External protection device and method based on interface detection

The external protection device with interface detection and specialized security measures addresses the issue of misconnection and unauthorized access by ensuring only predetermined types of devices can connect, enhancing security protection.

JP2025524623AActive Publication Date: 2025-07-30BEIJING BEYONDINFO TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025501322
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-07-11
Filing Date
2023-06-14
Publication Date
2025-07-30
Estimated Expiration
2043-06-14

AI Technical Summary

Technical Problem

Conventional security protection devices fail to provide specialized security measures tailored to different types of external devices, leading to increased security risks due to misconnection and unauthorized access.

Method used

An external protection device with interface detection capabilities, including a switch module, device type detection, and alarm module, which ensures that only predetermined types of external devices can connect to the protected device, and provides specialized security protection based on device type and content analysis.

Benefits of technology

The device effectively controls access of predetermined types of external devices, reducing security risks by ensuring appropriate connections and providing specialized security protection for different types of devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025524623000001_ABST
    Figure 2025524623000001_ABST
Patent Text Reader

Abstract

To provide an external protection device and method based on interface detection. 【Solution means】 The internal interface of the device is connected to the device to be protected, and the external interface is connected to an external device that needs to access the device to be protected, and is connected to the internal interface one-to-one via a switch module. At least two of the external interfaces are used to connect to a predetermined type of external device, and each internal interface is used to connect to all the external interfaces of the device to be protected one-to-one. The present invention detects the type of the external device connected to any external interface of the external protection device, and instructs the switch module to connect or disconnect the internal interface corresponding to the external interface according to the detection result, and an alarm sounds. The present invention adopts a specialized interface technology and helps to take security protection measures specialized for different types of external devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of device information security protection, and particularly relates to an external protection device and method based on interface detection.

Background Art

[0002] In recent years, with the development of computer and network technologies, the popularity of the network has advanced significantly. While people enjoy the convenience brought by the network, they are also facing new threats to network security and data security. Common threats include the intrusion of malicious code, virus / Trojan horse infection, DDoS attacks, information theft by hackers, unauthorized access, impersonation of legitimate users, destruction of data integrity, interference with the normal operation of the system, spread of viruses using the network, man-in-the-middle attacks, and so on.

[0003] To solve network security or data security problems, there are many technical methods such as installing and using network security products such as black / white lists, traffic control software, firewalls, antivirus software, and intrusion detection systems on hosts. However, even if the above methods are taken, various security incidents occur frequently. According to statistics, more than 80% of security incidents are caused by internal personnel illegally using major resources such as hosts, and the actual external threats are less than 20%. Due to the lack of security awareness when internal personnel use hosts and being behind the firewall, the access to various external devices is not standardized, and there are backdoors for viruses or Trojan horses embedded, which may lead to data leakage, virus infection, system crashes, and even network paralysis. In addition, incorrect operations or intentional destruction of the system may also cause adverse effects and significant losses.

[0004] In addition, in the case of some special devices, such as hosts equipped with special software control, and devices of engineering workstations / operator stations in specific industrial fields, suitable security protection software may not exist in the market, or problems of compatibility with the existing software of the host are likely to occur when installing security software, and it may further affect the performance. Note that after the official operation of the hosts of these engineering workstations or operator stations, basically the operating system is not upgraded, security protection software is not installed, and even after security software is installed, the software version and malicious code library are often not updated in a timely manner, resulting in a decline in the effectiveness and efficiency of security protection.

[0005] Therefore, in the prior art, an external terminal protection device (also called an external protection device) and a corresponding protection system (Patent Document 1) for solving the above problems are disclosed. The external protection device (External Protective Device, EPD) takes over each external interface of the protected device (Protected Device, PD), and enables an external device that needs to access various external interfaces of the protected device to be able to access only by connecting to the external protection device, so as to achieve the purpose of protecting the protected device without installing security protection software on the protected device.

[0006] However, for some interfaces, such as the USB interface, a wide variety of external devices are supported. For external devices that support the same interface standard but have different signal and content transmission modes, when connected to the PD via the EPD, the resulting risk patterns may be different. Therefore, according to the specific external device type, specialized security protection suitable for the device type must be implemented to effectively improve the level of security protection. However, the conventional EPD cannot do this yet.

Prior Art Documents

Patent Documents

[0007]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0008] An object of the present invention is to solve the technical problem that in the conventional security protection design, it is impossible to provide specialized security protection suitable for different types of external devices for different types of external devices.

