Summary of the invention
Based on this, it is necessary to there is a problem of that supervision security effectiveness is low for traditional USB port management method, provide one
Kind information monitoring system and method.
In a first aspect, the embodiment of the present invention provides a kind of information monitoring system, and the system comprises: universal serial bus
USB port lock module, radio receiver and supervising platform;The radio receiver respectively with the USB port lock module
It is communicated to connect with the supervising platform;Wherein,
The USB port lock module includes multiple USB port locks, and the USB port lock module to described for wirelessly connecing
Receiving apparatus sends the status data of the USB port lock;Whether the status data is used to indicate the USB port lock online;
The radio receiver is sent to the supervision for receiving the status data, and by the status data
Platform;
The supervising platform is locked into the USB port for receiving the status data, and according to the status data
Row monitoring.
The status data is using the encrypted number of oval asymmetric encryption ECC algorithm in one of the embodiments,
According to.
In one of the embodiments, between the USB port lock module, the radio receiver and the supervising platform
It is communicated by establishing remote-wireless electricity LoRa network.
The radio receiver is also used to establish LoRa network in one of the embodiments, forms LoRa network letter
Number covering;
The USB port lock module is also used to send the networking application of the USB port lock to the radio receiver;
The LoRa network is added for requesting in the networking application;
The radio receiver receives the networking application, judges whether the networking application is legal application;If institute
Stating networking application is legal application, then transmits into network data packet to corresponding USB port lock and the supervising platform;If described
Application network as illegal application, then abandons the networking application.
The radio receiver is specifically used for according to preset header information in one of the embodiments, will be described
The header information applied that networks is compared with preset header information, if the header information of the application that networks and preset report
Head information is consistent, it is determined that the networking application is legal application, if the header information of the application that networks and preset header
Information is inconsistent, it is determined that the networking application is illegal application.
The radio receiver is also used to be analyzed and processed the status data in one of the embodiments,
Generate communication log;The communication log is used to record the communication information of the USB port lock module and the supervising platform.
The supervising platform is also used to according to preset monitoring cycle in one of the embodiments, described in periodic monitoring
The status data of USB port lock.
The supervising platform is specifically used in preset monitoring cycle to the end USB in one of the embodiments,
Mouth lock sends Monitoring instruction, and the status data of the USB port lock is determined according to the overtime response times that the USB port is locked;
The Monitoring instruction is used to indicate the USB port and locks to supervising platform transmission response message.
The USB port lock is also used in off-position in one of the embodiments, and Xiang Suoshu supervising platform is sent
Power alarm information;
The supervising platform is also used to judge the corresponding USB of the power alarm information according to the power alarm information
Whether port lock is the USB port lock to have networked, confirmation instruction is sent if so, locking to the USB port, if it is not, then to institute
It states USB port lock and sends alarm command;The confirmation instruction is used to indicate the sealed method of the USB port;The alarm command is used
It is illegal in the instruction USB port lock.
The USB port lock is also used in power-up state in one of the embodiments, in preset time interval
Warning message is powered on to supervising platform transmission.
The USB port lock is also used to carry out the USB port of corresponding monitored equipment in one of the embodiments,
Physics blocks.
Second aspect, the embodiment of the present invention provide a kind of information monitoring method, and the method is applied to above-described embodiment institute
The information monitoring system stated, which comprises
USB port lock module sends the status data that each USB port is locked to radio receiver;The status data is used for
Indicate whether the USB port lock is online;
The radio receiver receives the status data, and the status data is sent to supervising platform;
The supervising platform receives the status data, and is supervised according to the status data to USB port lock
Control.
The USB port lock module sends the shape that each USB port is locked to radio receiver in one of the embodiments,
State data, comprising:
The USB port lock module encrypts the status data using oval asymmetric encryption ECC algorithm, obtains
Encrypted status data;
The encrypted status data is sent to the radio receiver by the USB port lock module.
The USB port lock module is using oval asymmetric encryption ECC algorithm to the shape in one of the embodiments,
State data are encrypted, and encrypted status data is obtained, comprising:
The USB port lock module carries out Hash operation to the status data message, obtains the shape of fixed byte length
State data message;
The USB port lock module is by the status data message of the fixed byte length and the USB port lock module
Private key be digitally signed, obtain encrypted status data.
