CN202205195U - Equipment for reading and writing physical memory of computer through IEEE 1394 interface - Google Patents

Equipment for reading and writing physical memory of computer through IEEE 1394 interface Download PDF

Info

Publication number
CN202205195U
CN202205195U CN2011202482000U CN201120248200U CN202205195U CN 202205195 U CN202205195 U CN 202205195U CN 2011202482000 U CN2011202482000 U CN 2011202482000U CN 201120248200 U CN201120248200 U CN 201120248200U CN 202205195 U CN202205195 U CN 202205195U
Authority
CN
China
Prior art keywords
interface
equipment
microcontroller
ieee
computer
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CN2011202482000U
Other languages
Chinese (zh)
Inventor
顾卫东
王连海
张磊
武鲁
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Shandong Computer Science Center
Original Assignee
Shandong Computer Science Center
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Shandong Computer Science Center filed Critical Shandong Computer Science Center
Priority to CN2011202482000U priority Critical patent/CN202205195U/en
Application granted granted Critical
Publication of CN202205195U publication Critical patent/CN202205195U/en
Anticipated expiration legal-status Critical
Expired - Fee Related legal-status Critical Current

Links

Images

Abstract

The utility model discloses equipment for reading and writing a physical memory of a computer through an IEEE 1394 interface. The equipment is characterized by comprising a micro controller which is used for executing a program and has a control function, a 1394 integrated controller which is connected with the micro controller, a clock module which is used for supplying a clock signal, and a power supply module which is used for supplying electric energy, wherein the micro controller and the 1394 integrated controller are provided with a universal serial bus (USB) interface connected with an evidence taking computer, and a 1394 interface connected with a target computer respectively; a decoder for expanding a control port is arranged between the micro controller and the 1394 integrated controller; and a program memory is expanded outside the micro controller. By arranging the 1394 interface which is connected with the target computer and the USB interface which is connected with the evidence taking computer, a plug-and-play function is realized; furthermore, the target computer can read and write memory information in a password protection state (such as a screen-saving state, a locked state and the like), so that the flexibility of online evidence taking is improved, the credibility of the online evidence taking is enhanced; and the equipment has extremely high use value.

