Computer information security protection device

By integrating hardware protection modules, intelligent threat detection modules and self-destructive protection mechanisms, the problems of insufficient identification capabilities for unknown threats, weak hardware protection and insufficient emergency response in the existing technology are solved, and efficient network threat protection and physical security guarantees are achieved.

CN120449175AInactive Publication Date: 2025-08-08GUANGZHOU ACADEMY OF FINE ARTS
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510460749.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-08-08
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing computer information security protection technology has limited ability to identify unknown threats, weak hardware protection, low processing efficiency, lacks physical security guarantee and emergency response capabilities, making it difficult to deal with complex and diverse cyber attacks.

Method used

It adopts hardware protection modules, intelligent threat detection modules, high-performance data processing units, adaptive control systems and self-destructive protection mechanisms, combined with encryption chips, physical isolation units, fingerprint identifiers and alarms, threats are identified through deep learning algorithms and critical hardware components are destroyed in extreme cases.

Benefits of technology

It significantly improves the identification ability and hardware protection level of unknown threats, improves processing efficiency and emergency response capabilities, provides flexible user experience and physical security guarantees, and effectively resists hardware vulnerabilities and physical intrusions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120449175A_ABST
    Figure CN120449175A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computer information security, in particular to a computer information security protection device, and aims to solve the defects in unknown threat identification, hardware protection, processing efficiency, physical security and emergency response in the prior art. The device provided by the invention comprises a hardware protection module, an intelligent threat detection module, a high-performance data processing unit, a self-adaptive control system and a self-destructive protection mechanism, the hardware protection module realizes data dual encryption through an encryption chip, and provides physical safety protection through a physical isolation unit in combination with a fingerprint identifier and an alarm; the intelligent threat detection module recognizes known and unknown threats by adopting a deep learning algorithm and combining with the dynamic feature database; the high-performance data processing unit supports parallel processing of multiple paths of data streams and ensures efficient data filtering; and the adaptive control system dynamically adjusts a strategy according to the threat level, and triggers a physical isolation or self-destruction mechanism to destroy the sensitive data when the threat level reaches a threshold value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer information security, and in particular to a computer information security protection device. Background Art

[0002] With the rapid development of internet technology and the increasing level of informatization, computer information security has become a major challenge for individuals, businesses, and even national security. Cyberattacks are becoming increasingly sophisticated and diverse, including distributed denial of service (DDoS) attacks, malware, data theft, and advanced persistent threats (APTs), posing a serious threat to the stable operation of computer systems and data security. According to the "2024 Global Cybersecurity Report," global cyberattack incidents increased by 35% year-over-year in 2024, with the average economic loss caused by corporate data breaches reaching $5 million.

[0003] Existing computer information security protection technologies primarily rely on software-based solutions, such as firewalls, antivirus software, and intrusion detection systems (IDS). These technologies identify known threats through rule matching and signature database comparison, and can, to a certain extent, intercept malicious traffic. For example, traditional firewalls filter data packets using access control lists (ACLs), while antivirus software scans files using virus signature databases. However, these technologies have the following shortcomings:

[0004] Limited ability to identify unknown threats: Traditional protection technologies rely on static signature databases, making them incapable of responding to new or zero-day attacks. For example, malware based on deepfake technology can generate numerous variants in a short period of time, bypassing signature database detection.

[0005] Weak hardware protection: Existing technologies primarily focus on the software layer and lack the ability to protect against hardware vulnerabilities. For example, hardware vulnerabilities such as Spectre and Meltdown can be exploited to directly steal memory data, and traditional software protection cannot effectively counter such attacks.

[0006] Low processing efficiency and difficulty meeting high concurrency requirements: In enterprise-level application scenarios, data traffic often reaches tens of Gbps. Traditional protection systems are prone to processing delays or even crashes in high-concurrency environments. For example, when processing 20Gbps of traffic, one enterprise-level firewall experienced an average latency of 200ms, severely impacting system performance.

