A storage medium read-only lock device with a thunderbolt interface
Patent Information
- Application Number
- CN202522289025.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-29
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2035-10-29
AI Technical Summary
然而,这种方式的可靠性较低,因为其依赖于操作系统的正确性和稳定性,容易受到系统更新、驱动冲突或恶意软件的影响而失效
[0013]本实用新型具有如下有益效果:通过雷电接口接入主机和协议转换桥接芯片,通过协议转换桥接芯片支持雷电接口和PCIe接口之间的互相转换;协议转换桥接芯片的另一端连接所述FPGA只读锁,FPGA只读锁的另一端连接所述PCIe交换机芯片,所述PCIe交换机芯片,用于将输入数据通过所述FPGA只读锁单向传输至所述协议转换桥接芯片,并用于通过外接的扩展接口接入所述多种存储接口。这样,主机通过雷电接口连接设备,数据流经FPGA只读锁,该FPGA只读锁通过硬件层面的指令识别与过滤,强制执行只读策略,仅允许读取操作通过,拦截写入指令,通过PCIe交换机芯片负责扩展接口兼容性,支持多种接口的扩展,从而实现了数据以单向、只读的方式高速回传至主机,并提高了数据传输的可靠性。
Smart Images

Figure CN224789197U_ABST
Abstract
Description
Technical Field
[0001] This utility model relates to the field of data processing technology, specifically to a read-only lock device for storage media with a lightning interface. Background Technology
[0002] In the fields of data forensics and data recovery, the core technology for implementing read-only locks lies in the interception and logical filtering of data transmission commands. The most common and reliable technical implementation is a hardware read-only lock. This type of device acts as a physical "man-in-the-middle" between the computer host and the storage medium to be forensically examined. By inspecting and filtering all data commands sent from the host to the storage medium, it identifies and discards all write operation commands (such as write, format, delete, etc.), allowing only read operation commands (such as read, query, etc.) to pass through. This hardware-level interception bypasses the operating system, thus possessing extremely high reliability; even if the operating system has vulnerabilities or experiences unexpected events, it cannot write to the source medium.
[0003] Besides the mainstream hardware read-only locks, some implementations use software and operating systems to achieve read-only mode, but these are generally not considered independent and rigorous read-only lock technology implementations. For example, in certain operating systems or specific tools, storage devices can be temporarily set to read-only mode. However, this method has lower reliability because it depends on the correctness and stability of the operating system and is susceptible to failure due to system updates, driver conflicts, or malware. Utility Model Content
[0004] The purpose of this utility model is to provide a read-only lock device for storage media with a lightning interface, and the specific technical solution adopted is as follows: This utility model embodiment provides a storage medium read-only lock device with a Thunderbolt interface. The device includes: a Thunderbolt interface, a protocol conversion bridge chip, an FPGA read-only lock, a PCIe switch chip, and multiple storage interfaces. The Thunderbolt interface has one end connected to the host and the other end connected to the protocol conversion bridge chip, which supports mutual conversion between the Thunderbolt interface and the PCIe interface. The other end of the protocol conversion bridge chip is connected to the FPGA read-only lock, and the other end of the FPGA read-only lock is connected to the PCIe switch chip. The PCIe switch chip is used to unidirectionally transmit input data to the protocol conversion bridge chip via the FPGA read-only lock and to access the multiple storage interfaces via an external expansion interface.
[0005] In some possible implementations, the FPGA read-only lock includes: a base interface circuit, the base interface circuit including: a first capacitor and a second capacitor connected in parallel, the second capacitor being connected to a device port, an FPGA output port, and a connected switch input port; the base interface circuit is used to connect the PCIe upstream and downstream data transmission interfaces of the FPGA read-only lock.
[0006] In some possible implementations, the PCIe switch chip is also used to extend PCIe branch links to provide multiple storage interfaces through the PCIe branch links.
[0007] In some possible implementations, the expansion interface includes: a Type C interface and a PCIe expansion interface; wherein, the Type C interface is used to connect to various USB storage media; and the PCIe expansion interface is used to connect to various PCIe adapters and bridges to connect to data storage media with different interfaces and protocols.
[0008] In some possible implementations, the PCIe expansion interface is a standard PCIe slot used to connect a PCIe adapter card or bridge.
