CN106845219A - A kind of intrusion detection smart machine for multiple types of data - Google Patents

A kind of intrusion detection smart machine for multiple types of data Download PDF

Info

Publication number
CN106845219A
CN106845219A CN201710028126.3A CN201710028126A CN106845219A CN 106845219 A CN106845219 A CN 106845219A CN 201710028126 A CN201710028126 A CN 201710028126A CN 106845219 A CN106845219 A CN 106845219A
Authority
CN
China
Prior art keywords
interface
card
backplane
data
digital
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201710028126.3A
Other languages
Chinese (zh)
Other versions
CN106845219B (en
Inventor
解仑
张雷
周育武
王志良
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Yingtan Zhihui Internet Of Things Application Research Institute Co ltd
Original Assignee
University of Science and Technology Beijing USTB
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by University of Science and Technology Beijing USTB filed Critical University of Science and Technology Beijing USTB
Priority to CN201710028126.3A priority Critical patent/CN106845219B/en
Publication of CN106845219A publication Critical patent/CN106845219A/en
Application granted granted Critical
Publication of CN106845219B publication Critical patent/CN106845219B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/552Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Bus Control (AREA)
  • Small-Scale Networks (AREA)

Abstract

本发明提供一种针对多种类型数据的入侵检测智能设备,能够对多种类型数据进行入侵检测。所述设备包括:背板,主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板和电源模块;其中,所述背板支持紧凑型PCI协议;所述后输入输出接口板,用于提供多种类型的输入输出接口,其中,所述多种类型的输入输出接口包括:加解密卡接口、网口、RS232串行接口、USB接口、CAN接口、AD接口和数字IO接口,每种类型的输入输出接口,用于实时获取相应类型的数据;所述主板模块,用于依据预设的入侵检测规则,对获取的所述数据进行入侵检测;所述加解密卡,用于对未被入侵的数据进行加解密和数字认证处理。本发明适用于现代工业控制与信息安全技术领域。

The invention provides an intrusion detection intelligent device for multiple types of data, capable of performing intrusion detection on multiple types of data. The device includes: a backplane, a main board module, a CAN&AD card, a digital IO card, an encryption and decryption card, a rear input and output interface board and a power supply module; wherein, the backplane supports a compact PCI protocol; the rear input and output interface board , for providing various types of input and output interfaces, wherein the various types of input and output interfaces include: encryption and decryption card interface, network port, RS232 serial interface, USB interface, CAN interface, AD interface and digital IO interface , each type of input and output interface is used to obtain corresponding types of data in real time; the main board module is used to perform intrusion detection on the obtained data according to preset intrusion detection rules; the encryption and decryption card is used to It is used for encryption, decryption and digital authentication of unintruded data. The invention is applicable to the technical fields of modern industrial control and information security.

Description

一种针对多种类型数据的入侵检测智能设备An intrusion detection smart device for multiple types of data

技术领域technical field

本发明涉及现代工业控制与信息安全技术领域,特别是指一种针对多种类型数据的入侵检测智能设备。The invention relates to the technical field of modern industrial control and information security, in particular to an intrusion detection intelligent device for various types of data.

背景技术Background technique

近年来,实现多种类型数据入侵检测的智能设备与工业信息控制网络互联已成为现代工业系统的重要组成部分,智能检测与通信设备具备多种类通信接口的功能。外围信息网络与智能通信设备的控制网络实现互联时,由于网络的不确定性和不可控性,如何保证工业过程控制网络的数据安全和机器指令安全就变成了一个严峻的问题。特别是对于钢铁冶金、石油化工、能源电力、水泥等生产工业和基础设施工业,它们对连续生产的安全性和可靠性有着极高的要求,而如果需要经由开放网络与工业控制网络之间的互联,就相当于将控制网络直接暴露给信息网络而面临被攻击的危险。而且由于工业现场设备的特殊性,一旦发生故障将产生破坏性很强的人力物力财产损失,并产生危害极大的社会影响。In recent years, the interconnection between intelligent devices and industrial information control networks that realize various types of data intrusion detection has become an important part of modern industrial systems, and intelligent detection and communication devices have the functions of various communication interfaces. When the peripheral information network and the control network of intelligent communication equipment are interconnected, due to the uncertainty and uncontrollability of the network, how to ensure the data security and machine instruction security of the industrial process control network becomes a serious problem. Especially for iron and steel metallurgy, petrochemical, energy and electric power, cement and other production industries and infrastructure industries, they have extremely high requirements for the safety and reliability of continuous production. Interconnection is equivalent to exposing the control network directly to the information network and facing the danger of being attacked. Moreover, due to the particularity of industrial field equipment, once a failure occurs, it will cause highly destructive human, material and property losses, and have a very harmful social impact.

在现代的工业及数据通信中,智能化程度越来越高,由智能装备构成的通信多种类型数据控制系统已经广泛地应用到航空航天、工程控制、环境、电网、医疗设备、通讯以及人们的日常生活工作中。其中,控制器局域网络(Controller Area Network,CAN),工业级CAN卡的CAN总线数据收发由CAN控制器和CAN收发器完成。这种接口的功能卡在汽车等行业中应用广泛,而且在工业控制、机器人、医疗器械、传感器等领域发展迅速。AD信号采集功能和数字信号IO功能在现实中也应用广泛,为了采集工业现场设备的多种信息,例如,采集AD信号电压数据、数字输入输出参数、串行UART信号通讯,以及使用集成度较高的CAN总线,同时还需要进行加密解密处理,在很多情况下,这些功能需要集成在一台设备上,但是,现有技术中,还没有一种集成CAN接口、AD接口、数字IO接口及加密解密功能的设备。In modern industry and data communication, the degree of intelligence is getting higher and higher. Various types of communication data control systems composed of intelligent equipment have been widely used in aerospace, engineering control, environment, power grid, medical equipment, communication and people. in daily life work. Among them, the controller area network (Controller Area Network, CAN), the CAN bus data transmission and reception of the industrial-grade CAN card is completed by the CAN controller and the CAN transceiver. Function cards of this interface are widely used in industries such as automobiles, and are developing rapidly in fields such as industrial control, robots, medical equipment, and sensors. AD signal acquisition function and digital signal IO function are also widely used in reality. In order to collect various information of industrial field equipment, for example, to collect AD signal voltage data, digital input and output parameters, serial UART signal communication, and to use integrated High CAN bus, but also needs to be encrypted and decrypted. In many cases, these functions need to be integrated on one device. However, in the prior art, there is no integrated CAN interface, AD interface, digital IO interface and Devices with encryption and decryption functions.

发明内容Contents of the invention

本发明要解决的技术问题是提供一种针对多种类型数据的入侵检测智能设备,以解决现有技术所存在的没有一种集成CAN接口、AD接口、数字IO接口及加密解密功能的设备的问题。The technical problem to be solved by the present invention is to provide an intrusion detection intelligent device for multiple types of data, to solve the existing problems in the prior art that there is no device integrating CAN interface, AD interface, digital IO interface and encryption and decryption functions. question.

为解决上述技术问题,本发明实施例提供一种针对多种类型数据的入侵检测智能设备,包括:背板,与所述背板进行连接的主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板和电源模块;其中,所述背板支持紧凑型PCI协议;In order to solve the above-mentioned technical problems, an embodiment of the present invention provides an intrusion detection intelligent device for various types of data, including: a backplane, a motherboard module connected to the backplane, a CAN&AD card, a digital IO card, and an encryption and decryption card , a rear input and output interface board and a power supply module; wherein, the backplane supports the compact PCI protocol;

所述后输入输出接口板,用于提供多种类型的输入输出接口,其中,所述多种类型的输入输出接口包括:加解密卡接口、网口、RS232串行接口、USB接口、CAN接口、AD接口和数字IO接口,每种类型的输入输出接口,用于实时获取相应类型的数据;The rear input and output interface board is used to provide multiple types of input and output interfaces, wherein the multiple types of input and output interfaces include: encryption and decryption card interface, network port, RS232 serial interface, USB interface, CAN interface , AD interface and digital IO interface, each type of input and output interface is used to obtain the corresponding type of data in real time;

所述CAN&AD卡,用于通过所述背板与所述CAN接口、AD接口进行通信;The CAN&AD card is used to communicate with the CAN interface and the AD interface through the backplane;

所述数字IO卡,用于通过所述背板与所述数字IO接口进行通信;The digital IO card is used to communicate with the digital IO interface through the backplane;

所述主板模块,用于依据预设的入侵检测规则,对获取的所述数据进行入侵检测;The mainboard module is used to perform intrusion detection on the acquired data according to preset intrusion detection rules;

所述加解密卡,用于对未被入侵的数据进行加解密和数字认证处理;The encryption/decryption card is used to perform encryption/decryption and digital authentication processing on unintruded data;

所述电源模块,用于为所述背板供电。The power module is used to supply power to the backplane.

进一步地,所述主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板及电源模块通过针孔式连接器与所述背板进行对插连接;Further, the main board module, CAN&AD card, digital IO card, encryption and decryption card, rear input and output interface board and power supply module are connected to the backplane through pinhole connectors;

其中,所述主板模块、CAN&AD卡、数字IO卡、加解密卡及电源模块位于所述背板的前侧,所述后输入输出接口板位于所述背板的后侧。Wherein, the main board module, CAN&AD card, digital IO card, encryption and decryption card and power supply module are located on the front side of the backplane, and the rear input and output interface board is located on the back side of the backplane.

进一步地,所述多种类型的输入输出接口包括:1路保密卡接口、2路网口、2路RS232串行接口、6路USB接口、2路CAN接口、10路AD接口、24路数字IO接口。Further, the multiple types of input and output interfaces include: 1 security card interface, 2 network ports, 2 RS232 serial interfaces, 6 USB interfaces, 2 CAN interfaces, 10 AD interfaces, 24 digital I/O interface.