[0007] Lack of physical security: Existing technologies rarely focus on physical protection. For example, when a device is physically invaded or maliciously operated, there is a lack of effective emergency response mechanisms, which may lead to direct exposure of sensitive data.

[0008] Inadequate emergency response capabilities: When faced with irreversible attacks (such as APTs), existing technologies can only log or disconnect, failing to fundamentally prevent data leaks. For example, after a bank system suffered an APT attack, despite detecting anomalies, the lack of physical isolation and destruction mechanisms still led to the theft of 10GB of sensitive data.

[0009] In recent years, several emerging technologies have attempted to address these issues. For example, machine learning-based security detection technology has achieved initial success by training models to identify abnormal traffic. However, its computational complexity is high, its real-time performance is limited, and it still relies on cloud-based signature library updates, making it incapable of addressing threats during network outages. Furthermore, some hardware protection solutions (such as TPM chips) provide encryption capabilities, but these functions are limited and inadequate for addressing diverse attack vectors. Furthermore, existing technologies lack emergency response mechanisms for extreme scenarios, such as physical theft of a device or irreversible attacks.

[0010] Therefore, the present application provides a computer information security protection device to solve the above problems. Summary of the Invention

[0011] The purpose of the present invention is to solve the existing technical problems raised in the above background technology and provide a computer information security protection device.

[0012] The above-mentioned purpose of the present invention is achieved like this: A computer information security protection device, comprising a hardware protection module, an intelligent threat detection module, a high-performance data processing unit, an adaptive control system, and a self-destruct protection mechanism; The hardware protection module is installed in the PCIe slot between the computer motherboard and the network interface card, and is used to perform real-time encryption and physical isolation protection on input and output data streams; The intelligent threat detection module has a built-in deep learning-based threat detection algorithm to identify known and unknown network threats; The high-performance data processing unit uses a multi-core processor and an FPGA acceleration chip to efficiently analyze and filter data streams; The adaptive control system dynamically adjusts the protection strategy according to the real-time threat level; The self-destruct protection mechanism destroys key hardware components to protect data security when an irreversible attack is detected.

[0013] Furthermore, the hardware protection module includes an encryption chip and a physical isolation unit; the encryption chip is a TPM2.0 compatible chip, installed in the PCIe slot near the power input terminal of the motherboard, and supports AES-256 and RSA-2048 dual encryption algorithms. The encryption process satisfies the following formula: Data encryption input ; Data decryption output ; Among them, M is the plaintext data, C is the ciphertext data, and k is the 256-bit key. The physical isolation unit adopts a dual-channel relay switch and is installed at the network signal input end of the hardware protection module; the relay switch is provided with a fingerprint identifier and an alarm, the fingerprint identifier is used to verify the identity of the operator, and the alarm emits an audible and visual alarm when unauthorized operation or threat is triggered.

[0014] Furthermore, the threat detection algorithm of the intelligent threat detection module is based on a hybrid model of convolutional neural networks and long short-term memory networks, and the specific implementation steps are as follows: Data preprocessing: The input data stream D(t) is segmented into 128-byte packets, and 64 eigenvalues are extracted from each packet using principal component analysis to generate a eigenvector ,in Represents the change of the i-th eigenvalue with time t, and the normalization formula is and are the mean and standard deviation of the i-th feature respectively; CNN feature extraction: calculated using a 3×3 convolution kernel ,in Extract from (V(t)); LSTM Time Series Analysis: Calculating Threat Probability in: is the original eigenvalue, is the mean, is the standard deviation, is the standardized eigenvalue, is the convolution kernel weight, (b) is the bias, F(t) is the feature output, 、 is the weight matrix, is the hidden state at the last moment, is the bias, P(t) is the range of threat probability P(t) O-1, is the Sigmoid function; when is considered a threat.

[0015] Furthermore, the intelligent threat detection module includes a dynamic feature database installed in the SSD storage unit below the hardware protection module. The dynamic feature database is updated once every 30 minutes, and the update formula is: Update threat signature increments ; Database capacity occupied S ; in: 、 is the amount of threat signature data, is the increment, S(t) is the database occupied capacity, and 0.3 is the compression factor.

