Idle network port protection device and protection method

By designing an idle network port protection device that can switch the self-locking state, the problem of easy removal of the grid port plug in the prior art is solved, effective sealing and safety protection of the idle network port is achieved, and the risk of large-scale power outages in the power system is avoided.

CN119995916APending Publication Date: 2025-05-13STATE GRID HEBEI ELECTRIC POWER CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411610309.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-12
Publication Date
2025-05-13

Smart Images

  • Figure CN119995916A_ABST
    Figure CN119995916A_ABST
Patent Text Reader

Abstract

The invention provides an idle network port protection device and protection method. The idle network port protection device comprises a plugging head and a control part, the plugging head is used for inserting and plugging the idle network port; a plugging assembly and a telescopic driving piece are arranged in the plugging head; the output end of the telescopic driving piece is connected with the plugging assembly. The blocking assembly is provided with a baffle which is rotationally arranged in the blocking head; a through hole suitable for the baffle to swing out is formed in the plugging head; the baffle is driven by the telescopic driving part to have a self-locking state of swinging out of the through hole and being clamped with the idle net opening, and an unlocking state of integrally swinging into the plugging head; and the control part is electrically connected with the telescopic driving piece to control the telescopic action of the telescopic driving piece. According to the idle network port protection device provided by the invention, the control part controls the plugging head to plug the idle network port, so that an external terminal can be prevented from easily accessing the idle network port, and the safety protection strength is improved. The invention further provides an unlocking method of the idle network port protection device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network equipment network port security protection, and in particular relates to an idle network port protection device and a protection method. Background Art

[0002] The power system communication network has extremely high requirements for network security. The power system communication network is physically isolated from the Internet. Some network devices in the internal communication network have idle network ports, which are usually open and prone to dust and debris accumulation. If an external terminal device mistakenly accesses an idle network port and causes erroneous operation on the network, it will cause a large-scale power outage in the power system, which will have a very serious impact.

[0003] In the prior art, network port plugs are usually used for protection, and the network port plugs are usually locked in a snap-on manner using plastic springs. After being inserted into the network port, the springs pop up, and the blocking groove inside the network port is used to lock the network port to prevent it from being easily pulled out. However, the network port plug can be easily removed by mechanical tools, and cannot prevent the external terminal device from mistakenly accessing the idle network port and causing erroneous operations on the internal communication network, and cannot truly play a safety protection function. Summary of the invention

[0004] The embodiments of the present invention provide an idle network port protection device and a protection method, aiming to solve the problems in the prior art that the network port plug is easy to remove and the safety protection factor is low.

[0005] To achieve the above-mentioned objectives, the technical solution adopted by the present invention is: in the first aspect, a free network port protection device is provided, including a blocking head and a control unit; the blocking head is used to insert and block the free network port; a blocking assembly and a telescopic driving member are arranged inside the blocking head; the output end of the telescopic driving member is connected to the blocking assembly; the blocking assembly has a baffle, which is rotatably arranged in the blocking head; a through hole suitable for the baffle to be swung out is opened on the blocking head; the baffle has a self-locking state in which it is swung out of the through hole and clamped with the free network port under the drive of the telescopic driving member, and an unlocked state in which it is swung into the inside of the blocking head as a whole; the control unit is electrically connected to the telescopic driving member to control the telescopic action of the telescopic driving member.

[0006] In combination with the first aspect, in a possible implementation, the sealing assembly also includes a fixed plate, a rotating plate and a connecting rod; the fixed plate is located below the top wall of the sealing head, one end of which is connected to the inner wall of the sealing head, and the other end is rotatably connected to the baffle; the rotating plate is located inside the sealing head, and the middle part of the rotating plate is rotatably connected to the sealing head; one end of the connecting rod is hinged to the lower surface of the baffle, and the other end is hinged to one end of the rotating plate; wherein, when the sealing assembly switches from a self-locking state to an unlocked state, the end of the rotating plate hinged to the connecting rod moves downward, and drives the baffle as a whole to swing into the interior of the sealing head.

[0007] In combination with the first aspect, in a possible implementation manner, a torsion spring is sleeved on the connecting shaft between the baffle plate and the fixing plate.

