Authentication server, authentication system, and authentication method
Through the authentication server, accessing the memory of the control device and writing the authentication results, the network authentication problem of PLC without the authentication protocol is solved, and unified user management is realized and management costs are reduced.
Patent Information
- Application Number
- CN202411900056.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-18
- Filing Date
- 2024-12-23
- Publication Date
- 2025-07-18
AI Technical Summary
It is difficult for prior art to provide network authentication for control devices (such as PLCs) that do not implement authentication protocols, and local authentication requires additional management and equipment costs.
The authentication server accesses data to the memory in the control device, detects and reads the authentication input information, compares it with the account information in the user DB, generates the authentication result, and writes the result to the memory. The control device decides whether to perform the control process based on the authentication result.
It realizes network authentication for devices that do not implement authentication protocols, reduces the management cost of local authentication, and supports unified user management, which is suitable for authentication systems of multiple PLCs.
Smart Images

Figure CN120342647A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication server, an authentication system, and an authentication method. Background Art
[0002] In pharmaceutical manufacturing, there is an obligation to store manufacturing records in accordance with benchmarks such as GMP (Good Manufacturing Practice). The location of record storage has gradually changed from paper to electronic data. In the process of electronic data conversion, since it is easy to copy and tamper with, it is required to store the original data or the information on the operation process for ensuring the authenticity of the stored data.
[0003] Regarding the processing of electronic data of pharmaceutical manufacturing records, international regulations such as "CFR21 PART 11" of the US Food and Drug Administration (FDA) and "Annex 11" of PIC / S (Pharmaceutical Inspection Convention and Pharmaceutical Inspection Co-operation Scheme) have been formulated.
[0004] Pharmaceutical manufacturers in each country have an obligation to manage the electronic data of pharmaceutical manufacturing records in order to meet these requirements. In these regulations, regarding the processing of electronic data of pharmaceutical manufacturing records, it is recorded "when", "who", "what", "what was done", and "the reason".
[0005] In this way, a mechanism for authenticating users who log in to a device in advance in order to record who the user of the operating device is is becoming widespread.
[0006] For example, in Patent Document 1, it is described that an authentication server that receives the ID and password input to an authentication switch queries an LDAP (Lightweight Directory Access Protocol) server, that is, an external directory server, to inquire whether the authentication is successful. In this way, by using network authentication, it is not necessary for the logged-in device itself to have a function of determining whether the authentication is successful.
[0007] Prior Art Documents
[0008] Patent Documents
[0009] Patent Document 1: Japanese Patent Application Laid-Open No. 2021-96512 Summary of the Invention
[0010] Problems to be Solved by the Invention
[0011] The authentication switch of Patent Document 1 has a function of sending an authentication request to an authentication server based on an ID and a password input by a user. If it is a device such as this authentication switch that has a performance level capable of performing authentication protocol processing, network authentication can be smoothly performed.
[0012] On the other hand, at a manufacturing site such as for pharmaceuticals, there are a control device PLC (Programmable Logic Controller) operated by a user to control manufacturing equipment and a terminal for inputting operation commands to the PLC. Most of the devices at this manufacturing site are of the proprietary standards of the manufacturer that provides the PLC, and most do not implement a standard authentication protocol. Therefore, it is difficult to directly obtain data such as who is the person inputting the operation command to the terminal and whether the input operation command can be permitted, which requires authentication.
[0013] Alternatively, consider implementing local authentication that does not perform network authentication but has a function inside the PLC to determine whether the authentication of the input ID and password is successful. In this local authentication, it is true that the authentication protocol does not need to be implemented, but in addition to the device cost of the high-performance PLC, it is also necessary to individually prepare the setting data for local authentication corresponding to the number of PLCs, which consumes management costs.
[0014] The present invention is derived considering such a situation, and the main problem is to provide network authentication for devices that do not implement an authentication protocol.
[0015] Technical solution for solving the problem
[0016] To solve the above problems, the authentication server of the present invention has the following characteristics.