进一步地,所述CAN&AD卡包括:第一转换模块和第一接口扩展模块;Further, the CAN&AD card includes: a first conversion module and a first interface expansion module;

所述第一转换模块,用于将PCI总线转换成本地总线,其中,所述本地总线与所述第一接口扩展模块相连;The first conversion module is configured to convert the PCI bus into a local bus, wherein the local bus is connected to the first interface expansion module;

所述第一接口扩展模块,用于扩展出多路CAN信号和多路AD信号,其中,所述多路CAN信号和多路AD信号通过所述背板连接到所述后输入输出接口板上,由所述后输入输出接口板提供多路CAN接口和多路AD接口。The first interface expansion module is used to expand multiple CAN signals and multiple AD signals, wherein the multiple CAN signals and multiple AD signals are connected to the rear input and output interface board through the backplane , the rear input and output interface board provides multiple CAN interfaces and multiple AD interfaces.

进一步地,所述数字IO卡包括:第二转换模块和第二接口扩展模块;Further, the digital IO card includes: a second conversion module and a second interface expansion module;

所述第二转换模块,用于将PCI总线转换成本地总线,其中,所述本地总线与所述第二接口扩展模块相连;The second conversion module is configured to convert the PCI bus into a local bus, wherein the local bus is connected to the second interface expansion module;

所述第二接口扩展模块,用于扩展出多路IO信号,其中,所述多路IO信号通过所述背板连接到所述后输入输出接口板上,由所述后输入输出接口板提供多路数字IO接口;The second interface expansion module is used to expand multiple IO signals, wherein the multiple IO signals are connected to the rear input and output interface board through the backplane, and are provided by the rear input and output interface board Multiple digital IO interface;

其中,所述多路数字IO接口中的每路数字IO接口可独立配置为输出接口或输入接口。Wherein, each digital IO interface in the multiple digital IO interfaces can be independently configured as an output interface or an input interface.

进一步地,所述设备还包括:与所述背板相连的第一网口扩展模块和与所述第一网口扩展模块相连的网口变压器;Further, the device further includes: a first network port expansion module connected to the backplane and a network port transformer connected to the first network port expansion module;

所述第一网口扩展模块和与所述第一网口扩展模块相连的网口变压器,用于扩展出第一路网口;The first network port expansion module and the network port transformer connected to the first network port expansion module are used to expand the first network port;

所述第一路网口,用于输入输出网络数据。The first network port is used for inputting and outputting network data.

进一步地,所述设备还包括:与所述背板相连的第二网口扩展模块;Further, the device further includes: a second network port expansion module connected to the backplane;

所述第二网口扩展模块,用于扩展出第二路网口;The second network port expansion module is used to expand the second network port;

所述第二路网口,用于输入输出网络数据。The second network port is used for inputting and outputting network data.

进一步地,所述设备还包括:与所述背板相连的交流滤波器;Further, the device further includes: an AC filter connected to the backplane;

所述交流滤波器,用于对220V交流电进行滤波处理。The AC filter is used for filtering the 220V AC.

进一步地,所述多种类型的输入输出接口还包括:显示口;Further, the multiple types of input and output interfaces also include: a display port;

所述显示口,用于接入液晶显示器。The display port is used for connecting to a liquid crystal display.

进一步地,所述设备还包括:与所述背板连接的备用板卡;其中,Further, the device further includes: a spare board connected to the backplane; wherein,

所述备用板卡包括:RS232串行接口卡、视频音频合成卡、1553B总线卡、基于紧凑型PCI总线的3U板卡、基于紧凑型PCI总线的6U板卡中的一种或多种。The spare boards include: one or more of RS232 serial interface cards, video and audio synthesis cards, 1553B bus cards, 3U boards based on compact PCI bus, and 6U boards based on compact PCI bus.

本发明的上述技术方案的有益效果如下:The beneficial effects of above-mentioned technical scheme of the present invention are as follows:

上述方案中,基于后输入输出接口板提供的网口、RS232串行接口、USB接口、CAN接口、AD接口和数字IO接口,能够实时获取AD、CAN、数字量等多种类型的数据,并依据预设的入侵检测规则,利用主板模块对获取的多种类型的数据实时地进行入侵检测;并利用加解密卡对未被入侵的数据进行加解密和数字认证处理,从而实现了数据的多样性,保证了数据的安全性及可靠性。In the above scheme, based on the network port, RS232 serial interface, USB interface, CAN interface, AD interface and digital IO interface provided by the rear input and output interface board, various types of data such as AD, CAN, and digital quantities can be obtained in real time, and According to the preset intrusion detection rules, the main board module is used to perform intrusion detection on various types of data obtained in real time; and the encryption and decryption card is used to encrypt, decrypt and digitally authenticate the data that has not been invaded, thereby realizing the diversity of data To ensure data security and reliability.

附图说明Description of drawings

图1为本发明实施例提供的针对多种类型数据的入侵检测智能设备的结构示意图;FIG. 1 is a schematic structural diagram of an intrusion detection smart device for multiple types of data provided by an embodiment of the present invention;

图2为本发明实施例提供的针对多种类型数据的入侵检测智能设备的详细结构示意图;FIG. 2 is a detailed structural schematic diagram of an intrusion detection smart device for multiple types of data provided by an embodiment of the present invention;

图3为本发明实施例提供的入侵检测智能设备功能板卡基本原理图;Fig. 3 is the basic schematic diagram of the intrusion detection smart device function board provided by the embodiment of the present invention;

图4为本发明实施例提供的PCI9054芯片内外部连接原理图;Fig. 4 is the internal and external connection principle diagram of the PCI9054 chip provided by the embodiment of the present invention;

图5为本发明实施例提供的数字量IO板卡功能实现电路框图;Fig. 5 is the digital quantity IO board function realization circuit block diagram provided by the embodiment of the present invention;

图6为本发明实施例提供的入侵检测智能设备外围系统连接框图。Fig. 6 is a connection block diagram of the peripheral system of the intrusion detection smart device provided by the embodiment of the present invention.

具体实施方式detailed description

为使本发明要解决的技术问题、技术方案和优点更加清楚,下面将结合附图及具体实施例进行详细描述。In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will describe in detail with reference to the drawings and specific embodiments.

本发明针对现有的没有一种集成CAN接口、AD接口、数字IO接口及加密解密功能的设备的问题,提供一种针对多种类型数据的入侵检测智能设备。The present invention aims at the problem that there is no existing device integrating CAN interface, AD interface, digital IO interface and encryption and decryption functions, and provides an intrusion detection intelligent device for various types of data.

如图1所示,本发明实施例提供的针对多种类型数据的入侵检测智能设备,包括:背板,与所述背板进行连接的主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板和电源模块;其中,所述背板支持紧凑型PCI协议;As shown in Figure 1, the intrusion detection intelligent device for multiple types of data provided by the embodiment of the present invention includes: a backplane, a motherboard module connected to the backplane, a CAN&AD card, a digital IO card, an encryption and decryption card, Rear input and output interface board and power supply module; wherein, the backplane supports compact PCI protocol;

所述后输入输出接口板,用于提供多种类型的输入输出接口,其中,所述多种类型的输入输出接口包括:加解密卡接口、网口、RS232串行接口、USB接口、CAN接口、AD接口和数字IO接口,每种类型的输入输出接口,用于实时获取相应类型的数据;The rear input and output interface board is used to provide multiple types of input and output interfaces, wherein the multiple types of input and output interfaces include: encryption and decryption card interface, network port, RS232 serial interface, USB interface, CAN interface , AD interface and digital IO interface, each type of input and output interface is used to obtain the corresponding type of data in real time;

所述CAN&AD卡,用于通过所述背板与所述CAN接口、AD接口进行通信;The CAN&AD card is used to communicate with the CAN interface and the AD interface through the backplane;

所述数字IO卡,用于通过所述背板与所述数字IO接口进行通信;The digital IO card is used to communicate with the digital IO interface through the backplane;

所述主板模块,用于依据预设的入侵检测规则,对获取的所述数据进行入侵检测;The mainboard module is used to perform intrusion detection on the acquired data according to preset intrusion detection rules;

所述加解密卡,用于对未被入侵的数据进行加解密和数字认证处理;The encryption/decryption card is used to perform encryption/decryption and digital authentication processing on unintruded data;

所述电源模块,用于为所述背板供电。The power module is used to supply power to the backplane.

本发明实施例所述的针对多种类型数据的入侵检测智能设备,基于后输入输出接口板提供的网口、RS232串行接口、USB接口、CAN接口、AD接口和数字IO接口,能够实时获取AD、CAN、数字量等多种类型的数据,并依据预设的入侵检测规则,利用主板模块对获取的多种类型的数据实时地进行入侵检测;并利用加解密卡对未被入侵的数据进行加解密和数字认证处理,从而实现了数据的多样性,保证了数据的安全性及可靠性。The intrusion detection intelligent device for multiple types of data described in the embodiment of the present invention can obtain real-time Various types of data such as AD, CAN, and digital quantities, and according to the preset intrusion detection rules, use the main board module to perform intrusion detection on the various types of data obtained in real time; and use the encryption and decryption card to detect the unintruded data Encryption and decryption and digital authentication processing are performed to realize data diversity and ensure data security and reliability.

