Industrial equipment authentication login method and device
Through the multi-factor verification method of biometric matching and password update, the problems of password leakage and replication of industrial equipment are solved, and the security of the equipment and the protection capabilities of the administrator system are improved.
Patent Information
- Application Number
- CN202211132036.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-16
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-09-16
AI Technical Summary
Passwords of industrial equipment are easily leaked or copied, resulting in serious challenges in password security management.
By collecting user's user biometrics, matching with pre-stored biometrics, and accepting the entered password and login password when matching, opening login permissions, updating and storing the login password at the same time, uploading it to the server.
Improve password security, prevent passwords from being copied, enhance the security of administrator equipment system, and reduce the risk of illegal intrusion.
Smart Images

Figure CN115529175B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial equipment safety technology, and in particular to an industrial equipment authentication login method and system. Background Art
[0002] Industrial equipment (such as sewage treatment equipment) requires more on-site processing than general equipment. For example, when industrial equipment fails or is debugged and upgraded, it may be necessary to log in to the administrator's equipment system on-site to view core data. The traditional login method is to enter the password directly on the touch screen or log in with a USB key. These two methods are prone to password leakage or key copying, which poses a serious challenge to the password security management of industrial equipment. Summary of the invention
[0003] The main purpose of the present invention is to provide an industrial equipment authentication login method and system to solve the technical problem that the password of industrial equipment is easily leaked or the key is copied.
[0004] To achieve the above-mentioned purpose, the first aspect of the present invention provides an industrial equipment authentication login method, which is applied to a control device. The industrial equipment authentication login method comprises the following steps:
[0005] Collect user biometrics of the operating user.
[0006] Match user biometrics with pre-stored biometrics.
[0007] When the user's biometric features match the pre-stored biometric features, the entered password within the first preset time period is accepted and matched with the login password.
[0008] When the entered password matches the login password, login permission is released.
[0009] Update your login password and save it.
[0010] Upload the updated login password to the server.
[0011] According to an embodiment of the present application, the biometric feature is at least one of a fingerprint feature, a facial feature, and an iris feature.
[0012] According to the implementation mode of the present application, it also includes:
[0013] The user's biometric features are stored and recorded as user information.
[0014] When the user biometric features collected within the first preset number of times do not match the pre-stored biometric features, the user information corresponding to the user biometric features collected within the first preset number of times is grouped into the same user information and marked as the first sensitive information.
[0015] According to the implementation mode of the present application, it also includes:
[0016] When the input passwords accepted within the second preset number of times do not match the login password, the user information corresponding to the user biometric features collected within the second preset time period will be marked as second sensitive information, and the second preset time period is greater than the first preset time period.
[0017] According to the implementation mode of the present application, it also includes:
[0018] The first sensitive information and the second sensitive information are uploaded to the server.
[0019] According to the implementation mode of the present application, it also includes:
[0020] When the input password accepted within the second preset number of times matches the login password, the user biometric features and user information collected within the second preset time period are deleted.
[0021] According to the implementation mode of the present application, it also includes:
[0022] When receiving the damage signal, the login password is updated and the updated login password is uploaded to the server. The damage signal is sent by the sensor, and the sensing part of the sensor is connected to the control device.
[0023] According to the implementation mode of the present application, it also includes:
[0024] When a damage signal is received, an alarm signal is generated and uploaded to the transport server.
[0025] A second aspect of the present invention provides an industrial equipment authentication login method, which is applied to a client and includes the following steps:
[0026] The identity information is accepted, and when the identity information matches the preset administrator information, the password information transmitted by the server is displayed. The password information is the updated login password uploaded by the control device to the server for storage.
[0027] A third aspect of the present invention provides an industrial equipment authentication login device, comprising:
[0028] The biometrics collection module is used to collect the user's biometrics of the operating user.
[0029] The biometric matching module is used to match the user's biometrics with pre-stored biometrics.
[0030] The password matching module is used to accept the input password within a first preset time period and match it with the login password when the user's biometric characteristics match the pre-stored biometric characteristics.
[0031] The login opening module is used to open the login permission when the input password matches the login password.
[0032] The password update module is used to update the login password and store it.
[0033] The password transmission module is used to upload the updated login password to the server.
