A security guard USB hub for storage device and authorization method

By using whitelist management and asymmetric encryption/decryption technology to securely protect USB hubs, the security and compatibility issues of USB hubs are resolved. This enables access control and authentication of connected devices, ensuring data security and simplifying management processes.

CN119646904BActive Publication Date: 2025-11-21WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411601067.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-11
Publication Date
2025-11-21
Estimated Expiration
2044-11-11

AI Technical Summary

Technical Problem

Existing USB hubs lack effective security management and access control, making them easy to connect to unauthorized devices, leading to computer attacks and data leaks. Furthermore, they suffer from serious compatibility issues with different operating systems, and the management software is complex and difficult to use.

Method used

A secure USB hub is adopted, and whitelist management is implemented through the main control module and management software. Asymmetric encryption and decryption and hash operation are used to configure permissions and authenticate the identity of access devices, ensuring the security of CRC check of device descriptors and signature of whitelist.

Benefits of technology

It improves the security and system scalability of USB storage devices, avoids compatibility issues, simplifies management processes, enhances the security and ease of use of whitelists, and prevents unauthorized devices from accessing the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119646904B_ABST
    Figure CN119646904B_ABST
Patent Text Reader

Abstract

The application discloses a security protection USB hub for a storage device and an authorization method, relates to the field of data transmission security, and discloses the USB hub, which comprises a USB hub body for connecting a plurality of USB storage devices; a security protection system comprising a master control module for authorizing and authenticating management software, obtaining a white list, and receiving a configuration instruction sent by the management software to configure the access right of the USB storage device; a storage module for storing device descriptor information and right configuration information of the USB storage device; an operation module for performing hash operation and signature on the white list; and management software for white list management of the USB hub, right setting of the USB storage device and generation of a configuration instruction. The application can realize one-to-one or one-to-many right authentication between the USB hub and the USB storage device, improve the security of the USB storage device access, and guarantee the information security of the host.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of security authentication, and more particularly to a security protection USB hub for storage device and an authorization method. BACKGROUND

[0002] A USB hub, in common parlance, is a device used to expand the number of USB ports and to manage them intensively within a certain distance. More USB connection ports can be expanded through a USB hub. A USB hub is divided into two types: a wired USB hub and a wireless USB hub. The wired USB hub refers to a hub with USB interface, which can be directly plugged into the USB port of a computer, while the wireless USB hub is connected with a terminal device through a USB data line.

[0003] At present, the most commonly used USB hub in the market is the wired USB hub. This hub is plugged into the USB port of the client through the USB interface to expand the USB port. The hub itself does not have a management function, and any USB device can be mounted on the computer through the USB interface. The existing technical solutions are as follows: the first solution is the protection at the operating system level, such as installing security software, firewall, etc. on the computer. The administrator can configure the operating system or the security software to allow only specific VID and PID devices to connect, and other devices not in the white list will be denied access. The operating system can also require the driver program of the USB device to be signed and verified to ensure that only trusted devices are allowed to connect. If an unsigned or mismatched device is found, the operating system can prevent the device from loading. The second solution is the protection at the firmware level. The data storage device uses a write-protected area or a hardware security module (HSM) to prevent tampering with the VID and PID in the firmware. Some storage devices also encrypt the firmware.

[0004] However, these existing technologies have the following problems: a. Security problem: First, the access permission of the security software is generally protected by a simple password, which is easy to crack. After cracking, the white list can be tampered with at will. Although the firmware of the data storage device has some anti-tampering measures, it can be easily read and copied

[0005] b. Compatibility problem: The security software relies on the computer operating system for permission control. Different operating systems may have different security policies and permission control mechanisms, which may cause system compatibility problems. Different storage device manufacturers have different protection methods for firmware, and the computer cannot verify or decrypt them.