[0016] Furthermore, the high-performance data processing unit includes an 8-core ARM Cortex-A76 processor and a Xilinx Zynq UltraScale+ FPGA chip, which is installed below the main heat sink in the center of the device. It supports parallel processing of 32 data streams. The throughput calculation formula is: ; Where: T is the data throughput, is the number of channels, GHz is the clock frequency, bit is the data bit width, divided by 8 Convert bit / s to Gbps.

[0017] Furthermore, the adaptive control system dynamically adjusts its strategy according to the threat level L(t). The threat level calculation formula is: ; Among them, L(t) is the threat level, P(t) is the threat probability, and the range of P(t) is O-1, is the abnormal traffic ratio, is the normalized attack frequency, The number of attacks in the past 24 hours, with a maximum of 100 times; When the device is in use, physical isolation or self-destruction mechanism is triggered.

[0018] Furthermore, the self-destruct protection mechanism includes a thermal fuse and a voltage overload circuit, which are installed above the encryption chip of the hardware protection module; When the threat level L(t)>0.98L(t)>0.98L(t)>0.98 and lasts for 5 seconds, the trigger mechanism: The thermal fuse heats up to 150°C, melting the encryption chip power line in less than 1 second; The voltage overload circuit outputs a 12V instantaneous high voltage, burning the NVRAM that stores the key.

[0019] Furthermore, the dual-channel relay switch of the physical isolation unit is connected to the adaptive control system via the I2C bus, supporting manual and automatic switching. The leakage current in the isolated state is less than 0.5 μA, and the response time formula is: ms+4ms=7ms; where: is the total response time, ms is the signal transmission time, ms is the execution time; The fingerprint recognition device installed on the relay switch is a capacitive fingerprint sensor with a storage capacity of 50 fingerprint templates. The switch operation can be triggered only after successful verification. The alarm is a combination of a buzzer and an LED light. The triggering conditions include fingerprint verification failure for more than 3 times or , the alarm duration is 30 seconds.

[0020] Furthermore, the FPGA chip has a built-in packet filtering algorithm, and the filtering rules are calculated based on weighted features: in, is the filter score, ranging from O to 1, 、 、 are the abnormal values of source IP, port number and packet length, and they are all normalized to 0-1; The processing delay is less than 40 microseconds.

[0021] Furthermore, the device also includes a user-defined interface installed on the top of the device, connected via a USB3.0 port, and supports parameter adjustment using a JSON format configuration file.

[0022] Compared with the prior art, the present invention has the following beneficial effects: 1. The computer information security protection device provided by the present invention overcomes the shortcomings of existing technologies and achieves significant technical advantages by integrating a hardware protection module, an intelligent threat detection module, a high-performance data processing unit, an adaptive control system, and a self-destruction protection mechanism. 2. This invention significantly improves threat identification capabilities and hardware protection levels. The intelligent threat detection module uses a deep learning algorithm, combined with a dynamic signature database, to effectively identify known and unknown network threats, significantly outperforming traditional technologies that rely on static signature libraries. The hardware protection module implements data encryption through an encryption chip, and combined with a physical isolation unit, fingerprint reader, and alarm, provides strong hardware-level protection, successfully resisting hardware vulnerability exploitation and physical intrusion. 3. This invention excels in processing efficiency and emergency response. The high-performance data processing unit supports parallel processing of multiple data streams, adapting to high-concurrency scenarios and ensuring real-time performance. The adaptive control system dynamically adjusts its strategy based on the threat level and, in extreme cases, destroys sensitive data through a self-destruct mechanism. This provides more efficient active protection compared to the passive response of existing technologies.

