Access device, access method and access system of USB (Universal Serial Bus) device

By introducing a microcontroller and a main controller into the USB device access system, configuring the communication mode and data list, and controlling the working status of the USB hub, the problem of low access security for USB devices in the prior art is solved, and higher security and user experience are achieved.

CN120012069APending Publication Date: 2025-05-16深圳市三旺通信股份有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510116371.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The prior art has low security and poor experience when accessing USB devices, and is vulnerable to attacks from malicious USB devices.

Method used

By providing an access device for a USB device, including a microcontroller, a main controller, a USB hub and a USB controller, the main controller configures the communication mode and data list of the microcontroller. The microcontroller controls whether the USB hub works normally based on the data list and the identifier of the USB device to be connected, and transmits the USB signal to the main controller during normal operation.

Benefits of technology

It realizes access verification of USB devices, effectively guarantees the security of the main controller system, and improves flexible management and configuration of access devices, improving user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012069A_ABST
    Figure CN120012069A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of USB communication, and discloses access equipment, an access method and an access system of USB equipment, and the equipment comprises a microcontroller, a main controller and a USB hub; the main controller is used for configuring a communication mode and a data list of the microcontroller; the microcontroller is used for controlling whether the USB concentrator works normally or not according to the received data list and the read identifier of the USB equipment to be connected in the first communication mode; and the USB concentrator is used for transmitting a USB signal of the USB equipment to be connected to the main controller during normal work. After the communication mode and the data list of the microcontroller are configured, whether the USB hub works normally or not is controlled according to the data list and the identifier of the USB device to be connected in the first communication mode, and the USB signal is transmitted to the main controller when the USB hub works normally, so that security authentication is realized, and the access security and experience feeling are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of USB communication, and in particular to an access device, an access method and an access system for a USB device. Background Art

[0002] Currently, the existing Linux secure access to USB devices generally directly reads the USB device ID and other information, and configures black and white lists to control the access permissions of USB devices.

[0003] Currently, USB communication is that the USB controller is directly connected to the CPU or the USB controller integrated inside the chip directly accesses the USB device. However, for malicious USB devices, it is easy to attack the system or the CPU hardware itself, such as instantly increasing the USB voltage to damage the CPU hardware itself.

[0004] Therefore the prior art still needs to be improved and enhanced. Summary of the invention

[0005] The present application provides an access device, an access method and an access system for a USB device, aiming to solve the problems of low security and poor user experience when accessing a USB device in the prior art.

[0006] In a first aspect, an embodiment of the present application provides an access device for a USB device, comprising: a microcontroller, a main controller, a USB hub and a USB controller; the main controller is connected to the microcontroller and the USB hub respectively, the microcontroller and the USB hub are also connected to the USB controller, the microcontroller is also connected to the USB hub, and the USB controller is also connected to a plurality of USB devices;

[0007] The main controller is used to configure the communication mode and data list of the microcontroller;

[0008] The microcontroller is used to control whether the USB hub works normally according to the received data list and the read identifier of the USB device to be connected in the first communication mode;

[0009] The controller is used to transmit the USB signal of the USB device to be connected to the main controller via the USB hub when the USB hub is working normally.

[0010] In some embodiments, the host controller is further used to obtain an identifier of a target USB device on the USB controller in the second communication mode;

[0011] Add the identifier of the target USB device to the black and white list to obtain the data list;

[0012] and transmitting the data list to the microcontroller;

[0013] Wherein, in the second communication mode, the USB hub remains in a normal working state.

[0014] In some embodiments, the microcontroller is connected to an enable pin of the USB hub to control whether the USB hub works normally through the enable pin;

[0015] The microcontroller is specifically used to, after identifying the identifier of the USB device to be connected, compare the identifier of the USB device to be connected with the white list in the data list;

[0016] and if it is compared that the identifier of the USB device to be connected exists in the white list, controlling the enable pin to be in an enabled state so that the USB hub can work normally;

[0017] Among them, the enable state is a high level state; and the first communication mode is a whitelist enable mode.

