Special network controlled terminal access device
Through the multi-layer security mechanism design of the dedicated network controlled terminal access device, the problem of insufficient legality judgment of the network access device is solved, and the security protection of the dedicated network is achieved, preventing illegal access and hardware damage, and ensuring network security.
Patent Information
- Application Number
- CN202521353768.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2035-06-30
AI Technical Summary
The existing network access devices lack an effective legality judgment mechanism, which leads to unauthorized equipment being able to easily access the network, increasing the difficulty of network security management, and the existing technology cannot detect illegal operations in a timely manner, making it difficult to prevent data leakage and system attacks.
A dedicated network controlled terminal access device is designed, including Ethernet cable locking mechanism, multi-level anti-picking self-locking mechanism, unlocking number recording mechanism, information sending mechanism and controlled terminal motherboard control mechanism. Through the linkage design of multi-layer security mechanisms, a full-chain security system is built, including network cable locking of custom line sequences, multi-level anti-picking self-locking, unlocking number recording, information transmission and motherboard control, forming a closed-loop response for detection-alarm-hardware damage.
It realizes legality control, physical pry protection, operational behavior audit and abnormal status alarms for dedicated network terminals, effectively resists malicious attacks, eliminates illegal plug-ins and unplugs and hardware damage, and ensures network security.
Smart Images

Figure CN223219154U_ABST
Abstract
Description
Technical Field
[0001] The utility model relates to the technical field of network access devices, and more specifically, to a dedicated network controlled terminal access device. Background Art
[0002] Existing network ports are highly versatile, allowing any host to easily connect to the network. Regardless of authorization or security risks, these hosts can connect to the network through these ports, creating an easy path for unauthorized users to steal or tamper with sensitive data. For example, unauthorized external devices could access private networks through general-purpose network ports, illegally obtaining confidential files or disrupting normal business operations.
[0003] The integrated nature of network ports means that almost all hosts have built-in network ports. This means that even with physical control over specific devices, it's still difficult to prevent malicious actors from exploiting the host's built-in network ports to illegally access private networks, significantly increasing the difficulty of network security management. Furthermore, simply disabling network ports in the BIOS doesn't fundamentally eliminate risks. Technically skilled users can easily bypass BIOS settings and re-enable network ports for illegal operations. The existing network security protection system lacks an effective warning mechanism for illegal use. Once security policies are bypassed or compromised, relevant personnel are unable to detect them in a timely manner, forcing them to react passively after the damage occurs. This makes it difficult to immediately contain serious consequences such as data leaks and system attacks, resulting in incalculable losses.
[0004] In the prior art, a dedicated network access method, device, storage medium and electronic device are disclosed in CN202210923685.1. The problem with this solution is that the terminal must first access the network before its legitimacy is judged and its traffic is finally diverted. There is a possibility of misuse from the moment of access to the network, and the problem of dedicated network and dedicated machine is not fundamentally solved. A dedicated network access method, relay UE, system and storage medium are disclosed in CN202210317344.X. This method is mainly for wireless services and is not suitable for use in wired networks. A dedicated network access method, computing device and storage medium are disclosed in CN202310076502.1. This method is characterized in that a specific plug-in needs to be installed on the host machine. This requirement may be rejected for a dedicated network.
[0005] In view of this, we propose a dedicated network controlled terminal access device. Utility Model Content
[0006] The purpose of the present utility model is to provide a dedicated network controlled terminal access device to solve the problems raised in the above background technology.
