Peripheral access management and control device and control method
By using an embedded system to manage multiple USB peripherals, hardware isolation and dynamic policy loading are employed to achieve accurate identification and access control of USB peripherals. This solves compatibility and security issues, improves interface availability and security, and is suitable for multi-platform environments.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- FUJIAN CENTM INFORMATION
- Filing Date
- 2026-01-15
- Publication Date
- 2026-05-19
AI Technical Summary
Existing USB peripheral management solutions suffer from compatibility issues and security risks, while hardware solutions sacrifice interface availability and fail to meet the usage requirements of legitimate peripherals.
This embedded system-based multi-USB peripheral management device achieves accurate identification and access control of multiple USB peripherals through hardware isolation and device identification, combined with dynamic policy loading. It utilizes detection modules and switching switches to manage devices at both the physical and protocol layers, independent of the host system.
It improves the availability and security of the interface, avoids the compatibility issues of traditional software solutions and the loss of availability of hardware solutions, supports cross-platform use, reduces deployment and maintenance costs, and has rapid response capabilities.
Smart Images

Figure CN122069063A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of peripheral access control technology, and in particular to a peripheral access management and control device and method. Background Technology
[0002] Currently, the management of USB peripherals is mainly achieved through whitelist software, which relies on the host system and also has compatibility issues. In addition, while some hardware solutions can block peripheral access, they sacrifice the availability of USB interfaces, making it difficult to meet the usage requirements of legitimate peripherals in business scenarios. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide a peripheral access management and control device and control method that improves interface availability while enhancing interface access security.
[0004] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows: A peripheral device access control device includes a peripheral device control module and a peripheral device switching module. The peripheral device switching module includes a switch and a detection module. The data output terminal of the detection module is connected to the data input terminal of the switch. The detection terminal of the detection module is connected to the detection terminal of the peripheral device control module, and the input terminal of the detection module is used to connect to the peripheral device. The first output terminal of the switch is connected to the peripheral device control module. The output terminal of the peripheral device control module is connected to the control input terminal of the switch. When the peripheral device control module detects that the peripheral device conforms to a built-in filtering strategy, it controls the second output terminal of the switch to connect to the host terminal through the control input terminal.
[0005] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows: A peripheral access control method is applied to a peripheral access control device as described above, the method comprising: The detection module detects the signal of the input interface. If an access signal is detected, the switch is controlled to connect to the peripheral control module. The peripheral device management module obtains device information of the connected peripheral devices, matches the device information with the filtering policy built into the peripheral device management module, and if the match is successful, controls the switch to connect to the host terminal.
[0006] The beneficial effects of this invention are as follows: By setting up a peripheral control module and a peripheral switching module, and connecting the detection module in the peripheral switching module to the input terminal of the switching switch and the detection terminal of the peripheral control module respectively, the peripheral control module is notified after a peripheral is detected to connect to the switching switch. The peripheral control module is then connected to the switching switch, and the peripheral data is collected and matched with the built-in filtering strategy. Only when the match is successful is the peripheral allowed to connect to the host terminal through the switching switch. This improves the availability of the interface while enhancing the security of the interface access to the host terminal. Attached Figure Description
[0007] Figure 1 This is a schematic diagram of the structure of a peripheral access control device according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a detection unit in a peripheral access control device according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of a switching switch in a peripheral access control device according to an embodiment of the present invention; Figure 4 This is a schematic diagram of another connection structure of a peripheral access control device according to an embodiment of the present invention; Figure 5 This is a flowchart illustrating the steps of a peripheral device access control method according to an embodiment of the present invention; Figure 6 This is a flowchart of another step in a peripheral access control method according to an embodiment of the present invention; Label Explanation: 100. Peripheral control module; 101. Peripheral control terminal; 102. Configuration terminal; 103. Selection module; 200. Peripheral switching module; 201. Switch; 202. Detection module. Detailed Implementation
[0008] To explain in detail the technical content, objectives, and effects of the present invention, the following description is provided in conjunction with the embodiments and accompanying drawings.
[0009] Definitions:
[0010] Currently, the USB interface has become the mainstream standard for connecting computers and external devices due to its plug-and-play functionality, high transmission speed, and wide compatibility. However, the convenience of USB peripherals also brings significant information security risks. Unauthorized USB devices (such as USB flash drives, external hard drives, and wireless network cards) connected to computers or internal networks may lead to data leaks, virus propagation, and malicious code injection, posing a serious threat to information security.