[0018] In some embodiments, the microcontroller is specifically used to control the enable pin of the USB hub to be in a non-enabled state if it is compared that the identifier of the USB device to be connected does not exist in the white list, so that the USB hub cannot work normally;

[0019] Wherein, the disabled state is a low level state.

[0020] In some embodiments, the main controller is further specifically used to add an identifier of a trusted device in the target USB device to a whitelist;

[0021] And adding identifiers of untrusted devices in the target USB device to a blacklist.

[0022] In some embodiments, the microcontroller is specifically used to compare the identifier of the USB device to be connected with the blacklist in the data list;

[0023] And if it is compared that the identifier of the USB device to be connected exists in the blacklist, the enable pin of the USB hub is controlled to be in a disabled state, so that the USB hub cannot work normally.

[0024] In some embodiments, the microcontroller is further used to control an enable pin of the USB hub to be in an enabled state in the second communication mode, so that the USB hub can work normally.

[0025] In some embodiments, the microcontroller is further specifically used to, in the third communication mode, control the enable pin to be in the non-enabled state so that the USB hub cannot work normally;

[0026] Among them, the third communication mode is the whitelist closed mode.

[0027] In a second aspect, an embodiment of the present application provides a method for accessing a USB device, comprising:

[0028] Use the main controller to configure the communication mode and data list of the microcontroller;

[0029] In the first communication mode, the microcontroller is used to control whether the USB hub works normally according to the received data list and the read identifier of the USB device to be connected;

[0030] When the USB hub starts to work normally, the USB controller is used to transmit the USB signal of the USB device to be connected to the main controller via the USB hub.

[0031] In a third aspect, an embodiment of the present application provides a USB device access system, comprising: the USB device access device as described above, and a plurality of USB devices;

[0032] The plurality of USB devices are respectively connected to the USB controller in the access device of the USB device.

[0033] Compared with the prior art, the present application provides an access device, access method and access system for a USB device. After the device configures the communication mode and data list of the microcontroller through the main controller, the microcontroller controls whether the USB hub is working normally according to the data list and the identifier of the USB device to be connected in the first communication mode. When working normally, the USB hub transmits the USB signal to the main controller, thereby realizing access verification of the USB device, effectively ensuring the security of the main controller system, and being able to flexibly manage and configure the access devices, thereby improving flexibility and user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0035] Figure 1 A schematic diagram of a structure of an access device for a USB device provided by this application;

[0036] Figure 2 A schematic diagram of a hardware framework of a USB device access device provided by this application;

[0037] Figure 3 A flowchart of a method for accessing a USB device provided in this application.

[0038] Reference numerals: 10: access device for USB device; 20: microcontroller; 30: host controller; 40: USB hub; 50: USB controller; 60: USB device. DETAILED DESCRIPTION

[0039] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments.

[0040] The components of the embodiments of the present application generally described and shown in the drawings herein may be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.

[0041] Hereinafter, the terms "including", "having" and their cognates used in various embodiments of the present application are intended only to indicate specific features, numbers, steps, operations, elements, components or a combination of the foregoing items, and should not be understood as first excluding the existence of one or more other features, numbers, steps, operations, elements, components or a combination of the foregoing items or increasing the possibility of one or more features, numbers, steps, operations, elements, components or a combination of the foregoing items. In addition, the terms "first", "second", "third" and the like are only used to distinguish descriptions and cannot be understood as indicating or implying relative importance.

[0042] Unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meanings as those generally understood by those skilled in the art to which the various embodiments of the present application belong. The terms (such as those defined in generally used dictionaries) will be interpreted as having the same meanings as the contextual meanings in the relevant technical field and will not be interpreted as having idealized meanings or overly formal meanings unless clearly defined in the various embodiments of the present application.