本实施例中,所述背板、主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板都支持且使用紧凑型PCI协议,其中,CAN&AD卡可以为工业级CAN&AD卡。本实施例中,如图1、图2所示,所述入侵检测智能设备提供了多个卡槽,其中,所述卡槽包括:系统槽、设备槽、电源槽,系统槽用于插入所述主板模块,设备槽用于插入CAN&AD卡、数字IO卡、加解密卡,电源槽用于插入电源模块。In this embodiment, the backplane, mainboard module, CAN&AD card, digital IO card, encryption and decryption card, and rear input and output interface board all support and use the compact PCI protocol, wherein the CAN&AD card can be an industrial-grade CAN&AD card. In this embodiment, as shown in Figure 1 and Figure 2, the intrusion detection smart device provides a plurality of card slots, wherein the card slots include: a system slot, a device slot, and a power slot, and the system slot is used to insert the The motherboard module is described above, the device slot is used to insert CAN&AD card, digital IO card, encryption and decryption card, and the power slot is used to insert the power module.

本实施例中,所述主板模块可以是COM-E(COM Express)核心板,所述COM-E核心板上可以运行着定制的麒麟Linux系统,所述定制的麒麟Linux系统为针对多种类型数据入侵检测规则对原麒麟Linux内核系统进行合理裁剪,既保证了裁剪后的麒麟Linux系统的稳定性、可靠性、硬件低功耗,又有多类型的CAN、USB、AD和IO等传输通信协议,实现数据的可靠、高效率的传输,并支持多种通信协议转换;其中,所述COM-E核心板的CPU为(因特尔)i7-4650U处理器,运行主频最高可达3.3GHz,运行温度范围可达-40℃-+95℃,满足特殊条件下、工业现场存贮温差较大的环境;所述COM-E核心板的CPU配有16GB DDR3内存;主板模块上载板对接连接器使用440pin贴片方式;所述主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板及供电模块是实现该COM-E核心板的外围扩展接口板。In this embodiment, the motherboard module can be a COM-E (COM Express) core board, and the customized Kirin Linux system can run on the COM-E core board, and the customized Kirin Linux system is for various types of The data intrusion detection rules reasonably tailor the original Kylin Linux kernel system, which not only ensures the stability, reliability, and low power consumption of the hardware after tailoring, but also has multiple types of CAN, USB, AD, and IO transmission communications. protocol, realize reliable and efficient transmission of data, and support conversion of multiple communication protocols; wherein, the CPU of the COM-E core board is (Intel) i7-4650U processor, the operating frequency can reach up to 3.3GHz, and the operating temperature range can reach -40°C-+95°C, which meets the special conditions and the environment with large temperature difference in industrial site storage; The CPU of the COM-E core board is equipped with 16GB DDR3 memory; the docking connector of the board on the main board module uses a 440pin SMT method; the main board module, CAN&AD card, digital IO card, encryption and decryption card, rear input and output interface board and power supply module It is the peripheral expansion interface board to realize the COM-E core board.

本实施例中,所述入侵检测智能设备可以支持RS232、RS485、CAN、AD、数字IO、USB等多种通信模式,可同时通讯EtherCAT、UDP、NetBEUI协议和RS232、RS485、CAN、AD及数字IO信号;所述后输入输出接口板上包含EtherCAT、UDP、NetBEUI等多种协议的输入输出接口;所述输入输出接口可以包括但不限于:1路加解密卡接口、2路光纤万兆网口、2路RS232串行接口、6路USB接口、2路CAN接口、10路AD接口和24路数字IO接口;基于所述后输入输出接口板上的多种类型的输入输出接口可以获取不同类型的数据,所述入侵检测智能设备能够对获取的各类型的数据进行入侵检测,功能全面。In this embodiment, the intrusion detection smart device can support multiple communication modes such as RS232, RS485, CAN, AD, digital IO, USB, etc., and can simultaneously communicate with EtherCAT, UDP, NetBEUI protocols and RS232, RS485, CAN, AD, and digital IO signal; the rear input and output interface board contains input and output interfaces of multiple protocols such as EtherCAT, UDP, NetBEUI; the input and output interfaces may include but not limited to: 1 road encryption and decryption card interface, 2 road optical fiber 10 Gigabit network port, 2-way RS232 serial interface, 6-way USB interface, 2-way CAN interface, 10-way AD interface and 24-way digital IO interface; based on the various types of input and output interfaces on the rear input and output interface board, different types of data, the intrusion detection smart device can perform intrusion detection on various types of data acquired, and has comprehensive functions.

本实施例中,由于所述入侵检测智能设备上有CAN接口、AD接口、数字IO接口和网口,其他设备(例如,工业现场设备和/或上位机)可以通过CAN信号线、AD信号线、IO信号线和/或网线与所述入侵检测智能设备进行连接通信,例如,所述入侵检测智能设备可以通过ISOEM-U5-P2-O7隔离器和AD7328BRUZ-TSSOP20芯片实现直流电压等数据的AD信号采集、双路CAN信号的采集,又能够经由数字IO卡实现数字量的输入输出(IO)。In this embodiment, since the intrusion detection smart device has a CAN interface, an AD interface, a digital IO interface and a network port, other equipment (for example, industrial field equipment and/or host computer) can pass the CAN signal line, the AD signal line , IO signal lines and/or network cables are connected and communicated with the intrusion detection smart device, for example, the intrusion detection smart device can realize the AD of data such as DC voltage through the ISOEM-U5-P2-O7 isolator and AD7328BRUZ-TSSOP20 chip Signal acquisition, dual-channel CAN signal acquisition, and digital input and output (IO) can be realized through the digital IO card.

本实施例中,所述入侵检测智能设备与其他设备(例如,工业现场设备和/或上位机)可以组成一个系统。In this embodiment, the intelligent intrusion detection device and other devices (for example, industrial field devices and/or host computers) may form a system.

本实施例中,所述数据可以为内外部用户的行为和系统活动所产生的多种类型数据,所述对获取的所述数据进行入侵检测的具体步骤可以包括:通过所述主板模块分析和检测内外部用户的行为和系统活动所产生的多种类型数据,分析设备或系统的缺陷和脆弱性,结合协议特征指定针对性检测规则;依据Snort检测规则识别攻击行为、异常行为,并进行响应;对其他设备和其他设备的控制模型进行系统资源和数据完整性评估,监控系统日志,存储访问记录和攻击脚印。接着,通过加解密卡对未被入侵的数据进行加解密和数字认证处理,从而实现数据的安全传输,通过网口、CAN接口、USB3.0接口、AD接口和数字IO接口实现了数据的多样性。In this embodiment, the data may be various types of data generated by internal and external user behaviors and system activities, and the specific step of performing intrusion detection on the acquired data may include: analyzing and Detect various types of data generated by internal and external user behavior and system activities, analyze device or system defects and vulnerabilities, and designate targeted detection rules based on protocol features; identify attack behaviors and abnormal behaviors based on Snort detection rules, and respond ; Conduct system resource and data integrity assessments of other devices and control models of other devices, monitor system logs, store access records and attack footprints. Then, through the encryption and decryption card, the unintruded data is encrypted, decrypted and digitally authenticated, so as to realize the safe transmission of data, and realize the variety of data through the network port, CAN interface, USB3.0 interface, AD interface and digital IO interface. sex.

本实施例中,所述加解密板卡上有FPGA芯片,承担加解密算法的计算任务,实现了硬件加解密操作,从而使加解密操作基本上不占用主板模块上CPU资源,且能够保证如直流电压、电流、力矩、转速等多种类型数据的加解密速度。In this embodiment, there is an FPGA chip on the encryption and decryption board, which undertakes the calculation task of the encryption and decryption algorithm, and realizes hardware encryption and decryption operations, so that the encryption and decryption operations basically do not occupy CPU resources on the main board module, and can guarantee as follows: Encryption and decryption speed of various types of data such as DC voltage, current, torque, and rotational speed.

本实施例中,所述加解密卡对未被入侵的数据进行加解密和数字认证处理时,而不单一采用纯软件的方法对未被入侵的数据进行加解密和数字认证处理,具体的,输入时,所述加解密卡通过加密算法对输入的数据进行加密和数字认证处理,输出时,所述加解密卡利用加密算法对应的解密算法对数据进行解密和数字认证处理;其中,所述加解密卡可以包含大唐电信加密芯片和FPGA芯片,所述加解密卡支持紧凑型PCI协议,紧凑型摒弃了传统型的金手指连接方式而采用针孔连接器插拔模式,具备高密度和高可靠性。In this embodiment, when the encryption and decryption card performs encryption, decryption and digital authentication processing on unintruded data, it does not only use pure software to perform encryption, decryption, and digital authentication processing on unintruded data. Specifically, When inputting, the encryption and decryption card performs encryption and digital authentication processing on the input data through an encryption algorithm, and when outputting, the encryption and decryption card uses a decryption algorithm corresponding to the encryption algorithm to decrypt and digitally authenticate the data; wherein, the The encryption and decryption card can include Datang Telecom encryption chip and FPGA chip. The encryption and decryption card supports the compact PCI protocol. The compact type abandons the traditional golden finger connection method and adopts the pinhole connector plug-in mode, which has high density and high reliability.

本实施例中,所述主板模块,还可以更新所述加解密卡中的加解密算法,从而进一步保障了工业级多种类型数据通信的安全性。In this embodiment, the mainboard module can also update the encryption and decryption algorithms in the encryption and decryption card, thereby further ensuring the security of various types of industrial data communication.

本实施例中,若所述输入输出接口包括2路光纤万兆网口、2路RS232串行接口、6路USB接口、2路CAN接口、10路AD接口和24路数字IO接口,则所述入侵检测智能设备可以同时对2路光纤万兆网口、2路RS232串行接口、6路USB接口、2路CAN接口、10路AD接口和24路数字IO接口的数据进行入侵检测和存储。In this embodiment, if the input and output interfaces include 2-way optical fiber 10 Gigabit network ports, 2-way RS232 serial interfaces, 6-way USB interfaces, 2-way CAN interfaces, 10-way AD interfaces and 24-way digital IO interfaces, then the The intrusion detection smart device mentioned above can perform intrusion detection and storage on the data of 2 optical fiber 10 Gigabit Ethernet ports, 2 RS232 serial ports, 6 USB ports, 2 CAN ports, 10 AD ports and 24 digital IO ports at the same time. .