Means for Solving the Problems

[0009] To solve the above technical problem, one aspect of the present invention proposes an external protection device based on interface detection, which includes an internal interface for connecting to a device to be protected, an external interface for connecting to an external device that needs to access the device to be protected, and a switch module. The external interface is connected to the internal interface one-to-one via the switch module, at least two of the external interfaces are used to connect to a predetermined type of external device, the type and number of the internal interfaces match the type and number of the external interfaces, and each internal interface is used to connect to all the external interfaces of the device to be protected one-to-one. The external protection device further includes a device type detection module and an alarm module. The device type detection module detects the type of the external device connected to any external interface, sends an alarm command to the alarm module according to the detection result, and instructs the switch module to connect or disconnect the internal interface corresponding to the external interface. The alarm module sounds an alarm according to the received alarm command.

[0010] According to a preferred embodiment of the present invention, when the type of the detected external device does not match the predetermined type of the external interface, the device type detection module instructs the switch module to disconnect the connection of the internal interface corresponding to the external interface, and sends an alarm command to the alarm module. When the type of the detected external device matches the predetermined type of the external interface, it is used to instruct the switch module to connect the internal interface corresponding to the external interface.

[0011] According to a preferred embodiment of the present invention, the external protection device further includes a content monitoring module for reviewing the data content from the external interface and instructing the switch module to connect or disconnect the internal interface corresponding to the external interface according to the content review result.

[0012] According to a preferred embodiment of the present invention, the content monitoring module includes a mirror module for mirroring the pass-through data from the external interface, and a data analysis module for analyzing all the data from the external interface and sending an alarm command to the alarm module according to the analysis result.

[0013] According to a preferred embodiment of the present invention, the external interface includes a tandem type serial external interface and a pass-through type serial external interface, the internal interface includes a tandem type serial internal interface and a pass-through type serial internal interface corresponding to the tandem type serial external interface and the pass-through type serial external interface one by one, and the data analysis module is used to analyze the data from the tandem type serial external interface and send an alarm command to the alarm module according to the analysis result.

[0014] According to a preferred embodiment of the present invention, the mirror module is used to mirror pass-through data from a pass-through type serial external interface, and the data analysis module is also used to analyze the pass-through data of the pass-through type serial external interface and send an alarm command to the alarm module according to the analysis result.

[0015] According to a preferred embodiment of the present invention, the external interface includes a USB external interface, the internal interface includes a USB internal interface corresponding to each USB external interface one by one, and a predetermined type of each USB external interface is the same as the type of the USB external interface of the protected device connected to the corresponding USB internal interface.

[0016] According to a preferred embodiment of the present invention, the USB external interface includes at least two predetermined types of a storage class USB external interface, a HID class USB interface, and a non-storage non-HID class USB interface.

[0017] According to a preferred embodiment of the present invention, the external interface includes a network external interface, and the internal interface includes a network internal interface connected to the network external interface.

[0018] According to a preferred embodiment of the present invention, the external protection device is used to send the data received from the network external interface to the network internal interface after confirming the validity of the data.

[0019] According to a preferred embodiment of the present invention, the external protection device detects whether a data cable or device connected to each external interface has been unplugged, detects whether a data cable connected to the internal interface has been unplugged, and detects whether a data cable connected to the internal interface has been unplugged from the device to be protected. After detecting the unplugged state described above, an alarm command is sent to the alarm module.

[0020] Another aspect of the present invention proposes an external protection method based on interface detection, including the following steps: taking over all external interfaces of the device to be protected using an external protection device, and connecting each internal interface of the external protection device to all external interfaces of the device to be protected one-to-one; connecting the external interface and the internal interface of the external protection device one-to-one by a switch module, and matching the type and number of the internal interfaces of the external protection device with the type and number of the external interfaces; determining at least two of the external interfaces for connecting external devices of a predetermined type; detecting the type of an external device connected to an arbitrary external interface of the external protection device, and instructing the switch module to connect or disconnect the internal interface corresponding to the external interface according to the detection result; and sounding an alarm according to the detection result.

[0021] According to a preferred embodiment of the present invention, when the detected type of the external device does not match the predetermined type of the external interface, the switch module is instructed to disconnect the connection of the internal interface corresponding to the external interface, and an alarm sounds. When the detected type of the external device matches the predetermined type of the external interface, the switch module is instructed to connect the internal interface corresponding to the external interface.

[0022] According to a preferred embodiment of the present invention, the method further includes the step of reviewing the data content from the external interface and instructing the switch module to connect or disconnect the internal interface corresponding to the external interface according to the content review result.

[0023] According to a preferred embodiment of the present invention, the step of reviewing the data content from the external interface includes mirroring the pass-through data from the external interface, analyzing all the data from the external interface, and sounding an alarm according to the analysis result.

[0024] According to a preferred embodiment of the present invention, the method detects whether the data cable or device connected to each external interface is unplugged, detects whether the data cable connected to the internal interface is unplugged, and detects whether the data cable connected to the internal interface is unplugged from the external interface of the protected device. After detecting the unplugged state described above, the method further includes the step of sounding an alarm.

Effect of the Invention

[0025] The external protection device of the present invention can control the connection of corresponding predetermined types of external devices to different external interfaces, realize a specialized interface, and overcome the security risk caused by the misconnection of the external device interface.