[0009] In some possible implementations, the expansion interface further includes a host bus adapter card, which is connected to the PCIe expansion interface for accessing different software systems.
[0010] In some possible implementations, the protocol conversion bridge chip is also used to convert the lightning signal output by the lightning interface into a PCIe signal and transmit it to the connected FPGA read-only lock; the FPGA read-only lock is also used to perform independent read-only control on different storage media connected to the multiple storage interfaces.
[0011] In some possible implementations, the PCIe switch chip, including read-only memory and crystal oscillator circuitry, is used to establish point-to-point data packet connections between upstream and downstream ports.
[0012] In some possible implementations, the size information of the device is smaller than a preset size threshold.
[0013] This invention offers the following advantages: It connects the host and a protocol conversion bridge chip via a Thunderbolt interface, supporting mutual conversion between the Thunderbolt and PCIe interfaces. The other end of the protocol conversion bridge chip connects to the FPGA read-only lock, and the other end of the FPGA read-only lock connects to the PCIe switch chip. The PCIe switch chip is used to unidirectionally transmit input data to the protocol conversion bridge chip via the FPGA read-only lock, and is also used to connect to various storage interfaces via external expansion interfaces. Thus, the host connects to the device via the Thunderbolt interface, and data flows through the FPGA read-only lock. This FPGA read-only lock enforces a read-only policy through hardware-level instruction recognition and filtering, allowing only read operations and blocking write commands. The PCIe switch chip handles interface compatibility expansion, supporting the expansion of multiple interfaces. This achieves high-speed, unidirectional, read-only data transmission back to the host and improves data transmission reliability. Attached Figure Description
[0014] To more clearly illustrate the technical solutions and advantages in the embodiments of this utility model or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this utility model. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0015] Figure 1 This is a schematic diagram of the composition structure of a storage medium read-only lock device with a lightning interface provided in an embodiment of this utility model; Figure 2 This is a schematic diagram of the circuit structure of a storage medium read-only lock device with a lightning interface provided in an embodiment of this utility model; Figure 3 This is another circuit structure diagram of a storage medium read-only lock device with a lightning interface provided in an embodiment of this utility model; Figure 4 This is another circuit structure diagram of a storage medium read-only lock device with a lightning interface provided in this utility model embodiment; Figure 5A This is another circuit structure diagram of a storage medium read-only lock device with a lightning interface provided in this embodiment of the utility model; Figure 5B This is another circuit structure diagram of a storage medium read-only lock device with a lightning interface provided in an embodiment of this utility model; Figure 6 This is another circuit structure diagram of a storage medium read-only lock device with a lightning interface provided in this utility model embodiment; Figure 7This is a schematic diagram of the implementation framework of a storage medium read-only lock device with a lightning interface provided in an embodiment of this utility model; Figure 8 This is a product diagram of the device provided in an embodiment of this utility model. Detailed Implementation
[0016] To further illustrate the technical means and effects adopted by this utility model to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of a storage medium read-only lock device with a lightning interface proposed according to this utility model. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments may be combined from any suitable form.
[0017] In the description of the embodiments of this utility model, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. "And / or" in the text is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of this utility model, "multiple" means two or more.
[0018] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature.
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0020] Although hardware read-only locks have provided highly reliable read-only protection in the field of data forensics, there are still some problems and shortcomings in products on the market that cannot be ignored, especially when dealing with increasingly complex storage technologies and rapidly changing forensics needs.
[0021] On the one hand, performance bottlenecks and efficiency issues are factors restricting the development of read-only locks. Although manufacturers emphasize performance improvements, hardware read-only locks inherently introduce additional latency because all data streams must pass through their internal processing. For large-capacity storage media exceeding terabytes, a complete read-only copy can consume a significant amount of time. If the throughput of the read-only lock is slower than the read speed of the source media, the entire forensic process will be slowed down, which is unacceptable in cases with extremely high time requirements. Moreover, with the widespread use of high-speed storage media such as NVMe SSDs, most read-only lock devices on the market, especially portable read-only locks, still use SATA or USB interfaces for data transfer with the host. The host's read speed from the storage media is less than 10Gbps, far from matching the high-speed data transfer characteristics of NVMe SSDs, severely restricting the efficiency of data forensics and copying, becoming the biggest bottleneck problem.
