CN210123554U - Evidence obtaining equipment - Google Patents

Evidence obtaining equipment Download PDF

Info

Publication number
CN210123554U
CN210123554U CN201921243642.9U CN201921243642U CN210123554U CN 210123554 U CN210123554 U CN 210123554U CN 201921243642 U CN201921243642 U CN 201921243642U CN 210123554 U CN210123554 U CN 210123554U
Authority
CN
China
Prior art keywords
data
data acquisition
module
evidence obtaining
interface
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201921243642.9U
Other languages
Chinese (zh)
Inventor
王进
吴兴德
王鸿南
陈兴文
段成阁
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Suzhou Longxin Mdt Infotech Ltd
Original Assignee
Suzhou Longxin Mdt Infotech Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Suzhou Longxin Mdt Infotech Ltd filed Critical Suzhou Longxin Mdt Infotech Ltd
Priority to CN201921243642.9U priority Critical patent/CN210123554U/en
Application granted granted Critical
Publication of CN210123554U publication Critical patent/CN210123554U/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Debugging And Monitoring (AREA)

Abstract

The embodiment of the utility model discloses equipment of collecting evidence. Wherein, this equipment includes: at least two data acquisition main boards; each data acquisition mainboard is provided with an interface, and the interface is used for connecting equipment to be forensics; each data acquisition mainboard is used for parallelly acquiring the evidence obtaining data of the equipment to be proved connected with the data acquisition mainboard through an interface. And by adopting a distributed architecture, the evidence obtaining of multiple mainboards is realized, and the evidence obtaining efficiency is improved. Through a plurality of collection mainboards independent operation simultaneously, avoid the interact between each mainboard, improve the high efficiency and the reliability of collecting evidence.