Description

A kind of equipment through IEEE 1394 interface writable computer physical memories
Technical field
The utility model relates to a kind of equipment through IEEE 1394 interface writable computer physical memories, in particular, relates in particular to a kind of plug and play and calculator memory is changed the very little equipment that passes through IEEE 1394 interface writable computer physical memories.
Background technology
Along with computer technology, computer networking technology and rapid development of Internet, computing machine are greatly promoting the progress of human society, and computing machine and electronic data have been deep into the various aspects of people's life.Computer technology has also been brought the computer crime problem when bringing our huge benefit.Cases such as all kinds of hacker attacks, network defraud, network pornography continue to bring out.The network crime has related to most social criminal phenomenas, has influenced normal economic order.And the technological means that the strike network crime mainly relies on is the computer forensics technology.
Storing place as program and intermediate data in the computer run process; Contain a large amount of useful informations in the calculator memory; The plaintext even the key that comprise program process running status, network connection, open port, password code, encrypt file, these information often play a key effect in the case investigation.Yet how accurately, intactly obtain the internal memory of system, and the internal memory change that as far as possible reduces goal systems becomes a difficult problem.Running memory obtains software and can cause internal memory to change in a large number on object computer, has destroyed the integrality of digital evidence; And because the C2 safe class of Windows, internal memory obtains software and must could move at open state, then can't move at the screen protection holding state.The equipment that obtains internal memory through hardware interface must be implemented in the object computer to be installed, and can't realize plug and play, obviously, is unpractical with this investigation and evidence collection that is used for the suspect.
Summary of the invention
The utility model provides a kind of plug and play and calculator memory has been changed the very little equipment that passes through IEEE 1394 interface writable computer physical memories in order to overcome the shortcoming of above-mentioned technical matters.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model, its special feature is: comprise microcontroller, 1394 integrated manipulators that are connected with microcontroller that executive routine and control use, be used to the power module that the clock module of clock signal is provided and electric energy is provided; Said microcontroller is respectively arranged with USB interface that is connected with the computing machine of collecting evidence and 1394 interfaces that are connected with object computer with 1394 integrated manipulators, also has been provided with the code translator of expansion control port between said microcontroller and 1394 integrated manipulators; The outside expansion of said microcontroller has program storage.Microcontroller can be controlled the duty of 1394 integrated manipulators as the equipment main control chip; 1394 integrated manipulators are the control chip of 1394 interfaces, and the realization of 1394 interfaces is connected with object computer.USB interface realizes and being connected of the computing machine of collecting evidence, and under the control of microcontroller, and the internal storage data of the object computer that transmits 1394 interfaces is sent to the evidence obtaining computing machine.Clock module provides working pulse for microcontroller and 1394 integrated manipulators; Power module provides electric energy to entire equipment.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model also is provided with the reseting module that microcontroller and 1394 integrated manipulators are controlled; The input end of said power module is connected with the power lead of USB interface, and the output terminal of power module all is connected with reseting module with microcontroller, 1394 integrated manipulators.Reseting module is the reset circuit of microcontroller and 1394 integrated manipulators, and the input end of power module is connected with power lead in the USB interface, and being used for the 5V voltage transitions is that the WV of microcontroller and 1394 integrated manipulators is exported.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model, the output terminal of said clock module all is connected with 1394 integrated manipulators with microcontroller.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model; Said 1394 integrated manipulators comprise Physical layer and link layer two parts, and it is the integrated independent chip of Physical layer and link layer or Physical layer and two integrated respectively chips of link layer.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model, the model of said 1394 integrated manipulators is TSB43AA82A.TSB43AA82A is 1394 protocol chips of TI company.
The equipment that passes through IEEE 1394 interface writable computer physical memories of the utility model, said microcontroller are the CY7C68013A chip that has 8051 controllers and USB interface.The CY7C68013A chip not only contains 8051 microcontrollers, but also is provided with USB interface, has promptly realized the control to entire equipment, has also realized being connected with the port of evidence obtaining computing machine.
The beneficial effect of the utility model is: the utility model through be provided with 1394 interfaces be connected with object computer and with the computing machine USB interface of collecting evidence, have plug-and-play feature; Directly read the data in the calculator memory through IEEE 1394 interfaces; And realized that object computer is in the following read/write memory information of cryptoguard state (like screen protection, lock-out state); Do not need operating software on computers; The object computer running status is changed very little, improved the dirigibility of online evidence obtaining and strengthened the credibility of online evidence obtaining, have very high use value.
Description of drawings
Fig. 1 is the circuit theory diagrams of the utility model;
Fig. 2 is the sample drawing of the utility model.
Among the figure: 1 USB interface, 2 1394 interfaces, 3 microcontrollers, 4 1394 integrated manipulators, 5 power modules, 6 reseting modules, 7 program storages, 8 code translators, 9 clock modules, 10 housings, 11 relay indicating lights.
Embodiment
Below in conjunction with accompanying drawing and embodiment the utility model is described further.
As shown in Figure 1, provided the circuit theory diagrams of the utility model, it comprises usb 1,1394 interfaces 2, microcontroller 3,1394 integrated manipulators 4, power module 5, reseting module 6, program storage 7, code translator 8, clock module 9; It is the chip of CY7C68013A that microcontroller 3 adopts model, not only is provided with 8051 controllers in this chip, but also is provided with usb 1; It is the chip of TSB43AA82A that 1394 integrated manipulators 4 adopt model, so that form 1394 interfaces 2.Microcontroller 3 not only is connected with 1394 integrated manipulators 4 through FPDP; But also through code translator 8 coupled connecing; Code translator is serial 3 lines-8 a line code translator, is that 1394 controller chips provide chip selection signal by 8051 single-chip microcomputer address buss in the microcontroller 3.1394 interfaces 2 and usb 1 be being connected of realization and object computer and evidence obtaining computing machine respectively, is respectively applied for the internal storage data of receiving target computing machine transmission and sends internal storage data to the evidence obtaining computing machine.The input end of power module 5 obtains voltage from the power lead of USB interface; Power module 5 uses linear voltage regulators to accomplish voltage-regulation, 5 volts of voltages on the usb bus is changed into the power input that is input to microcontroller 3 and 1394 integrated manipulators 4 behind 3.3 volts the voltage.Reseting module 6 is reset circuits of microcontroller 3 and 1394 integrated manipulators, realizes the reset response in the equipment running process.Clock module 9 is realized microcontrollers 3 and the required clock signal of 1394 integrated manipulators 4.Program storage 7 adopts the serial EEPROM chip, is used to deposit the firmware program of this equipment, is connected with USB controller chip 3 through the I2C bus.
Microcontroller 3 is responsible for the operation control of total systems, comprise that parameter receives, the configuration of 1394 integrated manipulators 4 and control, control internal storage data between 1394 integrated manipulators 4 and microcontroller 3 transmission and the internal storage data that obtains delivered to the evidence obtaining computing machine.1394 controllers 4 comprise Physical layer and link layer two parts, can select two independent chips or two-layer integrated chip, are responsible for the transmission and the reception of 1394 packets.Utilize 8051 controllers that the CY7C68013A chip carries to describe as the CSR of 3 couples of TSB43AA82A of microcontroller that description is configured with ConfigROM; Become Windows itself to carry the 1394 Mass Storage equipment class that drive and allow the physics request this equipment disposition; The function of realization equipment plug and play makes object computer operating system open the DMA function to this equipment.The CY7C68013A chip is coordinated control TSB43AA82A reading internal storage data.
In Fig. 2, provided the sample drawing of the utility model, the state of three present equipment operations of relay indicating light 11 indications.Red light is a power lights, the indication equipment energising; Amber light is idle lamp, the indication equipment normal load, but do not carry out data read-write operation; Green light is a running indicator, representes that present equipment is carrying out read-write operation.
Utility model patent can be opened the characteristics of DMA under specific circumstances based on 1394 bussing techniques and operating system, by means of the basic configuration and the plug-and-play feature of the DMA data transfer mode of I/O equipment, various operating systems.The equipment of the utility model is in the process of using; Usb 1 is connected with the evidence obtaining computing machine; 1394 interfaces 2 are connected with object computer; Mode through DMA realizes the visit to the object computer physical memory, and the physical memory packet that is read is sent to the evidence obtaining computing machine through Universal USB interface 2, under to the very little situation of object computer internal memory change, realizes obtaining of internal storage data.