[0022] On the other hand, the portability and ease of use of read-only lock devices are also a significant pain point for users. Many professional hardware read-only locks, while powerful, are often bulky and inconvenient to move and carry, making them less flexible in on-site evidence collection scenarios requiring rapid response. In emergencies, forensic personnel need to be able to quickly deploy devices and connect directly to the computer or storage device being investigated; bulky hardware undoubtedly increases operational complexity and slows down emergency response. Some relatively small USB read-only locks can only connect to USB interface storage media and also suffer from speed bottlenecks. This utility model provides a plug-and-play, compact, and easy-to-operate read-only lock product that is convenient to carry and use, thereby significantly improving the efficiency and convenience of data forensics.
[0023] To address the pain points of read-only lock products in terms of performance, interface compatibility, portability, and ease of use, this utility model provides a novel portable read-only lock with a Thunderbolt interface. Specifically, the read-only lock connects to the host via the Thunderbolt interface, achieving a high-speed data transfer rate exceeding 30 gigabits per second (Gbps), thus resolving the bottleneck issue of evidence collection speed. Simultaneously, the read-only lock expands its interface compatibility by using a PCIe switch chip to support both Type-C and PCIe connections. The Type-C connection allows access to various USB storage media, while the PCIe connection, through expansion cards such as HBA cards, allows access to various storage media including SATA / SAS / NVMe, significantly enriching interface compatibility. Furthermore, the device's size is similar to a lunchbox, making it simple to operate, plug-and-play, and highly convenient for users to carry and use.
[0024] The specific solution of a storage medium read-only lock device with a lightning interface provided by this utility model is described below with reference to the accompanying drawings. Please refer to the attached drawings. Figure 1This diagram illustrates the structural composition of a storage medium read-only lock device with a Thunderbolt interface according to an embodiment of the present invention. The device 100 includes: a Thunderbolt interface 101, a protocol conversion bridge chip 102, an FPGA read-only lock 103, a PCIe switch chip 104, and various storage interfaces 105; wherein: Thunderbolt interface 101, one end is connected to the host, and the other end is connected to the protocol conversion bridge chip 102. The protocol conversion bridge chip is used to support mutual conversion between Thunderbolt interface and PCIe interface. Here, the Thunderbolt interface uses a Type-C connector and supports the Thunderbolt 3 / 4 protocol. Power is supplied to the Thunderbolt interface 101 through its peripheral circuitry and power supply circuitry, working in conjunction with the main chip to provide various functions including voltage regulation, interference suppression, and indicator light status display. The Thunderbolt interface is used to connect to the host, providing a high-speed data transmission channel; the Thunderbolt / PCIe bridge chip (i.e., protocol conversion bridge chip) is used to convert between the Thunderbolt and PCIe interfaces; the Thunderbolt interface connects to the host, and the PCIe interface connects to the FPGA read-only lock; the FPGA read-only lock is used to implement hardware-level write protection, allowing only unidirectional data transmission from the storage medium to the host and preventing reverse writes; the PCIe switch chip (i.e., PCIe switch chip) is used to expand PCIe branch links, providing multiple interfaces; at least one storage medium interface is used to connect to the storage medium, the storage interface including a Type-C interface and / or a PCIe expansion interface.
[0025] The other end of the protocol conversion bridge chip is connected to the FPGA read-only lock 103, and the other end of the FPGA read-only lock is connected to the PCIe switch chip 104. The PCIe switch chip is used to transmit input data unidirectionally to the protocol conversion bridge chip through the FPGA read-only lock, and is used to access the multiple storage interfaces 105 through an external expansion interface.
[0026] Here, the device's size is smaller than a preset size threshold, which can be a custom threshold, indicating that the device is portable. The host connects via a Thunderbolt interface, and data is transmitted to the core module, the FPGA read-only lock, via protocol bridging. The FPGA read-only lock utilizes the characteristics of a programmable gate array to enforce a read-only policy at the hardware level, acting as a "one-way valve" for the data flow. This ensures that data can only be read from the storage medium to the host, while any attempt to write is recognized, intercepted, and discarded by the FPGA. The interface compatibility is further expanded through a PCIe switch chip, enabling support for various storage media.