[0026] Based on the specialized interface, the external protection device of the present invention can take security protection measures specialized for different types of external devices to improve the security protection performance.

Brief Description of the Drawings

[0027]

Fig. 1A

Fig. 1B

Fig. 2

Fig. 3

Fig. 4

Embodiments for Carrying Out the Invention

[0028] As described above, for a highly versatile interface such as a USB interface, various types of external devices can be accessed. In order to perform specialized security protection suitable for the device type based on the specific type of external device and improve the level of security protection, the present invention proposes a "specialized interface" design for use in an External Protective Device (EPD). The "specialized interface" in the present invention does not connect devices of different interface standards in the general sense to corresponding interfaces, but rather connects different types of devices with the same interface standard to interfaces with the same interface standard but different predetermined types. It should be noted that, for example, in the case of a USB interface, device types conforming to the USB interface standard include many types such as storage classes (USB flash drives, mobile hard drives, etc.), HID classes (Human Interface Devices such as mice, keyboards, game controllers, etc.), and non-storage non-HID classes (dongles, etc.). Obviously, it is not appropriate to use the same security protection measures for different types of USB devices. Therefore, the present invention determines in advance the type of specific external device to be connected to different external interfaces in the External Protective Device (EPD). Also, in order to ensure that the type of the connected device is correct, the present invention detects the type of the connected external device, checks whether a predetermined type of external device corresponding to the external interface is connected, and controls connection and disconnection according to the detection result, so that only external devices of a type that matches the predetermined type can access the protected device. Since external devices of a mismatched type cannot access the protected device through the external protection device, the present invention can overcome the security risk caused by incorrect connection of the external device interface.

[0029] On the one hand, due to the above design, the external protection device of the present invention can control the access of corresponding predetermined types of external devices on different external interfaces. Therefore, the external protection device of the present invention can provide security protection specialized for different types of external devices.

[0030] To make the objectives, technical means and advantages of the present invention clearer, the specific embodiments of the present invention will be specifically described below with reference to the drawings.

[0031] (The First Embodiment) FIG. 1A is a schematic configuration diagram of an external protection device based on interface detection according to the first embodiment of the present invention. As shown in FIG. 1A, the external protection device 100 of this embodiment is used to take over each interface of the device to be protected 200 and perform security protection. The external protection device 100 includes an internal interface, an external interface, and a switch module 130. The internal interface includes internal USB interfaces B1, B2, B3 and internal serial interfaces D1, D2. The external interface includes external USB interfaces A1, A2, A3 and external serial interfaces C1, C2. The internal interface is used to connect to the device to be protected 200, and the external interface is used to connect to external devices that need to access the device to be protected. Each of the external interfaces A1, A2, A3, C1, C2 is connected to the internal interfaces B1, B2, B3, D1, D2 one-to-one via the switch module 130.

[0032] It should be noted that the external interface and the internal interface correspond one-to-one and have a fixed correspondence relationship. That is, the external interfaces A1, A2, A3, C1, C2 are respectively connected to the internal interfaces B1, B2, B3, D1, D2. The switch module 130 only plays a role in connection and disconnection control without having an inter-switching function. This is the basis for realizing the "specialized interface" of the present invention.

[0033] As described above, in this embodiment, there are five external interfaces and five internal interfaces, and they correspond to each other one by one. However, this is merely an example, and the present invention does not limit the number of external interfaces and internal interfaces. It is necessary to ensure that any internal interface has a corresponding external interface uniquely, and any external interface has a corresponding internal interface uniquely. In a scheme where there is only one external interface and one internal interface, there is no need to set such a correspondence relationship. Therefore, the present invention is only applicable to embodiments where there are two or more external interfaces (and there must also be two or more internal interfaces).

[0034] According to the present invention, each internal interface is used to connect to all the interfaces of the device to be protected one by one. In other words, each interface on the device to be protected is taken over by the external protection device of the present invention, and there is no interface that is not taken over on the device to be protected. This is to avoid the security risk caused by directly inserting an external device into the device 200 to be protected, ensuring that all interfaces of the device to be protected are protected without omission by the external protection device of the present invention.

[0035] According to the present invention, the USB external interface of this embodiment is used to connect a predetermined type of external device. As described above, the so-called predetermined type not only means the standard adopted by the interface, but also different types of external devices that support the same interface standard. In this embodiment, the three USB external interfaces A1, A2, and A3 are respectively predetermined to connect to USB external devices of the storage class (such as USB flash drives, mobile hard drives, etc.), USB external devices of the HID class (Human Interface Device, such as mice, keyboards, game controllers, etc.) and USB external devices of the non-storage non-HID class (such as dongles). Since the type of the serial device itself is not clearly distinguished, in this embodiment, for the two serial external interfaces C1 and C2, the type of the external device to be connected is not predetermined.