[0011] Regarding the security issues of peripheral device access, the current management of USB peripherals is mainly achieved through whitelist software. However, the software solution relies on the computer operating system. If the system is compromised or permissions are bypassed, the management measures may fail. Furthermore, the differences in drivers and permission mechanisms of different operating systems (such as Windows, Linux, and macOS) make it difficult to unify management strategies and cause compatibility issues. Therefore, whitelist software for different platforms needs to be developed repeatedly, and users need to pay for cross-platform software separately.
[0012] In addition, while some hardware solutions (such as physically blocking USB ports) can completely block access, they sacrifice the availability of USB interfaces, making it difficult to meet the needs of legitimate peripheral devices in business scenarios.
[0013] To address the aforementioned technical issues, this invention proposes a multi-USB peripheral management device and method based on an embedded system. Through technologies such as hardware isolation, device identification, and dynamic policy loading, it enables accurate identification, access control, and peripheral management of multiple USB peripherals at the physical and protocol layers without the need to install additional management software on the host computer. It also allows for cross-platform use, avoiding dependence on the host system.
[0014] Please refer to Figure 1 A peripheral access management device includes a peripheral management module 100 and a peripheral switching module 200. The peripheral switching module 200 includes a switching switch 201 and a detection module 202. The data output terminal of the detection module 202 is connected to the data input terminal of the switching switch 201. The detection terminal of the detection module 202 is connected to the detection terminal of the peripheral management module 100, and the input terminal of the detection module 202 is used to connect to the peripheral. The first output terminal of the switching switch 201 is connected to the peripheral management module 100. The output terminal of the peripheral management module 100 is connected to the control input terminal of the switching switch 201. When the peripheral management module 100 detects that the peripheral conforms to the built-in filtering strategy, it controls the second output terminal of the switching switch 201 to connect to the host terminal through the control input terminal.
[0015] As can be seen from the above description, the beneficial effects of the present invention are as follows: by setting up a peripheral control module 100 and a peripheral switching module 200, and connecting the detection module 202 in the peripheral switching module 200 to the input terminal of the switching switch 201 and the detection terminal of the peripheral control module 100 respectively, the peripheral control module 100 is notified after a peripheral is detected to connect to the switching switch 201. After collecting peripheral data, the peripheral data is matched with the built-in filtering strategy. Only when the match is successful is the peripheral allowed to connect to the host terminal through the switching switch 201. This improves the availability of the interface and enhances the security of peripherals accessing the host terminal through the interface.
[0016] In one embodiment of this application, the detection module 202 includes an OR gate unit; the input terminal of the OR gate unit is used to connect to a peripheral device; and the output terminal of the OR gate unit is connected to the detection terminal of the peripheral device control module 100.
[0017] As described above, by setting the OR gate unit, when the USB interface is not connected to a peripheral device, both data terminals of the USB interface are at a low level, causing the OR gate to output a low-level signal; while when the USB interface is connected to a peripheral device, the two data terminals of the USB interface include a low level and a high level, causing the OR gate to output a high-level signal, thereby enabling the detection of the USB interface being connected to a peripheral device.
[0018] In one embodiment of this application, the switching switch 201 includes a single-pole triple-throw unit; the control input terminal of the single-pole triple-throw unit is connected to the control input terminal of the switching switch 201; the data input terminal of the single-pole triple-throw unit is connected to the output terminal of the detection module 202; and the output terminal of the single-pole triple-throw unit is connected to the peripheral control module 100, the host terminal, or the circuit breaker.
[0019] As described above, the setup uses a single-pole triple-throw unit. Utilizing the gating function of the single-pole triple-throw unit, it can select and connect with the peripheral control module 100, the host terminal, or the disconnect terminal when it receives different control signals, thereby achieving the switching of different paths.
[0020] In one embodiment of this application, the peripheral switching module 200 includes at least two; each peripheral switching module 200 is connected to the peripheral control module 100 and the host terminal respectively.
[0021] As described above, by setting up multiple peripheral switching modules 200 and connecting them to the peripheral management module 100 and the host terminal respectively, each peripheral switching module 200 is independent and does not interfere with each other. They are only subject to the detection and control of the peripheral management module 100, and the peripheral management module 100 performs policy matching and path switching in sequence, thereby realizing the independent management and control function of multiple USB peripherals.