[0006] In addition, since the interface of the USB hub is a USB male head, the current USB hub can be used unlimited times, and multiple USB hubs can be connected to the same USB port of the computer (if supported), so that the devices connected to the USB hub still have the following problems:

[0007] 1) Lack of management, easy to connect to illegal or unsafe USB storage devices, causing the risk of computer attack or data theft, such as malicious U disk, fake U disk, phishing U disk, U disk with virus or Trojan program, and removable disk;

[0008] 2) Lack of permission restriction, illegal access to the computer through the USB hub device, bypassing the security monitoring, thereby unauthorized access to data, such as copying important data through the USB hub storage device, causing serious consequences of security data leakage.

[0009] 3) The current USB hub is prevented by the device white list of the device manufacturer, and the white list management uses the black list technology managed by the computer, which can filter part of the virus and malicious attack at a certain level, but the security protection capability is still weak.

[0010] 4) The management software of the USB hub is complex to use, and each hub needs to be logged in by the user and needs to be configured and maintained separately. SUMMARY

[0011] In view of at least one defect or improvement demand of the prior art, the present application provides a secure USB hub for storage devices and an authorization method, which realizes the security of the hub through encrypted communication between the USB hub and the upper computer.

[0012] To achieve the above-mentioned purpose, according to the first aspect of the present application, a secure USB hub for storage devices is provided, comprising: a USB hub body and a security protection system, the USB hub body is used for connecting multiple USB storage devices; the security protection system comprises: a master control module, which is used for authorizing and authenticating the management software, and receiving the configuration instruction sent by the management software to configure the access USB storage device with permission, and obtaining a white list;

[0013] a storage module for storing device descriptor information and permission configuration information of the USB storage device; wherein the permission configuration information includes white list information and CRC value calculated when each storage device is authorized;

[0014] an operation module for performing hash operation and signature on the white list;

[0015] The management software is applied to an upper computer connected with the USB hub body, and is used for whitelist management of the USB hub and permission setting of the USB storage device and generation of configuration instructions.

[0016] Optionally, the user software is further included, applied to the upper computer connected with the USB hub body, and used for management of the storage device connected with the USB hub; the user software accesses the USB hub through the USB bus, and the user software is the permission software after successful authorization authentication.

[0017] Optionally, the operation module comprises:

[0018] a hash operation unit, configured to perform hash operation on the whitelist hash value, the device descriptor information and the identity information;

[0019] a signature unit, configured to perform signature on the hash value, perform signature on the whitelist hash value using the asymmetric encryption and decryption private key of the asymmetric encryption and decryption certificate, and generate a signature value.

[0020] Optionally, the whitelist management comprises:

[0021] whitelist initialization:

[0022] The USB hub is connected with the USB storage device, the host control module is connected with the first USB storage device, and the connection with the first USB storage device is established;

[0023] In the case that the first USB storage device passes the signature verification, the host control module enumerates the descriptors of all endpoints of the first USB storage device for verification, obtains a first CRC value, and adds the first USB storage device to the whitelist based on the first CRC value;

[0024] The operation module performs hash value calculation based on the whitelist, uses the signature verification private key to perform signature on the whitelist hash value to obtain a signature value, and stores the whitelist hash value and the signature value in the storage module;

[0025] Optionally, the whitelist management further comprises:

[0026] whitelist addition, deletion and modification:

[0027] The USB hub is connected with the second USB storage device, the host control module is connected with the second USB storage device, and the connection with the second USB storage device is established; in the case that the second USB storage device passes the signature verification, the descriptors of all endpoints of the second USB storage device are enumerated for verification, a second CRC value is obtained, and the whitelist is added, deleted or modified based on the second CRC value.

[0028] Optionally, the whitelist management further comprises:

[0029] White list export: the USB hub connects the third USB storage device, the storage module connects the third USB storage device, and a connection with the third USB storage device is established; in the case that the third USB storage device is successfully verified, the storage module exports the white list;

[0030] White list import: the USB hub connects the fourth USB storage device, and the operation module connects the fourth USB storage device; in the case that the fourth USB storage device is successfully verified, the operation module calculates the white list hash value based on the white list hash value, calculates a signature value based on the white list hash value, and writes the signature value and the hash value of the fourth USB storage device to the storage module.