[0017] The present invention is an authentication server capable of accessing data in the memory of a control device, characterized in that:
[0018] By performing access monitoring of the memory, the authentication input information written in the memory is detected and read,
[0019] By comparing the authentication input information with the account information registered in the user DB, an authentication result for the authentication input information is generated,
[0020] By writing the authentication result for the authentication input information into the memory in the control device, it is notified to the control device whether control processing can be performed, where whether control processing can be performed depends on the authentication result.
[0021] Other characteristics are described later.
[0022] According to the present invention, network authentication can also be provided for devices that do not implement an authentication protocol. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 is a structural diagram of the authentication system of this embodiment.
[0024] Figure 2 is a hardware structural diagram of each device of the authentication system of this embodiment.
[0025] Figure 3 is a sequence diagram showing the processing of the authentication system of this embodiment.
[0026] Figure 4 is a login screen diagram of this embodiment.
[0027] Figure 5 is an explanatory diagram showing the data content of the memory of this embodiment.
[0028] Figure 6 is an explanatory diagram showing the details of each database used in the authentication system of this embodiment.
[0029] Figure 7 is a control screen diagram of the PLC of this embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0031] Figure 1 is a structural diagram of the authentication system 100.
[0032] The authentication system 100 is composed of a PLC 21, terminals 11, an authentication server 40, and a directory server 50 connected by a network. First, the device control function provided by the authentication system 100 will be described.
[0033] The PLCs 21-23 are connected to manufacturing equipment and the like, and are control devices that issue control commands to these manufacturing equipment. The PLCs 21-23 can be devices that do not support authentication protocols such as LDAP, or can support authentication protocols.
[0034] The terminals 11-13 are terminals attached to the PLCs 21-23 for operating the PLCs 21-23.
[0035] PLC21 and the terminal 11 are configured on the same workbench 31 and are directly connected to each other. Similarly, PLC22 and the terminal 12 are configured on the same workbench 32, and PLC23 and the terminal 13 are configured on the same workbench 33. In other words, the only PLC that the terminal 11 can operate is PLC21, and it cannot access other PLCs 22 and 23. The means to achieve the direct connection between PLC21 and the terminal 11 is described as follows, for example.
[0036] · PLC21 and the terminal 11 are configured as one device housed in the same housing. In this case, for example, the function of the terminal 11 is realized as a touch panel attached to PLC21.
[0037] · A wired communication line such as a USB cable is used to connect between PLC21 and the terminal 11, and PLC21 is configured not to be connected to other terminals 12 and 13 by a wired communication line (for example, the USB port is one).
[0038] · A wireless protocol with a dedicated specification of PLC21 is used to connect between PLC21 and the terminal 11, thereby enabling data communication. In addition, the wireless protocol with the dedicated specification of PLC21 is not installed in the terminals 12 and 13.
[0039] · The workbenches 31 - 33 are physically separated by an interval of 10 m, etc., and are configured such that the terminal 11 cannot operate the physically distant PLCs 22 and 23.
[0040] Next, the authentication function provided by the authentication system 100 will be described. The "authentication" of the authentication function here refers to the process of determining which user is allowed to use which PLCs 21 - 23. For example, in order to perform the following three operations, a total of three authentications are required.
[0041] · User U1 performs the first operation via PLC21. For this purpose, user U1 writes his / her own ID and PW into the memory 21m in PLC21 via the terminal 11, thereby generating an authentication request.
[0042] · User U1 performs the second operation via PLC22. For this purpose, user U1 writes his / her own ID and PW into the memory 22m in PLC22 via the terminal 12, thereby generating an authentication request.
[0043] · User U2 performs the third operation via PLC22. For this purpose, user U2 writes his / her own ID and PW into the memory 22m in PLC22 via the terminal 12, thereby generating an authentication request.
[0044] The authentication server 40 monitors the memory 21m in PLC21 (for details, see Figure 5) When accessing, upon detecting the combination (ID, PW) of the user ID and password written to the memory 21m, an authentication request is generated based on this combination (ID, PW), and the authentication request is sent to the directory server 50.
