CN202205195U - Equipment for reading and writing physical memory of computer through IEEE 1394 interface - Google Patents
Equipment for reading and writing physical memory of computer through IEEE 1394 interface Download PDFInfo
- Publication number
- CN202205195U CN202205195U CN2011202482000U CN201120248200U CN202205195U CN 202205195 U CN202205195 U CN 202205195U CN 2011202482000 U CN2011202482000 U CN 2011202482000U CN 201120248200 U CN201120248200 U CN 201120248200U CN 202205195 U CN202205195 U CN 202205195U
- Authority
- CN
- China
- Prior art keywords
- interface
- equipment
- microcontroller
- ieee
- computer
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
Images
Abstract
The utility model discloses equipment for reading and writing a physical memory of a computer through an IEEE 1394 interface. The equipment is characterized by comprising a micro controller which is used for executing a program and has a control function, a 1394 integrated controller which is connected with the micro controller, a clock module which is used for supplying a clock signal, and a power supply module which is used for supplying electric energy, wherein the micro controller and the 1394 integrated controller are provided with a universal serial bus (USB) interface connected with an evidence taking computer, and a 1394 interface connected with a target computer respectively; a decoder for expanding a control port is arranged between the micro controller and the 1394 integrated controller; and a program memory is expanded outside the micro controller. By arranging the 1394 interface which is connected with the target computer and the USB interface which is connected with the evidence taking computer, a plug-and-play function is realized; furthermore, the target computer can read and write memory information in a password protection state (such as a screen-saving state, a locked state and the like), so that the flexibility of online evidence taking is improved, the credibility of the online evidence taking is enhanced; and the equipment has extremely high use value.
Description
Technical field
The utility model relates to a kind of equipment through IEEE 1394 interface writable computer physical memories, in particular, relates in particular to a kind of plug and play and calculator memory is changed the very little equipment that passes through IEEE 1394 interface writable computer physical memories.
Background technology
Along with computer technology, computer networking technology and rapid development of Internet, computing machine are greatly promoting the progress of human society, and computing machine and electronic data have been deep into the various aspects of people's life.Computer technology has also been brought the computer crime problem when bringing our huge benefit.Cases such as all kinds of hacker attacks, network defraud, network pornography continue to bring out.The network crime has related to most social criminal phenomenas, has influenced normal economic order.And the technological means that the strike network crime mainly relies on is the computer forensics technology.
Storing place as program and intermediate data in the computer run process; Contain a large amount of useful informations in the calculator memory; The plaintext even the key that comprise program process running status, network connection, open port, password code, encrypt file, these information often play a key effect in the case investigation.Yet how accurately, intactly obtain the internal memory of system, and the internal memory change that as far as possible reduces goal systems becomes a difficult problem.Running memory obtains software and can cause internal memory to change in a large number on object computer, has destroyed the integrality of digital evidence; And because the C2 safe class of Windows, internal memory obtains software and must could move at open state, then can't move at the screen protection holding state.The equipment that obtains internal memory through hardware interface must be implemented in the object computer to be installed, and can't realize plug and play, obviously, is unpractical with this investigation and evidence collection that is used for the suspect.
