Intelligent key device usage authorization method and system
By installing the smart key device in the management device and having it work in conjunction with the authorization device, and using a controllable on/off switch to control the connection path, the security risk of the smart key device being illegally removed is solved, and the security of legal use and the reliability of remote authorization are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENDYRON CORP
- Filing Date
- 2022-09-22
- Publication Date
- 2026-05-29
AI Technical Summary
Existing smart key devices may be illegally retrieved and used without authorization, posing a security risk.
The smart key device is installed in the management device and cannot be removed without authorization. Through the coordinated work of the management device and the authorization device, the authorized connection and disconnection of the communication channel with the operating host are controlled by a controllable on/off switch to ensure legitimate use.
It improves the security of smart key devices, prevents unauthorized use, and ensures the legality and security of remote authorization.
Smart Images

Figure CN115643050B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of electronic technology, and in particular to a method and system for authorizing the use of smart key devices. Background Technology
[0002] With the rapid development of the internet bringing immense convenience, people are increasingly reliant on it for various activities. For example, file transfer and online banking transactions have gradually become indispensable parts of people's lives and work. However, since the internet is ultimately a virtual environment with many insecurity factors, and data exchange is inevitable in this environment, especially activities like online banking and the transmission of confidential documents, high demands are placed on network security. Therefore, people have begun to vigorously develop network information security technologies.
[0003] Digital signature technology is a network information security technology designed to ensure that user data is not maliciously modified during network transmission. Essentially, digital signature technology is a method of identity authentication used to securely transmit commands and files. It processes the user data to be transmitted using a one-way function, producing an alphanumeric string used to authenticate the data's origin and verify its integrity. Typically, digital signatures use hash algorithms such as MD5 and SHA-1 to calculate a digest value for the transmitted data, then encrypt this digest value using an encryption algorithm before transmission. Currently, public-key cryptography is widely used in digital signatures, such as PKCS (Public Key Cryptography Standards) from RSA Data Security, Digital Signature Algorithm, x.509, and PGP (Pretty Good Privacy). The widespread adoption of public-key cryptography began in 1994 with the publication of the Digital Signature Standard (DSS) by the American Society for Standards and Technology (AS / RS). Digital signatures on digital documents are similar to handwritten signatures on paper; they are unforgeable. The recipient can verify that the document indeed came from the signer and that it has not been modified, thus ensuring the authenticity and integrity of the information within the received document. A robust digital signature technology should meet the following three conditions: First, the signer cannot later deny their signature; second, no other person can forge the signature; and third, if the parties involved dispute the authenticity of the signature, they can verify its authenticity before an impartial arbitrator.
[0004] Digitally signing data can significantly increase its security. However, the development of hacking techniques remains a major concern for users. If a malicious attacker gains control of a user's computer, they can intercept data in the computer's memory, harming the interests of legitimate users. Therefore, portable, mobile smart key devices, also known as USB keys, have been developed. These are small hardware devices with microprocessors that connect to the host computer via a data communication interface. The processor within the device typically uses a secure chip, utilizing built-in security mechanisms to perform functions such as key generation, secure key storage, and pre-installed encryption algorithms. All key-related calculations are performed within the authentication device, resulting in high security. However, this approach still presents security vulnerabilities. Unauthorized use of the USB key can occur without the user's knowledge, posing a significant security threat. Summary of the Invention
[0005] The present invention aims to solve the above-mentioned problems.
[0006] The main objective of this invention is to provide a method for authorizing the use of smart key devices;
[0007] Another object of the present invention is to provide a smart key device use authorization system.