[0023] 4. The present invention provides a flexible user experience and physical security protection; the user-defined interface supports adjustment of detection sensitivity, encryption strength and flow limit, is easy to operate, and adapts to the needs of different scenarios; the fingerprint reader and alarm of the physical isolation unit effectively prevent unauthorized operation, providing comprehensive protection for high-security environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0025] Figure 1 This is a schematic diagram of the specific structure of a computer information security protection device according to an embodiment of the present invention; Figure 2 It is a schematic diagram of the overall structure of a computer information security protection device in an embodiment of the present invention.

[0026] In the figure: 1. Hardware protection module; 2. Computer motherboard; 3. Intelligent threat detection module; 4. High-performance data processing unit; 5. Thermal fuse; 6. Voltage overload circuit; 7. Chassis; 11. Encryption chip; 12. Physical isolation unit; 121. Fingerprint reader; 122. Alarm. DETAILED DESCRIPTION

[0027] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0028] The following is combined with Figure 1 and Figure 2 , the specific implementation methods of the present invention are described in detail.

[0029] The solution of the present invention provides a computer information security protection device, which aims to enhance the computer system's protection capability against network threats through the collaborative work of hardware and software. The technical solution of the present invention is described in detail below with reference to specific implementation methods and examples.

[0030] The computer information security protection device provided by the present invention includes a hardware protection module 1, an intelligent threat detection module 3, a high-performance data processing unit 4, an adaptive control system and a self-destructive protection mechanism, wherein the computer motherboard 2, the hardware protection module 1, the intelligent threat detection module 3, and the high-performance data processing unit 4 are all arranged inside the chassis 7.

[0031] The hardware protection module 1 is installed in the PCIe slot between the computer motherboard 2 and the network interface card, and is responsible for real-time encryption and physical isolation protection of input and output data streams.

[0032] Encryption chip 11: A TPM2.0 compatible chip installed in the PCIe slot near the power input terminal of the computer motherboard 2. It supports dual encryption algorithms of AES-256 and RSA-2048. The encryption process satisfies the following formula:

[0033] Data encryption input ; Data decryption output ; Among them, M is the plaintext data (unit: byte), C is the ciphertext data (unit: byte), k is the 256-bit ciphertext data. , (unit: bit), encryption delay is less than 0.5ms.

[0034] Physical isolation unit 12: A dual-channel relay switch is used and installed at the network signal input end of the hardware protection module 1. The switch specification is 5V / 2A, and the disconnection response time is less than 8ms.

[0035] Fingerprint identifier 121: The model is a capacitive fingerprint sensor with a size of 10mm×10mm, a storage capacity of 50 fingerprint templates, a recognition time of less than 1 second, and an error recognition rate of less than 0.01%. It is connected to the adaptive control system through the I2C bus.

[0036] Alarm 122: A combination of a buzzer and an LED light, installed on the top of the physical isolation unit 12. The sound intensity is not less than 85 decibels. The triggering conditions include the fingerprint identifier 121 verification failure more than 3 times or the threat level L(t)>0.85L(t)>0.85L(t)>0.85. The alarm duration is 30 seconds.

[0037] Response time formula: ms+4ms=7ms; where: is the total response time, ms is the signal transmission time, ms is the execution time, the switch life is 150,000 times, and the leakage current in the isolated state is less than 0.5μA.

[0038] The intelligent threat detection module 3 has a built-in deep learning-based threat detection algorithm to identify known and unknown network threats.

[0039] Algorithm process: The algorithm is based on a hybrid model of convolutional neural network (CNN) and long short-term memory network (LSTM). The specific steps are as follows: Data preprocessing: The input data stream (D(t)) (unit: bytes / second) is segmented into 128-byte packets. 64 eigenvalues are extracted from each packet through principal component analysis (PCA) to generate a feature vector: ,in Represents the change of the i-th eigenvalue with time t, and the normalization formula is and are the mean and standard deviation of the i-th feature respectively; CNN feature extraction: calculated using a 3×3 convolution kernel ,in Extract from (V(t)); LSTM Time Series Analysis: Calculating Threat Probability in: is the original eigenvalue, is the mean, is the standard deviation, is the standardized eigenvalue, is the convolution kernel weight, (b) is the bias, F(t) is the feature output, 、 is the weight matrix, is the hidden state at the last moment, is the bias, P(t) is the range of threat probability P(t) O-1, is the Sigmoid function; when is considered a threat.