In information monitoring system provided by the above embodiment and method, information monitoring system includes general-purpose serial bus USB
Port lock module, radio receiver and supervising platform, USB port lock module include multiple USB port locks, are filled to wireless receiving
Set transmission indicate each USB port lock whether online status data, radio receiver receives the status data, and by the state
Data are sent to supervising platform, and supervising platform receives the status data, and is supervised according to the status data to USB port lock
Control, within the system, supervising platform can timely receive the status data of USB port lock by radio receiver, according to
The state that received status data locks USB port is monitored, and improves the safety management efficiency to USB port;In addition,
It include that multiple USB ports are locked in USB port lock module, supervising platform can obtain multiple USB by radio receiver simultaneously
The status data of port lock, is completed at the same time the monitoring to multiple USB ports lock, further increases while economizing on resources pair
The safety management efficiency of USB port.
Specific embodiment
It is with reference to the accompanying drawings and embodiments, right in order to which the objects, technical solutions and advantages of the application are more clearly understood
The application is further elaborated.It should be appreciated that specific embodiment described herein is only used to explain the application, not
For limiting the application.
Traditional USB port management method, most of is to carry out occupying using physical locks reusing lock latching, but physics
Lock is easily unlocked personnel's sled and takes, and user can not obtain the status information of physical locks in time, be easy to happen information leakage, make to succeed in one's scheme
Calculation machine equipment is among safety leakage and the crisis of system vulnerability, there is a problem of that supervision security effectiveness is low.
How technical solution of the present invention and technical solution of the present invention are solved with specific embodiment below above-mentioned
Technical problem is described in detail.These specific embodiments can be combined with each other below, for the same or similar concept
Or process may repeat no more in certain embodiments.
Fig. 1 is the information monitoring system schematic diagram that one embodiment provides.As shown in Figure 1, information monitoring system includes: logical
With serial bus USB port lock module 100, radio receiver 200 and supervising platform 300;The radio receiver 200 divides
It is not communicated to connect with the USB port lock module 100 and the supervising platform 300;Wherein, the USB port lock module 100 wraps
Multiple USB port locks 101 are included, the USB port lock module 100 is used to send each USB to the radio receiver 200
The status data of port lock 101;Whether the status data is used to indicate the USB port lock 101 online;The wireless receiving
Device 200 is sent to the supervising platform 300 for receiving the status data, and by the status data;The supervision is flat
Platform 300 is monitored USB port lock 101 for receiving the status data, and according to the status data.
Specifically, USB port lock module 100 includes multiple USB ports lock 101, USB port lock module 100 is used for nothing
Line reception device 200 sends the status data of each USB port lock 101.Wherein, the status data of USB port lock 101 is used to indicate
Whether USB port lock is online.Optionally, USB port lock module 100 can send each end USB to radio receiver 200 in real time
The status data of mouth lock 101 can also periodically send the status data of each USB port lock 101 to radio receiver 200.It can
Choosing, the status data that USB port lock module 100 is sent to radio receiver 200 can be the online of USB port lock 101
Data, or the off-line data of USB port lock 101.Optionally, USB port lock is also used to corresponding monitored equipment
USB port carry out physics closure.Optionally, USB port lock 101 can be used substation equipment, server in machine room or
On the USB port of other servers.
Above-mentioned radio receiver 200 locks 101 for receiving the status data of USB port lock 101, and by USB port
Status data is sent to supervising platform 300.Optionally, radio receiver 200 can receive the state of USB port lock 101 with side
The status data that data side transmits and receives, the status data received can also be stored, and it is flat to be periodically sent to supervision
Platform.Optionally, radio receiver 200 can transmit (Message Queuing Telemetry by message queue telemetering
Trabsport, MQTT) agreement by USB port lock 101 status data be sent to supervising platform 300.Optionally, wireless receiving
Device 200 can to receive to status data carry out processing analysis, reception is identified according to the analysis result to status data
The corresponding USB port information of the status data arrived.Optionally, radio receiver 200 can be gateway server.