[0022] Another embodiment of the present invention provides a peripheral access control method, applied to a peripheral access control device as described above, the method comprising: The detection module 202 detects the signal of the input interface. If an access signal is obtained, it controls the switch 201 to connect with the peripheral control module 100. The peripheral device management module 100 obtains device information of the accessed peripheral device, matches the device information with the filtering policy built into the peripheral device management module 100, and if the match is successful, controls the switch 201 to connect to the host terminal.
[0023] As described above, when the detection module 202 detects the access signal of the input interface, it controls the switch 201 to connect with the peripheral management module 100. This ensures that when a peripheral is connected, it does not connect directly to the host terminal, but first connects to the peripheral management module 100. The peripheral management module 100 then obtains the device information of the connected peripheral and matches it with the built-in filtering policy. Only when the match is successful will the switch 201 be controlled to connect with the host terminal, thus allowing the peripheral to connect to the host terminal. This improves both the availability of the interface and the security of peripherals accessing the host terminal through the interface.
[0024] In one embodiment of this application, matching the device information with a built-in filtering strategy includes: The device information is parsed to obtain general device data and device characteristic data; The device's general data and characteristic data are matched with the filtering strategy. If all matches are successful, the switch 201 is controlled to connect to the host terminal.
[0025] As described above, by parsing device information to obtain general device data and device characteristic data, it is possible to match filtering strategies based on the general device data and device characteristic data, thereby achieving the matching of general peripherals and special peripherals with filtering strategies.
[0026] In one embodiment of this application, it further includes: The detection module 202 detects the signal of the input interface. If a disconnect signal is obtained, the switch 201 is controlled to switch to the disconnect end.
[0027] As described above, when the input interface is detected as disconnected, the control switch 201 is switched to the disconnect end. That is, at this time, the switch 201 is not connected to the host terminal or the peripheral control module 100, so that the peripheral control module 100 can recognize that there is no peripheral connected at present.
[0028] In one embodiment of this application, matching the device information with the built-in filtering strategy further includes: If the matching fails, the current state of the switch 201 is maintained, and the peripheral control module 100 is controlled to disconnect from the switch 201.
[0029] As described above, when a peripheral device does not meet the filtering policy, the current state of the switch 201 is maintained, that is, the switch 201 is still connected to the peripheral control module 100, while the peripheral control module 100 is disconnected from the switch 201, so that the peripheral control module 100 can recognize that a peripheral device is currently connected and identify that the peripheral device is an abnormal peripheral device.
[0030] In one embodiment of this application, the detection of the input interface signal by the detection module 202 includes: The signal of the input interface on each peripheral switching module 200 is polled and detected. For the target peripheral switching module 200 polled, if the target peripheral switching module 200 is already connected to the peripheral control module 100 and the filtering policy is not executed, then the device information is matched with the built-in filtering policy for the peripheral connected to the target peripheral switching module 200.
[0031] As described above, by polling and detecting each peripheral switching module 200, independent control of multiple USB peripherals is achieved.
[0032] In one embodiment of this application, the process of matching the device information with a built-in filtering strategy includes: Receive configuration request; The filtering strategy is obtained from the initiator of the configuration request according to the configuration request.
[0033] As described above, the filtering strategy can be updated based on the configuration request, enabling different filtering strategies to be configured in different application scenarios.
[0034] This embodiment uses a USB interface as an example to illustrate the peripheral access management device of the present invention: Please refer to Figure 1A peripheral access control device includes a peripheral control module 100 and a peripheral switching module 200; the peripheral switching module 200 includes a switch 201 and a detection module 202; the peripheral control module 100 includes a peripheral control terminal 101, a configuration terminal 102 and a selection module 103; the configuration terminal 102 is mainly used to input the filtering policy of USB peripherals and send the filtering policy to the peripheral control terminal 101 through the communication port; the peripheral control terminal 101 adopts a microcontroller with a USB Host interface.
