CN106919855A - A kind of law enforcement evidence-obtaining system and its evidence collecting method based on USB flash disk - Google Patents

A kind of law enforcement evidence-obtaining system and its evidence collecting method based on USB flash disk Download PDF

Info

Publication number
CN106919855A
CN106919855A CN201710274035.8A CN201710274035A CN106919855A CN 106919855 A CN106919855 A CN 106919855A CN 201710274035 A CN201710274035 A CN 201710274035A CN 106919855 A CN106919855 A CN 106919855A
Authority
CN
China
Prior art keywords
evidence
module
law enforcement
usb flash
flash disk
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201710274035.8A
Other languages
Chinese (zh)
Inventor
王灵华
王丽萍
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Individual filed Critical Individual
Priority to CN201710274035.8A priority Critical patent/CN106919855A/en
Publication of CN106919855A publication Critical patent/CN106919855A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/78Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
    • G06F21/79Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in semiconductor storage media, e.g. directly-addressable memories

Abstract

The technical field of present invention law enforcement evidence-obtaining system, specially a kind of law enforcement evidence-obtaining system and its evidence collecting method based on USB flash disk, including authentication module:For ensuring USB flash disk use fairly;Presetting module:For being preset to evidence obtaining object before operation of collecting evidence;Camouflage module:Antivirus software or fire wall for tackling and preventing conventional computer;Identification module:For recognizing data and information in other side's storage device, the file type that discovery pre-sets.Replication module:For carrying out duplication operation to the file for recognizing;Memory module:Information for recording the generation instrument of evidence, record storage file and document source.Simple structure of the present invention, it is practical.