[0008] In combination with the first aspect, in a possible implementation, the output end of the telescopic drive member is a telescopic rod, which is used to abut against the lower end of the rotating plate under the drive of the telescopic drive member; wherein, when the blocking assembly switches from a self-locking state to an unlocked state, the telescopic rod extends forward and pushes the rotating plate to rotate.

[0009] In combination with the first aspect, in a possible implementation, the control unit includes a system chip and a power interface; the system chip is electrically connected to the telescopic drive component, and is used to receive and compare command information sent by an external unlocking terminal and perform corresponding operations. A memory is provided on the system chip, and the memory is used to store device information and mechanism algorithms; the power interface is connected to the system chip, and is used to connect to the external unlocking terminal to realize power supply.

[0010] In combination with the first aspect, in a possible implementation manner, a carrier is provided inside the control unit, and two ends of the carrier are electrically connected to the system chip and the power interface respectively.

[0011] The beneficial effects of the idle network port protection device provided by the present invention are as follows: compared with the prior art, the present invention adopts a blocking component that can be switched to a self-locking state, which can enable the baffle to be clamped on the inner wall of the idle network port, so that the blocking head is located inside the idle network port, thereby preventing the idle network port from being in an open state for a long time and causing dust and matter accumulation; the control unit is used to control the power on and off of the telescopic drive member and then control the switching state of the blocking component, so that the blocking head can be taken out from the idle network port, and the blocking head cannot be easily removed by mechanical tools. The blocking component can only be switched to an unlocked state for unlocking operation under the control of the control unit, which can prevent external terminal devices from erroneously accessing the idle network port and causing network failures, and can improve the strength of security protection.

[0012] In a second aspect, an embodiment of the present invention further provides a method for unlocking an idle network port protection device, using the idle network port protection device, comprising the following steps: Connect the external unlocking terminal to the control unit; The external unlocking terminal sends a read instruction to the control unit through an instruction set and an instruction structure; The control unit parses the read instruction, generates encrypted authority authentication information and assembles it into a response content and returns it to the external unlocking terminal; The response content is decrypted and an authentication instruction is sent through an external unlocking terminal. The control unit verifies the authentication instruction. After the verification is passed, the control unit obtains the authorization status; An unlocking instruction is sent through an external unlocking terminal, and the control unit decrypts the information in the unlocking instruction to obtain the unlocking duration; The control unit controls the telescopic driving member to drive the baffle to swing into the blocking head within the unlocking duration, and the blocking component switches to the unlocking state.

[0013] In conjunction with the second aspect, in a possible implementation, the response content is decrypted and an authentication instruction is sent through an external unlocking terminal, and the control unit verifies the authentication instruction. After the verification is passed, the control unit obtains the authorization status, including: An authorization command is issued through an external unlocking terminal, and the control unit accepts the authorization command; The control unit searches whether a read instruction has been returned within a specified time; Decrypting the authorization instruction through the control unit to obtain a trust code; The control unit compares the trust code and is in an authorized state after a successful comparison.

[0014] In combination with the second aspect, in a possible implementation, the control unit controls the telescopic driving member to drive the baffle to swing into the blocking head during the unlocking duration, and after the blocking assembly is switched to the unlocked state, the method further includes: A stop command is sent through an external unlocking terminal. After receiving the stop command, the control unit shrinks the output end of the telescopic drive component, the baffle swings out the blocking head, and the blocking component switches to a self-locking state.

[0015] In combination with the second aspect, in a possible implementation, the response content is decrypted and an authentication instruction is sent through an external unlocking terminal, and the control unit verifies the authentication instruction. After the verification is passed, the control unit obtains the authorization state and further includes: The configuration instruction is sent through the external unlocking terminal, and the control unit receives the configuration instruction and decrypts the information in the configuration instruction to obtain the configuration content that needs to be changed and execute it.