[0036] Since the internal interface and the external interface correspond one-to-one, in this embodiment, the internal interfaces B1, B2, and B3 are respectively interfaces of a predetermined type, that is, the three USB internal interfaces B1, B2, and B3 are also respectively predetermined to connect to USB external devices of the storage class (such as USB flash drives, mobile hard drives, etc.), USB external devices of the HID class (Human Interface Device, such as mice, keyboards, game controllers, etc.) and USB external devices of the non-storage non-HID class (such as dongles).

[0037] To attract the user's attention, a label with predetermined type information can be pasted near the interface. For both the internal interface and the external interface, an easily distinguishable indicator such as a label can be provided on the interface accessories.

[0038] In this embodiment, since the internal interfaces B1, B2, and B3 all have a predetermined type, when the protected device 200 is connected, the interface of the protected device 200 to be taken over can be selected and connected according to the predetermined interface types of the internal interfaces B1, B2, and B3. Of course, if the external interface of the protected device 200 does not specify a specific type of external device, as long as the interface specifications match, the internal interface of the external protection device 100 can be connected to the external interface of any protected device 200. However, as described above, it should be noted that in order to provide comprehensive and effective protection, all interfaces of the protected device 200 need to be taken over by the external protection device 100.

[0039] In this embodiment, since the USB interfaces U1 and U2 of the protected device 200 do not predefine the types of external devices to be connected, they can be respectively connected to the internal interfaces B1 and B3 of the external protection device 100. However, in practice, the USB interfaces U1 and U2 can be connected to any two of the internal interfaces B1, B2, and B3. The serial interface S of the protected device 200 is connected to the serial internal interface D2 of the external protection device 100. Similarly, it can also be connected to the serial internal interface D1.

[0040] Referring to FIG. 1A again, the external protection device of this embodiment further includes a device type detection module 110 and an alarm module 140. The device type detection module 110 detects the type of an external device connected to any external interface, sends an alarm command to the alarm module 140 according to the detection result, and instructs the switch module 130 to connect or disconnect the internal interface corresponding to the external interface. The alarm module 140 sounds an alarm according to the received alarm command.

[0041] The device type detection module 110 can be implemented by an electronic device having a data processing function such as a DSP, an MCU, a PLC, or an FPGA. The basic function is to connect to each USB external interface A1, A2, A3, and determine whether a USB external device is connected based on the change in current or voltage of the pins of the external interface. When it is determined that a USB external device is connected, the type of the connected USB external device is determined. Specifically, generally there are several judgment methods. One method is to directly read the type information of the USB external device including information such as the device subclass, VID, PID, and serial number, and determine the type of the USB external device based on the type information of the USB external device. Another method is to test the communication of the USB external device, analyze the protocol adopted by the USB external device during communication, obtain information such as the device subclass, VID, PID, and serial number included in the protocol data, and thereby determine the type of the USB external device. In addition, the switch module 130 first connects the external interface corresponding to the USB external device to the corresponding internal interface so that the USB external device and the device to be protected are connected, monitors the protocol communication data between the USB external device and the device to be protected, obtains information including the device subclass, VID, PID, serial number, etc., and thereby determines the type of the USB external device.

[0042] When the device type detection module 110 detects the type of a USB external device connected to any of the USB external interfaces A1, A2, and A3, it compares the detected type with a predetermined type of the USB external interface to determine whether they match. For example, the predetermined type of the USB external interface A1 is an external device of the USB storage class. When the user connects a USB mouse to the USB external interface A1, the device type detection module 110 determines that the types of the connected external devices do not match, sends an alarm command to the alarm module 140, and instructs the switch module 130 to keep the external interface disconnected from the corresponding internal interface. After receiving the alarm command, the alarm module 140 sounds an alarm, and the alarm sound may be any operation that attracts the user's attention, including sounds, lights, and electricity such as a buzzer.

[0043] Preferably, the device type detection module 110 is also used to detect the legitimacy of the connected external device. The so-called legitimacy is a relative concept with respect to the illegal operation of an illegal device. An illegal device generally refers to an external device that mimics a USB external device and has some hidden function. This hidden function often poses a security risk to the device to be protected. The present invention can incorporate a function of detecting the legitimacy of a device into the device type detection module 110 by, for example, writing a program corresponding to a DSP. As an example, the device type detection module 110 detects whether an external device connected to the USB external interface A2 is a USB external device of the HID class. For example, when a mouse is connected to the external interface A2, the device type detection module 110 determines that it belongs to a USB external device of the HID class. At this time, in order to detect the legitimacy of the mouse, the device type detection module 110 starts a legitimacy detection program and, for example, executes protocol analysis to determine whether the external device is a legitimate HID keyboard or mouse device. The switch module 130 controls the connection or disconnection of the internal interface B2 and the external interface A2 based on the determination result of the device type detection module 110 to prevent an illegal HID keyboard or mouse device from being connected to the protected device 200. In this way, a disguised or illegal HID keyboard or mouse device can no longer be connected to the internal interface B2, and it is fundamentally prevented that a person without access rights accesses the protected device in a way of disguising or forging an HID keyboard or mouse device.