[0034] In the above industrial equipment authentication login method, the user biometrics of the operating user are first verified, and then the input password is verified. Moreover, the login password will be updated after each login. Even if the original password is leaked during the login process, the industrial equipment cannot be logged in because the original password has expired. In this way, the security of the password is improved and it is not easy to be copied. The above industrial equipment authentication login method, through multiple verifications and strict password protection, can make the administrator's device system not easy to be invaded, the security is improved, and then the security of industrial equipment is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying creative work.
[0036] Figure 1 It is a flowchart of an industrial equipment authentication login method according to an embodiment of the present application;
[0037] Figure 2 It is a schematic diagram of the module structure of an industrial equipment authentication and login device according to one embodiment of the present application.
[0038] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with the implementation methods and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0039] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0040] It should be noted that all directional indications (such as up, down, etc.) in the embodiments of the present invention are only used to explain the relative position relationship, movement status, etc. between the components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.
[0041] In addition, in the present invention, the descriptions such as "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" or "second" may explicitly or implicitly include at least one of the features.
[0042] Furthermore, the technical solutions between the various embodiments of the present invention may be combined with each other, but this must be based on the fact that they can be implemented by ordinary technicians in the field. When the combination of technical solutions is mutually contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by the present invention.
[0043] The industrial equipment authentication login system includes control devices (such as programmable logic controllers (PLCs)), servers, and clients (such as PCs and mobile phones). For ease of description, the following control device is described using a programmable logic controller as an example.
[0044] Industrial equipment includes display devices (such as display screens) and input devices (such as physical input devices, buttons, keyboard lights, etc., and virtual input devices, electronic keyboards in display screens, etc.). In some embodiments, the display device and the input device can also be combined into one, such as a touch screen. For ease of description, an industrial touch screen is used as an example for description.
[0045] The programmable logic controller is set in the industrial equipment and can be connected to the industrial touch screen of the industrial equipment. For example, it is connected through an industrial switch to transmit data in both directions. Exemplarily, the programmable logic controller receives data input from the industrial touch screen, such as the input password and control instructions input by the operating user. Another exemplary embodiment is that the programmable logic controller transmits the feedback information of the password matching result and the control instruction to the industrial touch screen for display.
[0046] The programmable logic controller can also communicate with the server, for example, by sending information through a 4G module or a 5G module communication connection, such as sending password information, sensitive information, etc. to the server.
[0047] Similarly, the server and the client are also connected by communication, such as sending information through the 4G module and 5G module communication connection, such as receiving password information from the programmable logic controller and sensitive information to the client. The client displays the above information or further processes the above information.
[0048] The following describes the industrial equipment authentication login method from different perspectives.
[0049] First, let's describe the authentication and login method for industrial equipment. Figure 1 , the industrial equipment authentication login method comprises the following steps:
[0050] S101: Collect user biometrics of the operating user.
[0051] Biometric features include at least one of fingerprint features, facial features, and iris features. One of the biometric features, such as fingerprint features, can be collected; or several biometric features, such as fingerprint features and facial features, can be collected at the same time. Industrial equipment can have modules for collecting corresponding biometric features, such as a facial recognition module for collecting facial features of the operating user, a fingerprint recognition module for collecting fingerprint features of the operating user, and an iris collection module for collecting facial features of the operating user. The following takes the collection of fingerprint features of the operating user as an example for explanation. The fingerprint recognition module EEPROM collects the fingerprint information of the operating user.
[0052] S102: Match the user's biometric features with pre-stored biometric features.
[0053] The pre-stored biometric feature may be a fingerprint feature of an administrator stored in advance in the fingerprint recognition module EEPROM. There may be one or more administrators, and the fingerprint recognition module EEPROM may store at least one fingerprint feature of each administrator.
[0054] The fingerprint recognition module EEPROM stores the administrator's fingerprint features. The fingerprint recognition module EEPROM communicates with the fingerprint module processor through IIC and SPI. The fingerprint module processor matches the identified fingerprint with the fingerprint information stored in the EEPROM one by one. If no match is found, an error is displayed. The subsequent steps S103 to S106 are terminated.
[0055] In some embodiments, in order to reduce the impact of fingerprint mismatch caused by operational errors, such as recording the wrong fingerprint, the finger not aligning with the center of the fingerprint collection module during recording, or the finger being dirty, the fingerprint recognition and matching process can be performed for a first preset number of times (such as 3 times). That is, steps S101 and S102 are performed for the first preset number of times. After the fingerprint recognition and matching process is successfully matched within the first preset number of times, the subsequent steps S103 to S106 are continued.