[0027] In some possible implementations, the protocol conversion bridge chip is powered by its external power supply circuit to support simultaneous compliance with both PCIe and Thunderbolt protocols. This allows the protocol conversion bridge chip 102 to transmit the converted data to the host via Thunderbolt, enabling the host to complete the data forensics process. This circuit powers the protocol conversion bridge chip and works in conjunction with the main chip to provide various functions, including voltage regulation, interference suppression, and indicator light status display. Figure 2 As shown, the circuit includes: resistors R0402, R0805, R0603, capacitors C310, C313, and C316, insulated-gate field-effect transistor Q6, insulated-gate field-effect transistor Q5, diode D22, etc.
[0028] In some possible implementations, the FPGA read-only lock includes: a base interface circuit that provides basic peripheral services to the FPGA read-only lock to support it as a data one-way valve, enabling the transmission of only messages sent from the PCIe switch chip 104 to the protocol conversion bridge chip 102. For example... Figure 3 As shown, the base interface circuit includes: a first capacitor and a second capacitor (i.e., C178 and C179) connected in parallel; the second capacitor is connected to the device port (i.e., PC-side PCIEX8), the FPGA output port (i.e., FPGA output PCIEX8), and a connected switch input port (i.e., SW input PCIEX8). This base interface circuit is used to connect the PCIe upstream and downstream data transmission interfaces of the FPGA read-only lock. The FPGA output PCIEX8 can also be connected to multiple resistors. C178 has a capacitance of 22 microfarads (µF), and C179 has a capacitance of 100 nanofarads (nF).
[0029] In some possible implementations, there are multiple storage interfaces 105, including PCIe expansion interfaces and various other interfaces (such as USB, SATA, SAS, etc.). Among the multiple storage interfaces 105, the PCIe expansion interface does not require a PCIe adapter card for interface data conversion to achieve communication between the PCIe expansion interface and the PCIe switch chip 104. However, the other various interfaces in the multiple storage interfaces 105 (such as USB, SATA, SAS, etc.) require a PCIe adapter card for data interface conversion before the converted data is transmitted to the PCIe switch chip 104, thus enabling communication between the PCIe expansion interface and the PCIe switch chip 104.
[0030] The PCIe switch chip 104 communicates with the FPGA read-only lock 103 via a PCIe adapter card. The PCIe switch chip 104 can communicate with multiple storage interfaces simultaneously and transmit information to the FPGA read-only lock 103 via the PCIe adapter card.
[0031] The FPGA read-only lock 103 acquires the communication data of the PCIe switch chip and transmits the communication data to the protocol conversion bridge chip 102 through the PCIe adapter card. The protocol conversion bridge chip 102 can support both PCIe protocol and Thunderbolt protocol at the same time.
[0032] The protocol conversion bridge chip 102 transmits the converted data to the host via the Thunder protocol, completing the complete data forensics process. That is, the host that supports the Thunder protocol accepts all data from different types of interfaces among the various storage interfaces 105.
[0033] Among them, the FPGA read-only lock 103 is a one-way valve for information transmission. This one-way valve only transmits messages sent from the PCIe switch chip 104 to the protocol conversion bridge chip 102, while all write messages sent from the protocol conversion bridge chip 102 to the PCIe switch chip 104 are intercepted. In this way, data from various storage media can be acquired simultaneously, at high speed and with high accuracy through this device.
[0034] In some possible implementations, the PCIe switch chip includes: Read-Only Memory (ROM), i.e. Figure 4 The SPI ROM (78.125MHz) and crystal oscillator circuit X1 are used to establish point-to-point data packet connections between upstream and downstream ports to achieve high-speed, low-latency multi-channel parallel communication.
[0035] Here, the PCIe switch chip is also used to extend PCIe branch links to provide multiple storage interfaces through these links. The functional principle of the PCIe switch chip is to "branch" the PCIe network into multiple PCIe links, allowing more devices to connect to the PCIe bus while intelligently managing and routing communication between these devices. The PCIe switch chip includes upstream interface circuitry and downstream interface circuitry, wherein the upstream interface circuitry, such as... Figure 5A As shown; downstream interface circuit, such as Figure 5B As shown, the upstream interface circuit functions by receiving PCIe signals and data packets from the CPU or Root Complex and forwarding them to various downstream devices. The downstream interface circuit functions by receiving data packets from the upstream that have been routed through the switch and accurately sending them to the corresponding downstream devices based on their destination addresses.