[0044] In this preferred embodiment, since the USB external interface and the USB internal interface of the present invention are "specialized interfaces", the legitimacy determination of the HID device may be performed only for a specific interface. For example, in this embodiment, it is performed only for the external device connected to the external interface B2. Thereby, the legitimacy determination program of the HID device is also executed independently as another hardware module.

[0045] FIG. 1B is a schematic configuration diagram of an external protection device based on interface detection according to a modification of the first embodiment of the present invention. As shown in FIG. 1B, the legitimacy detection module 111 is provided between the USB external interface A2 and the USB internal interface B2 and is used to detect the legitimacy of a USB external device of the HID class connected to the USB external interface A2. The switch module can control the connection and disconnection between the USB external interface A2 and the USB internal interface B2 according to the detection result of the legitimacy detection module 111. When the legitimacy detection module 111 detects that the corresponding external device is illegal, an alarm command is sent to the alarm module 140 via the device type detection module 110. Of course, as an alternative, the legitimacy detection module 111 may be directly connected to the alarm module 140 in order to directly send an alarm command to the alarm module 140.

[0046] The advantage of separating the legitimacy detection module 111 is that it can reduce the complexity of the device type detection module 110, so that it can be implemented on a low-cost and highly reliable data processing device. In addition, since the present invention is a "specialized interface", the legitimacy detection module 111 does not need to be all possible interfaces, but only needs to be connected to a specific line, and the complexity of the hardware line can also be reduced. Moreover, since the legitimacy detection module 111 is specialized for HID devices, it is very convenient to optimize hardware or software with a single function, and the reduction of the device complexity and the improvement of the function specialization both contribute to improving the safety of the external protector itself.

[0047] The structure shown in FIG. 1B is a modification of the first embodiment of the present invention, but the present invention is not limited to this modification. In fact, any of the "specialized interfaces" of the present invention can be added to the device type detection module 110, or can be added to a security processing module of an external device corresponding to a specific type independently of the device type detection module 110, for example, a USB external interface A1. It is also possible to add a security protection module for USB external devices of the storage class, for example, a content detection module for detecting the security of the content of a USB storage device. It can be seen that the present invention enables a "one type, one security protection" approach by designing the method of the "specialized interface", and the "specialized interface" is the basis for realizing the function upgrade and improvement of the external protection device.

[0048] Referring back to FIG. 1A, as described above, the external interface and the internal interface correspond one-to-one, have a fixed correspondence relationship, and the serial external interfaces C1 and C2 are respectively connected to the serial internal interfaces D1 and D2. In the case of the USB interface, the types of devices supporting the USB standard protocol may be different, but in the case of the serial interface, although the serial standards are different, there are 9-pin interfaces and 25-pin interfaces. No matter which serial interface device is used, the data is transmitted in serial mode. In order to adaptively connect the serial standard protocol supported by the external device to the corresponding serial interface on the protected device 200 via the external protection device 100, the serial external interface and the serial internal interface connected to each other are serial interfaces that support the same serial standard protocol, that is, the serial external interface C1 and the serial internal interface D1 support the same serial standard protocol, and the serial external interface C2 and the serial internal interface D2 support the same serial standard protocol.

[0049] The external protection device 100 of the first embodiment further includes a serial detection module 120. The serial detection module 120 is used to detect the connection states of the serial external interfaces C1 and C2 and send an alarm message to the alarm module 140 according to the change of the connection state. In the first embodiment, the serial detection module 120 is only used to detect whether the serial external devices connected to the serial external interfaces C1 and C2 are unplugged when powered on. When it is detected that the serial external interfaces C1 and C2 are unplugged, an alarm message is sent to the alarm module 140. The alarm messages sent by the serial detection module 120 and the device type detection module 110 may be the same or different. When the messages sent by both are different, the alarm module 140 can sound different alarm sounds according to the difference of the alarm messages (such as different beep sounds, etc.).

[0050] (Second Embodiment) FIG. 2 is a schematic configuration diagram of an external protection device based on interface detection according to the second embodiment of the present invention. In the foregoing second embodiment, the serial detection module 120 does not detect the types of the serial external devices connected to the serial external interfaces C1 and C2 because the type of the serial external device itself is usually not directly related to the data transfer mode. However, regardless of which serial standard protocol the serial interface device supports, its data transfer mode is usually divided into two types: "pass-through" and "relay". It is meaningful to perform different security protection processes on these two types of data transfer modes. Therefore, the serial detection module 120 of the second embodiment of the present invention is also used to detect the data transfer mode of the serial interface device connected to the serial external interfaces C1 and C2 and execute different processes according to the data transfer mode.