[0008] To achieve the above objectives, the technical solution of the present invention is specifically implemented as follows:
[0009] This invention provides a method for authorizing the use of a smart key device, comprising: a control module of a management device sending an operation request to an authorization device via a remote communication module of the management device, the operation request including information to be authorized; wherein the management device includes: a controllable on / off switch, the control module, a first transmission interface, a second transmission interface, and the remote communication module; the first transmission interface is connected to the smart key device, the smart key device being disposed in the management device and not to be removed without authorization; the second transmission interface is connected to an operating host; the controllable on / off switch is in a default state of off, and the communication path between the operating host and the smart key device is disconnected; the authorization device receives the operation request and displays the information to be authorized; the authorization device obtains a confirmation instruction obtained from confirming the information to be authorized and sends the authorization instruction to the control module via the remote communication module; the control module receives the authorization instruction and controls the controllable on / off switch to close or open, connecting the communication path between the operating host and the smart key device.
[0010] Furthermore, before the control module of the management device sends the operation request to the authorized device through the remote communication module of the management device, the method further includes: the control module obtaining the operation request from the operation host through the second transmission interface; or the control module receiving the operation request generated by the user's operation on the management device.
[0011] In addition, before the control module receives the operation request generated by the user's operation on the management device, the method further includes: the control module obtaining the user's user information; the information to be authorized includes: the user information.
[0012] In addition, after the control module receives the authorization instruction, the method further includes: recording the time of receiving the authorization instruction and the user information.
[0013] In addition, the method also includes: the control module receiving a shutdown command sent by the authorized device, controlling the controllable on / off switch to disconnect, thereby disconnecting the communication path between the operating host and the smart key device.
[0014] In addition, after the control module receives the shutdown command, the method further includes: recording the time of receiving the shutdown command.
[0015] In addition, the authorization instruction includes: authorizing a connection time; after the authorized connection time expires, the control module controls the controllable on / off switch to disconnect, thereby disconnecting the communication path between the operating host and the smart key device.
[0016] In addition, the method also includes: the control module determines that the management device has been illegally opened and performs a self-destruct operation.
[0017] In another aspect, the present invention provides a smart key device authorization system, comprising: an authorization device, a management device, and a smart key device; the management device includes: a controllable on / off switch, a control module, a first transmission interface, a second transmission interface, and a remote communication module; the first transmission interface is connected to the smart key device, which is disposed in the management device and cannot be removed without authorization; the second transmission interface is connected to an operating host; the controllable on / off switch is in an off state by default, and the communication path between the operating host and the smart key device is disconnected; the control module is used to send an operation request to the authorization device through the remote communication module, the operation request including pending authorization information; the authorization device is used to receive the operation request, display the pending authorization information, obtain a confirmation instruction obtained from confirming the pending authorization information, and send the authorization instruction to the control module through the remote communication module; the control module is also used to receive the authorization instruction, control the controllable on / off switch to close, and connect the communication path between the operating host and the smart key device.
[0018] In addition, the control module is also used to receive a shutdown command sent by the authorization device, control the controllable on / off switch to open, and disconnect the communication path between the operating host and the smart key device; or, if the authorization command includes an authorization connection time, control the controllable on / off switch to open after the authorization connection time expires, and disconnect the communication path between the operating host and the smart key device.
[0019] As can be seen from the technical solution provided by the present invention above, the present invention provides a method and system for authorizing the use of smart key devices. Since the smart key device is set in the management device and cannot be removed without authorization, the unauthorized removal and unauthorized use of the smart key device are prevented, thus improving the security of using the smart key device. At the same time, the authorization of the management device can be achieved through the authorization device to connect the path between the smart key device and the operating host, and complete the corresponding operation, ensuring the remote authorized use of the smart key device. If no authorization is given by an authorized user, the unauthorized use of the smart key device is also prevented. Attached Figure Description
[0020] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a schematic diagram of the structure of the authorization system used by the smart key device provided in an embodiment of the present invention;
[0022] Figure 2 A flowchart illustrating the authorization method for using a smart key device provided in an embodiment of the present invention. Detailed Implementation
[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of the present invention.
[0024] Figure 1 This diagram illustrates the structure of the authorization system used by the smart key device according to an embodiment of the present invention. (See also...) Figure 1 The smart key device provided in this embodiment of the invention uses an authorization system, including: an authorization device, a management device, and a smart key device;
[0025] The management equipment includes: a controllable on / off switch, a control module, a first transmission interface, a second transmission interface, and a remote communication module;
[0026] The first transmission interface is connected to the smart key device, which is located in the management device and cannot be removed without authorization.
