Meanwhile, considering the differences between different operating systems, the driver adaptation module must have cross-platform capabilities, which means it not only has to understand the driver models on various platforms but also be able to handle their respective characteristics and limitations. By leveraging machine learning techniques, the system can learn from past experiences and gradually optimize its understanding of the characteristics of various operating systems. When encountering new situations that have not been seen before but have similar characteristics, the system can make reasonable inferences based on the existing knowledge base. Anomaly detection algorithms are introduced to monitor for unconventional behavior patterns. These algorithms can help identify combinations of instructions or parameter settings that deviate from the normal operation process, indicating the possible existence of different operating system types.
[0133] In a specific embodiment, the process of the anomaly detection algorithm is as follows:
[0134] Step 1: Data collection and preprocessing:
[0135] Log recording: Comprehensively record all activities related to device communication, including but not limited to received data packets, executed commands, and generated response results. These logs will serve as the basic materials for subsequent analysis.
[0136] Feature extraction: Extract valuable feature vectors from the original logs, including instruction frequencies, parameter ranges, and execution orders. These features will be used to describe the unique nature of each event and be passed as inputs to the subsequent analysis steps.
[0137] Step 2: Model training and selection:
[0138] Offline training: Use a labeled historical dataset to train multiple machine learning models, such as decision trees, random forests, and support vector machines, to find the best model suitable for the current task.
[0139] Online fine-tuning: As new data continuously flows in, gradually fine-tune the model parameters to make it more in line with the actual situation. At the same time, maintain a certain degree of flexibility to allow the model to make appropriate adjustments when encountering special situations.
[0140] Step 3: Real-time monitoring and warning:
[0141] Threshold setting: Based on the output probability distribution of the trained model, reasonably set the alarm threshold. When the occurrence probability of an event is lower than the set threshold, it is considered a potential abnormal event.
[0142] Contextual correlation analysis: Not only focus on individual isolated events but also conduct a comprehensive evaluation by combining other relevant activities within a certain period before and after. For example, the continuous occurrence of multiple low-probability events may indicate a certain regular abnormal behavior.
[0143] Immediate Response: Once an abnormal situation is detected, an alarm is immediately triggered and notifications are sent to relevant personnel. Meanwhile, further actions can be taken according to specific circumstances, such as pausing the current operation, requiring the user to verify their identity, or initiating a more in-depth security inspection process;
[0144] Step Four, Post-processing and Learning:
[0145] Cause Investigation: For each event marked as abnormal, a detailed cause investigation is required to identify the root cause and record it, which is very helpful for enriching the knowledge base and improving future detection accuracy;
[0146] Model Iterative Update: Regularly review the entire anomaly detection process, summarize experiences and lessons, and perform necessary iterative updates on the model to ensure that it always maintains good detection performance.
[0147] The specific operation steps for Step S8 to select the file format are as follows:
[0148] S801. Select the file format, and use the data management module to re-select the file format according to the operating system type comprehensively judged in Step S702, such as NTFS file format, exFAT file format, or HFS+ file format;
[0149] S802. File Reloading, implement an intelligent caching strategy for the files stored internally, pre-load commonly used files into the buffer area, and preferentially convert the commonly used files in the buffer area according to the re-selected file format for standby, and the remaining internal files are converted in sequence.
[0150] The specific operation steps for Step S9 to select the transmission protocol are as follows:
[0151] S901. Operating System Type Identification, evaluate the most commonly used transmission protocol in the operating system environment based on the information such as the type and version number of the currently running operating system obtained by comprehensive judgment in Step S702;
[0152] S902. Automatically Select the Transmission Protocol, use the data interaction module to find the best transmission protocol configuration solution suitable for the current environment to maintain optimal performance;
[0153] S903. Sign the Agreement, the communication parties complete the process of generating and exchanging security keys, clarify the service quality commitments of both parties regarding data transmission rate, latency, packet loss rate, etc., and provide a basis for solving possible problems;
[0154] S904. Introduce an advanced verification method, add extra redundant information during the data packaging stage, so that even if some data is lost, the original content can be restored through calculation. Before sending the data, use the strong hash function SHA-256 to calculate the digest value of the data to be transmitted, and send it to the receiving party together with the data. After the receiving end receives the data, recalculate the hash value independently to confirm that the data transmission is error-free;
[0155] In a specific embodiment, the introduced advanced verification method is to apply ECC encoding, add extra redundant information during the data packaging stage, so that even if some data is lost, the original content can be restored through calculation. This method is particularly suitable for application scenarios with extremely high requirements for data accuracy;
[0156] At the same time, use the strong hash function SHA-256 to calculate the digest value of the data to be transmitted, and send it to the receiving party together with the data;
[0157] After the receiving end receives the data, recalculate the hash value independently and compare it with the received digest. If the two are consistent, it means that the data transmission is error-free. Otherwise, prompt that there is an error and trigger the corresponding error correction process.
[0158] The above are only embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structural or equivalent process transformation made using the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be similarly included in the patent protection scope of the present invention.