[0036] The power supply circuit of the PCIe switch chip, such as Figure 6 As shown, this power supply circuit can provide 5V to the PCIe switch chip to support data communication between the PCIe switch chip and the FPGA read-only lock 103 through the PCIe adapter card. Moreover, the PCIe switch chip can communicate with multiple storage interfaces simultaneously and transmit various communication information to the FPGA read-only lock through the PCIe adapter card. The power supply circuit includes: an inductor FB6, one end of which is connected to a 12-volt (V) power supply, and the other end is connected to a capacitor C163. The capacitor C163 is connected in parallel with capacitors C161 and C164. The other end of capacitor C164 is connected to a resistor R157, and the other end of resistor R157 is connected to a resistor R159. The power supply circuit also includes: a resistor R162, a capacitor C171, a module U4, a capacitor C170, a resistor R156, a capacitor C162, a capacitor C165, an inductor L2, a resistor R158, a resistor R163, a capacitor C166, a capacitor C167, a capacitor C168, and a capacitor C169.
[0037] In some possible implementations, the PCIe switch chip, including a read-only memory and a crystal oscillator circuit, is used to establish point-to-point data packet connections between upstream and downstream ports. The PCIe switch chip implements mutual conversion between USB and PCIe protocols, enabling high-speed transmission of external USB data storage media to the PCIe switch chip via the Type-C interface, while ensuring stable power supply voltage and anti-interference functions.
[0038] In some possible implementations, the expansion interface includes: a Type C interface and a PCIe expansion interface; wherein, the Type C interface is used to connect to various USB storage media; The PCIe expansion interface is used to connect to various PCIe adapters and bridges to access data storage media with different interfaces and protocols. The expansion interface also includes: a host bus adapter card, which is connected to the PCIe expansion interface for accessing different software systems; wherein, the PCIe expansion interface is a standard PCIe slot for connecting a PCIe adapter card or bridge.
[0039] The PCIe expansion interface circuit functions by connecting various PCIe adapter cards and expansion cards, enabling access to data storage media with almost all different interfaces and protocols. Examples include NVMe expansion cards for M.2 NVMe SSDs, SATA expansion cards for SATA, SAS expansion cards (HBA / RAID cards) for SAS, and adapter cards for various data storage media. The PCIe expansion interface can be understood as a universal interface, combining various adapter cards and expansion cards to achieve access to different data storage media.
[0040] In some possible implementations, the protocol conversion bridge chip is also used to convert the lightning signal output by the lightning interface into a PCIe signal and transmit it to the connected FPGA read-only lock. The FPGA read-only lock is also used to perform independent read-only control on different storage media connected to the multiple storage interfaces.
[0041] In this embodiment of the invention, the host and the protocol conversion bridge chip are connected via a Thunderbolt interface. The protocol conversion bridge chip supports mutual conversion between the Thunderbolt interface and the PCIe interface. The other end of the Thunderbolt interface is connected to the FPGA read-only lock, and the other end of the FPGA read-only lock is connected to the PCIe switch chip. The PCIe switch chip is used to unidirectionally transmit input data to the protocol conversion bridge chip through the FPGA read-only lock, and is also used to access the various storage interfaces through external expansion interfaces. In this way, the host connects to the device through the Thunderbolt interface, and the data flows through the FPGA read-only lock. The FPGA read-only lock enforces a read-only policy through hardware-level instruction recognition and filtering, allowing only read operations to pass and blocking write instructions. The PCIe switch chip is responsible for expanding interface compatibility and supporting the expansion of multiple interfaces, thereby realizing high-speed unidirectional, read-only data transmission back to the host and improving the reliability of data transmission.