Description

A kind of law enforcement evidence-obtaining system and its evidence collecting method based on USB flash disk
Technical field
The technical field of present invention law enforcement evidence-obtaining system, specially a kind of law enforcement evidence-obtaining system and its evidence obtaining based on USB flash disk Method.
Background technology
At present, with the popularization of computer technology, all in swift electron, we progress into information-based society to various information Meeting.Equally, the crime of offender also increasingly has Informational Trend, is committed a crime using network technology electronic equipment more and more, The electronic information being thus stored in the electronic equipments such as related computer mobile phone is also more and more, electronic data also more and more into It is evidence of crime.
In face of increasing informationization crime, during investigation department wishes to obtain above-mentioned storage device by correlation means Electronic evidence demand it is also very urgent.But electronic evidence is generally rested in suspicion staff, unless grasped Other sufficient evidences, investigation department lacks absolutely front face and discloses evidence obtaining, can only otherwise startle suspect, once suspect destroys card Work can only be influenceed on the contrary according to flying far and high;Meanwhile, being destroyed except there is suspect's subjective aspect, changing electronic evidence May be outer, also other system crashes, evidence covering, the unpredictable objective factor influence such as be deleted, institute as The electronic evidence of orphan's card, both demand is urgent but should not disclose and transfer for law enforcement agency, faces many difficulties.
Therefore it provides one kind can be law enforcement agency's especially police unit efficient and convenient and secret duplication in investigation is handled a case The instrument of electronic evidence is extracted, and ensures the justice after electronic evidence extraction, be investigation department and related-art technology The technical problem of personnel's urgent need to resolve.
The content of the invention
In view of the shortcomings of the prior art, taken it is an object of the invention to provide a kind of efficient, law enforcement based on USB flash disk Card system and its evidence collecting method.
To achieve the above object, the invention provides following technical scheme:A kind of law enforcement evidence-obtaining system based on USB flash disk, bag Include
Authentication module:For ensuring USB flash disk use fairly;
Presetting module:For being preset to evidence obtaining object before operation of collecting evidence;
Camouflage module:Antivirus software or fire wall for tackling and preventing conventional computer;
Identification module:For recognizing data and information in other side's storage device, the file type that discovery pre-sets;
Replication module:For carrying out duplication operation to the file for recognizing;
Memory module:Information for recording the generation instrument of evidence, record storage file and document source.
The present invention is further arranged to:Described authentication module also includes secret generation module, in specific computer Or authentication password is generated on server.
The present invention is further arranged to:Described memory module also includes encrypting module, for the instrument of evidence that will be stored Generate the instrument of evidence of encryption.
The present invention is further arranged to:Described memory module also includes logging modle, for record storage timestamp, text The relevant informations such as part information, other side's computer hardware information, evidence obtaining process and evidence obtaining result.
The present invention is further arranged to:Described camouflage module also includes reminding module, is given when being completed for collecting evidence and carried Show.
A kind of evidence collecting method suitable for above-mentioned law enforcement evidence-obtaining system, comprises the following steps that:
A is examined:Law enforcement evidence obtaining USB flash disk is leading computer or server to examine using preceding need by law enforcement agency, obtains certification(I.e. Law enforcement agency leader ratifies)Afterwards, and on law enforcement agency's computer or server authentication password is generated, for USB flash disk when insertion is used Input validation;
B law enforcement modes are preset:USB flash disk is pre-set by the server or webpage of law enforcement agency, is preset law enforcement USB flash disk and is intended The file type of evidence obtaining;
C enters spoofing mode:When computer or other storage devices that the evidence obtaining USB flash disk insertion for presetting is collected evidence, input step a The authentication password that middle generation is obtained, USB flash disk is by pretending module automatically into spoofing mode;
D recognizes file:The data and information during module recognizes the computer or other storage devices collected evidence are set, discovery sets in advance The file type put;
E is replicated:Replication module runs, and automatic duplication is carried out to qualified specified file and is operated;
F is recorded:By logging modle, by the instrument of evidence of file storage generation encryption, the instrument of evidence includes qualified finger Determine file and this document information;
G is pointed out:After the file for meeting setting is all replicated storage, reminding module can be pointed out appropriately.U can now be extracted Disk, evidence obtaining is completed;
Contrast the deficiencies in the prior art, the beneficial effect that the technical scheme that the present invention is provided is brought:1. allow to have permission( To law enforcement agency leader approval)Law-executor use, to prevent other users from carrying out illegal operation;2. secret generation module, uses In specific(On law enforcement agency's computer or server)Computer or server on generate authentication password, for ensure it is rigorous, legal Using law enforcement evidence obtaining USB flash disk, law enforcement evidence obtaining USB flash disk examined by law enforcement agency leader using preceding need, obtain certification(Enforce the law single Position leader's approval)Afterwards, and on law enforcement agency's computer or server authentication password is generated, is input into when insertion is used for USB flash disk and tested Card.Meanwhile, the instrument of evidence that law enforcement evidence obtaining USB flash disk is obtained also could be only opened on the server or computer of law enforcement agency, with This prevents and controls the illegal of law enforcement USB flash disk to use and abuse;3., by the server or webpage of law enforcement agency, USB flash disk is carried out pre- First set, preset the file type that law enforcement USB flash disk intends evidence obtaining, by setting file type raising evidence obtaining speed and preventing hand of enforcing the law The abuse of section;4. it is used to record the information of the instrument of evidence of generation encryption, record storage file and document source, instrument of evidence bag Qualified specified file and this document information are included, this document information includes record storage timestamp, fileinfo, Dui Fang electricity The relevant information of brain hardware information, evidence obtaining process and evidence obtaining result, to embody the source objectivity of evident information, prevents illegal Distort;5. replication module:For carrying out the automatic disguise for replicating operation, improving during work to qualified specified file.
Brief description of the drawings
Fig. 1 is structural representation of the invention.
Specific embodiment