[0051] The external protection device according to the second embodiment further includes a content monitoring module for reviewing the data content from the external interface and instructing the switch module to connect or disconnect the internal interface corresponding to the external interface according to the content review result. When reviewing the data content, it is necessary to separately process the pass-through type data and the relay type data, and control the connection and disconnection of the connection line by controlling the switch module 130 according to the processing result. Therefore, as shown in FIG. 2, the switch module 130 of this embodiment is also used to control the connection and disconnection of the data cable of the serial interface.

[0052] In this embodiment, the content monitoring module 150 is a comprehensive data content review module that reviews not only the data content from the USB interface but also the data content from the serial interface. The present invention is not limited to the specific data review method of the content monitoring module 150, and any conventional data review method can be applied to the present invention. The purpose of data content review is to determine whether the data content poses a security risk to the device to be protected, such as whether the data contains viruses, Trojan horses, malicious operation commands, illegal operation commands, etc. In order to efficiently execute the review of the data content, the content monitoring module 150 is preferably implemented by an independent hardware module as in this embodiment. However, the present invention is not limited to this, and the content monitoring module 150 may be implemented as a sub-module of other data processing modules or as a computer program executed by other data processing devices.

[0053] As shown in FIG. 2, in the second embodiment, the content monitoring module 150 includes a mirroring module for mirroring the pass-through data from the external interface, and a data analysis module for analyzing all the data from the external interface and sending an alarm command to the alarm module 140 according to the analysis result. As described above, the serial detection module 120 of the second embodiment is also used to detect the data transfer mode of the serial interface device connected to the serial external interfaces C1 and C2 and execute different processes according to the data transfer mode. Therefore, further speaking, when the serial detection module 120 detects that the serial interface device connected to the serial external interface C1 or C2 is transmitting data in the "pass-through" mode, the mirroring module mirrors the pass-through data, and then the data analysis module analyzes the mirrored data. When the serial detection module 120 detects that the serial interface device connected to the serial external interface C1 or C2 is transmitting data in the "relay" mode, the data analysis module directly analyzes the relay data. In other words, regardless of whether the serial external interface is in the pass-through mode or the relay mode, the data analysis module needs to analyze the data, but in the pass-through mode, it is also necessary to mirror the pass-through data.

[0054] Here, it should be noted that the so-called "pass-through" mode means that the serial external device is directly connected to the serial internal interface via the switch module 130 and directly accesses the device to be protected. Other functional modules of the external protection device (including the content monitoring module 150) are only connected as a bypass to realize the interception of data in the pass-through. Here, the so-called "tandem" mode means that the serial external interface device is first connected to the functional module of the external protection device (including the content monitoring module 150), and after the security protection device performs data analysis and filtering, the legitimate data is transferred to the device to be protected via the serial internal interface.

[0055] As shown in FIG. 2, in the second embodiment, the content monitoring module 150 is also connected to the device type detection module 110. In this embodiment, a predetermined connection type of the USB external interface A2 is a USB external device of the HID class. Since the data transfer of the USB external device of the HID class is performed in the "pass-through" mode, the mirror module of the content monitoring module 150 is also used to mirror the data transferred by the USB external device of the HID class, and then the data analysis module analyzes the mirror data. In the case of a storage class or a non-storage non-HID class USB external device connected to the USB external interfaces A1 and A3, the data analysis module directly analyzes the transferred data. Since the mirror module and the data analysis module both need a storage sub-module for data storage to mirror the pass-through data or cache the non-pass-through data for data analysis.

[0056] (The third embodiment) FIG. 3 is a schematic configuration diagram of an external protection device based on interface detection according to the third embodiment of the present invention. Different from the first and second embodiments, the external interface of the third embodiment further includes a network external interface E, and the internal interface includes a network internal interface F connected to the network external interface. The network internal interface F is connected to the network external interface N of the device to be protected. In the present invention, the "network port" refers to a data interface connected to a network such as an RJ-45 Ethernet interface compliant with the IEEE802.3 standard, and may be an interface for a telephone line or an optical fiber. Similar to the serial interface, when the device to be protected and the external protection device support two or more types of network ports, the network protocol supported by the external network (which can be regarded as a special external device) is adaptively connected to the corresponding network interface on the device to be protected 200. Therefore, the mutually connected network external interface and network internal interface are network interfaces that support the same serial standard protocol.

[0057] Continuing to refer to FIG. 3, in the third embodiment, the external protection device 100 further includes a network port detection module 160. The network port detection module 160 is used to detect the connection state of the network external interface E and send an alarm message to the alarm module 140 according to the change of the connection state. In the third embodiment, the network port detection module 160 is only used to detect whether a serial external device connected to the network external interface E is unplugged. When it is detected that the network external interface E is unplugged, an alarm message is sent to the alarm module 140. The alarm messages sent by the network port detection module 160, the serial detection module 120, and the device type detection module 110 may be the same or different. When the messages sent from them are different, the alarm module 140 can sound different alarm sounds according to the differences in the alarm messages (for example, different beep sounds, etc.).