[0040] The dynamic feature database is installed in the SSD storage unit below the hardware protection module. The dynamic feature database is updated once every 30 minutes. The update formula is: Update threat signature increments ; Database capacity occupied S ; in: 、 is the amount of threat signature data, is the increment, S(t) is the database occupied capacity, and 0.3 is the compression factor.

[0041] The high-performance data processing unit 4 includes an 8-core ARM Cortex-A76 processor (main frequency 2.4GHz) and a Xilinx Zynq UltraScale+ FPGA chip. It is installed under the main heat sink in the center of the device and supports parallel processing of 32 data streams.

[0042] The throughput calculation formula is: ; Where (T) is the data throughput (unit: Gbps), is the number of channels (unitless), GHz is the clock frequency (unit: Hz), bit is the data bit width (unit: bit, converted to byte is 8 bytes), divided by 8× Convert bit / s to Gbps. The result is: ,

[0043] The FPGA chip has a built-in packet filtering algorithm, and the filtering rules are calculated based on weighted features: ; in, is the filter score (range 0-1, unitless), 、 、 are the outliers of source IP, port number, and packet length (all normalized to 0-1, unitless); when The processing delay is less than 40 microseconds.

[0044] The adaptive control system dynamically adjusts the protection strategy according to the threat level L(t). The threat level calculation formula is: ; Where, (L(t)) is the threat level (range 0-1, no unit), (P(t)) is the threat probability (range 0-1, no unit), R(t)= The proportion of abnormal traffic in the 、 The unit is bytes / second. is the normalized attack frequency (unitless, The number of attacks in the past 24 hours, unit: times, upper limit is 100 times). When the physical isolation unit 12 is disconnected or self-destructed, the disconnection or self-destruction mechanism is triggered.

[0045] The self-destruct protection mechanism includes a thermal fuse 5 and a voltage overload circuit 6, which are installed above the encryption chip 11 of the hardware protection module 1. And when it lasts for 5 seconds, the trigger mechanism:

[0046] The thermal fuse 5 heats up to 150°C, melting the power line of the encryption chip 11 in less than 1 second; The voltage overload circuit 6 outputs a 12V instantaneous high voltage to burn the NVRAM storing the key, ensuring that the data cannot be recovered.

[0047] The user-defined interface is installed on the top of the device and connected via the USB3.0 port. It supports JSON format configuration files to adjust parameters: threat detection sensitivity (range 0.1-1.0, default 0.8, no unit); encryption strength level (level 1: AES-128, level 2: AES-256, level 3: AES-256+RSA-2048); Traffic limit threshold (1Gbps-50Gbps, default 20Gbps); the adjustment takes effect in less than 0.5 seconds.

[0048] Example 1: Enterprise server protection scenario; In an enterprise data center, computer motherboard 2 processes approximately 15Gbps of traffic daily and faces the threat of DDoS attacks and data theft. The device is deployed in the PCIe slot between computer motherboard 2 and the NIC. The specific operation is as follows:

[0049] Configuration of hardware protection module 1: The administrator verifies his identity through the (121) fingerprint recognition device (recognition time 0.8 seconds, success rate 99.9%), stores 5 authorized fingerprint templates, enables the relay switch of the (12) physical isolation unit, and the initial state is physical connection. The encryption chip 11 uses AES- The mode encrypts the data stream, with an average delay of 0.4ms, and it takes about 40ms to process 100MB of data.

[0050] Intelligent threat detection module 3 operates as follows: the input data stream D(t) (15 Gbps) is segmented into 128-byte packets, and PCA is used to extract 64 eigenvalues to generate a eigenvector (V(t)).

[0051] calculate After CNN and LSTM processing, the abnormal traffic ratio was detected (Abnormal traffic Gbps, total traffic Gbps), attack frequency times), threat probability .