For secret law enforcement needs, solve suspect and destroy, hide or refuse to provide disclosed in the law enforcements such as electronic evidence Collect evidence the practical challenges of inconvenience, extract the evidence related to crime in time, it is special invented it is a kind of efficiently, the law enforcement based on USB flash disk Evidence-obtaining system and its evidence collecting method, the USB flash disk appearance are as good as with common U disk, specific function be for police unit, procurator's office, The law enforcement agencies such as security department, intelligence department are provided during one kind can quickly recognize the electronic storage devices such as other side's computer, mobile phone Respective file, be under the guise of friendship interface automatically, and secret reads electronic evidence material needed for replicating;And set by related system Put, the law enforcement USB flash disk can be prevented not to be illegally used or abuse.
The present invention will be further described for reference picture 1.
A kind of law enforcement evidence-obtaining system based on USB flash disk, including
Authentication module 1:For ensuring USB flash disk use fairly, the work for controlling USB flash disk only allows to have permission(Obtain Law enforcement agency leader ratifies)Law-executor use, to prevent other users from carrying out illegal operation.
Described authentication module 1 also includes secret generation module 11, for specific(Law enforcement agency's computer or server On)Computer or server on generate authentication password, to ensure rigorous, legal to use law enforcement evidence obtaining USB flash disk, law enforcement evidence obtaining USB flash disk Examined by law enforcement agency leader using preceding need, obtain certification(That is law enforcement agency leader approval)Afterwards, and in law enforcement agency's electricity Generate authentication password on brain or server, for USB flash disk when insertion is used input validation.Meanwhile, also only in the clothes of law enforcement agency The instrument of evidence that law enforcement evidence obtaining USB flash disk is obtained could be opened on business device or computer, prevents and control the illegal of law enforcement USB flash disk to use with this And abuse;
Presetting module 2:For being preset to evidence obtaining object before operation of collecting evidence, by the server or net of law enforcement agency Page, is pre-set to USB flash disk, presets the file type that law enforcement USB flash disk intends evidence obtaining, and evidence obtaining speed is improved by setting file type Spend and prevent the abuse of law enforcement means;
Camouflage module 3:Antivirus software or fire wall for tackling and preventing conventional computer, when the evidence obtaining USB flash disk insertion for presetting When the computer collected evidence or other storage devices, USB flash disk is that display " is recognized by pretending module 3 automatically into spoofing mode, on surface Card password login ", the raw authentication password of input, and backstage is then operation mask program, anti-antivirus is soft in being used to shield counterpart device The prompting of part, and the friendly interface that disguises oneself as is to screen secret evidence obtaining.
Identification module 4:For recognizing data and information in other side's storage device, the file type for pre-setting is found, The respective file in the electronic storage devices such as other side's computer, mobile phone can be quickly recognized, operating efficiency is further improved.
Replication module 5:For being replicated automatically to the file for recognizing;
Memory module 6:The information of the instrument of evidence for recording generation encryption, record storage file and document source, evidence text Part includes qualified specified file and this document information, and this document information includes record storage timestamp, fileinfo, right Square computer hardware information, evidence obtaining process and evidence obtaining result relevant information, to embody the source objectivity of evident information, prevent by Illegally distort;
Described memory module 6 also includes encrypting module 61, the instrument of evidence of the instrument of evidence generation encryption for that will store.
Described memory module 6 also includes logging modle 62, for record storage timestamp, fileinfo, other side's computer The relevant informations such as hardware information, evidence obtaining process and evidence obtaining result;
Described camouflage module 3 also includes reminding module 31, is given when being completed for collecting evidence and pointed out.
Processor 7:It is connected with each module(Authentication module 1, presetting module 2, camouflage module 3, identification module 4, replication module 5th, memory module 6), for processing server and the instruction and data of each module.
A kind of evidence collecting method suitable for above-mentioned law enforcement evidence-obtaining system, comprises the following steps that:
A is examined:To ensure rigorous, the legal USB flash disk of collecting evidence of enforcing the law that uses, law enforcement evidence obtaining USB flash disk is using preceding need by law enforcement agency Leader examines, and obtains certification(That is law enforcement agency leader approval)Afterwards, and on law enforcement agency's computer or server certification is generated close Code, for USB flash disk when insertion is used input validation.Meanwhile, also could only be opened on the server or computer of law enforcement agency and held The instrument of evidence that method evidence obtaining USB flash disk is obtained, prevents and controls the illegal of law enforcement USB flash disk to use and abuse with this;
B law enforcement modes are preset:USB flash disk is pre-set by the server or webpage of law enforcement agency, is preset law enforcement USB flash disk and is intended The file type of evidence obtaining, collect evidence speed and the abuse for preventing means are improved by setting file type;
C enters spoofing mode:When computer or other storage devices that the evidence obtaining USB flash disk insertion for presetting is collected evidence, USB flash disk is by puppet Die-filling piece 3 automatically into spoofing mode, when computer or other storage devices that the evidence obtaining USB flash disk insertion for presetting is collected evidence, USB flash disk It is display " authentication password login " automatically into spoofing mode, on surface by pretending module 3, is generated in input step a and obtained Authentication password, and backstage then be operation mask program, be used to shield the prompting of anti-virus software in counterpart device, and disguise oneself as Friendly interface is screening secret evidence obtaining;
D recognizes file:The data and information during module recognizes the computer or other storage devices collected evidence are set, discovery sets in advance The file type put, can quickly recognize the respective file in the electronic storage devices such as other side's computer, mobile phone, further improve work Make efficiency;
E is replicated:Replication module 5 runs, and automatic duplication is carried out to qualified specified file and is operated, hidden during raising work Covering property;
F is recorded:By logging modle 62, by the instrument of evidence of file storage generation encryption, the instrument of evidence includes qualified Specified file and this document information, this document information include record storage timestamp, fileinfo, other side's computer hardware information, The relevant information of evidence obtaining process and evidence obtaining result, to embody the source objectivity of evident information, prevents from illegally being distorted;
G is pointed out:After the file for meeting setting is all replicated storage, reminding module 31 can be pointed out appropriately.Can now pull out Go out USB flash disk, evidence obtaining is completed.
Presently preferred embodiments of the present invention is the foregoing is only, is not intended to limit the invention, those skilled in the art exists Common variations and alternatives are carried out in the range of technical solution of the present invention all should be comprising within the scope of the present invention.