[0016] The beneficial effect of the unlocking method of the idle network port protection device provided by the present invention is that: compared with the prior art, the present invention is connected to the idle network port protection device through an external unlocking terminal, and sends an instruction set to the control unit. After receiving the instruction, the control unit generates encrypted authority authentication information and returns it to the external unlocking terminal. The external unlocking terminal decrypts the encrypted authority authentication information and verifies it again to obtain authorization to control the switching state of the blocking component. The unlocking of the idle network port protection device depends on the mutual authentication of information between the external unlocking terminal and the control unit, which can avoid easy unlocking of the idle network port protection device, prevent external terminal equipment from easily accessing the idle network port to cause internal communication network failure, and improve the security protection strength. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 A schematic diagram of the front view of the structure of an idle network port protection device provided in an embodiment of the present invention; Figure 2 A schematic diagram of the front view structure of the idle network port protection device provided by an embodiment of the present invention when the idle network port is not blocked; Figure 3A schematic diagram of the front view structure of the idle network port protection device provided by an embodiment of the present invention when inserted into an idle network port; Figure 4 A schematic diagram of the front view structure of the idle network port protection device provided by an embodiment of the present invention when blocking an idle network port; Figure 5 A schematic diagram of the front view structure of the idle network port protection device provided by an embodiment of the present invention when blocking an idle network port; Figure 6 A schematic diagram of the working process of the control unit used in the embodiment of the present invention; Figure 7 A schematic diagram of the structure of an external unlocking terminal used in an embodiment of the present invention; Figure 8 A flowchart of unlocking an idle network port protection device provided by an embodiment of the present invention; In the figure: 10, plugging head; 11, through hole; 20, control unit; 21, system chip; 211, memory; 22, power interface; 23, carrier; 24, communication interface; 25, protection circuit; 26, indicator light; 30, plugging assembly; 31, baffle; 32, fixing plate; 33, rotating plate; 34, connecting rod; 35, torsion spring; 40, telescopic drive member; 41, telescopic rod; 50, external unlocking terminal; 51, power transmission interface; 52, unlocking interface; 53, main control module; 54, power supply module; 60, idle network port. DETAILED DESCRIPTION

[0018] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0019] It should be noted that when an element is referred to as being "disposed on" another element, it may be directly on the other element or indirectly on the other element. It should be understood that the orientation or positional relationship indicated by the terms "upper", "lower", "front", "rear", "top", "bottom", "inside", "outside", etc. is based on the orientation or positional relationship shown in the accompanying drawings, which is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present invention. The terms "first" and "second" are used only for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, the meaning of "multiple" is two or more, unless otherwise clearly and specifically defined.

[0020] Please also read Figures 1 to 4 , the idle network port protection device provided by the present invention is now described. The idle network port protection device comprises a plugging head 10 and a control unit 20; the plugging head 10 is used to insert and plug the idle network port 60; a plugging assembly 30 and a telescopic drive member 40 are arranged inside the plugging head 10; the output end of the telescopic drive member 40 is connected to the plugging assembly 30; the plugging assembly 30 has a baffle 31, and the baffle 31 is rotatably arranged inside the plugging head 10; a through hole 11 suitable for the baffle 31 to swing out is opened on the plugging head 10; the baffle 31 has a self-locking state of swinging out of the through hole 11 and engaging with the idle network port 60 under the drive of the telescopic drive member 40, and an unlocking state of swinging into the plugging head 10 as a whole; the control unit 20 is electrically connected to the telescopic drive member 40 to control the telescopic action of the telescopic drive member 40.

[0021] It should be noted that the idle network port protection device blocks or unlocks the idle network port 60 based on a trust mechanism, and the trust mechanism is an unlocking function in which the blocking device and the external unlocking terminal 50 authenticate each other; the control unit 20 is a core component of the device, and can receive and execute instructions to complete operations such as device information modification and unlocking; the blocking head 10 is normally in a self-locking state, and when the idle network port 60 is pushed in, the baffle 31 is rotated into the blocking head 10 under the contact and compression of the idle network port 60, and after entering the network port, one end rises and engages the idle network port 60; when the blocking assembly 30 is switched to an unlocked state, the telescopic drive member 40 drives the output end to abut against the bottom of the blocking assembly 30, driving the baffle 31 to rotate into the inside of the blocking head 10 to realize the removal of the blocking head 10.