[0042] Among some possible implementations, the core technical solution of this Thunderbolt read-only lock lies in building a system based on a high-speed Thunderbolt interface, and through flexible expansion, to achieve hardware-level read-only protection for various storage media. This system, for example... Figure 7As shown, the system consists of a host interface (module 1), a protocol conversion bridge chip (module 2), an FPGA read-only lock (module 3), a PCIe switch chip (module 4), and various storage interfaces (modules 5, 6, and 7). The host connects via a Thunderbolt interface, and data is transmitted to the core module, the FPGA read-only lock, via protocol bridging. This module utilizes the characteristics of a programmable gate array (FPGA) to enforce a read-only policy at the hardware level, acting as a "one-way valve" for the data flow, ensuring that data can only be read from the storage medium to the host, while any attempt to write is recognized and intercepted by the FPGA. Through the PCIe switch chip, the system further expands interface compatibility, supporting various interfaces including Type-C USB and PCIe expansion, and can flexibly connect to storage media such as SAS / SATA / NVMe, thus achieving support for various different storage media. Figure 7 In this module, Module 1 is a host with a Thunderbolt interface. The Thunderbolt-enabled storage medium read-only lock device connects to the host via the Thunderbolt interface. Module 2 is a Thunderbolt / PCIe bridge chip (i.e., a protocol conversion bridge chip), which enables mutual conversion between Thunderbolt and PCIe interfaces. One end of the Thunderbolt interface connects to Module 1, and the other end connects to Module 3. Module 3 is an FPGA read-only lock, possessing the core function of hardware-level read-only write protection. It connects Module 2 and Module 4, allowing data to be transmitted unidirectionally from Module 4 to Module 2, but not in reverse. Module 4 is a PCIe switch chip, enabling the expansion of PCIe branch links. Module 4 expands the interfaces of Modules 5 and 6. Module 5 has a Type-C interface, compatible with various USB storage media, including USB 3.2, 3.1, 3.0, and 2.0. Module 6 is a PCIe expansion interface, capable of connecting various PCIe adapters and bridges, enabling access to data storage media with different interfaces and protocols. Module 7 is an LSI. The 9500 HBA card connects to the PCIe interface of module 6 and enables the access of storage media such as SAS, SATA, and NVMe through the SFF-8654 interface; Module 8: data storage media with various interfaces and protocols.
[0043] In this system, data read requests originate from the host, pass through the Thunderbolt interface, and are converted to the correct protocol by the bridging chip before reaching the device. The data read command undergoes a "security check" by the FPGA read-only lock; once it confirms that it is only a read operation, the data flow is allowed. The data then travels through the PCIe switch to the corresponding storage interface (e.g., a directly connected USB device, or a SAS / SATA / NVMe storage medium connected via an HBA card). Data read from the storage medium passes through the storage interface and returns to the PCIe switch, where the FPGA read-only lock performs a final "release confirmation," ensuring that the data has not been tampered with or mixed with any write commands. Finally, it is converted to the Thunderbolt data transmission protocol by the bridging chip and transmitted back to the host at high speed. Due to the hardware-level interception characteristics of the FPGA read-only lock, all write commands are completely blocked before reaching the storage medium, thus ensuring the absolute security and integrity of the original data. By providing high-speed transmission through the Thunderbolt interface, combined with the hardware-level security protection of the FPGA, and the flexible expansion of multiple interfaces, this device effectively meets the dual demands of efficiency and compatibility in modern data forensics, providing a solid guarantee for the collection and analysis of digital evidence.
[0044] In this embodiment of the invention, the core technology of the Thunderbolt read-only lock lies in its constructed hardware-level unidirectional data transmission channel. The host connects to the device via a high-speed Thunderbolt interface, and data flows through the FPGA read-only lock, a key component. The FPGA enforces a read-only policy through hardware-level instruction recognition and filtering, allowing only read operations to pass and completely blocking any write instructions. The PCIe switch chip is responsible for expanding interface compatibility, supporting multiple interfaces such as Type-C USB and PCIe expansion, and further supporting storage media such as SAS / SATA / NVMe through an HBA card. Finally, data is transmitted back to the host at high speed in a unidirectional, read-only manner. This architecture fully utilizes the high-speed transmission characteristics of the Thunderbolt interface, combined with the hardware-level security of the FPGA and the flexible expansion of multiple interfaces, effectively solving the bottlenecks of traditional read-only locks in terms of performance, compatibility, and security, providing an efficient and reliable solution for digital forensics.
