A differential user identification and authorization system and method based on an encryption key algorithm

Through a differentiated user identification authorization system based on encryption key algorithm, dynamic random codes and multiple sets of decryption algorithms are used to identify user identities, the security and cost issues of user identification and permission management in the engineering vehicle display system are solved, and secure and simple user identity management is achieved.

CN115459978BActive Publication Date: 2025-08-05XUZHOU HEAVY MASCH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211059572.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-30
Publication Date
2025-08-05
Estimated Expiration
2042-08-30

AI Technical Summary

Technical Problem

Existing engineering vehicle display systems cannot achieve differentiated user identification and permission management, resulting in low security, cumbersome management and high hardware costs.

Method used

A differentiated user identification authorization system based on encryption key algorithm is adopted, including an on-board display unit, a background management unit and a mobile application. User identity is identified by generating dynamic random codes and multiple sets of decryption algorithms, dynamic authorization permissions are supported, and offline operations are supported.

Benefits of technology

It realizes the ability to identify user identities and authorize permissions without increasing hardware costs, simplify management processes, and is suitable for differentiated user needs of engineering vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115459978B_ABST
    Figure CN115459978B_ABST
Patent Text Reader

Abstract

The present invention discloses a differentiated user identification and authorization system and method based on an encryption key algorithm. The authorization system includes a vehicle-mounted display unit, a background management unit, and a mobile application end. The vehicle-mounted display unit is used to generate a dynamic random code and display a corresponding interaction mode based on the user identity type. The mobile application end is used for the user to establish a connection with the background management unit and call a corresponding encryption algorithm to encrypt the dynamic random code according to feedback from the background management unit. The background management unit is used to store and modify the user identity type and feedback the current user identity type to the mobile application end.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a differentiated user identification and authorization system and method based on an encryption key algorithm, and belongs to the technical field of engineering vehicle applications. Background Art

[0002] As the intelligence, automation, and refinement of my country's engineering vehicles continue to improve, the concept of full product lifecycle services continues to deepen. Display systems, as a crucial interface for direct communication between products and users, are a crucial bridge and window for achieving safe, efficient, and intelligent driving and operation for both humans and machines. From production line commissioning to delivery to customer hands, through initial installation and subsequent operational guidance and maintenance services, engineering vehicles face diverse user demands and experiences. Customers and operators seek simple, easy-to-use display systems, while commissioning users expect convenient configuration and auxiliary tools. Maintenance personnel prefer to provide customers with timely and accurate troubleshooting and problem resolution. Furthermore, user permissions are crucial for vehicle safety. In particular, users who lack formal training or experience gain high-level permissions and use them recklessly, which can easily lead to safety incidents and serious consequences.

[0003] Currently, the display systems of engineering vehicles mainly operate in offline mode and are unable to identify user identities and grant different permissions by connecting to the Internet. Therefore, a universal interface and operating method are often used, which cannot meet the differentiated needs of various users. For example, when additional maintenance personnel are needed, since the system is offline, the maintenance personnel information needs to be entered into the system of each engineering vehicle and the relevant permissions need to be granted. Entering personnel information is cumbersome. If the system is connected to the Internet and external detection devices are added to achieve identity recognition, the hardware cost needs to be increased on each engineering vehicle, which is very expensive. If the account and position are set to correspond only through passwords, the password is fixed and the security level is low. Summary of the Invention

[0004] In order to address the deficiencies of the prior art, the purpose of the present invention is to provide a differentiated user identification and authorization system and method based on an encryption key algorithm, which solves the problems of low differentiation mode, simple encryption method and high hardware cost in the prior art.

[0005] In order to achieve the above objectives, the present invention adopts the following technical solutions:

[0006] A differentiated user identification and authorization system based on an encryption key algorithm includes an on-board display unit, a background management unit, and a mobile application terminal;

[0007] The vehicle display unit is in an offline state and is used to generate a dynamic random code and display the corresponding interaction mode based on the user identity type;

[0008] The mobile application terminal is used to establish a connection between the user and the background management unit, and to call the corresponding encryption algorithm to encrypt the dynamic random code according to the feedback from the background management unit;

[0009] The background management unit is used to store and modify the user identity type and corresponding permissions, and to feedback the current user identity type to the mobile application end.