本实施例中,所述背板支持紧凑型PCI协议,紧凑型摒弃了传统型的金手指连接方式而采用针孔连接器插拔模式,具备高密度和高可靠性;由于所述背板支持紧凑型PCI协议,所述背板可以称为紧凑型PCI背板,按照紧凑型PCI协议,所述背板前面的功能板卡(例如,主板模块、CAN&AD卡、数字IO卡、加解密卡)上仅实现功能而没有对外接口,当对外输出信号时,所有信号经背板中继传输后经由后输入输出接口板上的对外接口输出,以CAN口举例,所述CAN&AD卡包括:CAN卡和AD卡,其中,所述CAN卡通过扩展芯片实现了两路CAN信号,经背板中继,需要在后输入输出接口板设置两路CAN口。In this embodiment, the backplane supports the compact PCI protocol, and the compact type abandons the traditional golden finger connection method and adopts the pinhole connector plug-in mode, which has high density and high reliability; because the backplane supports Compact PCI protocol, the backplane can be referred to as a compact PCI backplane, according to the compact PCI protocol, the functional boards (for example, motherboard modules, CAN&AD cards, digital IO cards, encryption and decryption cards) in front of the backplane It only realizes the function but has no external interface. When outputting signals externally, all signals are relayed through the backplane and then output through the external interface on the rear input and output interface board. Taking the CAN port as an example, the CAN&AD card includes: CAN card and The AD card, wherein, the CAN card implements two CAN signals through the expansion chip, and is relayed through the backplane, and two CAN ports need to be set on the rear input and output interface board.

本实施例中,为了扩展CAN总线的功能,设计了具有磁隔离CAN接口和紧凑型PCI协议的CAN卡,CAN卡可以使用ADM-3053和CTM1051A-3.3V芯片来实现磁隔离技术,CAN卡收集CAN总线上各个节点的信息,转发给上位机,并可将上位机的命令和数据转发给各个节点以及完成对CAN总线上的用户系统的部分监控和管理工作。In this embodiment, in order to expand the function of the CAN bus, a CAN card with a magnetically isolated CAN interface and a compact PCI protocol is designed. The CAN card can use the ADM-3053 and CTM1051A-3.3V chips to realize the magnetic isolation technology. The CAN card collects The information of each node on the CAN bus is forwarded to the host computer, and the commands and data of the host computer can be forwarded to each node and complete part of the monitoring and management of the user system on the CAN bus.

本实施例中,CAN卡板载两个CAN控制器,CAN卡板载的两个CAN控制器放置在CAN卡的不同位置,在控制器局域网络中可同时独立执行两个CAN控制器;两个CAN控制器之间实现磁隔离,实现的两路磁隔离CAN卡是为计算机提供联机能力的控制器局域网络,它具备自动传输重复功能,提供总线仲裁与错误侦测能力,这可以大幅降低数据损失的几率,并确保系统的可靠性。In this embodiment, two CAN controllers are carried on the CAN card board, and the two CAN controllers carried on the CAN card board are placed in different positions of the CAN card, and the two CAN controllers can be executed independently in the controller area network at the same time; Magnetic isolation is realized between two CAN controllers. The two-way magnetically isolated CAN card is a controller local area network that provides online capabilities for computers. It has automatic transmission repetition functions and provides bus arbitration and error detection capabilities, which can greatly reduce Chances of data loss and ensuring system reliability.

在前述针对多种类型数据的入侵检测智能设备的具体实施方式中,进一步地,所述主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板及电源模块通过针孔式连接器与所述背板进行对插连接;In the aforementioned specific implementation of intrusion detection smart devices for multiple types of data, further, the main board module, CAN&AD card, digital IO card, encryption and decryption card, rear input and output interface board and power supply module are connected through pinholes The device is plugged in with the backplane;

其中,所述主板模块、CAN&AD卡、数字IO卡、加解密卡及电源模块位于所述背板的前侧,所述后输入输出接口板位于所述背板的后侧。Wherein, the main board module, CAN&AD card, digital IO card, encryption and decryption card and power supply module are located on the front side of the backplane, and the rear input and output interface board is located on the back side of the backplane.

本实施例中,所述主板模块、CAN&AD卡、数字IO卡、加解密卡及电源模块位于所述背板的前侧,是实现入侵检测的关键板卡,位于所述背板前侧的板卡可以称为前侧板卡;所述后输入输出接口板位于所述背板的后侧,位于所述背板后侧的板卡可以称为后侧板卡;背板是前侧板卡和后侧板卡的中继,通过背板实现与前侧板卡、后侧板卡的中继连接,并完成接口的协议转换和数据传输;背板与前侧、后侧各个板卡在入侵检测智能设备中通过针孔式连接器形成垂直式插拔关系;例如,所述主板模块、CAN&AD卡、数字IO卡、加解密卡及电源模块可以通过二毫米高的密集型欧式针孔连接器与背板实现正面对插式连接,实现板卡间的电源和信号互通;背板通过J1/J4、J2/J5、J3这三种连接器与后输入输出接口板从背板的背面对插连接。信号由前面的各个板卡产生,经背板连接和中继,由后输入输出接口板上的相应接口输出,这样,入侵检测智能设备中通过高密度、高可靠性的欧式针孔连接器互联方式实现了电源和信号的传输及连接,能够提高整个设备的可靠性。In this embodiment, the main board module, CAN&AD card, digital IO card, encryption and decryption card, and power module are located on the front side of the backplane, and are key boards for realizing intrusion detection. The boards located on the front side of the backplane It can be called the front side board; the rear input and output interface board is located at the rear side of the backboard, and the board located at the rear side of the backboard can be called the rear side board; the backplane is the front side board and the backboard The relay of the rear board is to realize the relay connection with the front board and the rear board through the back board, and complete the protocol conversion and data transmission of the interface; Detect the vertical plug-in relationship through the pinhole connector in the smart device; for example, the motherboard module, CAN&AD card, digital IO card, encryption and decryption card and power module can be connected through the dense European pinhole connector with a height of 2 mm Realize front-to-side plug-in connection with the backplane to realize power and signal intercommunication between boards; the backplane connects with the rear input and output interface board from the back of the backplane through J1/J4, J2/J5, and J3 connectors connect. The signals are generated by the front boards, connected and relayed by the backplane, and output by the corresponding interfaces on the rear input and output interface boards. In this way, the intrusion detection smart devices are interconnected through high-density, high-reliability European-style pinhole connectors This method realizes the transmission and connection of power supply and signal, which can improve the reliability of the whole device.

在前述针对多种类型数据的入侵检测智能设备的具体实施方式中,进一步地,所述CAN&AD卡包括:第一转换模块和第一接口扩展模块;In the aforementioned specific implementation of the intrusion detection smart device for multiple types of data, further, the CAN&AD card includes: a first conversion module and a first interface expansion module;

所述第一转换模块,用于将PCI总线转换成本地总线,其中,所述本地总线与所述第一接口扩展模块相连;The first conversion module is configured to convert the PCI bus into a local bus, wherein the local bus is connected to the first interface expansion module;

所述第一接口扩展模块,用于扩展出多路CAN信号和多路AD信号,其中,所述多路CAN信号和多路AD信号通过所述背板连接到所述后输入输出接口板上,由所述后输入输出接口板提供多路CAN接口和多路AD接口。本实施例中,所述CAN&AD卡包括:第一转换模块和第一接口扩展模块,也就是说,所述第一转换模块和第一接口扩展模块是CAN&AD卡的部件,所述CAN&AD卡使用第一转换模块将将PCI总线转换成本地总线(所述本地总线也可以称为:局部总线),所述第一转换模块可以包括:PCI9054芯片和EEPROM芯片,其中,所述PCI9054芯片用于将PCI总线转换成本地总线,所述EEPROM芯片固化指令后长期存储PCI9054芯片的配置信息;所述本地总线连接第一接口扩展模块(其中,所述第一接口扩展模块可以为STM32F207ZGT6芯片)并扩展出10路AD信号和2路CAN信号,扩展出的10路AD信号和2路CAN信号经背板后连接到后输入输出接口板上,由后输入输出接口板对外提供10路AD接口和2路CAN接口,其中,STM32F207ZGT6芯片需要用J-Link工具和Keil5.0软件进行程序固化。The first interface expansion module is used to expand multiple CAN signals and multiple AD signals, wherein the multiple CAN signals and multiple AD signals are connected to the rear input and output interface board through the backplane , the rear input and output interface board provides multiple CAN interfaces and multiple AD interfaces. In this embodiment, the CAN&AD card includes: a first conversion module and a first interface expansion module, that is to say, the first conversion module and the first interface expansion module are components of the CAN&AD card, and the CAN&AD card uses the first A conversion module will convert the PCI bus into a local bus (the local bus can also be referred to as: local bus), and the first conversion module can include: PCI9054 chip and EEPROM chip, wherein, the PCI9054 chip is used to convert PCI The bus is converted into a local bus, and the configuration information of the PCI9054 chip is stored for a long time after the EEPROM chip curing instruction; 1-way AD signal and 2-way CAN signal, the extended 10-way AD signal and 2-way CAN signal are connected to the rear input and output interface board through the back panel, and the rear input and output interface board provides 10-way AD interface and 2-way CAN Interface, among them, the STM32F207ZGT6 chip needs to use the J-Link tool and Keil5.0 software for program curing.