[0043] The present application provides an access device, access method and access system for a USB device. After the access device of the USB device configures the communication mode and data list of the microcontroller through the main controller, the microcontroller controls whether the USB hub works normally according to the data list and the identifier of the USB device to be connected in the first communication mode, and when working normally, the USB hub transmits the USB signal to the main controller, realizes the access verification of the USB device, effectively ensures the security of the main controller system, and can also flexibly manage and configure the access device, thereby improving the flexibility and user experience.

[0044] The following describes the design scheme of the access device of the USB device through some specific embodiments.

[0045] See also Figure 1 The present application embodiment provides a USB device access device 10, including:

[0046] A microcontroller 20 , a host controller 30 , a USB hub 40 , and a USB controller 50 .

[0047] The main controller 30 is connected to the microcontroller 20 and the USB hub 40 respectively. The microcontroller 20 and the USB hub 40 are also connected to the USB controller 50 . The microcontroller 20 is also connected to the USB hub 40 . The USB controller 50 is also connected to a number of USB devices 60 .

[0048] The main controller 30 is used to configure the communication mode and data list of the microcontroller 20 .

[0049] The microcontroller 20 is used to control whether the USB hub 40 works normally in the first communication mode according to the received data list and the read identifier of the USB device 60 to be connected.

[0050] The USB controller 50 is used to transmit the USB signal of the USB device 60 to be connected to the main controller 30 via the USB hub 40 when the USB hub 40 is working normally.

[0051] Also see Figure 2, the main controller 30 includes: Linux system, that is, an operating system based on the Linux kernel; wherein the Linux kernel is an open source operating system core. The microcontroller 20 includes: MCU (Microcontroller Unit). The communication mode includes: a first communication mode, a second communication mode and a third communication mode; wherein the first communication mode is a whitelist on mode, the second communication mode is a full pass mode, and the third communication mode is a whitelist off mode; in the second communication mode, the USB (Universal Serial Bus, through the serial bus) hub remains in a normal working state; in the whitelist off mode, the USB hub 40 is disabled, so that the USB signal of the USB device to be connected is isolated from being transmitted to the main controller 30.

[0052] Among them, USB signal refers to the data signal transmitted through the universal serial bus, including the data stream of read and write operations, control commands and power signals; USB controller 50, that is, universal serial bus controller, is a hardware device used for communication between computers and external devices; USB devices 60 include: USB sound card, keyboard, mouse, USB network card and other devices with USB interface.

[0053] Exemplarily, the implementation process of the USB device access device 10 is as follows:

[0054] First, the main controller 30 communicates with the microcontroller 20 through I2C, configures the program on the microcontroller 20, and configures the USB communication strategy (i.e., communication mode) and the data list, so that the microcontroller 20 can use the white list in the data list to verify the external USB device 60 in the white list enable mode, and transmit the data list to the microcontroller 20.

[0055] Then, when the microcontroller 20 is configured in the whitelist on mode, the microcontroller 20 compares the identifiers (ID) read from the plurality of USB devices 60 using the USB controller 50 with the whitelist in the data list transmitted from the main controller 30, and controls whether the USB hub 40 operates normally according to the comparison result.

[0056] Finally, when the microcontroller 20 controls the USB hub 40 to work normally, the USB hub 40 transmits the USB signal of the USB device 60 transmitted by the USB controller 50 to the main controller 30 to perform communication between the USB device 60 and the main controller 30 .

[0057] It can be understood that in the present application, in the first communication mode, the microcontroller 20 compares the identifier of the USB device 60 to be connected with the data list, controls whether the USB hub 40 is working normally, and realizes the communication between the USB device 60 and the main controller 30 when working normally, thereby realizing the security authentication of the USB device 60 to be connected, avoiding the system paralysis caused by malicious devices directly and illegally accessing the main controller 30 and attacking the hardware, thereby effectively improving the security.

[0058] At the same time, because the USB hub 40 has the function of enhancing the stability of the transmission signal, the USB hub 40 is used as a relay of the USB signal in the present application. In a wiring or electromagnetic interference environment, the forwarded USB signal is more stable than the signal of the USB device 60 directly connected to the main controller 30.