[0058] In this embodiment, the network port detection module 160 is also connected to the content monitoring module 150. The content monitoring module 150 reviews the data content from the network port external interface E and instructs the switch module to connect or disconnect the internal interface corresponding to the external interface according to the content review result. Therefore, as shown in FIG. 3, the switch module 130 of this embodiment is also used to control the connection and disconnection of the data cable of the network interface.

[0059] In the third embodiment, the external protection device 100 further includes a firewall module 170 for transmitting data received from the network external interface to the network internal interface after performing validity detection of the data. The firewall module 170 is used to execute a firewall program. The firewall forms a protection barrier between the internal network environment and the external network environment and blocks insecure network elements of the computer. Only when the firewall agrees, the transmission of data from the network external interface E and the access to the protected device 200 are permitted; if it does not agree, they are blocked. When an external user attempts to access the computer, the firewall promptly issues a corresponding alarm. Since the network firewall technology is a mature prior art, a detailed description thereof is omitted here.

[0060] In this embodiment, since both the content monitoring module 150 and the firewall module 170 are used to review data from the network external interface E, as a modification, the two modules may be combined into one. For example, the functions of the firewall module 170 may be integrated into the content monitoring module 150.

[0061] (Fourth Embodiment) FIG. 4 is a schematic configuration diagram of an external protection device based on interface detection according to the fourth embodiment of the present invention.

[0062] This embodiment is further improved based on the third embodiment. The external protection device 100 of this embodiment further includes a plugging detection module 180 for detecting the interface connection state of the internal interface end. Specifically, in this fourth embodiment, detecting the plugging state of the connection cable between the device to be protected and the external protection device plays an important role in the security protection effect. Therefore, the plugging detection module 180 not only detects whether the data cable connected to the internal interface is unplugged, but also detects whether the data cable connected to each internal interface is unplugged from the device 200 to be protected. After detecting the above-mentioned unplugged state, an alarm command is sent to the alarm module 140.

[0063] To detect the plugging state, plugging detection sensors (such as pressure sensors) can be provided at each internal interface B1, B2, B3, D1, D2, F and the external interfaces U1, U2, S, N of the device to be protected. The plugging signal detected by the pressure sensor is sent to the plugging detection module 180 via the connection cable. The plugging detection module determines which interface has been illegally unplugged based on the received plugging signal and sends an alarm command to the alarm module 140.

[0064] In this embodiment, as described above, since the device type detection module 110, the serial detection module 120, and the network port detection module 160 can all detect the plugging state of the external interface, the external protection device of the fourth embodiment of the present invention realizes the plugging detection of all interfaces. Through this full-coverage type plugging detection and monitoring, illegal connection and disconnection of any line between the external protection device and the device to be protected can be effectively prevented, and the safety performance of the device to be protected can be improved.

[0065] In another modification example, the plug-and-play detection functions of the device type detection module 110, the serial detection module 120, and the network port detection module 160 can be integrated into the plug-and-play detection module 180. Thereby, the plug-and-play detection module 180 can comprehensively monitor the plug-and-play states of all the external interfaces and internal interfaces of the external protection device and the external interfaces of the devices to be protected, and transmit an alarm command when an abnormality is detected.

[0066] The above-described specific embodiments further elaborate on the object, technical means, and advantageous effects of the present invention in more detail. However, the present invention is not essentially related to a specific computer, virtual device, or electronic device, and the present invention can also be implemented with various general-purpose devices. The above is only a specific example of the present invention and is not used with the intention of limiting the present invention. Modifications, substitutions by equivalents, improvements, etc., made without departing from the spirit and principles of the present invention are also included in the protection scope of the present invention.

Claims

1. An external protection device based on interface detection, comprising an internal interface (B1 to B3, D1, D2) for connecting to a protected device (200), an external interface (A1 to A3, C1, C2) for connecting to an external device that needs to access the protected device (200), and a switch module (130), wherein the external interface (A1 to A3, C1, C2) is connected to the internal interface (B1 to B3, D1, D2) one-to-one via the switch module, at least two of the external interfaces are used for connecting to a predetermined type of external device, the type and number of the internal interfaces are the same as the type and number of the external interfaces, and each internal interface is used for connecting to all the external interfaces of the protected device one-to-one, the external protection device further comprises a device type detection module (110) and an alarm module (140), the device type detection module (110) detects the type of an external device connected to any of the external interfaces, sends an alarm command to the alarm module (140) according to the detection result, and instructs the switch module to connect or disconnect the internal interface corresponding to the external interface, the alarm module (140) sounds an alarm according to the received alarm command Characterized in that it is an external protection device based on interface detection.