Claims (6)

1. the equipment through IEEE 1394 interface writable computer physical memories is characterized in that: comprise microcontroller (3), 1394 integrated manipulators (4) that are connected with microcontroller, clock module (9) that is used to provide clock signal that executive routine and control are used and the power module (5) that electric energy is provided; Said microcontroller is respectively arranged with USB interface (1) that is connected with the computing machine of collecting evidence and 1394 interfaces (2) that are connected with object computer with 1394 integrated manipulators, also has been provided with the code translator (8) of expansion control port between said microcontroller and 1394 integrated manipulators; The outside expansion of said microcontroller has program storage (7).
2. the equipment through IEEE 1394 interface writable computer physical memories according to claim 1 is characterized in that: also be provided with the reseting module (6) that microcontroller (3) and 1394 integrated manipulators (4) are controlled; The input end of said power module (5) is connected with the power lead of USB interface (1), and the output terminal of power module all is connected with reseting module with microcontroller, 1394 integrated manipulators.
3. the equipment through IEEE 1394 interface writable computer physical memories according to claim 1 and 2, it is characterized in that: the output terminal of said clock module (9) all is connected with 1394 integrated manipulators (4) with microcontroller (3).
4. the equipment through IEEE 1394 interface writable computer physical memories according to claim 1 and 2; It is characterized in that: said 1394 integrated manipulators (4) comprise Physical layer and link layer two parts, and it is the integrated independent chip of Physical layer and link layer or Physical layer and two integrated respectively chips of link layer.
5. the equipment through IEEE 1394 interface writable computer physical memories according to claim 4, it is characterized in that: the model of said 1394 integrated manipulators (4) is TSB43AA82A.
6. the equipment through IEEE 1394 interface writable computer physical memories according to claim 1 and 2 is characterized in that: said microcontroller (3) is for having the CY7C68013A chip of 8051 controllers and USB interface.
CN2011202482000U 2011-07-14 2011-07-14 Equipment for reading and writing physical memory of computer through IEEE 1394 interface Expired - Fee Related CN202205195U (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2011202482000U CN202205195U (en) 2011-07-14 2011-07-14 Equipment for reading and writing physical memory of computer through IEEE 1394 interface