[0027] The second transmission interface is connected to the operating host;
[0028] The controllable on / off switch is in the off state by default, which disconnects the communication path between the operating host and the smart key device;
[0029] The control module is used to send operation requests to authorized devices via the remote communication module. The operation requests include information to be authorized.
[0030] The authorization device is used to receive operation requests, display information to be authorized, obtain confirmation instructions from the information to be authorized, and send the authorization instructions to the control module through the remote communication module.
[0031] The control module is also used to receive authorization instructions, control the on / off state of controllable devices, and connect the communication path between the operating host and the smart key device.
[0032] Specifically, the controllable on / off switch can receive commands from the control module to connect or disconnect the link. In practice, it can be implemented using optocoupler switches or mechanical switches, etc.
[0033] The first transmission interface is the interface for connecting to the smart key device, which is typically a USB female connector.
[0034] The second transmission interface is the interface for connecting to the host computer (such as a PC), and it can generally be a USB male connector.
[0035] The remote communication module can communicate remotely with authorized devices, and in specific implementations, it can be 4G, 5G, WIFI, etc.
[0036] The smart key device is housed within the management device and cannot be removed without authorization. In practice, the management device can be a locked box. Once the smart key device is inserted into its designated location, the lock engages, preventing unauthorized removal. This lock can be mechanical or electronic. Only users with a key, who know the electronic lock's password, or who can remotely control the electronic lock can legally remove it. Alternatively, the management device can incorporate a locking mechanism. Once the smart key device is inserted, the mechanism holds it in place, preventing removal. Only authorized users can unlock the mechanism to legally retrieve the smart key device.
[0037] As an optional implementation of this invention, the control module is further configured to determine if the management device has been illegally opened and execute a self-destruct operation. If the management device determines that it has been illegally clocked in, it can send a self-destruct command to the smart key device, instructing the smart key device to delete the corresponding key and perform other self-destruct operations, thereby preventing the smart key device from being illegally retrieved and used without authorization.
[0038] The controllable on / off switch is in the off state by default, meaning that the host computer and the smart key device cannot communicate, preventing unauthorized users from directly using the smart key device. When normal use is required, after the control module obtains authorization, the controllable on / off switch is controlled by the control module to close, connecting the communication path between the host computer and the smart key device, so that the smart key device can communicate normally with the host computer to complete the required operation.
[0039] The authorized device can receive operation requests from the management device. These requests may include user information, such as the user's ID. Upon receiving the request, the authorized device displays this user information so the authorized user can view it and determine whether to grant authorization. If authorization is granted, the authorized user receives confirmation (e.g., pressing an confirmation button) and generates an authorization command, which is then sent to the management device via the remote communication module. To ensure data transmission is not tampered with, data transmitted between the authorized and management devices can be encrypted.
[0040] As an optional implementation of this invention, before the control module of the management device sends the operation request to the authorization device through the remote communication module of the management device, the authorization method for the smart key device provided in this invention further includes: the control module obtaining the operation request from the operation host through a second transmission interface; or the control module receiving the operation request generated by the user's operation on the management device. The control module can obtain the operation request either by having the user directly operate buttons on the management device or by having the user input relevant information on the operation host.
[0041] As an optional implementation of this invention, the control module is further configured to receive a shutdown command sent by the authorization device, control the controllable on / off switch to disconnect, and disconnect the communication path between the operating host and the smart key device; or, if the authorization command includes an authorization connection time, control the controllable on / off switch to disconnect after the authorization connection time expires, disconnecting the communication path between the operating host and the smart key device. Specifically, after the authorization operation is completed, the authorized user can control the controllable on / off switch of the management device to disconnect, preventing subsequent unauthorized use; of course, the management device itself can also disconnect the controllable on / off switch after the authorization connection time expires, preventing subsequent unauthorized use.