[0007] To achieve the above objectives, the present invention provides the following technical solutions:
[0008] A dedicated network controlled terminal access device includes an Ethernet cable locking mechanism, a multi-level anti-pry self-locking mechanism, an unlocking times recording mechanism, an information sending mechanism, and a controlled terminal mainboard control mechanism;
[0009] The Ethernet cable locking mechanism is used to connect the Ethernet cable, including the A-end interface and the B-end interface, both of which are provided with binding posts; the locking mechanism and the insertion confirmation auxiliary detection pin are provided on the outside of the A-end interface;
[0010] The B-end interface is provided with a motherboard connector connected to the control mechanism of the controlled terminal motherboard, a locking limit block adapted to the locking mechanism is provided on the outside of the B-end interface, and an access confirmation detection module connected to the insertion confirmation auxiliary detection pin is also provided on the B-end interface;
[0011] The multi-stage anti-theft self-locking mechanism includes a first-level self-locking detection module, a second-level self-locking module, and a linkage module that are electrically connected to each other. The first-level self-locking detection module is used to monitor whether the device is fully inserted into the PCIE slot;
[0012] The unlocking times recording mechanism includes a counting module and a timestamp module, and the counting module is electrically connected to the unlocking signal output terminal of the secondary self-locking module;
[0013] The information sending mechanism includes a short-time power supply module, an ESIM module and an information storage module;
[0014] The control mechanism of the controlled terminal mainboard includes a high voltage generation module and a retractable RJ45 short-circuit module;
[0015] The retractable RJ45 shorting module includes a mechanical locking unit and an anti-violent removal unit. After the mechanical locking unit is inserted into the RJ45 interface of the motherboard, a limit plate pops out to close the interface. The anti-violent removal unit is electrically connected to the ESIM module and triggers an alarm when abnormal tension is detected.
[0016] Preferably, the secondary self-locking module is a limit lock provided on the outer edge of the device housing and the mainboard;
[0017] The multi-stage anti-theft self-locking mechanism further comprises an anti-theft metal sheet and a micro switch. The anti-theft metal sheet covers the joint of the device shell, and the micro switch contacts the anti-theft metal sheet.
[0018] Preferably, the short-time power supply module is used to power the ESIM module when the main power supply is disconnected. The ESIM module is electrically connected to the micro switch and the counting module, and is used to receive the anti-theft trigger signal or the unlocking signal and send an alarm message; the information storage module is electrically connected to the ESIM module, and is used to store unsent alarm messages.
[0019] Preferably, the high voltage generating module is electrically connected to the mainboard power supply module via a T-type connecting mechanism, which has a built-in thyristor. When the micro switch is triggered, the thyristor is turned on, and the high voltage generating module outputs a 2KHz high frequency pulse to break down the mainboard power supply module.
[0020] Preferably, the number of mechanical locking units of the retractable RJ45 shorting module corresponds to the number of RJ45 interfaces on the mainboard, thereby achieving a one-to-one physical closure.
[0021] Compared with the prior art, the beneficial effects of the present invention are:
[0022] This utility model utilizes a multi-layered, interconnected security design to establish a comprehensive security system, from physical access control to hardware tamper protection. A customizable Ethernet cable lock mechanism and a multi-stage anti-tamper self-locking mechanism create a dual physical barrier, ensuring full network cable access and mechanical locking. This, combined with the PCIE slot's electromagnetic lock and interlocking stopper, prevents unauthorized insertion and removal, as well as foreign object intrusion. Unlock count tracking and a timestamp mechanism ensure operational traceability, while a USB-T interface facilitates easy access to audit data. A short-term power supply design for the information transmitter ensures alarm capability in power outages, while unsent information storage prevents data loss. When the anti-tamper mechanism is triggered, the controlled terminal's motherboard control mechanism simultaneously physically seals the high-voltage breakdown power supply module and the RJ45 interface, forming a closed-loop response loop of "detection-alarm-hardware tamper protection." This system provides a five-pronged security solution for dedicated network terminals: access legitimacy control, physical anti-tamper protection, operational auditing, abnormal status alarms, and hardware tamper blocking, effectively defending against malicious attacks and illegal operations targeting network access. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 It is a schematic diagram of the overall structure of the utility model;
[0024] Figure 2 This is a schematic diagram of the A-end interface and B-end interface structure of the utility model;
[0025] Figure 3 This is a schematic diagram of the multi-stage anti-theft self-locking mechanism of the utility model;
[0026] Figure 4 This is a schematic diagram of the information sending mechanism of the present utility model;
[0027] Figure 5 This is a schematic diagram of the control mechanism of the controlled terminal motherboard of the present utility model. DETAILED DESCRIPTION
[0028] The technical solutions in the embodiments of the present invention will be described clearly and completely below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments.