[0022] The beneficial effects of the idle network port protection device provided by the present invention are as follows: compared with the prior art, the present invention adopts a blocking component 30 that can be switched to a self-locking state, which can enable the baffle 31 to be clamped on the inner wall of the idle network port 60, so that the blocking head 10 is located inside the idle network port 60, thereby preventing the idle network port 60 from being in an open state for a long time and causing dust and matter to accumulate; the control unit 20 is used to control the power on and off of the telescopic drive member 40 and then control the switching state of the blocking component 30, so that the blocking head 10 can be taken out of the idle network port 60, so that the blocking head 10 cannot be easily removed by mechanical tools, and the blocking component 30 can only be switched to an unlocked state for unlocking operation under the control of the control unit 20, which can prevent external terminal devices from erroneously accessing the idle network port 60 and causing network failures, and can improve the strength of security protection.

[0023] In one possible implementation, see Figure 1The sealing assembly 30 also includes a fixed plate 32, a rotating plate 33 and a connecting rod 34; the fixed plate 32 is located below the top wall of the sealing head 10, one end of which is connected to the inner wall of the sealing head 10, and the other end is rotatably connected to the baffle 31; the rotating plate 33 is located inside the sealing head 10, and the middle part of the rotating plate 33 is rotatably connected to the sealing head 10; one end of the connecting rod 34 is hinged to the lower surface of the baffle 31, and the other end is hinged to one end of the rotating plate 33; wherein, when the sealing assembly 30 switches from a self-locking state to an unlocking state, the end of the rotating plate 33 hinged to the connecting rod 34 moves downward, and drives the baffle 31 to swing into the interior of the sealing head 10 as a whole.

[0024] It should be noted that the middle part of the rotating plate 33 is hinged inside the sealing head 10, and the rotating plate 33 can rotate inside the sealing head 10. The rotating plate 33 can be a corrugated plate, and the upper end is hinged to the connecting rod 34, and the lower end can abut against the output end of the telescopic driving member 40 when the output end of the telescopic driving member 40 extends forward. The output end of the telescopic driving member 40 causes the lower side of the rotating plate 33 to rotate in the direction in which the output end of the telescopic driving member 40 extends, and the upper side of the rotating plate 33 rotates in the opposite direction, and drives the connecting rod 34 to move downward, and drives the baffle 31 hinged to the connecting rod 34 to move downward, so that the plugging assembly 30 can be cut. Switch to the unlocked state; the fixed plate 32 is fixed under the upper top wall of the blocking head 10 and is rotatably connected to one end of the baffle 31, and the other end of the baffle 31 can rotate around the fixed plate 32, and the edge of the through hole 11 of the blocking head 10 can abut against the upper surface of the baffle 31. When the blocking head 10 is subjected to an outward pulling force, the upper surface of the blocking head 10 limits the baffle 31 from rotating upward and one end of the baffle 31 abuts against the inner wall of the idle network port 60, and the inclined baffle 31 will rotate in the opposite direction when subjected to a pulling force, with a tendency to further swing out the blocking head, and can further achieve the blocking of the idle network port 60 when subjected to a pulling force.

[0025] The length of the blocking head 10 can be smaller than the depth of the idle network port 60. Before the baffle 31 is switched to the unlocked state, the blocking head 10 can be further pushed into the idle network port 60. At this time, the baffle 31 abutting against the inner wall of the idle network port 60 is separated from the inner wall of the idle network port 60, thereby preventing the baffle 31 from moving downward on the side close to the inner wall of the idle network port 60 when switching to the unlocked state, causing friction damage to the inner wall of the idle network port 60, which is beneficial to protecting the idle network port 60 and the blocking component 30.

[0026] In one possible implementation, see Figure 1 A torsion spring 35 is sleeved on the connecting shaft between the baffle plate 31 and the fixing plate 32 .

[0027] It should be noted that the self-locking state of the baffle 31 is achieved by the torsion spring 35 on the connecting shaft between the baffle 31 and the fixed plate 32. When the sealing head 10 is pushed into the idle mesh port 60, the baffle 31 is squeezed by the inner wall of the idle mesh port 60 to rotate downward and compress the torsion spring 35. After the baffle 31 enters the idle mesh port 60, the torsion spring 35 rebounds and drives one end of the baffle 31 to tilt upward and rest against the inner wall of the idle mesh port 60, thereby realizing the self-locking function of the device and improving the safety protection capability. When the sealing assembly 30 is in the unlocked state, the output end of the telescopic drive 40 extends forward and drives the baffle 31 to rotate toward the inside of the sealing head 10, and the torsion spring 35 will be compressed and deformed. After the output end of the telescopic drive 40 contracts, the torsion spring 35 drives the baffle 31 to rotate upward, so that the sealing assembly 30 returns to the self-locking state.