[0059] For example, in one implementation method, the main controller 30 is also used to, in the second communication mode, obtain the identifier of the target USB device 60 on the USB controller 50; add the identifier of the target USB device 60 to the black and white list to obtain a data list; and transmit the data list to the microcontroller 20.

[0060] The target USB device 60 is a trusted or untrusted USB device 60, which can be selectively configured.

[0061] Exemplarily, the main controller 30 configures the microcontroller 20 as follows:

[0062] First, in the second communication mode, the USB hub 40 is always kept in a normal working state, and at this time, the host controller 30 can directly read the identifier of the target USB device 60 from the USB controller 50 .

[0063] Then, the main controller 30 adds the identifier of the target USB device 60 to the blacklist and whitelist, for example, adds the trusted device to the whitelist, or adds the untrusted device to the blacklist, to obtain a data list.

[0064] Finally, the management software on the main controller 30 transmits the data list to the microcontroller 20 via I2C.

[0065] It can be understood that in the present application, by configuring the communication mode for the microcontroller 20 in advance through the main controller 30 and setting the data list, flexible management and setting of the access device is achieved.

[0066] For example, in one implementation method, the microcontroller 20 is further configured to, in the second communication mode, control the enable pin of the USB hub 40 to be in an enabled state, so that the USB hub 40 can work normally.

[0067] Exemplarily, when the microcontroller 20 is in the second communication mode, the microcontroller 20 controls the enable pin of the USB hub 40 to be in the enable state, that is, to be kept in the high level state, so that the USB hub 40 can keep working normally.

[0068] For example, in one implementation method, the main controller 30 is further specifically configured to add identifiers of trusted devices in the target USB device 60 to a whitelist; and add identifiers of untrusted devices in the target USB device 60 to a blacklist.

[0069] Exemplarily, when the main controller 30 performs specific configuration of the data list:

[0070] The identifiers of the trusted devices in the target USB device 60 are added to the white list, and the identifiers of the untrusted devices in the target USB device 60 are added to the black list, to obtain a configured data list.

[0071] It can be understood that in this application, by setting up corresponding trusted devices and untrusted devices in advance, a black and white list verification mechanism is implemented, which effectively improves the efficiency and accuracy of verification.

[0072] For example, in one implementation method, the microcontroller 20 is connected to an enable pin of the USB hub 40 to control whether the USB hub 40 works normally through the enable pin.

[0073] The microcontroller 20 is specifically used to, after identifying the identifier of the USB device 60 to be connected, compare the identifier of the USB device 60 to be connected with the white list in the data list; and if it is compared that the identifier of the USB device 60 to be connected exists in the white list, control the enable pin to be in an enabled state to enable the USB hub 40 to work normally.

[0074] Among them, the enable state is a high level state.

[0075] Exemplarily, the microcontroller 20 controls whether the USB hub 40 operates normally by controlling whether the enable pin is enabled.

[0076] When in the first communication mode, after the microcontroller 20 identifies the identifier of the USB device 60 to be connected on the USB controller 50 connected thereto, the identifier of the USB device 60 to be connected is compared with the white list in the data list:

[0077] If it is compared that the identifier of the USB device 60 to be connected exists in the white list, that is, the verification is passed. At this time, the USB device 60 to be connected is a trusted security device. The microcontroller 20 first disconnects the connection with the USB device 60 to be connected, and controls the output of a high-level signal to the enable pin, that is, controls the enable pin to be in an enabled state to control the USB hub 40 to work normally.

[0078] For example, in one implementation method, the microcontroller 20 is specifically configured to control the enable pin of the USB hub 40 to be in a disabled state if it is compared that the identifier of the USB device 60 to be connected does not exist in the white list, so that the USB hub 40 cannot work normally.

[0079] Among them, the disabled state is a low level state.