[0029] Example:
[0030] See also Figure 1-5 A dedicated network controlled terminal access device includes an Ethernet cable locking mechanism, a multi-level anti-pry self-locking mechanism, an unlocking times recording mechanism, an information sending mechanism and a controlled terminal mainboard control mechanism. Each mechanism is electrically connected through the device's main control circuit board; the multi-level anti-pry self-locking mechanism is electrically connected to the unlocking times recording mechanism, the information sending mechanism and the controlled terminal mainboard control mechanism; the Ethernet cable locking mechanism, the multi-level anti-pry self-locking mechanism and the controlled terminal mainboard control mechanism are all connected to the host machine mainboard.
[0031] The Ethernet cable locking mechanism is used to connect the Ethernet cable, including the A-end interface and the B-end interface, such as Figure 2 As shown, both the A-end interface and the B-end interface are provided with terminal posts; a locking mechanism and an insertion confirmation auxiliary detection pin are provided on the outside of the A-end interface; the B-end interface is provided with a mainboard connector connected to the control mechanism of the controlled terminal mainboard, and a locking limit block adapted to the locking mechanism is provided on the outside of the B-end interface. The B-end interface is also provided with an access confirmation detection module connected to the insertion confirmation auxiliary detection pin.
[0032] The Ethernet cable locking mechanism customizes the wiring sequence according to user requirements to prevent misuse of the device through conventional wiring sequences. The Ethernet cable locking mechanism triggers the network card operation condition as follows: The access confirmation detection module sends a start signal to the network card controller only when, and only when, the eight core wires of the Ethernet cable are fully inserted into the terminal posts of the A-end interface according to the customized wiring sequence, the insertion confirmation auxiliary detection pin is in electrical contact and conductive with the network cable core wires, and the mechanical lock is fully engaged with the locking limit block of the B-end interface to lock in place. This multi-condition linkage mechanism ensures that the network card can only operate when all core wires are fully connected to the A-end interface, the detection signal is conductive, and the mechanical lock is locked, effectively preventing bypass access by directly connecting to the B-end interface by skipping the A-end interface.
[0033] like Figure 3As shown, the multi-stage anti-theft self-locking mechanism includes a first-level self-locking detection module, a second-level self-locking module, and a linkage module, all electrically connected to each other. The first-level self-locking detection module monitors whether the device is fully inserted into the PCIE slot. Once the first-level self-locking detection module confirms that the device is connected to the motherboard PCIE slot, it sends a message to the linkage module, which notifies the second-level self-locking module to trigger a mechanical linkage to lock the device and the outer edge of the motherboard. Mechanical stoppers can also be installed around the PCIE slot, interlocking with the second-level self-locking module. When the second-level self-locking module is locked, the stoppers extend, preventing the device from being forcibly removed or other foreign objects from being inserted.
[0034] The secondary self-locking module is a limit lock installed on the outer edge of the device casing and the motherboard. The unlocking process of the multi-level anti-theft self-locking mechanism must meet the following requirements: after the key is inserted into the unlocking hole of the limit lock, it must be rotated clockwise at least 30° and reach 90° before the limit lock can be triggered to unlock and release the hard connection between this device and the host motherboard. During the unlocking process, the anti-theft metal sheet does not deform and the micro switch is not triggered.
[0035] The multi-level anti-theft self-locking mechanism also includes an anti-theft metal sheet and a micro switch. The anti-theft metal sheet and the micro switch constitute an anti-theft pressure-sensing module. The anti-theft metal sheet covers the seam of the device shell, and the micro switch contacts the anti-theft metal sheet. Once pried by external force, the anti-theft metal sheet deforms and triggers the internal micro switch, triggering subsequent protection actions.
[0036] The unlocking times recording mechanism is integrated on the main control circuit board of the device, and includes a counting module and a timestamp module. The counting module is electrically connected to the unlocking signal output end of the secondary self-locking module, and the timestamp module is electrically connected to the clock circuit. The unlocking times recording mechanism is provided with a USB-T interface for data reading. The data that can be read by the USB-T interface of the unlocking times recording mechanism include: the unique serial number of the device, the cumulative number of unlocking times, and the specific time of each unlocking.