Above-mentioned supervising platform 300, status data for receiving data, and according to the status data received to USB port
Lock 101 is monitored.Optionally, supervising platform 300 can generate the shape of USB port lock 101 according to the status data received
State data drawing list is monitored USB port lock 101 according to the chart of generation.Optionally, supervising platform 300 can be individual
Computer (Personal computer, PC), or mobile phone.
In the present embodiment, information monitoring system include general-purpose serial bus USB port lock module, radio receiver and
Supervising platform, USB port lock module include multiple USB port locks, send to radio receiver and whether indicate each USB port lock
Online status data, radio receiver receives the status data, and the status data is sent to supervising platform, and supervision is flat
Platform receives the status data, and is monitored according to the status data to USB port lock, and within the system, supervising platform can be with
The status data of USB port lock is timely received by radio receiver, status data locks USB port based on the received
State is monitored, and improves the safety management efficiency to USB port;In addition, including multiple ends USB in USB port lock module
Mouth lock, supervising platform can pass through the status data that radio receiver obtain multiple USB ports locks simultaneously, be completed at the same time to more
The monitoring of a USB port lock, further increases the safety management efficiency to USB port while economizing on resources.
In some scenes, the USB port that USB port lock module 100 is sent to supervising platform 300 in order to prevent locks 101
Status data be maliciously tampered, forge and malicious attack, need to encrypt status data.On the basis of above-described embodiment
On, as an alternative embodiment, the status data is using the encrypted number of oval asymmetric encryption ECC algorithm
According to.
Specifically, supervising platform 300 generating platform public key PK0 and platform private key SK0, and platform public key PK0 is sent to
USB port lock module 100 after USB port lock module 100 receives platform public key PK0, will also generate the public key of USB port lock 101
PK1 and private key SK1, and the public key PK1 of USB port lock 101 is returned back into supervising platform 300, at this point, supervising platform 300 and USB
Port lock module 100 possesses the public key of other side;Later, USB port lock module 100 is using oval asymmetric encryption (Elliptic
Curve cryptography, ECC) algorithm encrypts status data, and USB port lock module 100 is to status data message
Hash operation is carried out, obtains the status data message of fixed byte length, and by the status data report of regular length byte length
Text and the private key of USB port lock module 100 are digitally signed, and obtain encrypted status data, and by encrypted state
Data are sent to radio receiver 200.Optionally, USB port lock module 100 is obtaining the same of encrypted status data
When, the plaintext and signature value of encrypted status data can also be obtained, and obtained plaintext and signature value are sent to wirelessly
Reception device 200 is sent to supervising platform 300 by radio receiver 200.Optionally, supervising platform 300 receives encryption
After status data afterwards, according to the plaintext received, Hash operation is carried out to plaintext, in conjunction with the signature value received and reception
The public key PK1 of the USB port lock 101 arrived, judges whether encrypted status data passes through, supervises to the status data passed through
Control.
In the present embodiment, the status data for the USB port lock that USB port lock module is sent to radio receiver is to adopt
With the oval encrypted data of asymmetric encryption ECC algorithm, it can ensure the reliability of the status data of transmission, prevent illegal point
Son forge to the status data of transmission or illegally be distorted, and improves the safety management efficiency to USB port.
Fig. 2 is the LoRa communication network schematic diagram that the information monitoring system that one embodiment provides is established.As shown in Fig. 2,
By establishing remote-wireless between the USB port lock module 100, the radio receiver 200 and the supervising platform 300
Electric LoRa network is communicated.
Specifically, the communication between USB port lock module 100, radio receiver 200 and supervising platform 300 is by building
Vertical electric (Long Range Radio, LoRa) network of remote-wireless is communicated.Optionally, radio receiver 200 is built
Vertical LoRa network, forms the covering of LoRa network signal, and USB port lock module 100 sends USB port to radio receiver 200
The networking application for requesting that LoRa network is added of lock 101, radio receiver 200 receive USB port lock module 100 and send
Networking application, and judge whether received networking application is legal application, if the networking application is legal application, to correspondence
USB port lock 101 and supervising platform 300 transmit into network data packet, if the networking application is illegal application, abandons this and enter
Net application, USB port lock 101 represent LoRa network communication foundation after receiving networking data packet.Optionally, radio receiver
200 can according to preset header information, the header information for the networking application that USB port lock module 100 is sent with it is preset
Header information is compared, if the header information of the networking application is consistent with preset header information, it is determined that the networking application
For legal application, if the header information of the networking application and preset header information are inconsistent, it is determined that the networking application is non-
Method application.Optionally, which is the LoRa Local Area Network of 2.4GHZ.