[0035] The data output terminal of the detection module 202 is connected to the data input terminal of the switch 201; the detection terminal of the detection module 202 is connected to the detection terminal of the peripheral control module 100, and the input terminal of the detection module 202 is connected to the USB port A203 for connecting to a USB peripheral; the first output terminal of the switch 201 is connected to the USB port B204, and then connected to the selection module 103 of the peripheral control module 100 via the USB port B204, and the selection module 103 is connected to the peripheral control terminal 101; the output terminal (switching signal) of the peripheral control terminal 101 is connected to the control input terminal of the switch 201; when the peripheral control terminal 101 detects that the peripheral conforms to the built-in filtering strategy, it controls the second output terminal of the switch 201 to connect to the host terminal via the control input terminal (detection signal). When using a peripheral to access the control device, the USB port C205 of the peripheral access control device is connected to the host terminal; when a USB peripheral is needed, the USB peripheral is connected to the USB port A203 of the peripheral access control device.
[0036] Please refer to Figure 2In this embodiment, the detection module 202 includes an OR gate unit; the input of the OR gate unit is used to connect to a peripheral device; the output of the OR gate unit is connected to the detection terminal of the peripheral device control module 100. The detection module 202 can detect whether a USB peripheral device is connected to the USB port A203 without affecting the USB data signal. The OR gate unit is based on the real-time USB peripheral plugging and unplugging sensing mechanism designed according to the USB protocol and USB data signal specifications. Specifically: according to the USB protocol, the standard USB cable uses a 4-core connection, including the power line Vbus, the ground line GND, and the data lines D+ and D-. Since USB uses differential transmission mode, its data lines D+ and D- transmit data through differential signals. That is, when the USB peripheral device is connected to the host and is working normally, the levels of D+ and D- must be one high and one low. According to the USB protocol, both D+ and D- on the USB host side are connected to a 15K ohm pull-down resistor to ground by default. Therefore, it can be determined that when no USB peripheral device is connected, both D+ and D- on the host side are at a low level. In this embodiment, a high-impedance signal probe is added to each of the D+ and D- signal lines of the switch 201 connected to USB port A203 to detect the levels of D+ and D- respectively. The signals detected by the two probes are then input into a standard OR gate circuit, and the output signal of the OR gate circuit is used as the detection signal and connected to the peripheral control terminal 101. This ensures that when no USB peripheral is connected to USB port A203, both D+ and D- are low, and the detection signal output is low; when a USB peripheral is connected, one of D+ and D- must be high, and the detection signal output is high; when the USB peripheral is unplugged, D+ and D- return to low, and the detection signal returns to a low output level, thus enabling the peripheral control module 100 to detect the connection and disconnection of USB peripherals in the peripheral switching module 200.
[0037] Please refer to Figure 3In this embodiment, the switch 201 includes a single-pole triple-throw unit; the control input terminal of the single-pole triple-throw unit is connected to the control input terminal of the switch 201; the data input terminal of the single-pole triple-throw unit is connected to the output terminal of the detection module 202; the output terminal of the single-pole triple-throw unit is selectively connected to the peripheral management module 100, the host terminal, or the circuit breaker terminal. That is, the single-pole triple-throw unit is controlled by the peripheral management terminal 101 to switch the connection of the data signal of the USB peripheral connected to USB port A203: when the switch 201 is connected to the circuit breaker, the data signal of the USB peripheral is suspended; when the switch 201 is connected to USB port B204, the data line of the USB peripheral will be connected to the peripheral management module 100 through USB port B204 for USB enumeration and filtering strategy matching; when the switch 201 is connected to USB port C205, the data line of the USB peripheral will be connected to the USB HUB connected to the host terminal through USB port C205, thereby achieving connection with the host terminal.
[0038] Please refer to Figure 4 This embodiment also includes a method for managing multiple peripherals, which is achieved by combining a peripheral management module 100 with multiple peripheral switching modules 200. Each peripheral switching module 200 is connected to both the peripheral management module 100 and the host terminal. That is, the detection and control signals of each peripheral switching module 200 are connected to the peripheral management terminal 101, and the peripheral management terminal 101 polls and detects the USB peripheral access status of each peripheral switching module 200. In this embodiment, each peripheral switching module 200 is independent and does not interfere with each other. It is only subject to the detection and control of the peripheral management terminal 101, and the peripheral management terminal 101 performs policy matching and path switching sequentially through the selection module 103, thereby realizing the independent management function of multiple USB peripherals.