[0037] The information transmission mechanism includes a short-term power supply module, an ESIM module, and an information storage module. The short-term power supply module is used to power the ESIM module when the main power supply is disconnected. The ESIM module is electrically connected to the microswitch and the counting module to receive the anti-pry trigger signal or unlock signal and transmit an alarm message. The information storage module is electrically connected to the ESIM module to store unsent alarm messages. The alarm message content of the information transmission mechanism includes: device serial number, alarm type (anti-pry trigger / normal unlock / violent removal), and alarm time.
[0038] Specifically, when the anti-theft metal sheet of the multi-level anti-theft self-locking mechanism is touched, the information sending mechanism is triggered. The built-in short-time power supply module of the information sending mechanism can be used to send alarm SMS messages, which does not depend on whether the device is correctly powered. The alarm text message can still be sent even when the motherboard is unplugged. When unlocked normally, the information sending mechanism will also be triggered to send a normal unlocking message. When the retractable RJ45 short-circuit module is forcibly opened, an alarm message will be sent that the original network port of the motherboard is enabled. It has the ability to store unsent information. When the information is not sent correctly, the last alarm message is stored in the register of this mechanism. It can be read directly from the information storage module through the USB-T interface.
[0039] The control mechanism of the controlled terminal motherboard includes a high-voltage generating module and a retractable RJ45 short-circuit module; the retractable RJ45 short-circuit module includes a mechanical locking unit and an anti-violent demolition unit. After the mechanical locking unit is inserted into the RJ45 interface of the motherboard, a limit plate pops out to close the interface. The anti-violent demolition unit is electrically connected to the ESIM module and triggers an alarm when abnormal tension is detected.
[0040] The high-voltage generator module is electrically connected to the motherboard power supply module via a T-connector mechanism, also known as a T-connector, which houses a built-in thyristor. When the microswitch is triggered, the thyristor conducts, and the high-voltage generator module outputs a 2kHz high-frequency pulse that breaks down the motherboard power supply module. The number of mechanical locking units in the retractable RJ45 shorting module corresponds to the number of RJ45 ports on the motherboard, achieving a one-to-one physical seal.
[0041] Specifically, under normal circumstances, the host power supply is connected to the motherboard power port via a T-shaped connector, ensuring normal power supply to the motherboard. When the multi-stage self-locking anti-tamper mechanism or the tamper-resistant module of the retractable RJ45 shorting module is triggered, the high-voltage generator module generates instantaneous high voltage and sends a 2kHz high-frequency pulse back to the power module via the T-shaped connector, destroying the power module and disconnecting power to the motherboard, preventing further use of the terminal. A retractable RJ45 network port shorting module (consisting of an anti-violent removal unit and a mechanical locking unit) is included to accommodate hosts of varying sizes. Once the shorting connector is inserted, the mechanical locking unit pops out, sealing the original motherboard RJ45 port. To release the shorting connector, a specific key is inserted into the shorting connector and rotated 90 degrees to unlock it. Upon normal unlocking, a message transmission mechanism is activated. If the shorting connector is forcibly removed, the anti-violent removal unit inside the shorting connector is activated, triggering the message transmission mechanism to send a violent removal warning message. The retractable RJ45 network port short-circuit module can be expanded, and the corresponding number of short-circuit mechanisms can be expanded according to the number of user RJ45 network interfaces for one-to-one management.
[0042] In this utility model, the Ethernet cable locking mechanism features a user-defined cable sequence. All eight network cables must be connected and the locking mechanism fully engaged for the network card to function properly, preventing the device from being used by other means without the cable locking mechanism. A multi-stage anti-pry self-locking mechanism: Once the first stage self-locking mechanism confirms the device is connected to the motherboard's PCIE slot, the second stage self-locking module triggers a mechanical linkage to lock the device to the motherboard's outer edge. To unlock, the second stage lock is first released. Once the key is inserted and rotated at least 30° and reaches 90°, the mechanical linkage is triggered to release the hard connection between the device and the motherboard. The second stage self-locking module features a pry-proof metal plate. Once pried, the metal plate deforms, triggering an internal microswitch and initiating subsequent protection actions. An unlock count recorder increments the device's count by one with each unlock. The device's serial number, unlock count, and unlock time can be read via the recorder's USB-T port. A message sending mechanism: This mechanism is triggered when an alarm message is generated. This mechanism has a built-in short-term power supply module, enabling SMS alerts to be sent independently of proper device power supply. Even if the motherboard is unplugged, it can still send information normally. It has the ability to store unsent information. If a message fails to be sent correctly, the last alarm information is stored in the device's register. The controlled terminal's motherboard control mechanism can generate a high-voltage, high-frequency signal to penetrate the motherboard's power supply module when the anti-tamper mechanism is triggered, preventing further use of the terminal. It can also physically seal the original motherboard's RJ45 port to prevent misuse.