[0031] Optionally, before the management software performs white list initialization, the method further comprises:

[0032] verifying the white list signature value of the first USB storage device, and if the signature value is correct, performing white list initialization, and if the verification fails, not performing white list initialization.

[0033] According to a second aspect of the present application, a method for authorizing a secure protection USB hub for a storage device is also provided, which is used for authorizing the USB hub described in any of the above, and the method comprises:

[0034] The USB hub sends a signature verification certificate and an asymmetric encryption and decryption certificate to the management software, and receives a hash value ciphertext fed back by the management software;

[0035] The USB hub decrypts the hash value ciphertext and signs the hash value based on the signature verification certificate to the har , obtains a signature value of the hash value and sends it to the management software;

[0036] The management software verifies the signature value based on a signature verification public key in the signature verification certificate and compares the hash value, generates a first verification result and sends it to the USB hub; the first verification result is used to confirm the identity of the USB storage device accessed by the USB hub;

[0037] The USB hub reads a corresponding white list signature value based on the first verification result and sends it to the management software;

[0038] The management software verifies the white list signature value based on the signature verification public key in the signature verification certificate, generates a second verification result and sends it to the USB hub, and the second verification result is used to determine the authorization result of the USB hub.

[0039] Optionally, before the USB hub sends the signature verification certificate and the asymmetric encryption and decryption certificate to the management software and receives the hash ciphertext fed back by the management software, the USB hub comprises the following steps:

[0040] The USB hub generates a pair of public and private keys, and applies for a digital certificate from a certificate authority to obtain a signature verification certificate and an asymmetric encryption and decryption certificate.

[0041] Optionally, the step of obtaining the hash ciphertext comprises the following steps:

[0042] The management software receives the signature verification certificate and the asymmetric encryption and decryption certificate.

[0043] The management software generates a random number and calculates the hash value of the random number.

[0044] The management software encrypts the hash value based on the asymmetric encryption and decryption public key in the asymmetric encryption and decryption certificate to obtain the hash ciphertext.

[0045] Overall, compared with the prior art, the above technical solutions conceived by the present application can achieve the following beneficial effects:

[0046] (1) The present application provides a secure protection USB hub for storage devices. By implementing white list management in the management software, the host module limits the access rights of the USB storage devices according to the configuration instructions sent by the management software, thereby ensuring the security of the data in the USB storage devices. The USB hub and the management software use asymmetric encryption and decryption means and a secure authentication communication protocol to ensure the security of the data between the management software and the USB hub. At the same time, the USB hub verifies the identity information of the descriptors by CRC value, the computer management software must be authenticated by the USB hub before use, and the white list is signed to prevent tampering. The CRC of all descriptors of each USB storage device is calculated and added to the white list to prevent tampering of the device firmware information, thereby improving the authentication security. By maintaining the white list in the USB hub, the permission control is not dependent on the computer operating system, thereby avoiding compatibility problems. In addition, the present application can connect more USB devices through the expansion interface, thereby improving the expansibility and flexibility of the system.

[0047] (2) The computer user does not need to set the permission of each USB device, only the administrator configures the USB hub through the management software, and the multi-USB hub batch management can be realized through import and export, and then the user of the user software can use it, which improves the usability and maintainability of the system. In addition, the white list management is realized by using the white list signature algorithm and the hash value, the white list is encrypted and communicated and verified through the security authentication protocol, and the security of the white list is ensured. In addition, through the white list management, the unauthorized storage device is intercepted, and the CRC value of the enumerated device is checked through the identity recognition technology, so that the storage device is ensured to be a trusted device. BRIEF DESCRIPTION OF DRAWINGS

[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0049] Figure 1 An optional structure schematic diagram of the security protection USB hub for the storage device provided by the embodiments of the present application is provided.