[0010] Furthermore, the aforementioned vehicle-mounted display unit includes a dynamic random code generation module, an identity recognition module and an authorization interaction module;

[0011] Dynamic random code generation module, used to automatically generate dynamic random codes;

[0012] The identity recognition module is used to decrypt the verification code generated by the mobile application and identify the identity type of the current user to be logged in based on the decryption result;

[0013] The authorization interaction module authorizes the permissions and services that such users have according to the user identity type identified by the identity recognition module.

[0014] Furthermore, the dynamic random code is displayed in any form of numbers, uppercase and lowercase letters, and common symbols.

[0015] Furthermore, the aforementioned identity recognition module includes multiple sets of decryption algorithms, each set of decryption algorithms corresponds to a user identity type.

[0016] Furthermore, the aforementioned background management unit includes a user management module;

[0017] The user management module manages all types of users on different devices in a unified manner, assigns corresponding user identity types and permissions to all users, and assigns corresponding login information based on the user identity type.

[0018] Furthermore, the aforementioned mobile application terminal includes a key algorithm module;

[0019] The key algorithm module includes multiple encryption algorithms, each of which corresponds to an identity type. Based on the current user identity type transmitted by the background management unit, the key encryption algorithm corresponding to the identity type is called to encrypt the input dynamic random code, and then the encrypted verification code is output after completion.

[0020] Furthermore, the aforementioned mobile application terminal is in the form of application software or applet, which is directly ported to the mobile terminal.

[0021] A differentiated user identification and authorization method based on an encryption key algorithm comprises the following steps:

[0022] Log in to the vehicle display unit, and the dynamic random code generation module automatically generates a dynamic random code;

[0023] A dynamic random code is input on the mobile application side. The user management module identifies the user's identity type based on the login information of the mobile application side. The key algorithm module encrypts the input dynamic random code using the key encryption algorithm corresponding to the user's identity type to obtain a verification code and outputs the verification code.

[0024] The identity recognition module applies the key decryption algorithm corresponding to all user identity types to decrypt. After decryption is completed, all decrypted data is compared with the dynamic random code;

[0025] If the decrypted data is consistent with the dynamic random code, the authorization interaction module authorizes the user to obtain corresponding permissions and services based on the user identity type corresponding to the decrypted data.

[0026] The beneficial effects achieved by the present invention are:

[0027] 1. The differentiated user identity recognition and authorization system provided by the present invention does not require additional hardware and can identify identity types only through the vehicle-mounted display unit and the mobile application terminal. Compared with facial recognition modules, voiceprint recognition modules, smart cards and other means, it is lower in cost.

[0028] 2. The differentiated user identity recognition and authorization system provided by the present invention uniformly manages users and user identity types based on the user management module, thereby improving the convenience of data maintenance.

[0029] 3. The user identification method based on the key encryption algorithm provided by the present invention is based on dynamic random codes and multiple key encryption algorithms. Compared with fixed passwords and fixed algorithms, the information is more secure and reliable.

[0030] 4. The differentiated user identity recognition and authorization system provided by the present invention can be directly installed on the original vehicle system of the engineering vehicle to upgrade the software system. The application level and user management module remain consistent. The entire process supports network offline operation and is more suitable for engineering machinery vehicles with harsh working environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 It is the system composition of the present invention;

[0032] Figure 2 This is the differentiated user identification and authorization operation process of the present invention. DETAILED DESCRIPTION

[0033] The present invention will be further described below in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and are not intended to limit the scope of protection of the present invention.