In the present embodiment, between USB port lock module, radio receiver and supervising platform by establish LoRa network into
Row communication, and LoRa network has the characteristics that low latency, high transfer rate, the USB port in computer room for being distributed comparatively dense
The status information of lock also can carry out to high-speed being sent to supervising platform, supervise, improved to the end USB to USB port lock
The safety management efficiency of mouth.
In one embodiment, continuing with referring to fig. 2, the radio receiver 200 is also used to the status data
It is analyzed and processed, generates communication log;The communication log is for recording the USB port lock module 100 and the supervision
The communication information of platform 300.
Specifically, radio receiver 200 is also used to analyze the status data that USB port lock module 100 is sent
Processing generates the communication log of the communication information for recording USB port lock module 100 and supervising platform 300.Optionally, nothing
Line reception device 200 can be decrypted to status data is received, and analyzing the status data is that in USB port lock module 100
The status data of a USB port lock.
In the present embodiment, radio receiver is also used to be analyzed and processed the status data received, generates and uses
In the communication log of the communication information of record USB port lock module and supervising platform, USB can be checked by radio receiver
All communication data informations of port lock module and supervising platform can quickly search USB port lock module and supervising platform
Communication data improves the safety management efficiency locked to USB port convenient for the management locked to USB port.
In some scenes, user can supervise in platform configuration setting periodic detection duration, and supervising platform is according to setting
Fixed detection duration is monitored USB port lock module.On the basis of the above embodiments, as a kind of optional embodiment party
Formula, the supervising platform 300 are also used to according to preset monitoring cycle, the status number of the lock of USB port described in periodic monitoring 101
According to.
Specifically, supervising platform 300 is also used to according to preset monitoring cycle, the status number of periodic monitoring USB port lock
According to.Optionally, preset monitoring cycle can be five minutes, is also possible to ten minutes or is determined according to actual monitoring situation default
Monitoring cycle.Optionally, supervising platform 300 is specifically used for the end USB in the preset monitoring cycle into control range
Mouth lock 101, which is sent, is used to indicate the Monitoring instructions that USB port lock 101 sends response message to supervising platform 300, and USB port is locked
It after 101 receive Monitoring instruction, need to make an immediate response, otherwise overtime response times reach certain number, and platform will determine corresponding USB
Port lock is in off-line state, and supervising platform 300 determines the shape that USB port is locked according to the overtime response times of USB port lock 101
State data.Optionally, the status data for the USB port lock that supervising platform 300 determines can be off-line data, or online
Data.
In the present embodiment, supervising platform is also used to according to preset monitoring cycle, the state of periodic monitoring USB port lock
Data can in real time be monitored USB port lock, the status data of USB port lock be obtained in time, according to the state of acquisition
Data can judge the status information of USB port lock in time, improve the safety management efficiency to USB port, prevent information leakage.
During USB port is locked and extracts USB port, USB port lock can be powered off, and supervising platform can be according to the end USB
The power cut-off information of mouth lock is monitored USB port lock.Fig. 3 is that the supervising platform that one embodiment provides fills USB port lock
Power off the flow diagram of monitoring.As shown in figure 3, on the basis of the above embodiments, as an alternative embodiment, institute
It states USB port lock 101 to be also used in off-position, Xiang Suoshu supervising platform 300 sends power alarm information;The supervision is flat
Platform 300 is also used to according to the power alarm information, judge the corresponding USB port lock of the power alarm information 101 whether be
The USB port lock 101 to have networked, if so, confirmation instruction is sent to USB port lock 101, if it is not, then to the end USB
Mouth lock 101 sends alarm commands;The confirmation instruction is used to indicate the sealed method of the USB port;The alarm command is for referring to
Show that the USB port lock is illegal.