[0050] Figure 2 An optional route schematic diagram of the authorization method of the security protection USB hub for the storage device provided by the embodiments of the present application is provided.

[0051] Figure 3 An optional route schematic diagram of the authorization method of the security protection USB hub for the storage device provided by the embodiments of the present application is provided. DETAILED DESCRIPTION

[0052] In order to make the purpose, technical solutions and advantages of the present application more clear, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application. In addition, the technical features involved in each embodiment of the present application described below can be combined with each other as long as there is no conflict.

[0053] The terms "first", "second", "third", etc. in the specification and claims of the present application and in the above drawings are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units not listed, or can optionally include other steps or units inherent to the process, method, product or device.

[0054] According to an aspect of the embodiments of the present application, a secure USB hub for storage devices is provided. The following describes the secure USB hub for storage devices provided by the embodiments of the present application in combination with Figure 1 The secure USB hub for storage devices provided by the embodiments of the present application is described.

[0055] Figure 1 is a structural schematic diagram of an optional secure USB hub for storage devices provided by the embodiments of the present application, which includes a USB hub body for connecting a plurality of USB storage devices.

[0056] The USB hub body includes a USB hub, a USB interface, USB power supply, a reset button, etc., to realize the hardware function of the USB hub security protection system. The USB hub body can be made of ABS plastic. One USB connecting line is used to connect a computer and power supply, and a plurality of USB interfaces are provided for connecting different USB devices.

[0057] The security protection system provided in the USB hub includes a master control module for authorizing and authenticating the management software, receiving a configuration instruction sent by the management software to configure the access USB storage device, and obtaining a white list. A storage module is used to store the device descriptor information and the permission configuration information of the USB storage device. An operation module is used to perform hash operation and signature on the white list.

[0058] The management software is applied to an upper computer connected with the USB hub body, and is used to manage the white list of the USB hub and set the permission of the USB storage device and generate a configuration instruction.

[0059] In the embodiment, the control module is used for centralized management of the USB hub, including initiating an identity authentication process to the management software or user, accepting instructions and responses of the software, reading USB storage device descriptors, controlling access rights of the USB storage device to the host, etc. The operation module is used for calling various operation modes by the user, including hash value operation, CRC operation, signature verification and asymmetric encryption and decryption operation. The storage module is used for storing a white list and signature value, and can be read and written by the master control module.

[0060] The management software is installed on an administrator computer, and is mainly used for identity authentication of the USB hub and configuration of the USB hub, including initialization, addition, deletion, modification, import and export of the white list.

[0061] The USB hub communicates with the PC end through the USB interface, and the security protection system of the USB hub identifies and authorizes the USB storage device, so that security protection is realized.

[0062] In a preferred embodiment, the security protection USB hub for storage devices further comprises user software applied to an upper computer connected with the main body of the USB hub, and used for managing the storage devices connected with the USB hub. The user software accesses the USB hub through the USB bus, and the user software is a permitted software after successful authorization authentication.

[0063] Specifically, the user uses the USB hub by installing the user software on the user computer, connecting the USB hub, authenticating the identity of the USB hub, connecting the storage device using the USB hub, and then the rights of the storage device are controlled by the USB hub.

[0064] In a preferred embodiment, the operation module comprises:

[0065] A hash operation unit is used for performing hash operation on the white list hash value, device descriptor information and identity information.

[0066] A signature unit is used for signing the hash value, using the asymmetric encryption and decryption private key of the asymmetric encryption and decryption certificate to sign the white list hash value, and generating a signature value.

[0067] Figure 2 An optional authorization method for a security protection USB hub for storage devices provided by the embodiment of the application is shown in one of the flowcharts, as shown in the figure, the embodiment of the application provides an authorization method for a security protection USB hub for storage devices, and the authorization method comprises: Figure 2

[0068] ​S1, the USB hub sends a signature verification certificate and an asymmetric encryption and decryption certificate to the management software, and receives a hash value ciphertext fed back by the management software.