[0039] Please refer to Figure 5 as well as Figure 6 Regarding the aforementioned peripheral access control device, this embodiment provides a peripheral access control method, including: S0. Filtering policy configuration: The configuration terminal 102 sends the filtering policy to the peripheral management terminal 101, and then the peripheral management terminal 101 receives and saves the sent filtering policy.
[0040] S1. The input interface signal is detected by the detection module 202. If an access signal is detected, the switch 201 is controlled to connect to the peripheral control module 100. Specifically: S11. When a USB peripheral is connected to the USB port A203 of the device, the peripheral management terminal 101 identifies the peripheral connection through the detection module 202. S12. The peripheral management terminal 101 controls the switching switch 201 to connect the USB peripheral to the selection module 103 of the peripheral management module 100; that is, it controls the switching switch 201 to switch the USB peripheral to the USB port B204 to connect to the selection module 103, so that the peripheral management terminal 101 connects the newly connected USB peripheral to the USB Host port of the peripheral management terminal 101 through the control of the selection module 103.
[0041] S13. Since multiple USB peripherals may be connected simultaneously, the peripheral management terminal 101 will select a specific USB peripheral to connect to its USB Host interface via the control selection module 103. For example, by polling the signals of the input interfaces on each peripheral switching module 200, the data signals of USB peripherals that have been connected but not yet matched are switched to the selection module 103 via control signals. The selection module 103 is controlled by the peripheral management terminal 101 via selection signals, and only the USB data signals of the USB peripherals corresponding to the target peripheral switching module 200 that have been connected to the selection module 103 but for which the filtering policy has not yet been implemented are sequentially switched to the USB Host port of the peripheral management terminal 101. The peripheral management terminal 101 matches the device information of the peripherals connected to the target peripheral switching module 200 with the built-in filtering policy.
[0042] S2. After obtaining the device information of the accessed peripheral, the peripheral control module 100 matches the device information with the filtering policy built into the peripheral control module 100. If the match is successful, it controls the switch 201 to connect to the host terminal. Specifically: S21. After identifying a newly connected USB peripheral, the peripheral management terminal 101 performs a USB enumeration operation to obtain the device's USB device information. It then parses the device information to obtain general device data and device characteristic data. The general device data mainly includes information from the USB device descriptor, configuration descriptor, interface descriptor, and string descriptor, such as idVendor manufacturer ID, idProduct product ID, bDeviceClass and bDeviceSubClass device classes, bNumInterfaces number of interfaces, and bInterfaceClass and bInterfaceSubClass interface classes. Device characteristic data includes bString string information for the device and interfaces, Report descriptors, and, for HID devices, HID descriptors, etc., which are custom filtering strategies added based on device characteristics and requirements.
[0043] S22. Match the device's general data and device characteristic data with the filtering policy. If both match successfully, control the switch 201 to connect to the host terminal. That is, when the device's general data and device characteristic data match the corresponding description in the filtering policy, the USB peripheral is considered to meet the filtering policy. At this time, the peripheral management terminal 101 controls the switch 201 to switch the USB peripheral to USB port C205. USB port C205 is connected to the USB host port of the host terminal through a USB HUB. At this time, the USB peripheral will be directly connected to the host terminal.
[0044] S23. If the matching fails, the current state of the switch 201 is maintained, and the peripheral management module 100 is controlled to disconnect from the switch 201. At this time, the peripheral management terminal 101 controls the switch 201 to disconnect the USB interface of the USB peripheral.
[0045] S24. The peripheral device management terminal 101 detects the signal of the input interface through the detection module 202. If a disconnection signal is obtained, it controls the switch 201 to switch to the disconnection terminal. That is, when the USB peripheral is detected to be disconnected, the peripheral device management terminal 101 controls the switch 201 to disconnect the USB peripheral from the USB port B204 or the USB port C205 and connect it to the disconnection terminal.