[0042] As an optional embodiment of the present invention, the control module is further configured to record the time of receipt of the authorization instruction and user information after receiving the authorization instruction. As another optional embodiment of the present invention, if a shutdown instruction is received, the time of receipt of the shutdown instruction can be recorded. This allows for recording of each authorized use for subsequent auditing.
[0043] Therefore, the smart key device authorization system provided by this invention improves the security of using the smart key device because the smart key device is located in the management device and cannot be removed without authorization. This prevents the smart key device from being illegally removed and used without authorization. At the same time, the authorization device can authorize the management device to connect the smart key device and the operating host to complete the corresponding operation, ensuring the remote authorized use of the smart key device. If no authorization is given by an authorized user, the unauthorized use of the smart key device is also prevented.
[0044] Figure 2 This document illustrates a flowchart of a smart key device authorization method provided in an embodiment of the present invention. This method is applied to the aforementioned smart key device authorization system. The following is only a brief description of the flowchart of this smart key device authorization method; for other matters not covered herein, please refer to the relevant description of the aforementioned smart key device authorization system, which will not be elaborated upon here. See [link to relevant documentation]. Figure 2 The smart key device using the authorization method provided in this embodiment of the invention includes:
[0045] S1, the control module of the management device sends an operation request to the authorization device through the remote communication module of the management device. The operation request includes authorization information. The management device includes: a controllable on / off switch, a control module, a first transmission interface, a second transmission interface, and a remote communication module. The first transmission interface is connected to the smart key device, which is located in the management device and cannot be removed without authorization. The second transmission interface is connected to the operating host. The controllable on / off switch is in the off state by default, and the communication path between the operating host and the smart key device is disconnected.
[0046] S2, the authorized device receives the operation request and displays the information to be authorized;
[0047] S3, the authorized device obtains the confirmation instruction from the confirmation of the information to be authorized, and sends the authorization instruction to the control module through the remote communication module;
[0048] S4, the control module receives the authorization command, controls the controllable on / off switch, and connects the communication path between the operating host and the smart key device.
[0049] As an optional implementation of this invention, before the control module of the management device sends the operation request to the authorization device through the remote communication module of the management device, the authorization method for the smart key device provided in this invention further includes: the control module obtaining the operation request from the operation host through the second transmission interface; or the control module receiving the operation request generated by the user's operation on the management device.
[0050] As an optional implementation of this invention, before the control module receives the operation request generated by the user's operation on the management device, the smart key device authorization method provided in this embodiment further includes: the control module obtaining the user's user information; the information to be authorized includes: user information. Therefore, the authorized user can view the relevant information of the user using the authorization, thereby determining whether to grant authorization.
[0051] As an optional implementation of this invention, after the control module receives the authorization instruction, the smart key device authorization method provided in this embodiment further includes: recording the time of receiving the authorization instruction and user information. This allows for recording each authorized use for subsequent auditing.
[0052] As an optional implementation of this invention, the smart key device authorization method provided in this embodiment further includes: a control module receiving a shutdown command sent by the authorization device, controlling the controllable on / off switch to disconnect, and disconnecting the communication path between the operating host and the smart key device. Specifically, after the authorization operation is completed, the authorized user can control the controllable on / off switch of the management device to disconnect, preventing subsequent unauthorized use.
[0053] As an optional implementation of this invention, after the control module receives the shutdown command, the smart key device authorization method provided in this embodiment further includes: recording the time of receiving the shutdown command. This allows for recording each authorized use for subsequent auditing.
[0054] As an optional implementation of this invention, the authorization instruction includes: authorizing a connection time; after the authorized connection time expires, the control module controls the controllable on / off switch to disconnect, thus breaking the communication path between the operating host and the smart key device. Specifically, after the authorized connection time expires, the management device itself can disconnect the controllable on / off switch to prevent subsequent unauthorized use.
[0055] As an optional implementation of this invention, the smart key device authorization method provided in this embodiment further includes: a control module determining that the management device has been illegally opened and performing a self-destruct operation. If the management device determines that it has been illegally accessed, it can send a self-destruct command to the smart key device, instructing the smart key device to delete the corresponding key and perform other self-destruct operations, thereby preventing the smart key device from being illegally retrieved and used without authorization.