[0080] Exemplarily, when the microcontroller 20 compares the identifier of the USB device 60 to be connected with the white list:

[0081] If the microcontroller 20 compares and finds that the identifier of the USB device 60 to be connected is not in the white list, that is, the verification fails. At this time, the USB device 60 to be connected is an unknown device or an untrusted device, and the control outputs a low-level signal to the enable pin, that is, the enable pin is controlled to be in a non-enabled state, so as to control the USB hub 40 to be turned off, thereby disconnecting the connection between the USB device 60 and the main controller 30, thereby realizing physical isolation between Linux and the USB device 60.

[0082] It can be understood that in the present application, the identifier of the USB device 60 to be connected is compared with the white list through the microcontroller 20. When the white list verification is passed, the USB hub 40 is enabled to put it in a working state, and when the white list verification is not passed, the USB hub 40 is disabled, thereby achieving security verification, effectively improving security, and the verification process is simple and accurate.

[0083] For example, in one implementation method, the microcontroller 20 is specifically used to compare the identifier of the USB device 60 to be connected with the blacklist in the data list; and if the comparison shows that the identifier of the USB device 60 to be connected exists in the blacklist, the enable pin of the USB hub 40 is controlled to be in a non-enabled state, so that the USB device 60 cannot work normally.

[0084] Exemplarily, when performing the blacklist and whitelist comparison, not only can the whitelist be compared, but also the blacklist can be compared, that is, the identifier of the USB device 60 to be connected can be compared with the blacklist in the data list:

[0085] If the comparison shows that it exists in the blacklist, it means that the USB device 60 to be connected is a dangerous device, then the enable pin is controlled to be in a non-enabled state to control the USB hub 40 to be turned off.

[0086] It can be understood that in this application, not only a whitelist is set up, but also a blacklist is set up to more efficiently screen out dangerous devices, further improving the verification speed and security.

[0087] For example, in one implementation method, the microcontroller 20 is further specifically configured to, in the third communication mode, control the enable pin to be in a non-enabled state so that the USB hub 40 cannot work normally;

[0088] Exemplarily, when the microcontroller 20 is in the black and white list off mode, that is, the third communication mode, the microcontroller 20 always outputs a low-level signal to the enable pin of the USB hub 40, controls the enable pin to be in a non-enabled state, so that the USB hub 40 is always in a turned-off state, thereby isolating the communication between the USB device 60 and the main controller 30.

[0089] See also Figure 3 , the embodiment of the present application provides a method for accessing a USB device 60, comprising steps S100-S300:

[0090] S100 , using the main controller 30 to configure the communication mode and data list of the microcontroller 20 .

[0091] Exemplarily, the main controller 30, such as a Linux system, communicates with a microcontroller 20, such as an MCU, through the I2C protocol, and sets the communication mode (including whitelist on mode, full pass mode and whitelist off mode) and data list (including blacklist and whitelist) so that the microcontroller 20 can control the management of access devices, thereby providing a better user experience and higher flexibility.

[0092] S200 , in the first communication mode, the microcontroller 20 controls whether the USB hub 40 works normally according to the received data list and the read identifier of the USB device 60 to be connected.

[0093] Exemplarily, when the microcontroller 20 is in the first communication mode, that is, the whitelist start mode, the microcontroller 20 compares the data list received from the main controller 30 and the identifier read from the USB device 60, controls whether the USB hub 40 works normally according to the comparison result, and uses the MCU for preliminary processing to strengthen the Linux system's defense capability against malicious USB devices 60, thereby effectively preventing malicious devices from directly accessing the system and achieving security verification.

[0094] S300 , when the USB hub 40 starts to work normally, the USB controller 50 is used to transmit the USB signal of the USB device 60 to be connected to the main controller 30 via the USB hub 40 .

[0095] Exemplarily, when the microcontroller 20 compares the identifier of the USB device 60 to be connected with the data list, if the identifier is on the white list in the data list, the USB hub 40 is controlled to work normally. Then, the USB hub 40 transmits the USB signal of the USB device 60 to be connected on the USB controller 50 to the main controller 30 to complete the communication between the USB device 60 to be connected and the main controller 30.

[0096] The embodiment of the present application provides a system for accessing a USB device 60 , including: the USB device access device 10 as described above, and a plurality of USB devices 60 ; the plurality of USB devices 60 are all connected to a USB controller 50 in the USB device access device 10 .