[0056] S103: When the user's biometric features match the pre-stored biometric features, the entered password within the first preset time period is accepted and matched with the login password.
[0057] When the collected fingerprint features match one of the fingerprint features, the fingerprint relay module can output a high level. After receiving the high level signal, the industrial programmable logic controller opens the touch screen random password authentication module through the TCP / IP communication protocol.
[0058] The touch screen random password authentication module is turned on within the first preset time. The first preset time can be understood as the time required for the user to enter the password once. The time should be convenient for the user to operate, while not giving the operator too much operation time to prevent the operator from obtaining the login password through abnormal means. For example, the first preset time is 3 seconds, 5 seconds, etc.
[0059] The login password can be information stored in advance in the EEPROM, such as a 6-digit password. The industrial touch screen receives the operator's input information and obtains the input password. Then the input password is compared with the login password, such as converting the 6-digit password text entered on the touch screen and the 6-digit password of the login password into numeric data, and then judging whether the two values are equal. If they are equal, it is judged that the two match.
[0060] S104: When the input password matches the login password, the login permission is opened.
[0061] When the input password matches the login password, if it can be basically determined that the operator is an authorized user, such as an authorized engineer of an industrial equipment manufacturer, the login permission can be opened. In this way, the authorized user successfully logs into the administrator device system of the industrial equipment. Of course, in this step, the message notification module can also be called to prompt the comparison result on the industrial touch screen.
[0062] S105: Update the login password and save it.
[0063] When the entered password is correct, the login password can be updated to invalidate the original login password. In this way, even if the login password is recorded by other users or recording devices (such as mobile phone cameras) when the authorized user enters the login password normally, the password obtained is also an invalid password.
[0064] For example, a random password generation module is called (this module is based on the random system time) to generate a new random password and replace the login password previously stored in the EEPROM. After the replacement is successful, the 6-digit password data is written to the industrial programmable logic controller through the TCP / IP communication protocol. The industrial programmable logic controller receives the password data and stores it in the power-off retention area to prevent the password from being lost when the power is off.
[0065] It is understandable that the order of the two steps of updating the login password and storing it and opening the login permission can be reversed or performed simultaneously.
[0066] S106: Upload the updated login password to the server.
[0067] For example, the 4G module reads the corresponding random password storage block through the TCP / IP communication protocol when the random password of the industrial programmable logic controller changes, and uploads it to the server through the 4G or wired network. The server stores the latest password.
[0068] In the above industrial equipment authentication login method, the user biometrics of the operating user are first verified, and then the input password is verified. Moreover, the login password will be updated after each login. Even if the original password is leaked during the login process, the industrial equipment cannot be logged in because the original password has expired. In this way, the security of the password is improved and it is not easy to be copied. The above industrial equipment authentication login method, through multiple verifications and strict password protection, can make the administrator's device system not easy to be invaded, the security is improved, and then the security of industrial equipment is improved.
[0069] In some embodiments, the industrial device authentication login method further includes:
[0070] S107: Store the user's biometric features and record them as user information.
[0071] Step S107 may be between steps S101 and S102. The biometric features of the operating user are recorded as user information, so as to obtain the user information of the user who attempts to log in to the administrator device system in the industrial device, so that when the administrator device system is illegally invaded, suspicious user information can be screened from the user information.
[0072] S108: When the user biometric features collected within the first preset number of times do not match the pre-stored biometric features, the user information corresponding to the user biometric features collected within the first preset number of times is grouped into the same user information and marked as the first sensitive information.
[0073] For example, when the fingerprint features collected three times do not match the pre-stored fingerprint features, the user biometric features collected three times can be collected and marked as the same user. In this case, it can be determined that the user (for the sake of convenience, referred to as the first user) is an unauthorized user and may have attempted to log in to the administrator device system multiple times. Therefore, the user information corresponding to the first user can be marked as the first sensitive information, and all user biometric features collected from the first user can be collected. In this way, more complete information about the first user can be obtained later by splicing, so that when the administrator device system is illegally invaded later, the first user can be screened as the focus.
[0074] In some embodiments, the industrial device authentication login method further includes:
[0075] When the input passwords accepted within the second preset number of times do not match the login password, the user information corresponding to the user biometric features collected within the second preset time period will be marked as second sensitive information, and the second preset time period is greater than the first preset time period.