[0045] In addition, the directory server 50 is configured as an external authentication institution for an authentication server 40 such as an LDAP server. Additionally, it can also be configured as a single device in which the functions of the authentication server 40 and the directory server 50 are integrated in the same housing.
[0046] The authentication server 40 that can access the data in the memory 21m within the PLC 21 has the following functions.
[0047] · A function of detecting and reading the authentication input information written to the memory 21m through monitoring.
[0048] · A function of generating an authentication result for the authentication input information by comparing the authentication input information with the account information registered in the user DB 51.
[0049] · A function of notifying the PLC 21 whether control processing can be performed by writing the authentication result for the authentication input information to the memory 21m within the PLC 21, where whether control processing can be performed depends on (is based on) the authentication result.
[0050] The directory server 50 compares the user DB 51 (see details Figure 6 ) that manages the combination (ID, PW) of the user ID and password, etc. with the received authentication request, and allows the authentication request including the combination (ID, PW) registered in the user DB 51, and rejects the authentication request that does not include the combination (ID, PW).
[0051] The directory server 50 responds to the authentication server 40 in such a way that information indicating the authentication result (authentication allowed or authentication rejected) (hereinafter referred to as "Result") is written to the memory 21m within the PLC 21 that is the source of the authentication request. Thus, the PLC 21 can refer to the authentication result (Result) within its own memory 21m to decide whether to adopt the control command issued from the terminal 11 in the future.
[0052] Figure 2 It is the hardware structure diagram of each device (terminal 11, PLC 21, authentication server 40, directory server 50) of the authentication system 100.
[0053] Each device of the authentication system 100 is configured as a computer 900 having a CPU 901, a RAM 902, a ROM 903, an HDD 904, a communication I / F 905, an input / output I / F 906, and a medium I / F 907.
[0054] The communication I / F 905 is connected to an external communication device 915. The input / output I / F 906 is connected to an input / output device 916. The medium I / F 907 reads and writes data from and to a recording medium 917. Further, the CPU 901 controls each processing unit by executing a program (referred to as an application program or its abbreviation, an application) read into the RAM 902. Then, this program can be distributed via a communication line or distributed by being recorded in a recording medium 917 such as a CD-ROM.
[0055] Figure 3 It is a sequence diagram showing the processing of the authentication system 100.
[0056] As S11, the terminal 11 receives a combination of a user ID and a password (ID, PW) from the user as authentication input information. Additionally, as authentication input information, instead of using (ID, PW), any personal confirmation information such as biometric authentication input information like a fingerprint or tag information read from an employee ID held by the user can be used.
[0057] Figure 4 It is a login screen diagram of S11.
[0058] For the login screen 210 displayed on the terminal 11, after the user enters their own user ID in the ID field 211 and their own password in the PW field 212, the user clicks the OK button 213.
[0059] Return Figure 3 , as S12, the terminal 11 sends the authentication input information (ID, PW) input in S11 to the PLC 21.
[0060] As S13, the PLC 21 saves the (ID, PW) sent in S12 in its own memory 21m.
[0061] Figure 5 It is an explanatory diagram showing the data content of the memory 21m.
[0062] The memory area 101 in the memory 21m stores the (ID, PW) saved in S13 and the authentication result (Result) of the user who input the (ID, PW).
[0063] In addition, the terminal 11 and the authentication server 40 preset storage information on which address in which memory area 101 of the memory 21m stores each item (ID, PW, Result). Therefore, the terminal 11 and the authentication server 40 can directly specify the address of the memory area 101 in the memory 21m and read and write each item (ID, PW, Result) (using RAW-level means). Then, the authentication server 40 accesses the data in the memory 21m via an internationally standard protocol that can be interconnected, such as a PLC manufacturer-specific protocol or OPC (OLE for Process Control).
[0064] The storage content at the time point of S13 in the memory area 101 has (ID, PW) input in S11 written at that time point, but the Result is blank, indicating that authentication is in progress.
[0065] The memory area 102 is the first example of the storage content at the time point of S24 described later, and the authentication result (Result) indicating that the input (ID, PW) has passed authentication is appended.