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2011202482000U CN202205195U (en) 2011-07-14 2011-07-14 Equipment for reading and writing physical memory of computer through IEEE 1394 interface

Publications (1)

Publication Number Publication Date
CN202205195U true CN202205195U (en) 2012-04-25

Family

ID=45969307

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2011202482000U Expired - Fee Related CN202205195U (en) 2011-07-14 2011-07-14 Equipment for reading and writing physical memory of computer through IEEE 1394 interface

Country Status (1)

Country Link
CN (1) CN202205195U (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103399830A (en) * 2013-08-09 2013-11-20 山东省计算中心 Equipment and method for reading computer physical memory through PCI Express bus
CN104750591A (en) * 2013-12-30 2015-07-01 上海威亿实业有限公司 Evidence-taking device and method for computer
CN111737178A (en) * 2020-06-18 2020-10-02 济南互信软件有限公司 Computer memory forensics method and equipment and memory forensics analysis system
CN116383015A (en) * 2023-06-06 2023-07-04 成都安思科技有限公司 Physical memory noninductive evidence obtaining system and method based on extensible board plug-in type

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103399830A (en) * 2013-08-09 2013-11-20 山东省计算中心 Equipment and method for reading computer physical memory through PCI Express bus
CN103399830B (en) * 2013-08-09 2016-01-06 山东省计算中心 The Apparatus and method for of computer physics internal memory is read by PCI Express bus
CN104750591A (en) * 2013-12-30 2015-07-01 上海威亿实业有限公司 Evidence-taking device and method for computer
CN111737178A (en) * 2020-06-18 2020-10-02 济南互信软件有限公司 Computer memory forensics method and equipment and memory forensics analysis system
CN111737178B (en) * 2020-06-18 2024-02-09 济南互信软件有限公司 Method and equipment for obtaining evidence in computer memory and memory evidence analysis system
CN116383015A (en) * 2023-06-06 2023-07-04 成都安思科技有限公司 Physical memory noninductive evidence obtaining system and method based on extensible board plug-in type

Similar Documents

Publication Publication Date Title
CN202205195U (en) Equipment for reading and writing physical memory of computer through IEEE 1394 interface
CN103200199A (en) Out of band (OOB) data collection system
CN208188815U (en) BMC module system
CN103399830A (en) Equipment and method for reading computer physical memory through PCI Express bus
CN102880235B (en) Single-board computer based on loongson 2F central processing unit (CPU) as well as reset management and using method of single-board computer
CN106599677A (en) Password control system and control method used for baseboard management controller
CN104035731A (en) Storage head node of blade server
CN204390237U (en) A kind of encryption and decryption card of Based PC I-E bussing technique
CN102709990A (en) Double-lithium-battery charging and discharging management circuit
CN203386206U (en) Device for reading physical memory of computer through PCI Express interface
CN102650933A (en) Storage system for network communication recording device of digital substation
CN203204494U (en) Multifunctional high-stability slot structure and multifunctional card insertion module combined system
CN102176589A (en) Concentrator for universal serial bus (USB)-8 serial port RS422
CN105630400A (en) High-speed massive data storage system
CN201828970U (en) Train operation data recorder based on CAN (Controller Area Network) interface
CN201654772U (en) Storage medium interface conversion device
CN204697071U (en) A kind of side Multiple Channel Analysis assessment datum plate
CN103984543A (en) Method for implementing standby, hibernation and wake-up on domestic FeiTeng processor
CN201122436Y (en) Mobile hard disk case
CN204557492U (en) A kind of data in magnetic disk encrypted circuit plate
CN202771419U (en) Safe universal serial bus (USB) disk
CN103236122B (en) The tax control validity check card of Based PC I Bus Interface Chip and CPLD chip
CN105653477A (en) Double-port RAM-based method for communication of hard core and soft core in FPGA
CN202177896U (en) Encryption storage chip
CN206178529U (en) Main control board based on explain 411 majestic treaters and shen wei nest plate

Legal Events

Date Code Title Description
C14 Grant of patent or utility model
GR01 Patent grant
C17 Cessation of patent right
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20120425

Termination date: 20120714