本实施例中,如图3所示,PCI总线通过电路转换,并通过本地总线与板卡上的逻辑控制和处理电路相连完成接口对板卡的控制和信号的输入输出,逻辑控制和处理电路实现板卡功能需求,完成地址译码、数据格式转换、逻辑控制等功能,同时进行对外围功能电路和驱动电路的控制以及信号的输入和输出,其中,逻辑控制和处理电路可以通过FPGA器件实现。In this embodiment, as shown in Figure 3, the PCI bus is converted by the circuit, and is connected with the logic control and processing circuit on the board card through the local bus to complete the control of the board card and the input and output of the signal by the interface, and the logic control and processing circuit Realize the functional requirements of the board, complete address decoding, data format conversion, logic control and other functions, and at the same time control the peripheral functional circuits and drive circuits and input and output signals. Among them, the logic control and processing circuits can be realized by FPGA devices .

如图4所示,紧凑型PCI总线接口控制逻辑实现PCI9054芯片与64bit、66.6MHz PCI总线的接口;本地总线接口控制逻辑实现与PCI9054芯片的相连。PCI9054芯片的内部资源包括PCI配置内部寄存器、本地总线控制逻辑和一对读写FIFO,用于配置系统,并连接PCI总线与本地总线。PCI9054芯片的内部逻辑由串行EEPROM控制器和FIFO控制逻辑组成,前者用来从可选的外部串行EEPROM加载配置寄存器的值,后者控制读写FIFO,协调紧凑型PCI总线和本地总线。JTAG接口是通过Keil5.0软件及程序来调试电路的,通过这个接口将程序固化到发明的板卡中。As shown in Figure 4, the compact PCI bus interface control logic implements the interface between the PCI9054 chip and the 64bit, 66.6MHz PCI bus; the local bus interface control logic implements the connection with the PCI9054 chip. The internal resources of the PCI9054 chip include PCI configuration internal registers, local bus control logic and a pair of read-write FIFOs, which are used to configure the system and connect the PCI bus and the local bus. The internal logic of the PCI9054 chip is composed of a serial EEPROM controller and FIFO control logic. The former is used to load the configuration register value from an optional external serial EEPROM, and the latter controls the read and write FIFO, and coordinates the compact PCI bus and the local bus. The JTAG interface is used to debug the circuit through Keil5.0 software and program, and the program is solidified into the invented board through this interface.

其中,PCI9054芯片局部/本地总线有两种工作模式(MODE):非多路复用模式和多路复用模式。非多路复用模式下,当MODE输入为低的情况下,PCI9054采用非多路复用模式,相反,当MODE输入为高时,采用多路复用模式。多路复用模式下,LA[27:2]用来传输地址,LAD[63:32]是64位地址/数据复用总线;非多路复用模式下,LA[27:2]是地址总线,LD[63:32]是数据总线。Among them, the PCI9054 chip local/local bus has two working modes (MODE): non-multiplexing mode and multiplexing mode. In the non-multiplexing mode, when the MODE input is low, the PCI9054 adopts the non-multiplexing mode, on the contrary, when the MODE input is high, it adopts the multiplexing mode. In multiplexing mode, LA[27:2] is used to transmit the address, LAD[63:32] is a 64-bit address/data multiplexing bus; in non-multiplexing mode, LA[27:2] is the address bus, LD[63:32] is the data bus.

为了更好地理解本实施例,对紧凑型PCI总线信号进行说明:In order to better understand this embodiment, the compact PCI bus signal is described:

紧凑型PCI总线信号完成总线的时序转换,使入侵检测智能设备能控制各个组件(主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板和电源模块)的功能电路。本实施例使用PCI9054芯片加FPGA的接口方案,来完成CAN&AD卡和数字IO卡设计。将PLX公司生产的PCI9054芯片作为PCI控制器,利用Altera公司的FPGA进行读写逻辑和紧凑型PCI扩展功能设计。The compact PCI bus signal completes the timing conversion of the bus, so that the intrusion detection smart device can control the functional circuits of each component (mainboard module, CAN&AD card, digital IO card, encryption and decryption card, rear input and output interface board and power module). This embodiment uses the interface solution of PCI9054 chip plus FPGA to complete the design of CAN&AD card and digital IO card. The PCI9054 chip produced by PLX Company is used as the PCI controller, and the FPGA of Altera Company is used to design read and write logic and compact PCI expansion functions.

本实施例中,所述PCI9054是32/64位、频率33/66MHz的接口芯片,能使PCI信号最快传输速度达到264MB/s;支持本地总线多路复用和非多路复用32/64位地址或数据协议,并支持动态本地总线8位、16位和32位操作,本地时钟最高可达66.6MHz;支持5个PCI到本地地址空间映射,每个空间都允许单独编程等待状态、总线宽度和猝发传输功能;支持紧凑型PCI电源管理v2.2版本规范;支持关键产品数据(Vital Product Data,缩写为VPD)的PCI扩展及PCI目标预读取模式,可以增加带宽并减少读取延迟;PCI9054芯片有9个可编程通用目的I/O,可以用在多种用途;支持紧凑型PCI的热拔插;其电源支持DC3.3V和5V电压容错操作,并且具有可选的串行EEPROM接口。In the present embodiment, described PCI9054 is the interface chip of 32/64 bits, frequency 33/66MHz, can make the fastest transmission speed of PCI signal reach 264MB/s; Support local bus multiplexing and non-multiplexing 32/ 64-bit address or data protocol, and support dynamic local bus 8-bit, 16-bit and 32-bit operation, local clock up to 66.6MHz; support 5 PCI to local address space mapping, each space allows separate programming wait state, Bus width and burst transfer function; support compact PCI power management v2.2 specification; support PCI expansion of Vital Product Data (Vital Product Data, abbreviated as VPD) and PCI target pre-read mode, which can increase bandwidth and reduce read Delay; PCI9054 chip has 9 programmable general-purpose I/Os, which can be used for multiple purposes; supports hot plugging of compact PCI; its power supply supports DC3.3V and 5V voltage fault-tolerant operation, and has optional serial EEPROM interface.

紧凑型PCI总线的性能优异,采用欧式针孔连接器,可快速传输多种类型数据,其接口逻辑非常有深度,在总线的开发初期若要用FPGA来实现是比较困难的,而且可靠性较低,一般来说,采用专用的PCI接口芯片来实现紧凑型PCI的接口功能是一条非常有效、可靠的设计实现方法。The compact PCI bus has excellent performance. It adopts European-style pinhole connectors and can quickly transmit various types of data. Low, generally speaking, using a dedicated PCI interface chip to realize the interface function of the compact PCI is a very effective and reliable design implementation method.

本实施例中,使用的是美国ALTERA公司的FPGA器件及其开发环境及工具QUARTUSⅡ12.0,这是一种可由使用者根据所设计的数字系统的要求,在使用现场定义、配置的高密度专用数字集成电路。设计模块可在FPGA开发系统软件的支持下实现含有大规模逻辑门的数字系统的设计。In this embodiment, the FPGA device and its development environment and tool QUARTUSⅡ12.0 of ALTERA Company of the United States are used. This is a high-density special digital integrated circuits. The design module can realize the design of digital systems containing large-scale logic gates under the support of FPGA development system software.

FPGA的主要优点可归纳为以下三部分:The main advantages of FPGA can be summarized in the following three parts:

FPGA的用户现场可编程的特性大大缩短了设计周期,可以在较短的时间里,由设计者现场提供快速实现的样板。The FPGA's user-programmable feature greatly shortens the design cycle, and the designer can provide a fast-implementation template on-site in a short period of time.

FPGA可以提供比EPLD和CPLD器件大的多的有效逻辑容量密度,不仅大大减少印制电路板的空间,大大降低了系统功耗,同时大大提高了系统设计的工艺可实现性和产品的可靠性。FPGA can provide a much larger effective logic capacity density than EPLD and CPLD devices, which not only greatly reduces the space of printed circuit boards, greatly reduces system power consumption, but also greatly improves the process feasibility of system design and product reliability. .

FPGA器件可热擦写,反复编程,且可在开发过程中直接仿真,无工艺实现的损失。FPGA devices are thermally rewritable, reprogrammable, and can be simulated directly during the development process without loss of process implementation.

在前述针对多种类型数据的入侵检测智能设备的具体实施方式中,进一步地,所述数字IO卡包括:第二转换模块和第二接口扩展模块;In the aforementioned specific implementation of the intrusion detection smart device for multiple types of data, further, the digital IO card includes: a second conversion module and a second interface expansion module;

所述第二转换模块,用于将PCI总线转换成本地总线,其中,所述本地总线与所述第二接口扩展模块相连;The second conversion module is configured to convert the PCI bus into a local bus, wherein the local bus is connected to the second interface expansion module;

所述第二接口扩展模块,用于扩展出多路IO信号,其中,所述多路IO信号通过所述背板连接到所述后输入输出接口板上,由所述后输入输出接口板提供多路数字IO接口;The second interface expansion module is used to expand multiple IO signals, wherein the multiple IO signals are connected to the rear input and output interface board through the backplane, and are provided by the rear input and output interface board Multiple digital IO interface;

其中,所述多路数字IO接口中的每路数字IO接口可独立配置为输出接口或输入接口。Wherein, each digital IO interface in the multiple digital IO interfaces can be independently configured as an output interface or an input interface.