[0066] The memory area 103 is the second example of the storage content at the time point of S24 described later, and the authentication result (Result) indicating that the input (ID, PW) has been rejected is appended.
[0067] In addition, regarding the information written to the memory areas 101 to 103 in the memory 21m, an encryption method in which the PLC 21 and the authentication server 40 share information in advance can also be used.
[0068] · The PLC 21 writes the encrypted information for the information written to the memory 21m.
[0069] · The authentication server 40 decrypts the information read from the memory 21m.
[0070] Thereby, it is possible to prevent a direct data attack (writing illegal data, peeping, etc.) on the memory 21m by a third party.
[0071] Return Figure 3 , as S14, the authentication server 40 monitors the direct access to the memory 21m of the PLC 21 and reads the (ID, PW) when new (ID, PW) is written.
[0072] As S15, the authentication server 40 generates an authentication request including the read (ID, PW) and sends the authentication request to the directory server 50. In addition, the authentication request may also include the ID of the PLC 21 (PLC-ID).
[0073] As S21, the directory server 50 performs authentication processing for the authentication request of S15. That is, the directory server 50 compares each account registered in the user DB51 with the authentication request received in S14, and approves the authentication request including the account registered in the user DB51 while rejecting the unregistered authentication request.
[0074] As S22, the directory server 50 returns a response message associating the authentication result (Result) of S21 with the (ID, PW) of the authentication request to the authentication server 40.
[0075] In addition, when the authentication server 40 and the directory server 50 are in the same housing, as the processing of S22, if the ID of the PLC21 that detected the authentication input information is registered in the user DB51 in addition to the authentication input information, the authentication server 40 generates an authentication result (Result) indicating authentication approval. Therefore, in addition to the authentication input information, the ID of the PLC21 is also registered in association with the account information registered in the user DB51. Thus, it is possible to support different permissions for each PLC (device) for one user.
[0076] Figure 6 It is an explanatory diagram showing details of each database used in the authentication system 100.
[0077] The authentication server 40 manages the currently ongoing authentication status using the authentication status DB41. The authentication status DB41 stores in association information of the authentication request (ID, PW, PLC-ID), the current authentication status, and information of Result (operation permission, display name).
[0078] · The current authentication status indicates either "authenticating" before writing the issued Result at the time point of S15, or "authentication passed" or "authentication rejected" of the issued Result indicating whether authentication is successful at the time point of S22.
[0079] · The operation permission indicates the range of permissions of the allowed PLC21 when authentication is passed according to the job name ("operation permission") in the permission table 21T (manager or general). In addition, the permission table 21T associates the operation permission allowing each function within the PLC.
[0080] · The display name is the display name shown on the screen when the user who has passed authentication operates via the terminal 11.
[0081] In addition, in this way, only the current authentication status is recorded as a record in the authentication status DB41, but the authentication server 40 can also save the history of the past authentication status DB41 chronologically. Thus, when a problem occurs, it helps to trace the cause of issues such as who used which PLC at what time.
[0082] In addition, the authentication server 40 can also monitor the elapsed time during authentication (the elapsed time of S13 to S24). If this elapsed time exceeds the specified time, it is regarded as a timeout, and the authentication server 40 notifies the terminal 11 that the authentication process has failed (not authentication rejection). That is, when there is no response to the authentication request sent to the directory server 50 within the specified time, the authentication server 40 writes an authentication result indicating that the authentication process has failed to the memory 21m. It is considered that the reasons for this timeout include device abnormalities of the authentication server 40, device abnormalities of the directory server 50, or network abnormalities between the authentication server 40 and the directory server 50, etc.
[0083] When the authentication process of such network authentication fails on the terminal 11, the terminal 11 can perform login and grant operation permissions through local authentication using an emergency administrator's account prepared inside the PLC 21. Local authentication is authentication completed inside the PLC 21 without going through the authentication server 40 and the directory server 50.