[0052] Threat Level Calculation: ; High-performance data processing unit 4 and adaptive control system response: High-performance data processing unit 4 processes data at a throughput of 25.6Gbps FPGA filtering algorithm calculation (Does not reach the 0.9 threshold).

[0053] , isolation is not triggered, but the sensitivity is set to When adjusted to 0.9, alarm 122 is triggered (sound intensity 90 decibels, lasting 30 seconds), prompting the administrator to intervene manually.

[0054] Results: The abnormal traffic was intercepted at about 10Gbps, the data leakage rate was 0%, the server operation interruption time was less than 1 second, and the performance was restored to normal after recovery. .

[0055] Example 2: Financial transaction system protection scenario; In a certain bank transaction system, the data flow of computer motherboard 2 is as high as 20Gbps, which needs to be prevented from advanced persistent threats (APT).

[0056] After deployment, the device operates as follows: Hardware protection module 1 is configured: the administrator's identity is verified via fingerprint reader 121 (identification time 0.7 seconds), and physical isolation unit 12 is enabled. Encryption chip 11 encrypts in AES-256 mode, with a latency of 0.35ms, and it takes approximately 70ms to process 200MB of data.

[0057] Intelligent Threat Detection Module 3 operates: Data stream (D(t)) (20Gbps) is segmented and processed, V(t) feature vector is generated, and unknown threats are detected. Gbps), Second-rate).

[0058] Threat Level Calculation: High-performance data processing unit 4 and adaptive control system response: High-performance data processing unit 4 throughput 25.6Gbps, FPGA filtering (Not reached , triggering the disconnection of physical isolation unit 12 (response time 7ms), network interruption time is about 10ms. Alarm 122 is triggered (sound intensity 88dB).

[0059] This lasts for 5 seconds, triggering the self-destruct mechanism: the thermal fuse 5 heats up to 150°C, melting the power supply of the encryption chip 11 (taking 0.9 seconds), and the voltage overload circuit 6 outputs a high voltage of 12V, burning the NVRAM and destroying all keys.

[0060] Result: The APT attack was blocked, sensitive transaction data (approximately 500MB) was not leaked, and after the device completed self-destruction, the computer motherboard 2 was reset. Data recovery took approximately 2 hours, ensuring system security.

[0061] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A computer information security protection device, characterized in that: It includes hardware protection module, intelligent threat detection module, high-performance data processing unit, adaptive control system and self-destruct protection mechanism; The hardware protection module (1) is installed in the PCIe slot between the computer motherboard (2) and the network interface card, and is used to perform real-time encryption and physical isolation protection on input and output data streams; The intelligent threat detection module has a built-in deep learning-based threat detection algorithm to identify known and unknown network threats; The high-performance data processing unit uses a multi-core processor and an FPGA acceleration chip to efficiently analyze and filter data streams; The adaptive control system dynamically adjusts the protection strategy according to the real-time threat level; The self-destruct protection mechanism destroys key hardware components to protect data security when an irreversible attack is detected.

2. A computer information security protection device according to claim 1, characterized in that: The hardware protection module (1) includes an encryption chip (11) and a physical isolation unit (12); the encryption chip (11) is a TPM2.0 compatible chip, which is installed in the PCIe slot near the power input terminal of the motherboard and supports AES-256 and RSA-2048 dual encryption algorithms. The encryption process satisfies the following formula: Data encryption input ; Data decryption output ; Among them, M is the plaintext data, C is the ciphertext data, and k is the 256-bit key. , The physical isolation unit (12) uses a dual-channel relay switch and is installed at the network signal input end of the hardware protection module; a fingerprint identifier (121) and an alarm (122) are provided on the relay switch, the fingerprint identifier is used to verify the identity of the operator, and the alarm emits an audible and visual alarm when an unauthorized operation or threat is triggered.