本实施例中,所述数字IO卡使用第二转换模块将PCI总线转换成本地总线,所述第二转换模块可以包括:PCI9054芯片和EEPROM芯片,其中,所述PCI9054芯片用于将PCI总线转换成本地总线,所述EEPROM芯片固化指令后长期存储PCI9054芯片的配置信息;所述本地总线连接第二接口扩展模块(其中,所述第二接口扩展模块可以为数字IO卡板载的EP1C3T144C8N芯片)并扩展出24路IO信号,扩展出的24路IO信号经背板后连接到后输入输出接口板上,由后输入输出接口板对外提供24路数字IO接口,其中,数字IO卡板载的EP1C3T144C8N芯片加载并用软件编译FPGA程序,需要用USB Blaster仿真器和QuartusII12.0软件进行程序固化。In this embodiment, the digital IO card uses a second conversion module to convert the PCI bus into a local bus, and the second conversion module may include: a PCI9054 chip and an EEPROM chip, wherein the PCI9054 chip is used to convert the PCI bus Cost local bus, long-term storage configuration information of PCI9054 chip after described EEPROM chip hardening order; Described local bus connects second interface expansion module (wherein, described second interface expansion module can be the EP1C3T144C8N chip onboard of digital IO card) And expand 24-way IO signals, the expanded 24-way IO signals are connected to the rear input and output interface board through the back panel, and the rear input and output interface board provides 24 digital IO interfaces to the outside, among which, the onboard digital IO card The EP1C3T144C8N chip loads and compiles the FPGA program with software, and needs to use the USB Blaster emulator and QuartusII12.0 software for program curing.

本实施例中,所述24路数字IO接口用于提供24路TTL数字量输入输出IO端口,每组IO端口可独立配置为输出端口或输入端口。In this embodiment, the 24 digital IO interfaces are used to provide 24 TTL digital input and output IO ports, and each group of IO ports can be independently configured as output ports or input ports.

本实施例中,如图5所示为数字IO卡的功能电路框图,10MHz光耦使用HCPL2631器件,驱动电路使用SG2003J/883b。数字量输出要经过驱动电路,将高压拉至26VDC,26V的电源由外围直流电源提供。应用程序设置某一路输出信号时,通过驱动接口函数设置这路对应的寄存器,FPGA会根据寄存器的设置值输出相应信号,再经过驱动电路后变为26VDC信号或者0VDC信号。In this embodiment, as shown in Fig. 5 is a functional circuit block diagram of the digital IO card, the 10MHz optocoupler uses the HCPL2631 device, and the driving circuit uses the SG2003J/883b. The digital output needs to go through the drive circuit to pull the high voltage to 26VDC, and the 26V power supply is provided by the peripheral DC power supply. When the application program sets a certain output signal, set the corresponding register through the driver interface function, and the FPGA will output the corresponding signal according to the setting value of the register, and then turn it into a 26VDC signal or 0VDC signal after passing through the driving circuit.

本实施例中,数字量的输入通过限流电阻后接入至10MHz光耦HCPL2631芯片,当输入信号电压为直流14.9V~26.1V时,光耦导通,会输出对应一个High状态,当输入信号为直流0V~0.81V时,光耦不导通,此时输出相应另一种Low状态,光耦的输出线是连接至FPGA器件EP2C8Q208C8N的,FPGA内部逻辑根据光耦的两种状态即可判定输入信号的High或Low状态,将这路数字量的输入状态放置相应的寄存器中。当应用程序要读取这路的状态时,需要调用驱动接口函数,经过芯片ULN2803AFWG和工业级继电器JRC-089M-002-05-II,实现数字量快速开关和状态转换,驱动接口函数会返回这路数字量输入信号的状态,把返回的状态传递给采集软件,经由软件解析并处理后,实现数字IO卡的功能。In this embodiment, the digital input is connected to the 10MHz optocoupler HCPL2631 chip through a current limiting resistor. When the input signal voltage is DC 14.9V-26.1V, the optocoupler is turned on and the output corresponds to a High state. When the input When the signal is DC 0V~0.81V, the optocoupler is not conducting, and at this time the output corresponds to another Low state. The output line of the optocoupler is connected to the FPGA device EP2C8Q208C8N, and the internal logic of the FPGA can be based on the two states of the optocoupler. Determine the High or Low state of the input signal, and place the input state of this digital quantity in the corresponding register. When the application program wants to read the state of this channel, it needs to call the driver interface function. After the chip ULN2803AFWG and the industrial grade relay JRC-089M-002-05-II, the digital quantity is quickly switched and the state is converted. The driver interface function will return this The state of the digital input signal of the channel, and the returned state is passed to the acquisition software. After the software analyzes and processes, the function of the digital IO card is realized.

在前述针对多种类型数据的入侵检测智能设备的具体实施方式中,进一步地,所述设备还包括:与所述背板相连的第一网口扩展模块和与所述第一网口扩展模块相连的网口变压器;In the aforementioned specific implementation of the intrusion detection smart device for multiple types of data, further, the device further includes: a first network port expansion module connected to the backplane and a network port expansion module connected to the first network port Connected network port transformer;

所述第一网口扩展模块和与所述第一网口扩展模块相连的网口变压器,用于扩展出第一路网口;The first network port expansion module and the network port transformer connected to the first network port expansion module are used to expand the first network port;

所述第一路网口,用于输入输出网络数据。The first network port is used for inputting and outputting network data.

本实施例中,所述与所述背板相连的第一网口扩展模块可以为ICH9M网络芯片,所述网口变压器可以为IMG\M1801IG芯片;ICH9M网络芯片连接网口变压器IMG\M1801IG并拓展出一路网口,其中,所述网口可以为光纤网口。In this embodiment, the first network port expansion module connected to the backplane may be ICH9M network chip, the network port transformer can be IMG\M1801IG chip; The ICH9M network chip is connected to the network port transformer IMG\M1801IG and expands a network port, wherein the network port can be a fiber optic network port.

本实施例中,通过两路光纤网口可以实现网络数据的以太网快速输入和输出,支持Ethernet和Internet传输标准,且信号传输支持标准的TCP/IP、EtherCAT和UDP协议。In this embodiment, the Ethernet fast input and output of network data can be realized through two optical fiber network ports, supporting Ethernet and Internet transmission standards, and signal transmission supports standard TCP/IP, EtherCAT and UDP protocols.

在前述针对多种类型数据的入侵检测智能设备的具体实施方式中,进一步地,所述设备还包括:与所述背板相连的第二网口扩展模块;In the aforementioned specific implementation of the intrusion detection smart device for multiple types of data, further, the device further includes: a second network port expansion module connected to the backplane;

所述第二网口扩展模块,用于扩展出第二路网口;The second network port expansion module is used to expand the second network port;

所述第二路网口,用于输入输出网络数据。The second network port is used for inputting and outputting network data.

本实施例中,所述第二网口扩展模块用一个PCIE X4信号扩展出另一路光纤网口,这样,通过两路光纤网口可以实现网络数据的以太网快速输入和输出,支持Ethernet和Internet传输标准,且信号传输支持标准的TCP/IP、EtherCAT和UDP协议。In this embodiment, the second network port expansion module uses a PCIE X4 signal to expand another optical fiber network port, so that the Ethernet fast input and output of network data can be realized through the two optical fiber network ports, supporting Ethernet and Internet Transmission standard, and signal transmission supports standard TCP/IP, EtherCAT and UDP protocols.

在前述针对多种类型数据的入侵检测智能设备的具体实施方式中,进一步地,所述设备还包括:与所述背板相连的交流滤波器;In the specific implementation of the aforementioned intrusion detection smart device for multiple types of data, further, the device further includes: an AC filter connected to the backplane;

所述交流滤波器,用于对220V交流电进行滤波处理。The AC filter is used for filtering the 220V AC.

本实施例中,如图2所示,所述设备还包括:与所述背板相连的交流滤波器;市电220V交流电由交流滤波器滤波处理后经由背板引入电源模块,电源模块上使用可靠的欧式电源连接器母头,与背板上欧式电源连接器公头对插连接。In this embodiment, as shown in Figure 2, the device further includes: an AC filter connected to the backplane; the mains 220V AC is filtered and processed by the AC filter and then introduced into the power module via the backplane, used on the power module Reliable European-style power connector female head, mated connection with the European-style power connector male head on the back panel.

在前述针对多种类型数据的入侵检测智能设备的具体实施方式中,进一步地,所述多种类型的输入输出接口还包括:显示口;In the aforementioned specific implementation of the intrusion detection smart device for multiple types of data, further, the multiple types of input and output interfaces further include: a display port;

所述显示口,用于接入液晶显示器。The display port is used for connecting to a liquid crystal display.

本实施例中,如图2所示,入侵检测智能设备的输入输出接口包括:加解密卡接口、网口、RS232串行接口、USB接口、CAN接口、AD接口和数字IO接口,如图6所示,所述入侵检测智能设备可以通过所述输入输出接口接入万兆交换机、键盘、鼠标、防火墙实现其对外接口。外部电压等数据、工业CAN设备发出的信号或数字IO信号经采集后存储至入侵检测智能设备之主板模块内嵌的硬盘中,并可通过上位机软件对数据进行读写操作。In this embodiment, as shown in Figure 2, the input and output interfaces of the intrusion detection smart device include: encryption and decryption card interface, network port, RS232 serial interface, USB interface, CAN interface, AD interface and digital IO interface, as shown in Figure 6 As shown, the intelligent intrusion detection device can be connected to a 10-Gigabit switch, a keyboard, a mouse, and a firewall through the input and output interfaces to realize its external interface. Data such as external voltage, signals from industrial CAN devices or digital IO signals are collected and stored in the hard disk embedded in the motherboard module of the intrusion detection smart device, and the data can be read and written through the host computer software.

本实施例中,所述多种类型的输入输出接口还可以包括:1个显示口,其中,所述显示口可以用于接入液晶显示器。In this embodiment, the multiple types of input and output interfaces may further include: a display port, wherein the display port may be used to connect to a liquid crystal display.