Description

Evidence obtaining equipment
Technical Field
The embodiment of the utility model provides a relate to the electron medium technique of collecting evidence, especially relate to an equipment of collecting evidence.
Background
With the rapid development of social economy and the continuous updating of information technology, more and more application scenes related to electronic storage medium evidence obtaining are provided in the case handling process of public security institutions.
In the face of the evidence obtaining requirements of a large number of electronic storage media, a traditional evidence obtaining mode is that data collection is usually carried out on a plurality of storage media by a data collection main board, when a certain part in the main board breaks down or is in drive conflict or insufficient power supply, the whole evidence obtaining equipment can not work normally, and the conditions of low evidence obtaining efficiency, low stability, poor reliability and the like are caused.
Disclosure of Invention
An embodiment of the utility model provides a device of collecting evidence to realize that many mainboards are parallel to collect evidence, improve the efficiency of collecting evidence.
The embodiment of the invention provides evidence obtaining equipment, which comprises at least two data acquisition main boards; each data acquisition mainboard is provided with an interface, and the interface is used for connecting equipment to be forensics;
each data acquisition mainboard is used for parallelly acquiring the evidence obtaining data of the equipment to be proved connected with the data acquisition mainboard through an interface.
Optionally, the interface type includes at least one of the following: USB, SATA, E-SATA, TF, CF, and SD.
Optionally, the device further includes a control main board and a data exchange unit, where the control main board is configured to obtain the forensics data of the data acquisition main board through the data exchange unit.
Optionally, the control main board includes a data collection module, a data analysis module and a data display module;
the data collection module is used for acquiring evidence obtaining data of the data acquisition main board through the data exchange unit;
the data analysis module is used for calling a pre-configured evidence obtaining application to carry out evidence obtaining analysis on the evidence obtaining data obtained by the data collection module;
and the data display module is used for displaying the evidence obtaining analysis result of the data analysis module.
Optionally, the control main board further includes a report export module;
the report exporting module is connected with the data display module and the data analysis module and used for exporting evidence obtaining analysis results.
Optionally, a CPU, an internal memory, and a hard disk are integrated in the data acquisition motherboard, and are used to acquire and store the forensic data of the device to be forensic.
Optionally, any data acquisition main board of the device is connected to the at least two interfaces, and the types of the at least two interfaces connected to the data acquisition main board are different.
Optionally, the forensic device is a PC.
The embodiment of the utility model provides a through corresponding two at least independent data acquisition mainboards and storage medium each other, carry out parallel processing to data, each other does not influence between each data acquisition mainboard, avoids taking place the drive conflict, improves the efficiency of collecting evidence, guarantees the reliability of collecting evidence.
Drawings
FIG. 1 is a schematic diagram of a forensic device in an embodiment of the present invention;
FIG. 2 is a schematic diagram of a forensic device in an embodiment of the present invention;
FIG. 3 is a schematic diagram of a forensic device in an embodiment of the present invention;
FIG. 4 is a schematic diagram of a forensic device in an embodiment of the present invention;
fig. 5 is a schematic structural diagram of a forensic apparatus in an embodiment of the present invention.
Detailed Description
The present invention will be described in further detail with reference to the accompanying drawings and examples. It is to be understood that the specific embodiments described herein are merely illustrative of the invention and are not limiting of the invention. It should be further noted that, for the convenience of description, only some of the structures related to the present invention are shown in the drawings, not all of the structures.
Fig. 1 is the embodiment of the utility model provides a data acquisition mainboard sketch map of equipment of collecting evidence, as shown in fig. 1, this equipment of collecting evidence 10 can include two at least data acquisition mainboard 110, and every data acquisition mainboard 110 is provided with at least one interface 111, and interface 111 is used for connecting the equipment of collecting evidence of treating that contains storage medium, and every data acquisition mainboard 110 is arranged in parallel obtaining the data of collecting evidence in the equipment of treating collecting evidence that connects through interface 111. The data acquisition main boards 110 are independent from each other and do not affect each other, hardware such as a CPU, an internal memory and a hard disk are integrated in the data acquisition main boards 110, the evidence acquisition data in the equipment to be subjected to evidence acquisition is acquired and stored, the original data in different storage media can be acquired, after the data acquisition main boards 110 acquire the original data, the data are analyzed into structured data which can be loaded by evidence acquisition software, and the structured data are packed, compressed and transmitted.
Optionally, the interface type includes at least one of the following: USB, SATA, E-SATA, TF, CF and SD, can be inserted into the mobile phone, U disk and other devices to be forensics containing storage media. Any data acquisition mainboard can be connected with at least two interfaces, and the type of the at least two interfaces that this data acquisition mainboard is connected can be different, and the data acquisition mainboard can be one-to-one or one-to-many independently gather, store and analyze the original data in the storage medium. For example, the data acquisition main board may be connected to a device with a USB interface and may also be connected to a device with an SD interface, and different interfaces on the same data acquisition main board do not affect each other. When a certain data acquisition mainboard breaks down or supplies power insufficiently, other data acquisition mainboards still normally work, and different data acquisition mainboards are mutually independent, avoid taking place the drive conflict.