Summary of the invention
The utility model provides a kind of plug and play and calculator memory has been changed the very little equipment that passes through IEEE 1394 interface writable computer physical memories in order to overcome the shortcoming of above-mentioned technical matters.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model, its special feature is: comprise microcontroller, 1394 integrated manipulators that are connected with microcontroller that executive routine and control use, be used to the power module that the clock module of clock signal is provided and electric energy is provided; Said microcontroller is respectively arranged with USB interface that is connected with the computing machine of collecting evidence and 1394 interfaces that are connected with object computer with 1394 integrated manipulators, also has been provided with the code translator of expansion control port between said microcontroller and 1394 integrated manipulators; The outside expansion of said microcontroller has program storage.Microcontroller can be controlled the duty of 1394 integrated manipulators as the equipment main control chip; 1394 integrated manipulators are the control chip of 1394 interfaces, and the realization of 1394 interfaces is connected with object computer.USB interface realizes and being connected of the computing machine of collecting evidence, and under the control of microcontroller, and the internal storage data of the object computer that transmits 1394 interfaces is sent to the evidence obtaining computing machine.Clock module provides working pulse for microcontroller and 1394 integrated manipulators; Power module provides electric energy to entire equipment.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model also is provided with the reseting module that microcontroller and 1394 integrated manipulators are controlled; The input end of said power module is connected with the power lead of USB interface, and the output terminal of power module all is connected with reseting module with microcontroller, 1394 integrated manipulators.Reseting module is the reset circuit of microcontroller and 1394 integrated manipulators, and the input end of power module is connected with power lead in the USB interface, and being used for the 5V voltage transitions is that the WV of microcontroller and 1394 integrated manipulators is exported.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model, the output terminal of said clock module all is connected with 1394 integrated manipulators with microcontroller.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model; Said 1394 integrated manipulators comprise Physical layer and link layer two parts, and it is the integrated independent chip of Physical layer and link layer or Physical layer and two integrated respectively chips of link layer.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model, the model of said 1394 integrated manipulators is TSB43AA82A.TSB43AA82A is 1394 protocol chips of TI company.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model, said microcontroller are the CY7C68013A chip that has 8051 controllers and USB interface.The CY7C68013A chip not only contains 8051 microcontrollers, but also is provided with USB interface, has promptly realized the control to entire equipment, has also realized being connected with the port of evidence obtaining computing machine.
The beneficial effect of the utility model is: the utility model through be provided with 1394 interfaces be connected with object computer and with the computing machine USB interface of collecting evidence, have plug-and-play feature; Directly read the data in the calculator memory through IEEE 1394 interfaces; And realized that object computer is in the following read/write memory information of cryptoguard state (like screen protection, lock-out state); Do not need operating software on computers; The object computer running status is changed very little, improved the dirigibility of online evidence obtaining and strengthened the credibility of online evidence obtaining, have very high use value.
Description of drawings
Fig. 1 is the circuit theory diagrams of the utility model;
Fig. 2 is the sample drawing of the utility model.
Among the figure: 1 USB interface, 2 1394 interfaces, 3 microcontrollers, 4 1394 integrated manipulators, 5 power modules, 6 reseting modules, 7 program storages, 8 code translators, 9 clock modules, 10 housings, 11 relay indicating lights.
Embodiment
Below in conjunction with accompanying drawing and embodiment the utility model is described further.
As shown in Figure 1, provided the circuit theory diagrams of the utility model, it comprises usb 1,1394 interfaces 2, microcontroller 3,1394 integrated manipulators 4, power module 5, reseting module 6, program storage 7, code translator 8, clock module 9; It is the chip of CY7C68013A that microcontroller 3 adopts model, not only is provided with 8051 controllers in this chip, but also is provided with usb 1; It is the chip of TSB43AA82A that 1394 integrated manipulators 4 adopt model, so that form 1394 interfaces 2.Microcontroller 3 not only is connected with 1394 integrated manipulators 4 through FPDP; But also through code translator 8 coupled connecing; Code translator is serial 3 lines-8 a line code translator, is that 1394 controller chips provide chip selection signal by 8051 single-chip microcomputer address buss in the microcontroller 3.1394 interfaces 2 and usb 1 be being connected of realization and object computer and evidence obtaining computing machine respectively, is respectively applied for the internal storage data of receiving target computing machine transmission and sends internal storage data to the evidence obtaining computing machine.The input end of power module 5 obtains voltage from the power lead of USB interface; Power module 5 uses linear voltage regulators to accomplish voltage-regulation, 5 volts of voltages on the usb bus is changed into the power input that is input to microcontroller 3 and 1394 integrated manipulators 4 behind 3.3 volts the voltage.Reseting module 6 is reset circuits of microcontroller 3 and 1394 integrated manipulators, realizes the reset response in the equipment running process.Clock module 9 is realized microcontrollers 3 and the required clock signal of 1394 integrated manipulators 4.Program storage 7 adopts the serial EEPROM chip, is used to deposit the firmware program of this equipment, is connected with USB controller chip 3 through the I2C bus.