在前述针对多种类型数据的入侵检测智能设备的具体实施方式中,进一步地,所述设备还包括:与所述背板连接的备用板卡;其中,In the aforementioned specific implementation of the intrusion detection smart device for multiple types of data, further, the device further includes: a backup board connected to the backplane; wherein,

所述备用板卡包括:RS232串行接口卡、视频音频合成卡、1553B总线卡、基于紧凑型PCI总线的3U板卡、基于紧凑型PCI总线的6U板卡中的一种或多种。The spare boards include: one or more of RS232 serial interface cards, video and audio synthesis cards, 1553B bus cards, 3U boards based on compact PCI bus, and 6U boards based on compact PCI bus.

本实施例中,所述设备还包括:与所述背板连接的备用板卡,所述备用板卡位于所述背板的前侧;所述备用板卡可以根据实际情况,对所述设备的功能进行扩展,例如,所述备用板卡包括:RS232串行接口卡、视频音频合成卡、1553B总线卡、基于紧凑型PCI总线的3U板卡、基于紧凑型PCI总线的6U板卡中的一种或多种,如图2所示,可以通过备用卡槽插入备用板卡,从而进一步丰富入侵检测智能设备的功能性能,其中,6U板卡插槽可以插入3U板卡,具有很强的兼容性;紧凑型PCI总线摒弃了传统PCI总线的金手指形式,采用稳定可靠的针孔连接器形式,具备高密度和高可靠性,同时设备支持板卡的热插拔功能,实现多类型协议、多功能板卡的集成。In this embodiment, the device further includes: a spare board connected to the backplane, the spare board is located on the front side of the backplane; function expansion, for example, the spare board includes: RS232 serial interface card, video and audio synthesis card, 1553B bus card, 3U board card based on compact PCI bus, 6U board card based on compact PCI bus One or more, as shown in Figure 2, can be inserted through the spare card slot to further enrich the functional performance of the intrusion detection smart device. Among them, the 6U board slot can be inserted into the 3U board, which has a strong Compatibility: The compact PCI bus abandons the golden finger form of the traditional PCI bus, and adopts a stable and reliable pinhole connector form, which has high density and high reliability. At the same time, the device supports the hot-swappable function of the board and realizes multiple types of protocols. , Integration of multi-function boards.

本实施例中,所述背板、主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板、备用板卡都采用符合航空级或军品级的电子元器件,并使用符合紧凑型PCI标准、外观优美的结构件,能够保护内部板卡及其上芯片和元器件不被外部应力损伤。In this embodiment, the backplane, mainboard module, CAN&AD card, digital IO card, encryption and decryption card, rear input and output interface board, and spare board all use electronic components that meet aviation grade or military grade, and use compact PCI standard, beautiful structural parts, can protect the internal board and its chips and components from damage by external stress.

以上所述是本发明的优选实施方式,应当指出,对于本技术领域的普通技术人员来说,在不脱离本发明所述原理的前提下,还可以作出若干改进和润饰,这些改进和润饰也应视为本发明的保护范围。The above description is a preferred embodiment of the present invention, it should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present invention, some improvements and modifications can also be made, and these improvements and modifications can also be made. It should be regarded as the protection scope of the present invention.

Claims (10)

1.一种针对多种类型数据的入侵检测智能设备,其特征在于,包括:背板,与所述背板进行连接的主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板和电源模块;其中,所述背板支持紧凑型PCI协议;1. An intrusion detection intelligent device for multiple types of data, characterized in that it comprises: a backplane, a mainboard module connected to the backplane, a CAN&AD card, a digital IO card, an encryption and decryption card, and a rear input and output interface Board and power supply module; Wherein, described backplane supports compact PCI protocol; 所述后输入输出接口板,用于提供多种类型的输入输出接口,其中,所述多种类型的输入输出接口包括:加解密卡接口、网口、RS232串行接口、USB接口、CAN接口、AD接口和数字IO接口,每种类型的输入输出接口,用于实时获取相应类型的数据;The rear input and output interface board is used to provide multiple types of input and output interfaces, wherein the multiple types of input and output interfaces include: encryption and decryption card interface, network port, RS232 serial interface, USB interface, CAN interface , AD interface and digital IO interface, each type of input and output interface is used to obtain the corresponding type of data in real time; 所述CAN&AD卡,用于通过所述背板与所述CAN接口、AD接口进行通信;The CAN&AD card is used to communicate with the CAN interface and the AD interface through the backplane; 所述数字IO卡,用于通过所述背板与所述数字IO接口进行通信;The digital IO card is used to communicate with the digital IO interface through the backplane; 所述主板模块,用于依据预设的入侵检测规则,对获取的所述数据进行入侵检测;The mainboard module is used to perform intrusion detection on the acquired data according to preset intrusion detection rules; 所述加解密卡,用于对未被入侵的数据进行加解密和数字认证处理;The encryption/decryption card is used to perform encryption/decryption and digital authentication processing on unintruded data; 所述电源模块,用于为所述背板供电。The power module is used to supply power to the backplane. 2.根据权利要求1所述的针对多种类型数据的入侵检测智能设备,其特征在于,所述主板模块、CAN&AD卡、数字IO卡、加解密卡、后输入输出接口板及电源模块通过针孔式连接器与所述背板进行对插连接;2. The intrusion detection intelligent device for multiple types of data according to claim 1, wherein the main board module, CAN&AD card, digital IO card, encryption and decryption card, rear input and output interface board and power supply module pass through the needle The hole connector is plugged into the backplane; 其中,所述主板模块、CAN&AD卡、数字IO卡、加解密卡及电源模块位于所述背板的前侧,所述后输入输出接口板位于所述背板的后侧。Wherein, the main board module, CAN&AD card, digital IO card, encryption and decryption card and power supply module are located on the front side of the backplane, and the rear input and output interface board is located on the back side of the backplane. 3.根据权利要求1所述的针对多种类型数据的入侵检测智能设备,其特征在于,所述多种类型的输入输出接口包括:1路保密卡接口、2路网口、2路RS232串行接口、6路USB接口、2路CAN接口、10路AD接口、24路数字IO接口。3. The intrusion detection intelligent device for multiple types of data according to claim 1, wherein the multiple types of input and output interfaces include: 1 security card interface, 2 network ports, 2 RS232 serial ports Line interface, 6-way USB interface, 2-way CAN interface, 10-way AD interface, 24-way digital IO interface. 4.根据权利要求1或3所述的针对多种类型数据的入侵检测智能设备,其特征在于,所述CAN&AD卡包括:第一转换模块和第一接口扩展模块;4. according to claim 1 or 3 described for the intrusion detection intelligent equipment of multiple types of data, it is characterized in that, described CAN&AD card comprises: the first conversion module and the first interface expansion module; 所述第一转换模块,用于将PCI总线转换成本地总线,其中,所述本地总线与所述第一接口扩展模块相连;The first conversion module is configured to convert the PCI bus into a local bus, wherein the local bus is connected to the first interface expansion module; 所述第一接口扩展模块,用于扩展出多路CAN信号和多路AD信号,其中,所述多路CAN信号和多路AD信号通过所述背板连接到所述后输入输出接口板上,由所述后输入输出接口板提供多路CAN接口和多路AD接口。The first interface expansion module is used to expand multiple CAN signals and multiple AD signals, wherein the multiple CAN signals and multiple AD signals are connected to the rear input and output interface board through the backplane , the rear input and output interface board provides multiple CAN interfaces and multiple AD interfaces. 5.根据权利要求1或3所述的针对多种类型数据的入侵检测智能设备,其特征在于,所述数字IO卡包括:第二转换模块和第二接口扩展模块;5. according to claim 1 or 3 described for the intrusion detection intelligent equipment of multiple types of data, it is characterized in that, described digital IO card comprises: the second conversion module and the second interface expansion module; 所述第二转换模块,用于将PCI总线转换成本地总线,其中,所述本地总线与所述第二接口扩展模块相连;The second conversion module is configured to convert the PCI bus into a local bus, wherein the local bus is connected to the second interface expansion module; 所述第二接口扩展模块,用于扩展出多路IO信号,其中,所述多路IO信号通过所述背板连接到所述后输入输出接口板上,由所述后输入输出接口板提供多路数字IO接口;The second interface expansion module is used to expand multiple IO signals, wherein the multiple IO signals are connected to the rear input and output interface board through the backplane, and are provided by the rear input and output interface board Multiple digital IO interface; 其中,所述多路数字IO接口中的每路数字IO接口可独立配置为输出接口或输入接口。Wherein, each digital IO interface in the multiple digital IO interfaces can be independently configured as an output interface or an input interface. 6.根据权利要求1或3所述的针对多种类型数据的入侵检测智能设备,其特征在于,所述设备还包括:与所述背板相连的第一网口扩展模块和与所述第一网口扩展模块相连的网口变压器;6. according to claim 1 or 3 described for the intrusion detection intelligent equipment of multiple types of data, it is characterized in that, described equipment also comprises: the first network port expansion module that links to each other with described backplane and with described second A network port transformer connected to the network port expansion module; 所述第一网口扩展模块和与所述第一网口扩展模块相连的网口变压器,用于扩展出第一路网口;The first network port expansion module and the network port transformer connected to the first network port expansion module are used to expand the first network port; 所述第一路网口,用于输入输出网络数据。The first network port is used for inputting and outputting network data. 7.根据权利要求1或3所述的针对多种类型数据的入侵检测智能设备,其特征在于,所述设备还包括:与所述背板相连的第二网口扩展模块;7. The intrusion detection intelligent device for multiple types of data according to claim 1 or 3, wherein the device further comprises: a second network port expansion module connected to the backplane; 所述第二网口扩展模块,用于扩展出第二路网口;The second network port expansion module is used to expand the second network port; 所述第二路网口,用于输入输出网络数据。The second network port is used for inputting and outputting network data. 8.根据权利要求1或3所述的针对多种类型数据的入侵检测智能设备,其特征在于,所述设备还包括:与所述背板相连的交流滤波器;8. The intrusion detection intelligent device for multiple types of data according to claim 1 or 3, wherein the device further comprises: an AC filter connected to the backplane; 所述交流滤波器,用于对220V交流电进行滤波处理。The AC filter is used for filtering the 220V AC. 9.根据权利要求1或3所述的针对多种类型数据的入侵检测智能设备,其特征在于,所述多种类型的输入输出接口还包括:显示口;9. The intrusion detection intelligent device for multiple types of data according to claim 1 or 3, wherein the multiple types of input and output interfaces further include: a display port; 所述显示口,用于接入液晶显示器。The display port is used for connecting to a liquid crystal display. 10.根据权利要求1或3所述的针对多种类型数据的入侵检测智能设备,其特征在于,所述设备还包括:与所述背板连接的备用板卡;其中,10. The intrusion detection intelligent device for multiple types of data according to claim 1 or 3, wherein the device further comprises: a spare board connected to the backplane; wherein, 所述备用板卡包括:RS232串行接口卡、视频音频合成卡、1553B总线卡、基于紧凑型PCI总线的3U板卡、基于紧凑型PCI总线的6U板卡中的一种或多种。The spare boards include: one or more of RS232 serial interface cards, video and audio synthesis cards, 1553B bus cards, 3U boards based on compact PCI bus, and 6U boards based on compact PCI bus.
CN201710028126.3A 2017-01-13 2017-01-13 An intelligent device for intrusion detection for various types of data Active CN106845219B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201710028126.3A CN106845219B (en) 2017-01-13 2017-01-13 An intelligent device for intrusion detection for various types of data