Claims (8)

1. a kind of law enforcement evidence-obtaining system based on USB flash disk, including processor, it is characterised in that:Also include
Authentication module:For ensuring USB flash disk use fairly;
Camouflage module:Antivirus software or fire wall for tackling and preventing conventional computer;
Replication module:For carrying out duplication operation to the file for recognizing;
Memory module:Information for recording the generation instrument of evidence, record storage file and document source;
Processor:It is connected with authentication module, camouflage module, replication module, replication module respectively.
2. a kind of law enforcement evidence-obtaining system based on USB flash disk according to claim 1, it is characterised in that:Also include presetting module: For being preset to evidence obtaining object before operation of collecting evidence.
3. a kind of law enforcement evidence-obtaining system based on USB flash disk according to claim 1 and 2, it is characterised in that:Also include identification mould Block:For recognizing data and information in other side's storage device, the file type that discovery pre-sets.
4. a kind of law enforcement evidence-obtaining system based on USB flash disk according to claim 1, it is characterised in that:Described authentication module Also include secret generation module, for generating authentication password on specific computer or server.
5. a kind of law enforcement evidence-obtaining system based on USB flash disk according to claim 1, it is characterised in that:Described memory module Also include encrypting module, the instrument of evidence of the instrument of evidence generation encryption for that will store.
6. a kind of law enforcement evidence-obtaining system based on USB flash disk according to claim 1, it is characterised in that:Described memory module Also include logging modle, for record storage timestamp, fileinfo, other side's computer hardware information, evidence obtaining process and evidence obtaining knot The relevant informations such as fruit.
7. a kind of law enforcement evidence-obtaining system based on USB flash disk according to claim 1, it is characterised in that:Described camouflage module Also include reminding module, given when being completed for collecting evidence and pointed out.
8. a kind of 1-7 suitable for claim any one enforce the law evidence-obtaining system evidence collecting method, it is characterised in that:Specifically according to Secondary step is as follows:
A is examined:Law enforcement evidence obtaining USB flash disk is leading computer or server to examine using preceding need by law enforcement agency, obtains certification(I.e. Law enforcement agency leader ratifies)Afterwards, and on law enforcement agency's computer or server authentication password is generated, for USB flash disk when insertion is used Input validation;
B law enforcement modes are preset:USB flash disk is pre-set by the server or webpage of law enforcement agency, is preset law enforcement USB flash disk and is intended The file type of evidence obtaining;
C enters spoofing mode:When computer or other storage devices that the evidence obtaining USB flash disk insertion for presetting is collected evidence, input step a The authentication password that middle generation is obtained, USB flash disk is by pretending module automatically into spoofing mode;
D recognizes file:The data and information during module recognizes the computer or other storage devices collected evidence are set, discovery sets in advance The file type put;
E is replicated:Replication module runs, and automatic duplication is carried out to qualified specified file and is operated;
F is recorded:By logging modle, by the instrument of evidence of file storage generation encryption, the instrument of evidence includes qualified finger Determine file and this document information;
G is pointed out:After the file for meeting setting is all replicated storage, reminding module can be pointed out appropriately, can now extract U Disk, evidence obtaining is completed.
CN201710274035.8A 2017-04-25 2017-04-25 A kind of law enforcement evidence-obtaining system and its evidence collecting method based on USB flash disk Pending CN106919855A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201710274035.8A CN106919855A (en) 2017-04-25 2017-04-25 A kind of law enforcement evidence-obtaining system and its evidence collecting method based on USB flash disk

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201710274035.8A CN106919855A (en) 2017-04-25 2017-04-25 A kind of law enforcement evidence-obtaining system and its evidence collecting method based on USB flash disk

Publications (1)

Publication Number Publication Date
CN106919855A true CN106919855A (en) 2017-07-04

Family

ID=59567453

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201710274035.8A Pending CN106919855A (en) 2017-04-25 2017-04-25 A kind of law enforcement evidence-obtaining system and its evidence collecting method based on USB flash disk