Specifically, USB port lock 101 in off-position, can send power alarm information to supervising platform 300;Supervision
Platform 300 judges whether the corresponding USB port lock 101 of the power alarm information has networked according to the power alarm information
USB port lock, if so, to the USB port lock send be used to indicate the sealed method of the USB port confirmation instruction, if it is not, then to
USB port lock transmission is used to indicate the USB port and locks illegal alarm command.Optionally, supervising platform 300 can be according to disconnected
Whether the corresponding USB port lock of electric alarm information has networking data packet to judge that the corresponding USB port lock of the power alarm information is
The no USB port lock to have networked, port lock is if the USB port lock for sending power alarm information has networking data packet
Otherwise the legal port lock to network is locked for illegal port.
In the present embodiment, USB port lock is also used in off-position, sends power alarm information to supervising platform,
So that supervising platform according to the power alarm information, judges that the corresponding USB port of power alarm information is whether to have networked
USB port lock, USB port lock is monitored, to reduce the risk for illegally employing USB port generation, is improved to having entered
The security control of the USB port lock of net.
During USB port locks insertion USB port, USB port lock can be powered on, and supervising platform can be according to the end USB
The power information that powers on of mouth lock is monitored USB port lock.Continuing with referring to Fig. 3, on the basis of the above embodiments, as one
The optional embodiment of kind, the USB port lock 101 is also used in power-up state, to described in preset time interval
Supervising platform transmission powers on warning message.
Specifically, USB port lock 101 is also used in power-up state, to supervising platform 300 in preset time interval
Transmission powers on warning message.Optionally, preset time interval can run out of the duration of selfcapacity for USB port lock 101.
Optionally, electric alarm can use non-acknowledgement frame on USB port lock 101, only power on warning message to the transmission of supervising platform 300,
It replys and confirms without supervising platform 300.In the present embodiment, USB port lock can also be in power-up state, in the preset time
Warning message is powered on to supervising platform transmission in interval, supervising platform can be made to obtain the status information of USB port lock in time, it is right
USB port lock is monitored, and can be improved the security control to the USB port lock to have networked.
Fig. 4 is the flow diagram for the information monitoring method that one embodiment provides.As shown in figure 4, this method comprises:
S401, USB port lock module send the status data that each USB port is locked to radio receiver;The status number
According to being used to indicate, whether the USB port lock is online;
S402, the radio receiver receives the status data, and the status data is sent to supervising platform;
S403, the supervising platform receives the status data, and is locked into according to the status data to the USB port
Row monitoring.
Information monitoring method provided by the above embodiment, implementing principle and technical effect and above- mentioned information monitoring system are real
It is similar to apply example, details are not described herein.
Fig. 5 is the flow diagram for the information monitoring method that another embodiment provides.As shown in figure 5, above-mentioned S401, packet
It includes:
S501, the USB port lock module add the status data using oval asymmetric encryption ECC algorithm
It is close, obtain encrypted status data;
The encrypted status data is sent to the radio receiver by S502, the USB port lock module.
Information monitoring method provided by the above embodiment, implementing principle and technical effect and above- mentioned information monitoring system are real
It is similar to apply example, details are not described herein.
Fig. 6 is the flow diagram for the information monitoring method that another embodiment provides.As shown in fig. 6, above-mentioned S501, packet
It includes:
S601, the USB port lock module carry out Hash operation to the status data message, obtain fixed byte length
Status data message;
S602, the USB port lock module lock the status data message of the fixed byte length and the USB port
The private key of module is digitally signed, and obtains encrypted status data.
Information monitoring method provided by the above embodiment, implementing principle and technical effect and above- mentioned information monitoring system are real
It is similar to apply example, details are not described herein.
Each technical characteristic of embodiment described above can be combined arbitrarily, for simplicity of description, not to above-mentioned reality
It applies all possible combination of each technical characteristic in example to be all described, as long as however, the combination of these technical characteristics is not deposited
In contradiction, all should be considered as described in this specification.
The embodiments described above only express several embodiments of the present invention, and the description thereof is more specific and detailed, but simultaneously
It cannot therefore be construed as limiting the scope of the patent.It should be pointed out that coming for those of ordinary skill in the art
It says, without departing from the inventive concept of the premise, various modifications and improvements can be made, these belong to protection of the invention
Range.Therefore, the scope of protection of the patent of the invention shall be subject to the appended claims.