In Fig. 2, provided the sample drawing of the utility model, the state of three present equipment operations of relay indicating light 11 indications.Red light is a power lights, the indication equipment energising; Amber light is idle lamp, the indication equipment normal load, but do not carry out data read-write operation; Green light is a running indicator, representes that present equipment is carrying out read-write operation.
Utility model patent can be opened the characteristics of DMA under specific circumstances based on 1394 bussing techniques and operating system, by means of the basic configuration and the plug-and-play feature of the DMA data transfer mode of I/O equipment, various operating systems.The equipment of the utility model is in the process of using; Usb 1 is connected with the evidence obtaining computing machine; 1394 interfaces 2 are connected with object computer; Mode through DMA realizes the visit to the object computer physical memory, and the physical memory packet that is read is sent to the evidence obtaining computing machine through Universal USB interface 2, under to the very little situation of object computer internal memory change, realizes obtaining of internal storage data.
Claims (6)
1. the equipment through IEEE 1394 interface writable computer physical memories is characterized in that: comprise microcontroller (3), 1394 integrated manipulators (4) that are connected with microcontroller, clock module (9) that is used to provide clock signal that executive routine and control are used and the power module (5) that electric energy is provided; Said microcontroller is respectively arranged with USB interface (1) that is connected with the computing machine of collecting evidence and 1394 interfaces (2) that are connected with object computer with 1394 integrated manipulators, also has been provided with the code translator (8) of expansion control port between said microcontroller and 1394 integrated manipulators; The outside expansion of said microcontroller has program storage (7).
2. the equipment through IEEE 1394 interface writable computer physical memories according to claim 1 is characterized in that: also be provided with the reseting module (6) that microcontroller (3) and 1394 integrated manipulators (4) are controlled; The input end of said power module (5) is connected with the power lead of USB interface (1), and the output terminal of power module all is connected with reseting module with microcontroller, 1394 integrated manipulators.
3. the equipment through IEEE 1394 interface writable computer physical memories according to claim 1 and 2, it is characterized in that: the output terminal of said clock module (9) all is connected with 1394 integrated manipulators (4) with microcontroller (3).
4. the equipment through IEEE 1394 interface writable computer physical memories according to claim 1 and 2; It is characterized in that: said 1394 integrated manipulators (4) comprise Physical layer and link layer two parts, and it is the integrated independent chip of Physical layer and link layer or Physical layer and two integrated respectively chips of link layer.
5. the equipment through IEEE 1394 interface writable computer physical memories according to claim 4, it is characterized in that: the model of said 1394 integrated manipulators (4) is TSB43AA82A.