[0034] This embodiment discloses a differentiated user identification and authorization system based on an encryption key algorithm. When different users (mainly customers, but also including other users throughout the life cycle, such as design engineers, debugging engineers, service engineers, etc., but not limited to these user identities) operate engineering vehicles, they need to obtain services and permissions corresponding to their identities: first, they apply for login on the on-board display unit, and the on-board display unit generates a dynamic random code; then the user applies for a verification code generated through a mobile application based on the dynamic random code and enters it into the on-board display unit; the on-board display unit performs identity recognition, identifies the user type (such as debugging, service, administrator, etc.), and based on the user type and according to the vehicle safety level requirements, authorizes different permission levels and displays differentiated scenario interaction modes that match the identity type.

[0035] Specifically, as attached Figure 1 As shown, the system includes an on-board display unit, a background management unit, and a mobile application terminal. The on-board display unit includes a dynamic random code generation module, an identity recognition module, and an authorization interaction module; the background management unit includes a user management module; the mobile application terminal includes a key algorithm module. The mobile application terminal is generally an application software or a small program that can be directly transplanted to a mobile terminal (such as a mobile phone, a laptop computer, etc.). Without additional hardware costs, data interaction between the mobile application terminal and the background management unit can be achieved. The specific content and function of each module are as follows, and the specific workflow is as follows. Figure 2 shown.

[0036] 1) Dynamic random code generation module: When a user needs to log in to the vehicle interaction system, this module automatically generates a dynamic random code (in any form), which can be any combination of numbers, uppercase and lowercase letters, common symbols, etc.

[0037] 2) Identity Recognition Module: This module includes multiple decryption algorithms, each corresponding to a specific identity type. The verification code output by the mobile application is decrypted using the key decryption algorithm corresponding to each identity type and compared with the dynamic random code. If the decrypted verification code matches the initial dynamic random code, the identity type corresponding to the decryption algorithm is the identity type of the current user. If the decryption does not match, the identity type matching fails.

[0038] 3) Authorization interaction module: Based on the user identity type identified by the identity recognition module, the vehicle operation permissions, interfaces, interaction content and modes, etc. are authorized to such users, which not only ensures the safety of the vehicle but also better meets the customer's usage needs. At the same time, other vehicle assistants can better and more efficiently serve the vehicle.

[0039] 4) User Management Module: This module centrally manages various user types (including customers / operators, commissioning engineers, service engineers, design engineers, administrators, and others) across different devices. Login information for each user is assigned to each user. Modifications to users or user identity types (including adding, deleting, and replacing) are performed centrally within this module, streamlining management and eliminating the need for separate operations on each device. The aforementioned identity recognition module and authorization interaction module pre-configure user identity types and their corresponding permissions. If a new user is added solely through the user management module and granted the pre-configured user type and permissions, the identity recognition and authorization interaction modules remain unchanged. If a new user identity type and its corresponding permissions are added through the user management module, the software upgrade can be directly installed on the original onboard display unit of the engineering vehicle, making the corresponding changes to the identity recognition and authorization interaction modules. Specifically, the new user identity type and its corresponding decryption algorithm are added to the identity recognition module, and the permissions corresponding to the newly added user identity type are added to the authorization interaction module. The onboard display unit operates entirely offline, eliminating the need for a network connection to the backend management unit, reducing additional hardware costs.

[0040] 5) Key algorithm module: This is usually placed on the mobile application side. The mobile application side is generally an application software or applet that can be directly ported to a mobile terminal (such as a mobile phone, laptop, tablet, etc.) for user convenience. It contains multiple encryption algorithms, each corresponding to an identity type. The user first logs in to the mobile application side using the login information to establish a connection with the user management module. The user management module identifies the current user identity type based on the login information. The user enters a randomly generated dynamic random code on the logged-in mobile application side. The mobile application side calls the key encryption algorithm corresponding to the identity type according to the current user identity type passed by the user management module for encryption, and outputs the encrypted verification code after completion. When a new user identity type and its corresponding permissions are added through the user management module, a new encryption algorithm corresponding to it can be directly added to the key algorithm module.