[0056] Therefore, the smart key device authorization method provided in this embodiment of the invention improves the security of using the smart key device because the smart key device is located in the management device and cannot be removed without authorization, thus preventing unauthorized removal and unauthorized use of the smart key device. At the same time, authorization can be granted to the management device through the authorization device to connect the smart key device and the operating host, and complete the corresponding operation, ensuring the remote authorized use of the smart key device. If no authorization is granted by an authorized user, unauthorized use of the smart key device is also prevented.
[0057] Although embodiments of the present invention have been shown and described above, it is to be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention without departing from the principles and spirit of the invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. An authorization method for using a smart key device, characterized in that, include: The control module of the management device sends an operation request to the authorization device through the remote communication module of the management device. The operation request includes authorization information. The management device includes: a controllable on / off switch, the control module, a first transmission interface, a second transmission interface, and the remote communication module. The first transmission interface is connected to the smart key device, which is located within the management device and cannot be removed without authorization. The second transmission interface is connected to the operating host. The controllable on / off switch is in an off state by default, disconnecting the communication path between the operating host and the smart key device. The authorized device receives the operation request and displays the information to be authorized; The authorization device obtains a confirmation instruction from the confirmation of the information to be authorized, and sends the authorization instruction to the control module through the remote communication module; The control module receives the authorization command and controls the controllable on / off switch to connect the communication path between the operating host and the smart key device.
2. The method according to claim 1, characterized in that, Before the control module of the management device sends the operation request to the authorized device through the remote communication module of the management device, it also includes: The control module obtains the operation request from the operating host through the second transmission interface; or The control module receives operation requests generated by the user's actions on the management device.
3. The method according to claim 2, characterized in that, Before the control module receives the operation request generated by the user's operation on the management device, the method further includes: the control module obtaining the user's user information; The information to be authorized includes: the user information.
4. The method according to claim 3, characterized in that, After receiving the authorization instruction, the control module further includes: Record the time of receiving the authorization instruction and the user information.
5. The method according to claim 1, characterized in that, Also includes: The control module receives a shutdown command sent by the authorized device and controls the controllable on / off switch to disconnect, thus breaking the communication path between the operating host and the smart key device.
6. The method according to claim 5, characterized in that, After receiving the shutdown command, the control module further includes: Record the time when the shutdown command is received.
7. The method according to claim 1, characterized in that, The authorization instruction includes: authorization of connection time; After the authorized connection time expires, the control module controls the controllable on / off switch to disconnect, thus breaking the communication path between the operating host and the smart key device.
8. The method according to claim 1, characterized in that, Also includes: The control module determines that the management device has been illegally opened and executes a self-destruct operation.
9. A smart key device authorization system, characterized in that, include: Authorized devices, management devices, and smart key devices; The management device includes: a controllable on / off switch, a control module, a first transmission interface, a second transmission interface, and a remote communication module; The first transmission interface is connected to the smart key device, which is located in the management device and cannot be removed without authorization; The second transmission interface is connected to the operating host; The controllable on / off switch is in the off state by default, and the communication path between the operating host and the smart key device is disconnected. The control module is used to send an operation request to the authorized device through the remote communication module, the operation request including authorization information; The authorization device is used to receive the operation request, display the information to be authorized, obtain a confirmation instruction obtained from confirming the information to be authorized, and send the authorization instruction to the control module through the remote communication module. The control module is also used to receive the authorization instruction, control the controllable on / off switch, and connect the communication path between the operating host and the smart key device.
10. The system according to claim 9, characterized in that, The control module is also configured to receive a shutdown command sent by the authorization device, control the controllable on / off switch to disconnect, and disconnect the communication path between the operating host and the smart key device; or, if the authorization command includes an authorization connection time, control the controllable on / off switch to disconnect after the authorization connection time expires, and disconnect the communication path between the operating host and the smart key device.