2. When the type of the detected external device does not match the predetermined type of the external interface, the device type detection module (110) instructs the switch module to disconnect the connection of the internal interface corresponding to the external interface, sends an alarm command to the alarm module, and when the type of the detected external device matches the predetermined type of the external interface, it is used to instruct the switch module to connect the internal interface corresponding to the external interface The external protection device based on interface detection according to Claim 1.

3. Further comprising a content monitoring module (150) for reviewing the data content from the external interface and instructing the switch module to connect or disconnect the internal interface corresponding to the external interface according to the content review result. The external protection device based on interface detection according to claim 2.

4. The content monitoring module (150) includes a mirror module for mirroring the pass-through data from the external interface, and a data analysis module for analyzing all the data from the external interface and sending an alarm command to the alarm module (140) according to the analysis result. The external protection device based on the interface detection according to claim 3.

5. The external interface includes a tandem type serial external interface and a pass-through type serial external interface, and the internal interface includes a tandem type serial internal interface and a pass-through type serial internal interface corresponding to the tandem type serial external interface and the pass-through type serial external interface one by one. The data analysis module is used to analyze the data from the tandem type serial external interface and send an alarm command to the alarm module (140) according to the analysis result. The external protection device based on interface detection according to claim 4.

6. The mirror module is used to mirror the pass-through data from the pass-through type serial external interface. The data analysis module is also used to analyze the pass-through data of the pass-through type serial external interface and send an alarm command to the alarm module according to the analysis result. The external protection device based on interface detection according to claim 5.

7. The external interface includes a USB external interface, and the internal interface includes a USB internal interface corresponding to each of the USB external interfaces one by one. The predetermined type of each of the USB external interfaces is the same as the type of the USB external interface of the device to be protected connected to the corresponding USB internal interface. An external protection device based on interface detection according to any one of claims 1 to 4.

8. The USB external interface includes at least two predetermined types of USB external interfaces of a storage class, a USB interface of an HID class, and a non-storage non-HID class. An external protection device based on interface detection according to claim 7.

9. The external interface includes a network external interface, and the internal interface includes a network internal interface connected to the network external interface. An external protection device based on interface detection according to any one of claims 1 to 4.

10. It further includes a firewall module for transmitting data to the network internal interface after detecting the validity of data received from the network external interface. An external protection device based on interface detection according to claim 9.

11. Detect whether the data cable or device connected to each of the external interfaces is unplugged, detect whether the data cable connected to the internal interface is unplugged, and detect whether the data cable connected to the internal interface is unplugged from the device to be protected. After detecting the unplugged state described above, send an alarm command to the alarm module. An external protection device based on interface detection according to any one of claims 1 to 4.

12. An external protection method based on interface detection, comprising: A step of taking over all the external interfaces of a device to be protected using an external protection device and connecting each internal interface of the external protection device to all the external interfaces of the device to be protected one by one. Connecting the external interface and the internal interface of the external protection device one-to-one by a switch module, and matching the type and number of the internal interface of the external protection device with the type and number of the external interface; Determining at least two of the external interfaces for connecting to an external device of a predetermined type; Detecting the type of an external device connected to any of the external interfaces of the external protection device, and instructing the switch module to connect or disconnect the internal interface corresponding to the external interface according to the detection result; and Causing an alarm to sound according to the detection result. An external protection method based on interface detection, characterized in that.

13. When the type of the detected external device does not match a predetermined type of the external interface, instruct the switch module to disconnect the connection of the internal interface corresponding to the external interface, and cause an alarm to sound; When the type of the detected external device matches a predetermined type of the external interface, instruct the switch module to connect the internal interface corresponding to the external interface. The external protection method based on interface detection according to claim 12.

14. Further comprising reviewing the data content from the external interface, and instructing the switch module to connect or disconnect the internal interface corresponding to the external interface according to the content review result. The external protection method based on interface detection according to claim 13.

15. The step of reviewing the data content from the external interface includes mirroring the pass-through data from the external interface, analyzing all the data from the external interface, and causing an alarm to sound according to the analysis result. The external protection method based on interface detection according to claim 14.

16. Detect whether a data cable or device connected to each of the external interfaces is unplugged, detect whether a data cable connected to the internal interface is unplugged, and detect whether a data cable connected to the internal interface is unplugged from the external interface of the device to be protected. After detecting the unplugged state as described above, the method further includes a step of sounding an alarm. An external protection method based on interface detection according to any one of claims 12 to 15.

Citation Information

Patent Citations

  • Information processor

    JP2009193358A

  • Methods and devices for controlling access to computer systems

    JP2014502757A

  • USB relay apparatus and control method for USB relay apparatus

    JP2018073260A

  • External terminal protection device and protection system

    JP2021522616A

  • Data transfer control method and system based on hardware control logic

    JP2021522619A