[0028] In one possible implementation, the output end of the telescopic drive member 40 is a telescopic rod 41, which is used to abut against the lower end of the rotating plate 33 under the drive of the telescopic drive member 40; wherein, when the blocking assembly 30 switches from a self-locking state to an unlocked state, the telescopic rod 41 extends forward and pushes the rotating plate 33 to rotate.

[0029] It should be noted that the telescopic drive member 40 can be a cylinder, and the telescopic drive member 40 can also be arranged inside the control unit 20 to adapt to a smaller working space so that the blocking assembly 30 can be switched to an unlocked state; the telescopic rod 41 is the output end of the telescopic drive member 40, which can obtain a longer working stroke when extended, and maintain a smaller structural size when retracted. It can effectively abut the bottom of the rotating plate 33 to drive the baffle 31 to rotate into the blocking head 10, and move away from the blocking device after retraction, avoiding the blocking device from being unable to switch to a self-locking state, so that the blocking head 10 can effectively block the idle network port 60 and improve the safety protection strength.

[0030] In one possible implementation, the control unit 20 includes a system chip 21 and a power interface 22; the system chip 21 is electrically connected to the telescopic drive member 40, and is used to receive and compare command information sent by the external unlocking terminal 50 and perform corresponding operations. The system chip 21 is provided with a memory 211, and the memory 211 is used to store device information and mechanism algorithms; the power interface 22 is connected to the system chip 21, and is used to connect to the external unlocking terminal 50 to realize power supply.

[0031] It should be noted that after the external unlocking terminal 50 is connected to the control unit 20, the external unlocking terminal 50 supplies power to the system chip 21, so that the system chip 21 can receive and compare the command information sent by the external unlocking terminal 50; the memory 211 has the device information of the device, and can provide the device information of the device for device verification when the external unlocking terminal is connected; the mechanism algorithm stored in the memory 211 is an encrypted trust code generated based on the trust mechanism. When the system chip 21 and the external unlocking terminal authenticate each other through the trust mechanism, the external unlocking terminal sends a trust code to the system chip 21, and the system chip 21 compares the received trust code with the encrypted trust code stored in the memory 211. After the comparison is successful, the idle network port protection device and the external unlocking terminal 50 are mutually authenticated.

[0032] The control unit 20 may also include a communication interface 24, a protection circuit 25 and an indicator light 26. The communication interface 24 is the input and output port of the idle network port protection device, which is used to receive instructions and return execution information; the protection circuit 25 can be divided into a power protection circuit 25 and a drive protection circuit 25. The power protection circuit 25 is an anti-reverse connection protection circuit 25, which can prevent the interface from being reversed and avoid damage to the internal circuit; the drive protection circuit 25 can power on the telescopic drive 40 and has a freewheeling diode to prevent the telescopic drive 40 from generating high voltage and damaging the circuit when the power is off; the indicator light 26 is a status display output terminal, which is used to reflect the status of the device.

[0033] In a possible implementation, a carrier 23 is disposed inside the control unit 20 , and two ends of the carrier 23 are electrically connected to the system chip 21 and the power interface 22 , respectively.

[0034] It should be noted that the carrier 23 can serve as an intermediate carrier for electrically connecting the system chip 21 and the power interface 22, and can also carry the system chip 21, so that the system chip 21 is fixed on the carrier 23 and installed in the control unit 20, thereby realizing the electrical connection between the system chip 21 and the external unlocking terminal 50 and the telescopic drive member 40 respectively; it can avoid direct connection between the system chip 21 and the power interface 22, prevent the external unlocking terminal 50 from causing damage to the system chip 21 when connecting to or disconnecting from the control unit 20, and improve the safety protection capability of the device.