[0045] The read-only lock device with a Thunderbolt interface provided in this embodiment of the invention is of great significance in the fields of electronic data forensics, data copying, and data recovery. Its high-speed data transmission capability, thanks to the Thunderbolt interface, enables host transfer speeds exceeding 30Gbps, significantly shortening data mirroring and forensic time for large-capacity storage media, greatly improving work efficiency, especially crucial in cases with high time requirements. Furthermore, the device boasts broad compatibility and powerful expandability. It supports various interface storage devices such as USB, SATA, SAS, and NVMe, ensuring stable and reliable forensic operations in various data storage environments. The PCIe expansion channel provides excellent adaptability for connecting other storage devices and prepares the device for future emerging technologies, ensuring its technological lifecycle. Finally, the device's lightweight and portable design and plug-and-play functionality greatly enhance usability, making it convenient for users to carry and deploy. In conclusion, this Thunderbolt read-only lock not only improves data forensics efficiency and enhances data security, but also plays a vital role in addressing the challenges of technological change, making it a powerful tool in the field of data forensics.
[0046] In some embodiments, the appearance of a storage medium read-only latch device with a Thunderbolt interface is as follows: Figure 8 As shown, this Thunderbolt read-only lock is designed to provide high-speed and secure read-only access for data forensics and recovery. Its core strength lies in its integration of multiple interfaces and its hardware-level read-only protection mechanism to ensure the integrity of the original data.
[0047] The device connects to the host 82 via Thunderbolt interface 81 (module 1), and uses a Thunderbolt / PCIe bridge chip (module 2) to convert Thunderbolt signals into PCIe signals, which are then connected to the FPGA read-only lock (module 3). Module 3 is the key component of this device, implementing hardware-level read-only write protection, allowing data to be transferred unidirectionally from the storage medium to the host, and preventing any reverse writes.
[0048] Following the FPGA read-only lock is a PCIe switch chip (module 4), which expands to two interfaces: a Type-C interface 83 (module 5), compatible with USB storage media; and a PCIe expansion interface 84 (module 6), used to connect various PCIe adapters and bridges. By connecting an LSI 9500 HBA card (module 7), the device further expands its support for various storage media such as SAS, SATA, and NVMe (module 8), achieving broad compatibility with various mainstream storage media.
[0049] In this embodiment of the invention, Thunderbolt protocol is used to provide a data transmission rate exceeding 30Gbps, breaking through the performance bottleneck of traditional interfaces and significantly improving data transmission efficiency. Hardware-level write protection is implemented through a programmable logic device (FPGA) to ensure that data can only be read in one direction, fundamentally preventing data tampering. A PCIe switch chip is used to expand the interface, supporting multiple storage interfaces such as Type-C and PCIe, improving product compatibility and scalability. By integrating multiple storage interfaces (USB, SATA, SAS, NVMe, etc.) and expansion capabilities, broad support for mainstream and emerging storage media on the market is achieved. Thus, the ingenious structural design and plug-and-play characteristics significantly improve the portability and ease of use of the device, meeting the rapid deployment needs of on-site forensics.
[0050] Optionally, the transmission medium can be a wired link (e.g., but not limited to, coaxial cable, optical fiber, and Digital Subscriber Line (DSL)) or a wireless link (e.g., but not limited to, Wireless Fidelity (WIFI), Bluetooth, and mobile device networks). It should be noted that the control device provided in the above embodiments is only an example illustrating the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the computer device can be divided into different functional modules to complete all or part of the functions described above. Furthermore, the method embodiments provided in the above embodiments belong to the same concept, and their specific implementation processes are detailed in the method embodiments, and will not be repeated here.
[0051] Furthermore, this utility model embodiment also protects a control device, which may include a memory and a processor. The memory stores executable program code, and the processor is used to call and execute the executable program code to execute the storage medium read-only lock device with a Thunderbolt interface provided in this utility model embodiment. This embodiment can correspond to individual functional modules, or it can integrate two or more functions into one processing module. The integrated module can be implemented in hardware. It should be noted that the module division in this embodiment is illustrative and only represents a logical functional division; in actual implementation, there may be other division methods. It should also be noted that all relevant content of each step involved in the above embodiment can be referenced to the functional description of the corresponding functional module, and will not be repeated here.