[0069] The USB hub generates a pair of public and private keys, applies for a digital certificate from a certificate authority, and obtains a signature verification certificate and an asymmetric encryption and decryption certificate, wherein the public key is used as a signature verification public key, and the private key is used as a signature verification private key.

[0070] The obtaining of the hash value ciphertext comprises the following steps:

[0071] S11, the USB hub receives the signature verification certificate and the asymmetric encryption and decryption certificate.

[0072] S12, the management software receives the signature verification certificate and the asymmetric encryption and decryption certificate.

[0073] S13, the management software generates a random number and calculates a hash value of the random number.

[0074] S14, the hash value is encrypted based on the public key in the asymmetric encryption and decryption certificate, and a hash value ciphertext is obtained.

[0075] S2, the USB hub decrypts the hash value ciphertext and signs the hash value based on the signature verification certificate, obtains a signature value of the hash value, and sends the signature value to the management software.

[0076] S3, the management software verifies the signature value based on the signature verification public key in the signature verification certificate, compares the hash value, generates a first verification result, and sends the first verification result to the USB hub, wherein the first verification result is used to confirm the identity of the USB storage device accessed by the USB hub.

[0077] S4, the USB hub reads a corresponding whitelist signature value based on the first verification result, and sends the whitelist signature value to the management software.

[0078] S5, the management software verifies the whitelist signature value based on the signature verification public key in the signature verification certificate, generates a second verification result, and sends the second verification result to the USB hub, wherein the second verification result is used to determine the authorization result of the USB hub.

[0079] Before S1, S0 is further included, wherein the host module initializes the USB hub accessed, calculates a check code of a device descriptor, and compares the check code with a check code stored in a storage module, if the check codes are the same, the USB hub is initialized, and if the check codes are different, a failure is reported.

[0080] S1 specifically comprises: the USB hub is connected with the host computer through the USB bus, and sends a signature verification certificate and an asymmetric encryption and decryption certificate to the host computer, the signature verification certificate is a signature verification public key, and if the host computer is not verified, the white list initialization is ended.

[0081] S2 specifically comprises: the host computer receives the signature verification certificate and the asymmetric encryption and decryption certificate, and extracts the signature verification public key in the signature verification certificate; the USB hub reads the stored CRC code of the device descriptor from the storage module, calculates the check code of the device descriptor, and then sends the calculated check code of the device descriptor and the read value of the stored check code of the device descriptor to the host computer, and the host computer compares them. If the values are the same, the hash value of the random number is calculated; if the values are different, the failure is reported.

[0082] S3 specifically comprises: the host computer sends the calculated hash value ciphertext and the verification message to the USB hub, the USB hub performs hash operation on the random number based on the verification message; and compares the hash value with the value in the storage module. If they are inconsistent, the failure is reported. If they are consistent, the hash value is signed and verified using the private key in the asymmetric encryption and decryption certificate, and then sent to the host computer. At the same time, the hash value authentication success is reported.

[0083] S4 specifically comprises: the USB hub sends the white list and the signature message of the white list to the host computer, and reports the white list authentication success.

[0084] S5 specifically comprises: the host computer extracts the white list signature value information according to the signature message of the white list, and obtains the signature verification public key from the signature verification certificate for verification; if the value is correct, the white list authorization success is displayed, and if the value is incorrect, the white list authorization failure is displayed.

[0085] Preferably, the white list management process comprises:

[0086] The management software realizes the white list management, can read the white list, calculate the white list hash value, perform HASH operation on the new device white list, calculate the CRC value, write the white list HASH value into the storage module, calculate the signature value, realize the white list initialization, and realize the white list adding, deleting and modifying, white list importing and white list exporting.