[0076] For example, when the input passwords received three times do not match the pre-stored login passwords, in this case, it can be determined that the user (for the sake of convenience, referred to as the second user) is an unauthorized user and may have attempted to log in to the administrator device system multiple times. Therefore, the user biometrics collected within a relatively close time before the second user enters the password are identified as the user biometrics of the second user, and the corresponding user information is the second sensitive information. Since the input password is collected within the first preset time length, and the user biometrics are collected before the password is entered, the second preset time length must be greater than the first preset time length.
[0077] The specific length of the second preset time can be reasonably set according to the length of the first preset time and the number of the first preset times, so as to ensure that the second preset time can determine the user's biometric characteristics before the password is input, and at the same time, the second preset time should not be too long, otherwise the biometric characteristics of a non-second user (e.g., the administrator device system that normally logs in before the second user) will also be identified as the user biometric characteristics of the second user, and the user information of the user will also be marked as the second sensitive information. In this way, the accuracy of the second sensitive information is reduced.
[0078] Similarly, the second sensitive information helps to identify key screening targets when the administrator's device system is illegally invaded later.
[0079] In some embodiments, the industrial device authentication login method further includes:
[0080] The first sensitive information and the second sensitive information are uploaded to the server.
[0081] In this way, the operation administrator can receive the first sensitive information and the second sensitive information from the server in time and maintain the security of the industrial equipment in time. At the same time, the data of the first sensitive information and the second sensitive information are also more secure to prevent local destruction or damage to the data.
[0082] In some embodiments, the industrial device authentication login method further includes:
[0083] When the input password accepted within the second preset number of times matches the login password, the user biometric features and user information collected within the second preset time period are deleted.
[0084] When the input password received within the second preset number of times matches the login password, especially if the user has passed the user biometric verification, in this case, it can be determined that the user (for ease of explanation, referred to as the third user) exists as an authorized user, and therefore, the user biometrics and user information of the third user can be deleted. In this way, the amount of data stored in the programmable logic controller is reduced.
[0085] In some embodiments, the industrial device authentication login method further includes:
[0086] The user biometrics and user information are uploaded to the server within a third preset time period, and then the user biometrics and user information are deleted.
[0087] In this embodiment, within the third preset time period (such as 7 days), that is, every seven days, the user biometrics and user information are uploaded to the server, and then the local data is deleted. In this way, the data is cleaned up regularly, reducing the amount of data stored in the programmable logic controller.
[0088] In some embodiments, the industrial equipment authentication login method further includes: when receiving a damage signal, updating the login password and uploading the updated login password to the server. The damage signal is sent by a sensor, and the sensing part of the sensor is connected to the control device.
[0089] A sensor (such as a vibration sensor) is set in the industrial equipment, for example, connected to a programmable logic controller. When the sensor senses the vibration of the programmable logic controller, it can be determined that the programmable logic controller is at risk of being damaged by human beings to obtain the password. At this time, the sensor sends a signal and transmits it to the programmable logic controller. The programmable logic controller updates the login password and uploads the updated login password to the server. The programmable logic controller does not store the updated login password, or deletes the login password of the programmable logic controller after uploading the updated login password to the server.
[0090] In some embodiments, the industrial equipment authentication login method further includes: when a damage signal is received, generating an alarm signal and uploading it to a transport server.
[0091] In this way, the operation administrator can receive alarm signals from the server in a timely manner and maintain the safety of industrial equipment in a timely manner.
[0092] The industrial equipment authentication login method is now described from the client side. A second aspect of the present invention provides an industrial equipment authentication login method, which is applied to the client and includes the following steps:
[0093] The identity information is accepted, and when the identity information matches the preset administrator information, the password information transmitted by the server is displayed. The password information is the updated login password uploaded by the control device to the server for storage.
[0094] Administrators with advanced privilege accounts log in through the mobile app or computer web page, and obtain the random login password of the industrial touch screen stored on the server after verification through 4G, 5G or wired network.
[0095] Based on the same inventive concept, the embodiment of the present application also provides a device for implementing the above industrial equipment authentication login. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more industrial equipment authentication login device embodiments provided below can refer to the limitations of the industrial equipment authentication login method above, and will not be repeated here.