3. A computer information security protection device according to claim 1, characterized in that: The threat detection algorithm of the intelligent threat detection module is based on a hybrid model of convolutional neural networks and long short-term memory networks. The specific implementation steps are as follows: Data preprocessing: The input data stream D(t) is segmented into 128-byte packets, and 64 eigenvalues are extracted from each packet using principal component analysis to generate a eigenvector ,in Represents the change of the i-th eigenvalue with time t, and the normalization formula is and are the mean and standard deviation of the i-th feature respectively; CNN feature extraction: calculated using a 3×3 convolution kernel ,in Extract from (V(t)); LSTM Time Series Analysis: Calculating Threat Probability in: is the original eigenvalue, is the mean, is the standard deviation, is the standardized eigenvalue, is the convolution kernel weight, (b) is the bias, F(t) is the feature output, 、 is the weight matrix, is the hidden state at the last moment, is the bias, P(t) is the range of threat probability P(t) O-1, is the Sigmoid function; when is considered a threat.

4. A computer information security protection device according to claim 1, characterized in that: The intelligent threat detection module (3) includes a dynamic feature database, which is arranged in the SSD storage unit below the hardware protection module. The dynamic feature database is updated once every 30 minutes, and the update formula is: Update threat signature increments ; Database capacity occupied S ; in: 、 is the amount of threat signature data, is the increment, S(t) is the database occupied capacity, and 0.3 is the compression factor.

5. A computer information security protection device according to claim 1, characterized in that: The high-performance data processing unit (4) includes an 8-core ARM Cortex-A76 processor and a Xilinx Zynq UltraScale+ FPGA chip, which is installed below the main heat sink in the center of the device and supports parallel processing of 32 data streams. The throughput calculation formula is: ; Where: T is the data throughput, is the number of channels, GHz is the clock frequency, bit is the data bit width, divided by 8 Convert bit / s to Gbps.

6. A computer information security protection device according to claim 1, characterized in that: The adaptive control system dynamically adjusts its strategy according to the threat level L(t). The threat level calculation formula is: ; Among them, L(t) is the threat level, P(t) is the threat probability, and the range of P(t) is O-1, is the abnormal traffic ratio, is the normalized attack frequency, The number of attacks in the past 24 hours, with a maximum of 100 times; When the device is in use, physical isolation or self-destruction mechanism is triggered.

7. A computer information security protection device according to claim 1, characterized in that: The self-destruct protection mechanism includes a thermal fuse (5) and a voltage overload circuit (6), which are installed above the encryption chip of the hardware protection module; When the threat level L(t)>0.98L(t)>0.98L(t)>0.98 and lasts for 5 seconds, the trigger mechanism: The thermal fuse heats up to 150°C, melting the encryption chip power line in less than 1 second; The voltage overload circuit outputs a 12V instantaneous high voltage, burning the NVRAM that stores the key.

8. A computer information security protection device according to claim 2, characterized in that: The dual-channel relay switch of the physical isolation unit is connected to the adaptive control system via the I2C bus, supporting manual and automatic switching. The leakage current in the isolated state is less than 0.5 μA, and the response time formula is: ms+4ms=7ms; where: is the total response time, ms is the signal transmission time, ms is the execution time; The fingerprint recognition device installed on the relay switch is a capacitive fingerprint sensor with a storage capacity of 50 fingerprint templates. The switch operation can be triggered only after successful verification. The alarm is a combination of a buzzer and an LED light. The triggering conditions include fingerprint verification failure for more than 3 times or , the alarm duration is 30 seconds.

9. A computer information security protection device according to claim 5, characterized in that: The FPGA chip has a built-in packet filtering algorithm, and the filtering rules are calculated based on weighted features: in, is the filter score, ranging from O to 1, 、 、 are the abnormal values of source IP, port number and packet length, and they are all normalized to 0-1; The processing delay is less than 40 microseconds.

10. A computer information security protection device according to claim 1, characterized in that: The device also includes a user-defined interface installed on the top of the device, connected via a USB 3.0 port, and supports parameter adjustment using a JSON format configuration file.

Citation Information

Cited By

  • Computer communication security processing device

    CN121441620A