The data acquisition main board is used for acquiring, analyzing and transmitting data. Fig. 2 is a schematic structural diagram of the data acquisition main board 110 of the evidence obtaining apparatus in the embodiment of the present invention, as shown in fig. 2, the data acquisition main board 110 may include a data acquisition module 1101, a data analysis module 1102 and a data transmission module 1103, wherein the data acquisition module 1101 is connected to the evidence obtaining apparatus through an interface 111, and is configured to obtain original data and send the data to the data analysis module 1102; the data analysis module 1102 is connected to the data acquisition module 1101 and the data transmission module 1103, and is configured to run data analysis software, analyze the original data extracted from the data acquisition module 1101 into structured data that can be loaded by forensic software through computing capabilities provided by hardware such as a CPU and a memory in the data acquisition motherboard 110, and perform packing and compression; the data transmission module 1103 is connected to the data analysis module 1102, and configured to transmit the analyzed data to the control motherboard through the data exchange unit via the network card in the data acquisition motherboard 110. It should be noted that the type of the data analysis software is not particularly limited in this embodiment.
Fig. 3 is a schematic structural diagram of a forensic apparatus according to an embodiment of the present invention, as shown in fig. 3, the forensic apparatus 10 further includes a control motherboard 120 and a data exchange unit 130, the control motherboard 120 is configured to obtain forensic data of the data acquisition motherboard 110 through the data exchange unit 130, and perform storage, analysis, result display and report derivation; the data exchange unit 130 serves as a data transmission medium to transmit the plurality of forensic data in the data acquisition motherboard 110 to the control motherboard 120.
Fig. 4 is a schematic structural diagram of a forensic apparatus according to an embodiment of the present invention, and as shown in fig. 4, the control motherboard 120 includes a data collection module 1201, a data analysis module 1202, a data display module 1203, and a report derivation module 1204. The data collection module 1201 is connected to the data analysis module 1202, is composed of a storage disk, has a large-capacity storage space, and is configured to receive and store the packed forensic data in the data collection motherboard 110 through the data exchange unit 130 and send the forensic data to the data analysis module 1202; the data analysis module 1202 is connected to the data collection module 1201, the data display module 1203 and the report export module 1204, and is configured to invoke a pre-configured forensics application software to obtain forensics data obtained by the data collection module 1201, load and run the forensics application software by using hardware devices such as a multi-core processor, a memory and a graphics card, decompress and forensics data packed and compressed in the data collection motherboard 110, and send the analyzed data to the data display module 1203 and/or the report export module 1204, where the forensics application software may include domestic forensics software and foreign forensics software; the data display module 1203 is connected to the data analysis module 1202 and the report export module 1204, and is configured to display a forensics analysis result of the data analysis module 1202 and send the result to the report export module 1204; the report export module 1204 is connected to the data display module 1203 and the data analysis module 1202 for exporting the evidence-obtaining analysis result. It should be noted that the type of the forensic application software is not particularly limited in this embodiment.
Fig. 5 is a schematic structural diagram of a forensic apparatus according to an embodiment of the present invention, as shown in fig. 5, the forensic apparatus 10 includes at least two independent data acquisition motherboards 110, a control motherboard 120, a data exchange unit 130 and an interface 111, and each data acquisition motherboard 110 independently reads original data in each device to be forensic. Illustratively, eight data acquisition main boards can be provided, each data acquisition main board is connected with two devices to be proved, original data are analyzed in the data acquisition main boards, the data are packed and compressed and sent to a data collection module in the control main board through a data exchange unit, the data collection module receives data sent by the data exchange unit, the data are stored and sent to a data analysis module, the data analysis module decompresses and analyzes the data, an analysis result is generated, the analysis result is sent to a data display module to be displayed, the data display module sends display contents to a report export module, and the report is exported.
Optionally, the forensic device may be a PC.
Illustratively, the mobile terminal, the U disk and the SD card which store data are simultaneously inserted into the PC and correspondingly inserted into the interfaces of the three data acquisition modules, the three data acquisition modules simultaneously read corresponding data and transmit the data to the control mainboard through the data exchange unit, and the data analysis module in the control mainboard analyzes the data through evidence obtaining software and can export an analysis result into a report. The data acquisition system has the advantages that different data are processed simultaneously, conflict can not occur in each data acquisition mainboard in the processing process, the evidence obtaining speed is increased, and the evidence obtaining analysis efficiency is effectively improved.
It should be noted that the foregoing is only a preferred embodiment of the present invention and the technical principles applied. It will be understood by those skilled in the art that the present invention is not limited to the particular embodiments described herein, but is capable of various obvious changes, rearrangements and substitutions as will now become apparent to those skilled in the art without departing from the scope of the invention. Therefore, although the present invention has been described in greater detail with reference to the above embodiments, the present invention is not limited to the above embodiments, and may include other equivalent embodiments without departing from the scope of the present invention.