[0087] In a preferred embodiment, Figure 3 An optional authorization method for a security protection USB hub for storage devices provided by the embodiment of the application is shown in FIG. 2. When the USB hub is connected to the administrator computer or the user computer, the USB hub first sends an identity authentication application to the management software or the user software, and can be configured or used only after the authentication is successful. The specific steps of the identity authentication are shown in FIG. 2. Figure 3 ​

[0088] ①USB hub generates a signature verification public-private key pair and an asymmetric encryption-decryption public-private key pair, and applies for a digital certificate to a trusted certificate authority (CA). The CA verifies the identity of the applicant, and then signs the signature verification public key and the asymmetric encryption-decryption public key of the applicant using the private key of the CA, to generate a signature verification certificate and an asymmetric encryption-decryption certificate. The certificate contains the public key, identity information, certificate validity period, issuer information, and the like of the applicant.

[0089] ②The computer connects the USB hub, and the USB hub sends an identity authentication request to the management software or user software, accompanying its two digital certificates. At this time, the identity information of the USB hub is transmitted to the server through the certificate.

[0090] The management software verifies the validity of the USB hub certificate using a trusted CA list, including checking the signature, certificate chain, validity period, and the like of the certificate.

[0091] ③The management software or user software generates a random number, calculates the hash value of the random number, encrypts the hash value using the asymmetric encryption-decryption public key in the asymmetric encryption-decryption certificate of the USB hub, and sends the ciphertext to the USB hub.

[0092] ④The USB hub decrypts the hash value using the asymmetric encryption-decryption private key, signs the hash value using the signature verification private key, and sends the signature value to the management software or user software.

[0093] ⑤The management software or user software verifies the signature using the signature verification public key in the signature verification certificate, and after successful verification, compares the hash value of the random number, and if the comparison is successful, the identity of the USB hub is confirmed.

[0094] The management software or user software reads the white list signature value, verifies the signature, and after successful verification, can trust the content stored by the USB hub.

[0095] White list management includes white list initialization:

[0096] The USB hub connects the USB storage device, the master control module connects the first USB storage device, and establishes a connection with the first USB storage device. In the case that the first USB storage device is successfully verified, the master control module enumerates the descriptors of all endpoints of the first USB storage device for verification, obtains a first CRC value, and based on the first CRC value, adds the first USB storage device to the white list. The operation module calculates the white list hash value based on the white list, signs the white list hash value using the signature verification private key, and stores the white list hash value and the signature value in the storage module.

[0097] Further, it also includes white list addition, deletion, and modification:

[0098] The USB hub connects the second USB storage device, the master control module connects the second USB storage device, and the connection of the second USB storage device is established; in the case that the second USB storage device is successfully verified, descriptors of all endpoints of the second USB storage device are enumerated for checking, a second CRC value is obtained, and the white list is added, deleted or modified based on the second CRC value.

[0099] Further, the white list export is further included:

[0100] The USB hub connects the third USB storage device, the storage module connects the third USB storage device, and the connection of the third USB storage device is established; in the case that the third USB storage device is successfully verified, the storage module exports the white list.

[0101] Further, the white list import is further included:

[0102] The USB hub connects the fourth USB storage device, and the operation module connects the fourth USB storage device; in the case that the fourth USB storage device is successfully verified, the operation module calculates the white list hash value, calculates the signature value, and writes the signature value and the hash value of the fourth USB storage device to the storage module.

[0103] In an optional embodiment, the white list management includes: ① white list initialization: the computer connects the USB hub, the USB hub connects the USB storage device,

[0104] The device will first send its device descriptors through the USB bus. These descriptors include the device's vendor ID (VID), product ID (PID), device class, sub-class, protocol version, etc.

[0105] On the management software interface, the instruction for authorizing the USB storage device is sent to the USB hub, the USB hub calculates the CRC of all descriptors of the USB storage device, the USB hub adds the CRC, VID and PID into the white list, the hash value of the white list is calculated, the signature value of the hash value is calculated by the signature verification private key, and is stored in the USB hub.