[0046] In summary, this invention provides a technical solution for managing multiple USB peripherals by combining embedded systems with hardware isolation technology. Through the interception and parsing of the embedded device at the physical layer and USB protocol layer, and the collaboration between the peripheral management module and the peripheral switching module, a mechanism for dynamically switching the physical connection path of USB peripherals is established, enabling proactive management of peripherals. The hardware isolation mechanism completely avoids the risk of management failure caused by operating system permission vulnerabilities or malicious process injection in traditional software solutions, fundamentally improving security. Furthermore, the solution is completely independent of the host computer software (host terminal) ecosystem, requiring no driver or agent program installation on the host system, avoiding cross-operating system compatibility issues. The management logic is executed autonomously by the embedded device, ensuring the mandatory execution of peripheral access policies even if the host system is compromised or in an unauthorized state. It also supports dynamic policy configuration based on device information, allowing updates to the device's filtering policy library via a separate terminal. Policies are bound to the device rather than coupled to the host system, making the configured management device plug-and-playable for different platforms, significantly reducing deployment and maintenance costs in multi-terminal environments. Furthermore, its hardware-level protocol parsing and policy matching based on embedded MCUs can block abnormal device access within milliseconds, avoiding the control lag caused by system scheduling delays in traditional software solutions. The control process does not consume host system CPU or memory resources, making it particularly suitable for resource-constrained industrial control equipment or older terminals. It also ensures ease of use for legitimate peripherals, demonstrating significant commercial value and industry applicability.
[0047] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent modifications made based on the content of the present invention specification and drawings, or direct or indirect applications in related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A peripheral access control device, characterized in that, This includes peripheral control modules and peripheral switching modules; The peripheral switching module includes a switching switch and a detection module; The data output terminal of the detection module is connected to the data input terminal of the switch. The detection end of the detection module is connected to the detection end of the peripheral control module, and the input end of the detection module is used to connect to the peripheral. The first output terminal of the switch is connected to the peripheral control module; The output terminal of the peripheral control module is connected to the control input terminal of the switch. When the peripheral device management module detects that the peripheral device conforms to the built-in filtering policy, it controls the second output terminal of the switching switch to connect to the host terminal through the control input terminal.
2. The peripheral access control device according to claim 1, characterized in that, The detection module includes an OR gate unit; The input terminal of the OR gate unit is used to connect to a peripheral device; The output terminal of the OR gate unit is connected to the detection terminal of the peripheral control module.
3. The peripheral access control device according to claim 1, characterized in that, The switching switch includes a single-pole triple-throw unit; The control input terminal of the single-pole three-throw unit is connected to the control input terminal of the switching switch; The data input terminal of the single-blade three-throw unit is connected to the output terminal of the detection module; The output terminal of the single-pole triple-throw unit is selectively connected to the peripheral control module, host terminal, or circuit breaker.
4. A peripheral access control device according to claim 1, 2 or 3, characterized in that, The peripheral switching module includes at least two; Each of the peripheral switching modules is connected to the peripheral control module and the host terminal, respectively.
5. A method for managing peripheral device access, characterized in that, Applied to a peripheral access control device as described in any one of claims 1-4, the method includes: The detection module detects the signal of the input interface. If an access signal is detected, the switch is controlled to connect to the peripheral control module. The peripheral device management module obtains device information of the connected peripheral devices, matches the device information with the filtering policy built into the peripheral device management module, and if the match is successful, controls the switch to connect to the host terminal.
6. The peripheral device access control method according to claim 5, characterized in that, The step of matching the device information with the built-in filtering strategy includes: The device information is parsed to obtain general device data and device characteristic data; The device's general data and characteristic data are matched with the filtering strategy. If both matches are successful, the switch is controlled to connect to the host terminal.
7. The peripheral device access control method according to claim 5, characterized in that, Also includes: The detection module detects the signal of the input interface. If a disconnect signal is detected, the switch is controlled to switch to the circuit breaker position.
8. The peripheral device access control method according to claim 5, characterized in that, The step of matching the device information with the built-in filtering strategy also includes: If the matching fails, the current state of the switch is maintained, and the peripheral control module is controlled to disconnect from the switch.
9. A peripheral device access control method according to claim 5, characterized in that, The detection of signals from the input interface via the detection module includes: The system polls and detects the signals of the input interfaces on each peripheral switching module. For the target peripheral switching module that is polled, if the target peripheral switching module is already connected to the peripheral control module and the filtering policy is not executed, then the system performs the matching of the device information with the built-in filtering policy on the peripheral connected to the target peripheral switching module.
10. A peripheral device access control method according to claim 5, characterized in that, The process of matching the device information with the built-in filtering strategy includes: Receive configuration request; The filtering strategy is obtained from the initiator of the configuration request according to the configuration request.