Claims
1. Full-platform detection system, characterized in that, Including: A USB interface module, which is used for power-on initialization and self-check of the device, and is connected to the terminal interfaces of multiple different operating systems for information interaction; An analysis and judgment module, which is used for preliminary instruction screening and execution, and judging the type of operating system according to the instruction operation sequence; A dynamic adjustment module, which is used for continuously monitoring instructions, tracking and identifying the quality of decisions, and updating the confidence score; A driver adaptation module, which is used for preparing driver programs according to the type of operating system preliminarily determined by the analysis and judgment module and the confidence score evaluated by the dynamic adjustment module, and loading the most matching driver for high-confidence situations; A data management module, which is used for automatically selecting the most suitable operating system file format; A data interaction module, which is used for automatically selecting the optimal transmission protocol according to the type of operating system judged by the analysis and judgment module; A security encryption module, which is used for multi-factor authentication encryption of important data according to different versions and types of driver programs installed by the driver adaptation module and different transmission protocols adopted by the data interaction module; The analysis and judgment module includes an instruction analysis unit and a system discrimination unit. The instruction analysis unit is used for listening and capturing the first SETUP packet, and at the same time parsing and judging the execution instruction of the bRequest field of the first SETUP packet. The system discrimination unit is used for according to the instruction name sequence executed by the instruction analysis unit, if the instruction execution sequence is the same as a specific execution sequence, sending a detection command and receiving feedback, otherwise not sending, and then preliminarily judging which operating system's terminal interface the USB interface module is connected to.
2. The full-platform detection system according to claim 1, wherein The dynamic adjustment module includes a monitoring score unit and a tracking score unit. The monitoring score unit is used for listening at any time to the key instructions in various new SETUP packets interacted by the USB interface module or the key instructions in other interaction processes, and giving a basic confidence score to the key instructions processed according to the type of operating system judged from the existing data; The tracking score unit then adds or subtracts the confidence score on the basis of the basic confidence score given by the monitoring score unit according to the key instructions processed by the monitoring score unit and given a basic confidence score, combined with the same batch or multiple associated key instructions and specific control transmission instructions set, so as to generate a comprehensive confidence score, and feedback the comprehensive confidence score to the driver adaptation module.
3. Identification method of the full-platform detection system, applicable to the full-platform detection system described in claim 2, characterized in that, The method includes the following steps: S1. Device insertion, inserting the USB interface module into the terminal interface of the operating system; S2. Power-on self-check, the USB interface module activates the hardware circuit and checks the power status; S3. Screening and parsing, using the instruction analysis unit to listen and capture the first SETUP packet, and parsing the bRequest field in the SETUP packet. At this time, the hardware acceleration technology is used to speed up the parsing process, and the detailed command library is used to quickly identify the characteristic instructions; S4. Judgment Execution: Determine whether the key instruction parsed from the bRequest field is a specific key instruction. If so, execute it immediately; otherwise, temporarily store it for subsequent instruction analysis, and record the timestamp of the instruction for subsequent confidence scoring; S5. Sequential Judgment: Use the unit discriminated by the system to compare the execution sequence of the key instructions in the judgment execution of step S4 with the preset special sequence. If they are the same, send a detection command and wait for a reply, and then preliminarily determine the operating system type. Otherwise, continue to listen for new instructions; S6. Scoring Judgment: For each key instruction, first, the monitoring and scoring unit gives a basic confidence score, and then adjusts the comprehensive confidence score according to the key instructions of the same batch or multiple associations and the specifically set control transfer instructions by the tracking and scoring unit; S7. Driver Installation: Use the driver adaptation module to prepare the most suitable driver according to the preliminarily determined operating system type and comprehensive confidence score. For high-confidence cases, directly load the driver and use memory mapping technology to accelerate the loading process, but strict signature verification and other necessary security checks must be completed before that; S8. Select File Format: Use the data management module to reselect the file format according to the operating system type, implement an intelligent caching strategy, preload common files into the buffer, and preferentially convert the common files in the buffer into the selected format, and the remaining internal files are converted in sequence; S9. Select Transmission Protocol: Use the data management module to automatically select the optimal transmission protocol according to the operating system type, sign the protocol, and implement an intelligent retransmission strategy to ensure data integrity, and introduce a higher-level error correction code ECC and content-based verification methods; S10. Data Encryption: Select an encryption algorithm that conforms to the characteristics of the target operating system according to the characteristics of different operating systems, and set multi-factor authentication and fine-grained permission management to implement end-to-end encryption of sensitive data.