[0106] ② White list addition, deletion and modification: the USB hub connects another USB storage device, the instruction for adding authorization to the USB storage device is sent on the management software interface, the USB hub, the management software verifies the signature value of the white list, after successful verification, the USB hub calculates the CRC of all descriptors of the USB storage device, the USB hub adds the CRC, VID and PID into the white list, the hash value of the white list is calculated again, the signature value of the hash value is calculated by the signature verification private key, and is stored in the USB hub. The deletion and modification of the USB storage device are the same.

[0107] ③ White list export and import: the management software verifies the signature value of a USB hub white list signature, after successful verification, sends a white list export command, and the USB hub exports the white list.

[0108] The management software imports the white list to another USB hub, the USB hub calculates the hash value of the white list, and the hash value is verified by the signature verification private key of its own signature to calculate the signature value and store it.

[0109] Before the management software initializes the white list, it also includes verifying the signature verification public key in the signature verification certificate, if the verification is successful, the white list initialization is executed, if the verification fails, the white list initialization is not executed.

[0110] It should be noted that for the foregoing method embodiments, in order to simply describe, they are all expressed as a combination of a series of actions, but those skilled in the art should know that the present application is not limited to the order of the actions described, because according to the present application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions and modules involved are not necessarily necessary for the present application.

[0111] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.

[0112] In several embodiments provided in the present application, it should be understood that the disclosed device can be implemented by other ways. For example, the device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some service interface, device or unit, and can be electrical or other forms.

[0113] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiment scheme.

[0114] In addition, each of the function units in the embodiments of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.

[0115] When the integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable memory. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present application. The aforementioned memory includes: a U disk, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0116] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by a program instructing relevant hardware, and the program can be stored in a computer readable memory, which can include a flash disk, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disk, etc.

[0117] The above is only exemplary embodiments of the present disclosure, and cannot limit the scope of the present disclosure. That is, any equivalent changes and modifications made according to the teachings of the present disclosure are still within the scope of the present disclosure. Those skilled in the art will easily think of embodiments of the present disclosure after considering the specification and practicing the disclosure herein. The present application is intended to cover any variations, uses or adaptive changes of the present disclosure, which follow the general principles of the present disclosure and include common knowledge or conventional technical means in the technical field not described in the present disclosure. The specification and examples are only considered as exemplary, and the scope and spirit of the present disclosure are defined by the claims.

[0118] Each of the technical features of the above embodiments can be combined arbitrarily. In order to make the description simple, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combinations of the technical features do not exist contradictory, they should be considered as the scope of the present disclosure.

[0119] Those skilled in the art can easily understand that the above description is only the preferred embodiment of the present application, and is not intended to limit the present application. Any modification, equivalent replacement and improvement made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A security-protected USB hub for storage devices, characterized in that, include: USB hub body and security system, wherein the USB hub body is used to connect multiple USB storage devices; The security protection system includes: a main control module, used to authorize and authenticate the management software, and to receive configuration instructions sent by the management software to configure permissions for the connected USB storage devices and obtain a whitelist; The storage module is used to store the device descriptor information and permission configuration information of the USB storage device; the permission configuration information includes whitelist information and CRC value calculated when authorizing each storage device. The computation module is used to perform hash operations and signatures on the whitelist; the whitelist management includes: Whitelist initialization; the USB hub connects to the USB storage device, and the main control module connects to the first USB storage device, establishing a connection with the first USB storage device; if the signature verification of the first USB storage device is successful, the main control module enumerates the descriptors of all endpoints of the first USB storage device for verification, obtains the first CRC value, and adds the first USB storage device to the whitelist based on the first CRC value; the calculation module performs hash value calculation based on the whitelist, uses the signature verification private key to sign the whitelist hash value to obtain the signature value, and stores the whitelist hash value and the signature value in the storage module; The management software is used by a host computer connected to the USB hub to manage whitelists for the USB hub and to set permissions for USB storage devices and generate configuration commands.