[0035] The embodiment of the present invention further provides a method for unlocking an idle network port protection device, using the idle network port protection device, comprising the following steps: Connecting the external unlocking terminal 50 to the control unit 20; The external unlocking terminal 50 sends a read instruction to the control unit 20 through an instruction set and an instruction structure; The control unit 20 parses the read instruction, generates encrypted authority authentication information and assembles it into a response content and returns it to the external unlocking terminal 50; The response content is decrypted and an authentication instruction is sent through the external unlocking terminal 50, and the control unit 20 verifies the authentication instruction. After the verification is passed, the control unit 20 obtains the authorization status; The unlocking command is sent through the external unlocking terminal 50, and the control unit 20 decrypts the information in the unlocking command to obtain the unlocking duration; The control unit 20 controls the telescopic driving member 40 to drive the baffle 31 to swing into the blocking head 10 during the unlocking duration, and the blocking assembly 30 switches to the unlocked state.

[0036] It should be noted that the external unlocking terminal 50 has a power transmission interface 51 and an unlocking interface 52. The power transmission interface 51 supplies power to the system chip 21. The control unit 20 receives the command of the external unlocking terminal 50 and the system chip 21 parses it. After the system chip 21 is powered on, it reads the device information to complete the initialization and enters the standby state; the external unlocking terminal 50 also has a main control module 53 and a power supply module 54. The main control module 53 completes the trust mechanism and business control, and the power supply module 54 completes the power supply; the external unlocking terminal 50 can be an electronic key, the main control module 53 is an embedded system, and the power supply module 54 is a rechargeable lithium battery; the external unlocking terminal 50 can also be an integrated The integrated authorization unlocking terminal has a lithium battery and a type-c port. The lithium battery serves as a power module, and the type-c port can serve as both a power transmission interface 51 and an unlocking interface 52. The corresponding application is installed on the integrated authorization unlocking terminal as a main control module 53 to realize a trust mechanism and business control. When the instruction operation parsed by the system chip 21 is an unlocking instruction, it will first check whether the current control unit 20 is in an authorized state. If not, the unauthorized instruction will be executed directly. When it is confirmed that the control unit 20 is in an authorized state, the information content in the instruction will be decrypted to obtain the unlocking duration, and then the unlocking operation will be executed, maintaining the corresponding time length. After the end, a successful unlocking command will be returned to the external unlocking terminal 50.

[0037] The external unlocking terminal 50 and the idle network port protection device use a custom instruction set for communication, which can improve the security of communication data; the instruction set can use a hexadecimal code structure, which can reduce the character encoding and decoding process and improve communication efficiency; the instruction structure is a "start character + command character + length character + information content + check character" structure, which can not only ensure the correctness of the instruction through the check rule, but also make the instruction parsing process simpler by using a fixed-length start character, command character and length character; when the system chip 21 parses the instruction operation as a read instruction, the system chip 21 will generate a random code, and then The random code (RAND) and the device number are combined according to a special rule. The S_ID and RAND, both of which are 16 bits in length, are combined in such a way that the i-th bit of S_ID (numbered from 0 to 15) is XORed with the 15-i-th bit of RAND to obtain a new 16-bit string (S_ID2). Then, each bit of S_ID2 is cross-combined with RAND to form S_ID3. The encryption algorithm (MD5) is then used to encrypt the combined data S_ID3 to obtain the transmitted device number. Finally, it is assembled into the response content according to the command response structure and returned to the external unlocking terminal 50.

[0038] The beneficial effect of the unlocking method of the idle network port protection device provided by the present invention is that: compared with the prior art, the present invention is connected to the idle network port protection device through an external unlocking terminal 50, and sends an instruction set to the control unit 20. After receiving the instruction, the control unit 20 generates encrypted authority authentication information and returns it to the external unlocking terminal 50. The external unlocking terminal 50 decrypts the encrypted authority authentication information and verifies it again to obtain authorization to control the switching state of the blocking component 30. The unlocking of the idle network port protection device depends on the mutual authentication of information between the external unlocking terminal 50 and the control unit 20, which can avoid the easy unlocking of the idle network port protection device, prevent external terminal devices from easily accessing the idle network port 60 to cause internal communication network failures, and improve the security protection strength.