4. The recognition method of the full-platform detection system according to claim 3, characterized in that, The specific operation steps for screening and parsing in step S3 are as follows: S301. Start Listening: Once a new device is detected and inserted, immediately start listening for data packets on the USB bus. At this time, the hardware accelerator starts working, filters out irrelevant traffic, and focuses on capturing the first SETUP packet from the host; S302. Capture SETUP Packet: When a data frame that meets the expected format is received, immediately save it completely; S303. Preliminary Parsing: Use the auxiliary functions provided by the hardware accelerator to quickly extract the key elements in the SETUP packet; S304. Find Matching Items: According to the extracted bRequest value, search for the corresponding entry in the command library. If a complete match is found, a conclusion can be directly drawn; otherwise, proceed to the next step of in-depth analysis and comparison; S305. In-depth Analysis: For those commands that do not directly hit but have a certain similarity, further check other relevant fields and make a judgment in combination with the context information; S306. Record Timestamp: Append a timestamp to each successfully parsed command; S307. Output and send. Once the operating system type is confirmed, generate a brief report listing the parsing methods used and the basis, and send this report to the analysis and judgment module.
5. The recognition method of the full-platform detection system according to claim 4, wherein The specific operation steps of step S4 judgment are as follows: S401. Receive and judge the instruction. Receive the brief report sent from step S307, extract the parsed SETUP packet information from the brief report, especially the value of the bRequest field, and compare it with the preset key instruction features to determine whether they match. S402. Execute the instruction. If the key instruction features match the preset instruction features, directly execute the key instruction. Otherwise, if it is not a key instruction, temporarily store it in a queue and wait for further analysis. S403. Sequential feedback. After completing the execution of the instruction in step S402, send the running order of the key instruction to the system discrimination unit, inform that the current instruction has been properly processed, and be ready to receive the next instruction or continue to execute the next step.
6. The recognition method of the full-platform detection system according to claim 5, characterized in that, The specific operation steps of step S5 sequential judgment are as follows: S501. Receive the running order. Receive the running order of the key instruction sent by the instruction analysis unit. S502. Judge the order. Determine whether it is consistent with the preset special order. If it is consistent with the special arrangement order, it is determined to be an iOS system and a Mac OS system. Otherwise, it is a non-iOS system and a non-Mac OS system. S503. Send a detection command. If the order judged in step S502 is consistent with the predetermined special order, send a detection command and wait for a reply, and then further judge the iOS system and the Mac OS system.
7. The recognition method of the full-platform detection system according to claim 6, characterized in that The specific operation steps of step S6 scoring judgment are as follows: S601. Dynamic adjustment and confirmation. Continuously monitor each new instruction according to the monitoring scoring unit. S602. Judge the instruction source. Judge whether each new instruction is a SETUP packet or other key instruction. If so, analyze the bRequest feature. Otherwise, continue to monitor. S603. Basic scoring. For the analyzed bRequest feature, perform a basic confidence scoring according to whether the new key instruction itself can corroborate the operating system type determined by the existing step S5 sequential judgment. S604. Dynamic scoring. Use the tracking scoring unit to perform addition or subtraction of confidence scoring on the instruction given the basic confidence scoring, in combination with the same batch or multiple associated key instructions and specific control transfer instructions set, based on the basic confidence scoring given by the monitoring scoring unit, to generate a comprehensive confidence scoring and feedback the comprehensive confidence scoring to the driver adaptation module.
8. The recognition method of the full-platform detection system according to claim 7, characterized in that, The specific operation steps of step S7 driver installation are as follows: S701. Receive the confidence scoring. Receive the comprehensive confidence scoring sent by the tracking scoring unit. S702. Comprehensive judgment. Make a comprehensive judgment on the type of the operating system according to the basic type judged by the analysis and judgment module and the comprehensive confidence scoring sent by the tracking scoring unit. S703. Install the driver. Based on the type of operating system comprehensively judged according to the steps in S702, install the corresponding and matching driver, and at the same time use the memory mapping technology to accelerate the loading process.
9. The recognition method of the full-platform detection system according to claim 8, characterized in that The specific operation steps for selecting the file format in step S8 are as follows: S801. Select the file format. Use the data management module to reselect the file format according to the type of operating system comprehensively judged according to the steps in S702. S802. Reload the file. Implement an intelligent caching strategy for the files stored internally, preload the frequently used files into the buffer area, and preferentially convert the frequently used files in the buffer area according to the reselected file format for standby use, and the remaining internal files are converted in sequence.
10. The recognition method of the full-platform detection system according to claim 9, characterized in that, The specific operation steps for selecting the transmission protocol in step S9 are as follows: S901. Identify the operating system type. Based on the type and version number information of the currently running operating system obtained by comprehensive judgment according to step S702, evaluate the most frequently used transmission protocol in this operating system environment. S902. Automatically select the transmission protocol. Use the data interaction module to find the best transmission protocol configuration scheme that suits the current environment to maintain the optimal performance. S903. Sign the agreement. The two communication parties complete the process of generating and exchanging security keys, and clarify the service quality commitments of both parties regarding data transmission rate, latency, and packet loss rate. S904. Introduce an advanced verification method. Add additional redundant information during the data packaging stage so that even if some data is lost, the original content can be restored through calculation. Before the data is sent, use a strong hash function to calculate the digest value of the data to be transmitted and send it to the receiving party together with the data. After the receiving end receives the data, recalculate the hash value independently to confirm that the data transmission is correct.
Citation Information
Patent Citations
Software testing system and testing method
CN101042673A
Method for testing peripheral component interconnect bus level pressure
CN101354667A