2. The security protection USB hub for storage devices as described in claim 1, characterized in that, It also includes user software, which is applied to a host computer connected to the main body of the USB hub and is used to manage the storage devices connected to the USB hub; the user software is connected to the USB hub via the USB bus, and the user software is licensed software that has been successfully authorized and certified.

3. The security protection USB hub for storage devices as described in claim 1, characterized in that, The computing module includes: The hash operation unit is used to perform hash operations on whitelist hash values, device descriptor information, and identity information; The signature unit is used to sign hash values. It uses the asymmetric encryption / decryption private key of the asymmetric encryption / decryption certificate to sign whitelisted hash values ​​and generate signature values.

4. The security protection USB hub for storage devices as described in claim 1, characterized in that, The whitelist management also includes: Adding, deleting, and modifying the whitelist: The USB hub connects to the second USB storage device, and the main control module connects to the second USB storage device to establish a connection with the second USB storage device. If the signature verification of the second USB storage device is successful, the descriptors of all endpoints of the second USB storage device are enumerated and verified to obtain the second CRC value. Based on the second CRC value, the whitelist is added, deleted, or modified.

5. The security protection USB hub for storage devices as described in claim 1, characterized in that, The whitelist management also includes: Whitelist Export: The USB hub connects to the third USB storage device, the storage module connects to the third USB storage device, and a connection is established with the third USB storage device; if the third USB storage device successfully verifies the signature, the storage module exports the whitelist. Whitelist import: The USB hub connects to the fourth USB storage device, and the computing module connects to the fourth USB storage device. If the signature verification is successful on the fourth USB storage device, the computing module calculates the whitelist hash value from the whitelist hash value, calculates the signature value from the whitelist hash value, and writes the signature value and hash value of the fourth USB storage device to the storage module.

6. The security protection USB hub for storage devices as described in claim 1, characterized in that, Before the management software initializes the whitelist, it also includes: The whitelist signature value of the first USB storage device is verified. If the signature value is correct, whitelist initialization is performed. If the verification fails, whitelist initialization is not performed.

7. An authorization method for a security protection USB hub for storage devices, characterized in that, Authorization for a USB hub according to any one of claims 1-6, the authorization method comprising: The USB hub sends a signature verification certificate and an asymmetric encryption / decryption certificate to the management software, and receives the hash value ciphertext from the management software. The USB hub decrypts the ciphertext of the hash value and signs the hash value based on the signature verification certificate to obtain the signature value of the hash value and sends it to the management software; The management software verifies the signature value based on the signature verification public key in the signature verification certificate and compares the hash value to generate a first verification result, which is then sent to the USB hub. The first verification result is used to confirm the identity of the USB storage device connected to the USB hub. The USB hub reads the corresponding whitelist signature value based on the first signature verification result and sends it to the management software; The management software verifies the whitelist signature value based on the signature verification public key in the signature verification certificate, generates a second verification result, and sends it to the USB hub. The second verification result is used to determine the authorization result of the USB hub.

8. The licensing method for a security-protected USB hub for storage devices as described in claim 7, characterized in that, Before the USB hub sends the signature verification certificate and asymmetric encryption / decryption certificate to the management software and receives the hash value ciphertext from the management software, it includes: The USB hub generates a public-private key pair and applies for a digital certificate from a certificate authority, obtaining a signature verification certificate and an asymmetric encryption / decryption certificate.

9. The licensing method for a security-protected USB hub for storage devices as described in claim 7, characterized in that, The steps for obtaining the hash value ciphertext include: The management software receives the signature verification certificate and the asymmetric encryption / decryption certificate; The management software generates random numbers and calculates the hash value of the random numbers; The management software encrypts the hash value based on the asymmetric encryption / decryption public key in the asymmetric encryption / decryption certificate to obtain the hash value ciphertext.

Citation Information

Patent Citations

  • USB equipment management and control method and device and electronic equipment

    CN114021104A

  • USB storage device management method and device, terminal device and storage medium

    CN117493029A