[0039] In a possible implementation, in a possible implementation, the external unlocking terminal 50 decrypts the response content and sends an authentication instruction, the control unit 20 verifies the authentication instruction, and after the verification is passed, the control unit 20 obtains the authorization state including: The external unlocking terminal 50 issues an authorization command, and the control unit 20 receives the authorization command; The control unit 20 searches whether a read instruction has been returned within a specified time; Decrypting the authorization instruction by the control unit 20 to obtain a trust code; The trust code is compared by the control unit 20, and after the comparison is successful, the control unit 20 is in an authorized state.

[0040] It should be noted that when the instruction operation parsed by the system chip 21 is an authentication instruction, it will first check whether a read instruction has been returned to the external unlocking terminal 50 within the specified time. If no authentication failure instruction has been directly returned to the external unlocking terminal 50, if the read instruction has been returned, the information content in the instruction will be decrypted (MD5), and after decryption, it will be disassembled according to specific rules to first disassemble S_KEY2 and RAND bit by bit, and then the i-th bit of S_KEY2 (numbered from 0 to 15) and the 15-i-th bit of RAND are XORed to obtain the trust code (S_KEY), and then the trust code is compared with the encrypted trust code stored in the system chip 21. If the comparison is successful, the authentication success instruction is returned to the external unlocking terminal 50, otherwise the authentication failure instruction is returned.

[0041] In a possible implementation, in a possible implementation, the control unit 20 controls the telescopic driving member 40 to drive the baffle 31 to swing into the blocking head 10 during the unlocking duration, and after the blocking assembly 30 is switched to the unlocked state, it also includes: A stop command is sent through the external unlocking terminal 50 , and after receiving the stop command, the control unit 20 shrinks the output end of the telescopic driving member 40 , the baffle 31 swings out the blocking head 10 , and the blocking assembly 30 switches to a self-locking state.

[0042] It should be noted that when the blocking component 30 is in the unlocked state, the external unlocking terminal 50 is supported to send a stop command to the system chip 21. After parsing the stop command, the system chip 21 will control the output end of the telescopic drive 40 to shrink, and the baffle 31 will be swung into the plugging head 10, so that the blocking component 30 can switch to the self-locking state to block the idle network port 60; if the external unlocking terminal 50 does not send a stop command, the system chip 21 will control the output end of the telescopic drive 40 to extend within the unlocking time, and then control the output end of the telescopic drive 40 to shrink after the unlocking time is reached. After the system chip 21 receives the stop command, the authorization state will also become invalid, and the system chip 21 will re-enter the waiting state.

[0043] In a possible implementation, the external unlocking terminal 50 decrypts the response content and sends an authentication instruction, and the control unit 20 verifies the authentication instruction. After the verification is passed and the authorization state is entered, the following further includes: The configuration instruction is sent through the external unlocking terminal 50, and the control unit 20 receives the configuration instruction and decrypts the information in the configuration instruction to obtain the configuration content that needs to be changed and execute it.

[0044] It should be noted that when the instruction operation parsed by the system chip 21 is a configuration instruction, it will first check whether it is currently in an authorized state. If not, it will directly return an unauthorized instruction. When it is confirmed to be in an authorized state, the information content in the configuration instruction will be decrypted to obtain the configuration content that needs to be changed, and then the configuration content will be modified. If the modification is successful, a success instruction will be returned. If it fails, an instruction on the modification failure and the reason for the failure will be returned.

[0045] Exemplarily, the verification method of the instruction structure adopts the CRC16 verification method: the verification character polynomial is 0x9937 (b11001100100110111 in binary). First, the CRC16 verification value excluding the start character is calculated, and then the CRC16 verification value is shifted right by 6 bits, the lower 8 bits are taken, and then the inversion is performed. For example, the CRC16 verification value is 0x3946 (b0011100101000110), the 6th to 13th bits are 0xE5 (b11100101), and the bitwise inversion is 0x1A (b00011010).

[0046] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. An idle network port protection device, characterized in that: It comprises a blocking head and a control unit; the blocking head is used to insert into and block an idle network port; a blocking assembly and a telescopic driving member are arranged inside the blocking head; the output end of the telescopic driving member is connected with the blocking assembly; the blocking assembly has a baffle, which is rotatably arranged inside the blocking head; a through hole suitable for the baffle to be swung out is provided on the blocking head; the baffle, driven by the telescopic driving member, has a self-locking state in which it is swung out of the through hole and engaged with the idle network port, and an unlocking state in which it is swung into the inside of the blocking head as a whole; the control unit is electrically connected to the telescopic driving member to control the telescopic action of the telescopic driving member.