[0041] This embodiment also involves a differentiated user identification and authorization method based on an encryption key algorithm, utilizing the aforementioned system. When a user requests a verification code, the user management module transmits the user's identity type. The user management module then invokes the key encryption algorithm corresponding to the user's identity type to encrypt the input dynamic random code to generate a verification code. The verification code is then output, and the identity recognition module decrypts the code using the key decryption algorithm corresponding to all user identity types. After decryption, all decrypted data is compared with the dynamic random code. If any decrypted data matches the initial dynamic random code, the user identity type corresponding to the decrypted data is correct, indicating successful user identification. Otherwise, the user identity has been successfully identified. The authorization interaction module then authorizes the user with the vehicle operation permissions, interfaces, interaction content, and modes identified by the user's identity type.

[0042] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A differentiated user identification and authorization system based on an encryption key algorithm, characterized in that: Including vehicle display unit, background management unit and mobile application terminal; The vehicle-mounted display unit is in an offline state and is used to generate a dynamic random code and display a corresponding interaction mode based on the user identity type; The mobile application terminal is used for the user to establish a connection with the background management unit, encrypts the input dynamic random code using the key encryption algorithm corresponding to the user identity type to obtain a verification code, and outputs the verification code; The backend management unit is used to store and modify the user identity type and corresponding permissions, and to feedback the current user identity type to the mobile application end; The vehicle-mounted display unit includes a dynamic random code generation module, an identity recognition module and an authorization interaction module; The dynamic random code generation module is used to automatically generate a dynamic random code; The identity recognition module is used to decrypt the verification code generated by the mobile application terminal and identify the identity type of the current user to be logged in based on the decryption result; The authorization interaction module authorizes the permissions and services that such user has according to the user identity type identified by the identity recognition module.

2. A differentiated user identification and authorization system based on an encryption key algorithm according to claim 1, characterized in that: The dynamic random code may be displayed in any form of numbers, uppercase and lowercase letters, or common symbols.

3. The differentiated user identification and authorization system based on encryption key algorithm according to claim 1, characterized in that: The identity recognition module includes multiple sets of decryption algorithms, each set of decryption algorithms corresponds to a user identity type.

4. A differentiated user identification and authorization system based on an encryption key algorithm according to claim 1, characterized in that: The background management unit includes a user management module; The user management module manages all types of users on different devices in a unified manner, assigns corresponding user identity types and permissions to all users, and assigns corresponding login information based on the user identity type.

5. The differentiated user identification and authorization system based on encryption key algorithm according to claim 1 is characterized in that: The mobile application terminal includes a key algorithm module; The key algorithm module includes multiple sets of encryption algorithms, each set of encryption algorithms corresponds to an identity type. Based on the current user identity type transmitted by the background management unit, the key encryption algorithm corresponding to the identity type is called to encrypt the input dynamic random code, and after completion, the encrypted verification code is output.

6. A differentiated user identification and authorization system based on encryption key algorithm according to claim 5, characterized in that: The mobile application terminal is in the form of application software or applet, which is directly transplanted to the mobile terminal.

7. A differentiated user identification and authorization method based on an encryption key algorithm, characterized in that: The method applied to a differentiated user identification and authorization system based on an encryption key algorithm as described in any one of claims 1 to 6 comprises the following steps: Log in to the vehicle display unit, and the dynamic random code generation module automatically generates a dynamic random code; A dynamic random code is input on the mobile application side. The user management module identifies the user's identity type based on the login information of the mobile application side. The key algorithm module encrypts the input dynamic random code using the key encryption algorithm corresponding to the user's identity type to obtain a verification code and outputs the verification code. The identity recognition module applies the key decryption algorithm corresponding to all user identity types to decrypt. After decryption is completed, all decrypted data is compared with the dynamic random code; If the decrypted data is consistent with the dynamic random code, the authorization interaction module authorizes the user to obtain corresponding permissions and services based on the user identity type corresponding to the decrypted data.

Citation Information

Patent Citations

  • Method and device for managing vehicle control authority

    CN109102593A