[0043] The above shows and describes the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions are merely preferred examples of the present invention and are not intended to limit the present invention. Various changes and improvements may be made to the present invention without departing from the spirit and scope of the present invention, and such changes and improvements fall within the scope of the present invention. The scope of protection claimed in the present invention is defined by the appended claims and their equivalents.
Claims
1. A dedicated network controlled terminal access device, characterized in that: It includes an Ethernet cable locking mechanism, a multi-level anti-theft self-locking mechanism, an unlocking times recording mechanism, an information sending mechanism, and a controlled terminal mainboard control mechanism; The Ethernet cable locking mechanism is used to connect the Ethernet cable, including the A-end interface and the B-end interface; The multi-stage anti-theft self-locking mechanism includes a primary self-locking detection module, a secondary self-locking module and a linkage module electrically connected to each other; The unlocking times recording mechanism includes a counting module and a timestamp module, and the counting module is electrically connected to the unlocking signal output terminal of the secondary self-locking module; The information sending mechanism includes a short-time power supply module, an ESIM module and an information storage module; The controlled terminal mainboard control mechanism includes a high voltage generating module and a retractable RJ45 short circuit module; The retractable RJ45 short-circuit module includes a mechanical locking unit and an anti-violent removal unit. After the mechanical locking unit is inserted into the RJ45 interface of the motherboard, a limit plate pops out to close the interface. The anti-violent removal unit is electrically connected to the ESIM module and triggers an alarm when abnormal tension is detected.
2. A dedicated network controlled terminal access device according to claim 1, characterized in that: The A-end interface and the B-end interface are both provided with binding posts, and the outer side of the A-end interface is provided with a locking mechanism and an auxiliary detection pin for insertion confirmation; The B-end interface is provided with a mainboard connector, a locking limit block and an access confirmation detection module. The mainboard connector is connected to the mainboard control mechanism of the controlled terminal, the locking limit block is adapted to the locking mechanism, and the access confirmation detection module is connected to the insertion confirmation auxiliary detection pin.
3. A dedicated network controlled terminal access device according to claim 2, characterized in that: The secondary self-locking module is a limit lock provided on the outer edge of the device housing and the mainboard; The multi-stage anti-pry self-locking mechanism further comprises an anti-pry metal sheet and a micro switch. The anti-pry metal sheet covers the joint of the device housing, and the micro switch contacts the anti-pry metal sheet.
4. A dedicated network controlled terminal access device according to claim 3, characterized in that: The short-time power supply module is used to power the ESIM module when the main power supply is disconnected. The ESIM module is electrically connected to the micro switch and the counting module, and is used to receive the anti-theft trigger signal or the unlocking signal and send an alarm message; the information storage module is electrically connected to the ESIM module, and is used to store unsent alarm messages.
5. A dedicated network controlled terminal access device according to claim 4, characterized in that: The high voltage generating module is electrically connected to the mainboard power supply module via a T-type connecting mechanism, which has a built-in thyristor. When the micro switch is triggered, the thyristor is turned on, and the high voltage generating module outputs a 2KHz high frequency pulse to break down the mainboard power supply module.
6. A dedicated network controlled terminal access device according to claim 5, characterized in that: The number of mechanical locking units of the retractable RJ45 shorting module corresponds one-to-one to the number of RJ45 interfaces on the mainboard, thus achieving a one-to-one physical closure.
Citation Information
Patent Citations
Dedicated network access method, device, storage medium and electronic device
CN115297529B
Private network access method, computing device and storage medium
CN116055478A
Private network access method, relay UE, system and storage medium
CN116939765A