[0052] It should be understood that the control device provided in this embodiment is used to execute the above-described storage medium read-only lock device with a Thunderbolt interface, and therefore can achieve the same effect as the device described above. When using an integrated unit, the control device may include a processing module and a storage module. When the control device is applied to a device, the processing module can be used to control and manage the device's actions. The storage module can be used to support the device in executing mutual program code, etc. The processing module may be a processor or a controller, which can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this utility model. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of Digital Signal Processing (DSP) and a microprocessor, etc., and the storage module may be a memory. Furthermore, the control device provided in the embodiments of this utility model may specifically be a chip, component, or module. The chip may include a connected processor and a memory; wherein the memory is used to store instructions, and when the processor calls and executes the instructions, the chip can execute the storage medium read-only lock device with a Thunderbolt interface provided in the above embodiments. This embodiment also provides a computer-readable storage medium storing computer program code. When the computer program code is run on a computer, the computer executes the aforementioned related method steps to implement the storage medium read-only lock device with a Thunderbolt interface provided in the above embodiment.
[0053] This embodiment also provides a computer program product. When the computer program product is run on a computer, it causes the computer to execute the aforementioned related steps to realize the storage medium read-only lock device with a Thunderbolt interface provided in the above embodiment. The control device, computer-readable storage medium, computer program product, or chip provided in this embodiment are all used to execute the corresponding device provided above. Therefore, the beneficial effects they achieve can be referred to the beneficial effects in the corresponding device provided above, and will not be repeated here. Through the description of the above embodiments, those skilled in the art can understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the control device can be divided into different functional modules to complete all or part of the functions described above. In the embodiments provided by this utility model, it should be understood that the disclosed control device and apparatus can be implemented in other ways. For example, the control device embodiments described above are merely illustrative. For example, the division of modules or units is merely a logical functional division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another control device, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual couplings, direct couplings, or communication connections can be indirect couplings or communication connections through some interfaces, control devices, or units, and can be electrical, mechanical, or other forms. It should be noted that the order of the above embodiments of this utility model is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. The processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired results. In some embodiments, multiple task processing and parallel processing are also possible or may be advantageous. The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. The above content is only a specific embodiment of this utility model, but the protection scope of this utility model is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this utility model should be included within the protection scope of this utility model.
Claims
1. A read-only lock device for a storage medium with a lightning interface, characterized in that, The device includes: a Thunderbolt interface, a protocol conversion bridge chip, an FPGA read-only lock, a PCIe switch chip, and various storage interfaces; wherein: The Thunderbolt interface is connected to the host at one end and to the protocol conversion bridge chip at the other end. The protocol conversion bridge chip is used to support mutual conversion between the Thunderbolt interface and the PCIe interface. The other end of the protocol conversion bridge chip is connected to the FPGA read-only lock, and the other end of the FPGA read-only lock is connected to the PCIe switch chip. The PCIe switch chip is used to transmit input data unidirectionally to the protocol conversion bridge chip through the FPGA read-only lock, and is used to access the various storage interfaces through an external expansion interface.
2. The apparatus according to claim 1, characterized in that, The FPGA read-only lock includes: a base interface circuit, which includes: a first capacitor and a second capacitor connected in parallel, the second capacitor being connected to a device port, an FPGA output port, and a connected switch input port; The base interface circuit is used to connect the PCIe upstream and downstream data transmission interfaces of the FPGA read-only lock.
3. The apparatus according to claim 1, characterized in that, The PCIe switch chip is also used to extend PCIe branch links to provide multiple storage interfaces through the PCIe branch links.
4. The apparatus according to claim 3, characterized in that, The expansion interface includes: a Type C interface and a PCIe expansion interface; wherein, the Type C interface is used to connect to various USB storage media; The PCIe expansion interface is used to connect to various PCIe adapters and bridges to access data storage media with different interfaces and protocols.
5. The apparatus according to claim 4, characterized in that, The PCIe expansion interface is a standard PCIe slot used to connect a PCIe adapter card or bridge.
6. The apparatus according to claim 5, characterized in that, The expansion interface also includes a host bus adapter card, which is connected to the PCIe expansion interface for accessing different software systems.
7. The apparatus according to claim 1, characterized in that, The protocol conversion bridge chip is also used to convert the lightning signal output by the lightning interface into a PCIe signal and transmit it to the connected FPGA read-only lock. The FPGA read-only lock is also used to perform independent read-only control on different storage media connected to the multiple storage interfaces.
8. The apparatus according to claim 1, characterized in that, PCIe switch chips, including read-only memory and crystal oscillator circuits, are used to establish point-to-point data packet connections between upstream and downstream ports.
9. The apparatus according to claim 1, characterized in that, The size information of the device is less than a preset size threshold.