6. the equipment through IEEE 1394 interface writable computer physical memories according to claim 1 and 2 is characterized in that: said microcontroller (3) is for having the CY7C68013A chip of 8051 controllers and USB interface.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2011202482000U CN202205195U (en) | 2011-07-14 | 2011-07-14 | Equipment for reading and writing physical memory of computer through IEEE 1394 interface |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2011202482000U CN202205195U (en) | 2011-07-14 | 2011-07-14 | Equipment for reading and writing physical memory of computer through IEEE 1394 interface |
Publications (1)
Publication Number | Publication Date |
---|---|
CN202205195U true CN202205195U (en) | 2012-04-25 |
Family
ID=45969307
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN2011202482000U Expired - Fee Related CN202205195U (en) | 2011-07-14 | 2011-07-14 | Equipment for reading and writing physical memory of computer through IEEE 1394 interface |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN202205195U (en) |
Cited By (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103399830A (en) * | 2013-08-09 | 2013-11-20 | 山东省计算中心 | Equipment and method for reading computer physical memory through PCI Express bus |
CN104750591A (en) * | 2013-12-30 | 2015-07-01 | 上海威亿实业有限公司 | Evidence-taking device and method for computer |
CN111737178A (en) * | 2020-06-18 | 2020-10-02 | 济南互信软件有限公司 | Computer memory forensics method and equipment and memory forensics analysis system |
CN116383015A (en) * | 2023-06-06 | 2023-07-04 | 成都安思科技有限公司 | Physical memory noninductive evidence obtaining system and method based on extensible board plug-in type |
-
2011
- 2011-07-14 CN CN2011202482000U patent/CN202205195U/en not_active Expired - Fee Related
Cited By (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103399830A (en) * | 2013-08-09 | 2013-11-20 | 山东省计算中心 | Equipment and method for reading computer physical memory through PCI Express bus |
CN103399830B (en) * | 2013-08-09 | 2016-01-06 | 山东省计算中心 | The Apparatus and method for of computer physics internal memory is read by PCI Express bus |
CN104750591A (en) * | 2013-12-30 | 2015-07-01 | 上海威亿实业有限公司 | Evidence-taking device and method for computer |
CN111737178A (en) * | 2020-06-18 | 2020-10-02 | 济南互信软件有限公司 | Computer memory forensics method and equipment and memory forensics analysis system |
CN111737178B (en) * | 2020-06-18 | 2024-02-09 | 济南互信软件有限公司 | Method and equipment for obtaining evidence in computer memory and memory evidence analysis system |
CN116383015A (en) * | 2023-06-06 | 2023-07-04 | 成都安思科技有限公司 | Physical memory noninductive evidence obtaining system and method based on extensible board plug-in type |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN202205195U (en) | Equipment for reading and writing physical memory of computer through IEEE 1394 interface | |
CN103200199A (en) | Out of band (OOB) data collection system | |
CN208188815U (en) | BMC module system | |
CN103399830A (en) | Equipment and method for reading computer physical memory through PCI Express bus | |
CN102880235B (en) | Single-board computer based on loongson 2F central processing unit (CPU) as well as reset management and using method of single-board computer | |
CN106599677A (en) | Password control system and control method used for baseboard management controller | |
CN104035731A (en) | Storage head node of blade server | |
CN204390237U (en) | A kind of encryption and decryption card of Based PC I-E bussing technique | |
CN102709990A (en) | Double-lithium-battery charging and discharging management circuit | |
CN203386206U (en) | Device for reading physical memory of computer through PCI Express interface | |
CN102650933A (en) | Storage system for network communication recording device of digital substation | |
CN203204494U (en) | Multifunctional high-stability slot structure and multifunctional card insertion module combined system | |
CN102176589A (en) | Concentrator for universal serial bus (USB)-8 serial port RS422 | |
CN105630400A (en) | High-speed massive data storage system | |
CN201828970U (en) | Train operation data recorder based on CAN (Controller Area Network) interface | |
CN201654772U (en) | Storage medium interface conversion device | |
CN204697071U (en) | A kind of side Multiple Channel Analysis assessment datum plate | |
CN103984543A (en) | Method for implementing standby, hibernation and wake-up on domestic FeiTeng processor | |
CN201122436Y (en) | Mobile hard disk case | |
CN204557492U (en) | A kind of data in magnetic disk encrypted circuit plate | |
CN202771419U (en) | Safe universal serial bus (USB) disk | |
CN103236122B (en) | The tax control validity check card of Based PC I Bus Interface Chip and CPLD chip | |
CN105653477A (en) | Double-port RAM-based method for communication of hard core and soft core in FPGA | |
CN202177896U (en) | Encryption storage chip | |
CN206178529U (en) | Main control board based on explain 411 majestic treaters and shen wei nest plate |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
C17 | Cessation of patent right | ||
CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20120425 Termination date: 20120714 |