Country Status (1)

Country Link
CN (1) CN106919855A (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107506471A (en) * 2017-08-31 2017-12-22 湖北灰科信息技术有限公司 Quick evidence collecting method and system
CN108229187A (en) * 2017-12-28 2018-06-29 北京奇虎科技有限公司 A kind of method and system intelligently collected evidence using movable memory equipment
CN109213630A (en) * 2018-08-16 2019-01-15 郑州云海信息技术有限公司 A kind of data copy method and relevant apparatus of USB flash disk

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040260733A1 (en) * 2003-06-23 2004-12-23 Adelstein Frank N. Remote collection of computer forensic evidence
CN101807424A (en) * 2010-03-03 2010-08-18 孟晋 Multifunctional U disk and U disk system
CN102842001A (en) * 2012-07-20 2012-12-26 西安邮电大学 System and method for detecting computer security information based on U disc authentication
CN103413101A (en) * 2013-08-30 2013-11-27 梁效宁 System and method for preventing electronic data from being tampered
CN103888544A (en) * 2014-04-14 2014-06-25 北京工业大学 Android mobile phone remote information acquisition system and method
CN104318145A (en) * 2014-09-26 2015-01-28 来安县新元机电设备设计有限公司 Method and system for privacy protection

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040260733A1 (en) * 2003-06-23 2004-12-23 Adelstein Frank N. Remote collection of computer forensic evidence
CN101807424A (en) * 2010-03-03 2010-08-18 孟晋 Multifunctional U disk and U disk system
CN102842001A (en) * 2012-07-20 2012-12-26 西安邮电大学 System and method for detecting computer security information based on U disc authentication
CN103413101A (en) * 2013-08-30 2013-11-27 梁效宁 System and method for preventing electronic data from being tampered
CN103888544A (en) * 2014-04-14 2014-06-25 北京工业大学 Android mobile phone remote information acquisition system and method
CN104318145A (en) * 2014-09-26 2015-01-28 来安县新元机电设备设计有限公司 Method and system for privacy protection

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107506471A (en) * 2017-08-31 2017-12-22 湖北灰科信息技术有限公司 Quick evidence collecting method and system
CN108229187A (en) * 2017-12-28 2018-06-29 北京奇虎科技有限公司 A kind of method and system intelligently collected evidence using movable memory equipment
CN109213630A (en) * 2018-08-16 2019-01-15 郑州云海信息技术有限公司 A kind of data copy method and relevant apparatus of USB flash disk

Similar Documents

Publication Publication Date Title
US11030311B1 (en) Detecting and protecting against computing breaches based on lateral movement of a computer file within an enterprise
US8712047B2 (en) Visual universal decryption apparatus and methods
JP6456970B2 (en) Method, apparatus, program, and recording medium for acquiring certification material
Okutan A framework for cyber crime investigation
CN104023332B (en) A kind of electric terminal and its SMS encryption, decryption method
CN106919855A (en) A kind of law enforcement evidence-obtaining system and its evidence collecting method based on USB flash disk
CN110598879A (en) Garbage recycling method, device and equipment based on block chain and storage medium
CN107871081A (en) A kind of computer information safe system
CN104717343A (en) Intelligent digital watermarking mobile phone
CN104346550A (en) Information processing method and electronic equipment
US20200278948A1 (en) Method, apparatus and system for managing electronic fingerprint of electronic file
Taylor et al. Cryptocurrencies investigation: A methodology for the preservation of cryptowallets
CN108073820A (en) Security processing, device and the mobile terminal of data
CN108537040A (en) Telecommunication fraud trojan horse program hold-up interception method, device, terminal and storage medium
Khan et al. Digital forensics and cyber forensics investigation: security challenges, limitations, open issues, and future direction
SONMEZ et al. Review of evidence collection and protection phases in digital forensics process
CN103888260A (en) Digital signature device corresponding to handwritten signature reliably
Čisar et al. Methodological frameworks of digital forensics
US20200026866A1 (en) Method and device for covering private data
CN103390121B (en) Copyright ownership authentication method and system
CN106651686A (en) Electronic contract signing method and terminal
WO2017207998A1 (en) Method of associating a person with a digital object
CN101989324A (en) Information security system based on computer and mobile storage device
JP5359650B2 (en) Data file disguise processing device
WO2023046104A1 (en) Object moving method and device

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20170704

RJ01 Rejection of invention patent application after publication