Claims (8)

1. Evidence obtaining equipment is characterized by comprising at least two data acquisition main boards; each data acquisition mainboard is provided with an interface, and the interface is used for connecting equipment to be forensics;
each data acquisition mainboard is used for parallelly acquiring the evidence obtaining data of the equipment to be proved connected with the data acquisition mainboard through an interface.
2. The apparatus of claim 1, wherein the interface type comprises at least one of: USB, SATA, E-SATA, TF, CF, and SD.
3. The device according to claim 1, further comprising a control motherboard and a data exchange unit, wherein the control motherboard is configured to obtain forensics data of the data acquisition motherboard through the data exchange unit.
4. The device of claim 3, wherein the control motherboard comprises a data collection module, a data analysis module and a data presentation module;
the data collection module is used for acquiring evidence obtaining data of the data acquisition main board through the data exchange unit;
the data analysis module is used for calling a pre-configured evidence obtaining application to carry out evidence obtaining analysis on the evidence obtaining data obtained by the data collection module;
and the data display module is used for displaying the evidence obtaining analysis result of the data analysis module.
5. The apparatus of claim 3, wherein the control motherboard further comprises a report export module;
the report exporting module is respectively connected with the data display module and the data analysis module and is used for exporting evidence obtaining analysis results.
6. The device according to claim 1, wherein a CPU, a memory and a hard disk are integrated in the data acquisition motherboard, and are used for acquiring and storing the forensic data of the device to be forensic.
7. The apparatus of claim 1, wherein any one of the data acquisition motherboards is connected to the at least two interfaces, and the type of the at least two interfaces connected to the data acquisition motherboard is different.
8. The device of claim 1, wherein the forensic device is a PC.
CN201921243642.9U 2019-08-02 2019-08-02 Evidence obtaining equipment Active CN210123554U (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201921243642.9U CN210123554U (en) 2019-08-02 2019-08-02 Evidence obtaining equipment

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201921243642.9U CN210123554U (en) 2019-08-02 2019-08-02 Evidence obtaining equipment

Publications (1)

Publication Number Publication Date
CN210123554U true CN210123554U (en) 2020-03-03

Family

ID=69634589

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201921243642.9U Active CN210123554U (en) 2019-08-02 2019-08-02 Evidence obtaining equipment

Country Status (1)

Country Link
CN (1) CN210123554U (en)

Similar Documents

Publication Publication Date Title
CN108446215B (en) POS machine test method, device, system and terminal
CN105338358A (en) Image decoding method and device
CN103955441A (en) Equipment management system, equipment management method and IO (Input/Output) expansion interface
CN108509652A (en) Data processing system and method
CN111694866A (en) Data searching and storing method, data searching system, data searching device, data searching equipment and data searching medium
CN111367764A (en) PCIE monitoring method, system, equipment and computer storage medium
CN106227506A (en) A kind of multi-channel parallel Compress softwares system and method in memory compression system
CN210123554U (en) Evidence obtaining equipment
CN100524267C (en) Data processing system and data processing method
CN112882833B (en) Data acquisition method and device, computer equipment and storage medium
CN109510740A (en) A kind of method, apparatus, terminal and the storage medium of automatic monitoring network interface card MTU value
CN109347899A (en) The method of daily record data is written in distributed memory system
CN111913861A (en) Performance test method, device, equipment and medium of Internet of things system
US11687377B1 (en) High performance computer with a control board, modular compute boards and resource boards that can be allocated to the modular compute boards
CN104484305B (en) Server debugging analysis interface device
CN114218000A (en) Log management method and device, electronic equipment and computer readable storage medium
CN101751283A (en) Virtual machine monitor, virtual machine system and client operation system state acquiring method
CN112181891B (en) NVMe (network video recorder) -based storage board card and data processing method
WO2021237513A1 (en) Data compression storage system and method, processor, and computer storage medium
CN113805854A (en) Method, system and device for realizing Hook of application layer based on Linux system and storage medium
CN114550809A (en) Multi-memory card testing method and device, computer equipment and storage medium
CN109194529B (en) Interaction method and device for virtual SIM card and server apdu
CN112468829B (en) Sharing method of cache video, electronic device and computer readable storage medium
CN212588368U (en) High-load portable data transmission all-in-one machine based on mobile Internet
CN103617030A (en) Equipment panel generating method and equipment panel generating device

Legal Events

Date Code Title Description
GR01 Patent grant
GR01 Patent grant