[0096] The present invention also provides an industrial equipment authentication login device, see Figure 2 ,include:
[0097] The biometrics collection module 100 is used to collect the biometrics of the operating user.
[0098] The biometric matching module 200 is used to match the user's biometrics with pre-stored biometrics.
[0099] The password matching module 300 is used to accept the input password within a first preset time period and match it with the login password when the user's biometric characteristics match the pre-stored biometric characteristics.
[0100] The login opening module 400 is used to open the login permission when the input password matches the login password.
[0101] The password update module 500 is used to update the login password and store it.
[0102] The password transmission module 600 is used to upload the updated login password to the server.
[0103] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0104] The above technical solutions of the present invention are only preferred embodiments of the present invention, and the patent scope of the present invention is not limited thereto. All equivalent structural changes made by using the contents of the present invention specification and drawings under the technical concept of the present invention, or directly / indirectly applied in other related technical fields are included in the patent protection scope of the present invention.
Claims
1. An industrial equipment authentication login method, applied to control equipment; characterized in that: The following steps are involved: Collect user biometrics of the operating user; matching the user's biometric features with pre-stored biometric features; When the user biometric feature matches the pre-stored biometric feature, accepting the input password within a first preset time period and matching it with the login password; When the input password matches the login password, the login permission is opened; Update the login password and store it; Upload the updated login password to the server; storing the user's biometric features and recording them as user information; When the user biometric features collected within the first preset number of times do not match the pre-stored biometric features, the user information corresponding to the user biometric features collected within the first preset number of times are grouped into the same user information and marked as the first sensitive information; the collected user biometric features are spliced to obtain a more complete user biometric feature; when the industrial equipment is illegally invaded, the corresponding first user is screened by the first sensitive information; The biometric feature is at least one of a fingerprint feature, a facial feature, and an iris feature; Also includes: When the input passwords received within a second preset number of times do not match the login password, the user information corresponding to the user biometric features collected within a second preset time period is marked as second sensitive information, and the second preset time period is greater than the first preset time period; Also includes: Uploading the first sensitive information and the second sensitive information to the server; Also includes: When the input password accepted within the second preset number of times matches the login password, deleting the user biometric features and user information collected within the second preset time period; Also includes: When receiving a damage signal, the login password is updated and the updated login password is uploaded to the server; the damage signal is sent by a sensor, and the sensing part of the sensor is connected to the control device; Also includes: When a damage signal is received, an alarm signal is generated and uploaded to the transport server.
2. An industrial equipment authentication login device, characterized in that: include: A biometrics collection module, used to collect user biometrics of the operating user; A biometric matching module, used to match the user's biometrics with pre-stored biometrics; A password matching module, configured to accept an input password within a first preset time period and match it with a login password when the user biometric feature matches the pre-stored biometric feature; A login opening module, used to open the login permission when the input password matches the login password; A password update module, used to update the login password and store it; Password transmission module, used to upload the updated login password to the server; storing the user's biometric features and recording them as user information; When the user biometric features collected within a first preset number of times do not match the pre-stored biometric features, the user information corresponding to the user biometric features collected within the first preset number of times is grouped into the same user information and marked as first sensitive information; when the industrial equipment is illegally invaded, the corresponding first user is screened through the first sensitive information; The biometric feature is at least one of a fingerprint feature, a facial feature, and an iris feature; Also includes: When the input passwords received within a second preset number of times do not match the login password, the user information corresponding to the user biometric features collected within a second preset time period is marked as second sensitive information, and the second preset time period is greater than the first preset time period; Also includes: Uploading the first sensitive information and the second sensitive information to the server; Also includes: When the input password accepted within the second preset number of times matches the login password, deleting the user biometric features and user information collected within the second preset time period; Also includes: When receiving a damage signal, the login password is updated and the updated login password is uploaded to the server; the damage signal is sent by a sensor, and the sensing part of the sensor is connected to the industrial equipment authentication login device; Also includes: When a damage signal is received, an alarm signal is generated and uploaded to the transport server.
Citation Information
Patent Citations
Method and device for user login authentication in cloud data centre
CN104125225A
Input method and device of login information and terminal equipment
CN105138887A
Anti-theft system and method for portable equipment
CN111046359A
Terminal equipment, control method thereof and computer readable storage medium
CN112528256A
Password updating method and device of electronic equipment, equipment and storage medium
CN112560015A