2. The idle network port protection device according to claim 1, characterized in that: The blocking component also includes: A fixed plate, located below the top wall of the plugging head, one end of which is connected to the inner wall of the plugging head, and the other end of which is rotatably connected to the baffle; A rotating plate is located inside the plugging head, and a middle portion of the rotating plate is rotatably connected to the plugging head; A connecting rod, one end of which is hinged to the lower surface of the baffle plate, and the other end of which is hinged to one end of the rotating plate; When the blocking assembly switches from the self-locking state to the unlocking state, the end of the rotating plate hinged to the connecting rod moves downward, and drives the baffle to swing into the blocking head as a whole.

3. The idle network port protection device according to claim 2, characterized in that: A torsion spring is sleeved on the connecting shaft between the baffle plate and the fixing plate.

4. The idle network port protection device according to claim 2, characterized in that: The output end of the telescopic driving member is a telescopic rod, and the telescopic rod is used to abut against the lower end of the rotating plate under the drive of the telescopic driving member; Wherein, when the blocking assembly switches from the self-locking state to the unlocking state, the telescopic rod extends forward and pushes the rotating plate to rotate.

5. The idle network port protection device according to claim 1, characterized in that: The control unit includes: A system chip, the system chip is electrically connected to the telescopic drive member, and is used to receive and compare the instruction information sent by the external unlocking terminal and perform corresponding operations. The system chip is provided with a memory, and the memory is used to store device information and mechanism algorithms; A power interface is connected to the system chip and is used to connect to an external unlocking terminal to realize power supply.

6. The idle network port protection device according to claim 5, characterized in that: A carrier is disposed inside the control unit, and two ends of the carrier are electrically connected to the system chip and the power interface respectively.

7. A method for unlocking an idle network port protection device, characterized in that: The idle network port protection device according to any one of claims 1 to 6 comprises the following steps: connecting the external unlocking terminal to the control unit; The external unlocking terminal sends a read instruction to the control unit; The control unit parses the read instruction, generates encrypted authority authentication information and assembles it into a response content and returns it to the external unlocking terminal; The response content is decrypted by the external unlocking terminal and an authentication instruction is sent, and the control unit verifies the authentication instruction. After the verification is passed, the control unit obtains the authorization status; Sending an unlocking instruction via the external unlocking terminal, the control unit decrypts the information in the unlocking instruction to obtain the unlocking duration; The control unit controls the telescopic driving member to drive the baffle to swing into the blocking head within the unlocking duration, and the blocking assembly switches to the unlocking state.

8. The method for unlocking an idle network port protection device according to claim 7, characterized in that: The external unlocking terminal decrypts the response content and sends an authentication instruction, the control unit verifies the authentication instruction, and the control unit obtains the authorization status after the verification is passed, including: An authorization instruction is issued through an external unlocking terminal, and the control unit accepts the authorization instruction; Searching by the control unit whether the read instruction has been returned within a specified time; Decrypting the authorization instruction by the control unit to obtain a trust code; The control unit compares the trust code, and after the comparison is successful, the control unit is in the authorized state.

9. The method for unlocking an idle network port protection device according to claim 7, characterized in that: The control unit controls the telescopic driving member to drive the baffle to swing into the blocking head during the unlocking duration, and after the blocking assembly is switched to the unlocking state, the following further comprises: A stop command is sent through an external unlocking terminal, and after receiving the stop command, the control unit shrinks the output end of the telescopic drive component, the baffle swings out the blocking head, and the blocking assembly switches to a self-locking state.

10. The method for unlocking an idle network port protection device according to claim 7, characterized in that: The external unlocking terminal decrypts the response content and sends an authentication instruction, the control unit verifies the authentication instruction, and after the verification is passed, the control unit obtains the authorization state, and further includes: The configuration instruction is sent through the external unlocking terminal, and the control unit receives the configuration instruction and decrypts the information in the configuration instruction to obtain the configuration content that needs to be changed and execute it.