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201710028126.3A CN106845219B (en) 2017-01-13 2017-01-13 An intelligent device for intrusion detection for various types of data

Publications (2)

Publication Number Publication Date
CN106845219A true CN106845219A (en) 2017-06-13
CN106845219B CN106845219B (en) 2019-05-10

Family

ID=59124637

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201710028126.3A Active CN106845219B (en) 2017-01-13 2017-01-13 An intelligent device for intrusion detection for various types of data

Country Status (1)

Country Link
CN (1) CN106845219B (en)

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107656889A (en) * 2017-08-04 2018-02-02 上海航天电子有限公司 A kind of aerospace electronic product universal detection device
CN108021125A (en) * 2017-12-28 2018-05-11 深圳市永达电子信息股份有限公司 Industrial system signal of communication detecting system
CN108809727A (en) * 2018-06-15 2018-11-13 北京科技大学 A kind of intrusion prevention system of DC motor control system
CN109766301A (en) * 2018-12-25 2019-05-17 北京航天晨信科技有限责任公司 For infusing the bus apparatus of the signal communication of key function
CN113110395A (en) * 2021-04-30 2021-07-13 西安热工研究院有限公司 Multi-bus testing device and method for high-temperature gas cooled reactor control system
CN113204804A (en) * 2021-04-25 2021-08-03 山东英信计算机技术有限公司 Security module, server mainboard and server
CN113242214A (en) * 2021-04-19 2021-08-10 国电南瑞科技股份有限公司 Encryption authentication device, system and method between power secondary equipment board cards
CN113253263A (en) * 2021-06-22 2021-08-13 湖南华诺星空电子技术有限公司 Three-dimensional through-wall radar system
CN113472964A (en) * 2021-06-05 2021-10-01 山东英信计算机技术有限公司 Image processing device and system
CN115847451A (en) * 2022-12-26 2023-03-28 江西洪都航空工业集团有限责任公司 Distributed intelligent robot control system

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102223320A (en) * 2011-03-31 2011-10-19 华车(北京)交通装备有限公司 CANOPEN-HDLC gateway based on ARM 7
CN103491530A (en) * 2013-09-11 2014-01-01 辽源市信长城信息技术研发有限公司 Intelligent PAD with information safety mechanism
CN204884126U (en) * 2015-07-30 2015-12-16 国家电网公司 An intrusion detection information collection communication device
CN205283601U (en) * 2016-01-15 2016-06-01 成都智扬易方软件有限公司 Take intrusion detection's network security isolated system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102223320A (en) * 2011-03-31 2011-10-19 华车(北京)交通装备有限公司 CANOPEN-HDLC gateway based on ARM 7
CN103491530A (en) * 2013-09-11 2014-01-01 辽源市信长城信息技术研发有限公司 Intelligent PAD with information safety mechanism
CN204884126U (en) * 2015-07-30 2015-12-16 国家电网公司 An intrusion detection information collection communication device
CN205283601U (en) * 2016-01-15 2016-06-01 成都智扬易方软件有限公司 Take intrusion detection's network security isolated system

Cited By (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107656889A (en) * 2017-08-04 2018-02-02 上海航天电子有限公司 A kind of aerospace electronic product universal detection device
CN108021125A (en) * 2017-12-28 2018-05-11 深圳市永达电子信息股份有限公司 Industrial system signal of communication detecting system
CN108809727A (en) * 2018-06-15 2018-11-13 北京科技大学 A kind of intrusion prevention system of DC motor control system
CN108809727B (en) * 2018-06-15 2020-08-07 北京科技大学 Intrusion prevention system of direct current motor control system
CN109766301A (en) * 2018-12-25 2019-05-17 北京航天晨信科技有限责任公司 For infusing the bus apparatus of the signal communication of key function
CN113242214A (en) * 2021-04-19 2021-08-10 国电南瑞科技股份有限公司 Encryption authentication device, system and method between power secondary equipment board cards
CN113242214B (en) * 2021-04-19 2022-09-23 国电南瑞科技股份有限公司 Device, system and method for encryption authentication between boards of power secondary equipment
CN113204804A (en) * 2021-04-25 2021-08-03 山东英信计算机技术有限公司 Security module, server mainboard and server
CN113204804B (en) * 2021-04-25 2022-03-22 山东英信计算机技术有限公司 Security module, server mainboard and server
CN113110395A (en) * 2021-04-30 2021-07-13 西安热工研究院有限公司 Multi-bus testing device and method for high-temperature gas cooled reactor control system
CN113472964A (en) * 2021-06-05 2021-10-01 山东英信计算机技术有限公司 Image processing device and system
CN113472964B (en) * 2021-06-05 2024-04-16 山东英信计算机技术有限公司 Image processing device and system
CN113253263A (en) * 2021-06-22 2021-08-13 湖南华诺星空电子技术有限公司 Three-dimensional through-wall radar system
CN113253263B (en) * 2021-06-22 2021-10-15 湖南华诺星空电子技术有限公司 Three-dimensional through-wall radar system
CN115847451A (en) * 2022-12-26 2023-03-28 江西洪都航空工业集团有限责任公司 Distributed intelligent robot control system

Also Published As

Publication number Publication date
CN106845219B (en) 2019-05-10

Similar Documents

Publication Publication Date Title
CN106845219B (en) An intelligent device for intrusion detection for various types of data
CN108628791B (en) High-speed security chip based on PCIE interface
CN103207852B (en) Multibus embedded processing device
CN108829567A (en) Support the monolithic NVMe hard disk backboard of dual lighting and the ignition method of hard disk backboard
KR101035832B1 (en) Integrated endpoint device, integrated PCI Express endpoint device and PCI Express communication system
CN104021104B (en) A kind of cooperative system and its communication means based on dual-bus structure
CN208188815U (en) BMC module system
CN103399830B (en) The Apparatus and method for of computer physics internal memory is read by PCI Express bus
US20190271740A1 (en) Non-intrusive on-chip debugger with remote protocol support
CN204595692U (en) Based on the VPX computer motherboard of Shen prestige 410 processor and Shen Wei nest plate
CN107645457A (en) A kind of PCIe switch system and method
CN102880235B (en) Single-board computer based on loongson 2F central processing unit (CPU) as well as reset management and using method of single-board computer
CN104461796B (en) JTAG debugging modules and adjustment method for embedded 8051CPU
CN111737178B (en) Method and equipment for obtaining evidence in computer memory and memory evidence analysis system
CN104375916A (en) Method and device for directly achieving computer hardware diagnosis through USB interface
CN207650794U (en) A kind of desktop mainboard based on Feiteng processor
CN101226571B (en) Information safety computer
CN106548099A (en) A kind of chip of circuit system safeguard protection
CN203502954U (en) Computer device and identification device thereof
CN202205195U (en) Equipment for reading and writing physical memory of computer through IEEE 1394 interface
CN203386206U (en) Device for reading physical memory of computer through PCI Express interface
CN203759602U (en) Nest plate-based CPCI (Compact Peripheral Component Interconnect) industrial control computer mainboard
CN101169767B (en) Access control device and access control method
CN107770228B (en) 1-Wire communication system and method based on CPCI master control
CN205318283U (en) Special isolation equipment mainboard based on explain 410 majestic treaters and shen wei nest plate

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant
TR01 Transfer of patent right

Effective date of registration: 20200708

Address after: Room 608, block a, building 1, liantai Times Plaza, 699 Shimao Road, Honggutan New District, Nanchang City, Jiangxi Province

Patentee after: Nanchang Minshun Technology Co., Ltd

Address before: 100083 Haidian District, Xueyuan Road, No. 30,

Patentee before: University OF SCIENCE AND TECHNOLOGY BEIJING

TR01 Transfer of patent right
TR01 Transfer of patent right

Effective date of registration: 20200819

Address after: Room 1411, Juneng building, high tech Industrial Development Zone, Yingtan City, Jiangxi Province

Patentee after: Yingtan Zhihui Internet of things Application Research Institute Co.,Ltd.

Address before: Room 608, block a, building 1, liantai Times Plaza, 699 Shimao Road, Honggutan New District, Nanchang City, Jiangxi Province

Patentee before: Nanchang Minshun Technology Co., Ltd

TR01 Transfer of patent right