[0097] Exemplarily, by controlling the opening and closing of the USB hub 40, the connection between the USB device 60 and the main controller 30 is controlled, and physical isolation is achieved. The signal of the USB device 60 does not directly contact the pins on the Linux system, which protects the chip hardware to a certain extent.

[0098] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and structure diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, program segment or a part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in an alternative implementation, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the structure diagram and / or the flow diagram, and the combination of boxes in the structure diagram and / or the flow diagram, can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0099] In addition, the functional modules or units in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0100] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a smart phone, a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in the various embodiments of the present application.

[0101] The above description is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application.

Claims

1. A USB device access device, characterized in that: include: A microcontroller, a main controller, a USB hub and a USB controller; the main controller is connected to the microcontroller and the USB hub respectively, the microcontroller and the USB hub are also connected to the USB controller, the microcontroller is also connected to the USB hub, and the USB controller is also connected to a plurality of USB devices; The main controller is used to configure the communication mode and data list of the microcontroller; The microcontroller is used to control whether the USB hub works normally according to the received data list and the read identifier of the USB device to be connected in the first communication mode; The USB controller is used to transmit the USB signal of the USB device to be connected to the main controller via the USB hub when the USB hub is working normally.

2. The USB device access device according to claim 1, characterized in that: The main controller is further used to obtain an identifier of a target USB device on the USB controller in the second communication mode; Add the identifier of the target USB device to the black and white list to obtain the data list; and transmitting the data list to the microcontroller; Wherein, in the second communication mode, the USB hub remains in a normal working state.

3. The USB device access device according to claim 1, characterized in that: The microcontroller is connected to the enable pin of the USB hub to control whether the USB hub works normally through the enable pin; The microcontroller is specifically used to, after identifying the identifier of the USB device to be connected, compare the identifier of the USB device to be connected with the white list in the data list; and if it is compared that the identifier of the USB device to be connected exists in the white list, controlling the enable pin to be in an enabled state so that the USB hub can work normally; Among them, the enable state is a high level state; and the first communication mode is a whitelist enable mode.

4. The USB device access device according to claim 3, characterized in that: The microcontroller is specifically used for controlling the enable pin of the USB hub to be in a non-enabled state if it is compared that the identifier of the USB device to be connected does not exist in the white list, so that the USB hub cannot work normally; Wherein, the disabled state is a low level state.

5. The USB device access device according to claim 2, characterized in that: The main controller is further specifically used to add the identifier of the trusted device in the target USB device to the whitelist; And adding identifiers of untrusted devices in the target USB device to a blacklist.

6. The USB device access device according to claim 4, characterized in that: The microcontroller is specifically used to compare the identifier of the USB device to be connected with the blacklist in the data list; And if it is compared that the identifier of the USB device to be connected exists in the blacklist, the enable pin of the USB hub is controlled to be in a disabled state, so that the USB hub cannot work normally.

7. The USB device access device according to claim 2, characterized in that: The microcontroller is further configured to, in the second communication mode, control an enable pin of the USB hub to be in an enabled state, so that the USB hub can operate normally.

8. The USB device access device according to claim 4, characterized in that: The microcontroller is further specifically configured to, in the third communication mode, control the enable pin to be in the disabled state so that the USB hub cannot work normally; Among them, the third communication mode is the whitelist closed mode.

9. A method for accessing a USB device, characterized in that: include: Use the main controller to configure the communication mode and data list of the microcontroller; In the first communication mode, the microcontroller is used to control whether the USB hub works normally according to the received data list and the read identifier of the USB device to be connected; When the USB hub starts to work normally, the USB controller is used to transmit the USB signal of the USB device to be connected to the main controller via the USB hub.

10. A USB device access system, characterized in that: include: An access device for a USB device as claimed in any one of claims 1 to 8, and a plurality of USB devices; The plurality of USB devices are all connected to a USB controller in an access device of the USB device.