[0084] In the user DB 51, information (ID, PW, PLC-ID) prepared by a manager or the like for comparison with the authentication request and information (operation permissions, display name) included in the Result when the comparison is successful are used as account information. In addition, by including the PLC-ID in the user DB 51, even for the same user U1, it is possible to grant the operation permissions of a manager to the PLC 21 of manufacturing equipment that the user is good at operating (such as "cultivation equipment", "purification equipment", "reaction tank", etc. used in the pharmaceutical process), but grant general operation permissions to the PLC 22 of logistics equipment outside the user's professional field of operation, etc., and individually grant operation permissions corresponding to the individual's professional field.
[0085] In addition, for each device controlled via the PLCs 21 - 23, when its set value is changed, the manufacturing quality changes significantly. Therefore, by managing permissions in the user DB 51 in such a way that only highly professional users are allowed to perform operations that have a great impact on quality, the user DB 51 can manage both the manufacturing quality and the user's account management.
[0086] On the other hand, the following items can also be omitted from the user DB 51.
[0087] · Omit the display name. As a result, the display name is no longer displayed on the screen of the terminal 11, but it has no impact on the authentication process.
[0088] · Omit the operation permissions. As a result, the unit allowed during authentication is replaced from "a certain function within the PLC 21" to "all functions within the PLC 21".
[0089] · Omit the PLC-ID, whereby the unit allowed in the authentication is replaced from "the specific PLC21 requesting authentication among PLC21 - 23" to "any PLC requesting authentication among PLC21 - 23".
[0090] Return Figure 3 , as S23, the authentication server 40 writes the authentication result (Result) received in S22 corresponding to the authentication request (ID, PW) into the memory 21m in the PLC21 that is the source of the authentication request to notify the PLC21. That is, when the authentication server 40 writes the authentication result into the memory 21m in the PLC21, by writing the information indicating the operation authority together, it notifies the PLC21 of the control process within the range where the operation authority is allowed based on the authentication result. Therefore, in addition to the account information registered in the user DB51, the information indicating the operation authority in the functions provided by the PLC21 is also registered associatively.
[0091] As S24, the PLC21 stores the authentication result (Result) of S23 in the memory 21m as shown in the memory area 102 (when the authentication is allowed "OK", the operation authority and display name are also written together) or the memory area 103 (when the authentication is rejected "NG"). Figure 5
[0092] As S25, the terminal 11 reads the authentication result (Result) for the login information (ID, PW) sent in S12 from the memory 21m in the PLC21.
[0093] As S31, the terminal 11 displays the control screen of the PLC reflecting the authentication result (Result) of S25 and accepts the input of the control command from the user. Additionally, if Result is authentication rejection, it displays the login failure screen and returns to the login screen of another user. When Result is authentication approval, as S32, the PLC21 executes the control command by communicating the user's control command received from the terminal 11 in S31 to devices (not shown).
[0094] Alternatively, instead of the terminal 11 reading the authentication result (Result) of S25, it can be read by the PLC21. In this case, as S32, the PLC21 compares the user's control command received from the terminal 11 with the authentication result (Result) of S25 and only executes the control command within the range of the "operation authority" in the authority table 21T.
[0095] Furthermore, the terminal 11 can also set a limit time (such as 15 minutes) for the operation acceptance time of S31. If there is no operation within this limit time, the authentication result (Result) saved in S24 is deleted and forced logout is executed. That is, after the authentication server 40 writes the authentication result into the memory 21m in the PLC 21 and receives a notification from the PLC 21 indicating that the logout state is forced due to no operation input to the PLC 21 for a specified time, the authentication result is deleted from the memory 21m in the PLC 21. Thus, after the user U1 successfully authenticates the PLC 21, it is possible to appropriately prohibit the user U2 from operating the PLC 21 while the user U1 is away.
[0096] Figure 7 It is a control screen diagram of the PLC.
[0097] The control screen 220 is a control screen for operation authority = administrator, and it displays the display name = UserLV2. Similar to the operation authority for the administrator in the permission table 21T as shown in Figure 6 , all the operation buttons provided by the PLC 21 (acquire sensor value, control conveyor belt, control robotic arm, change tank temperature) are made valid in such a way that they can be input.
[0098] The control screen 230 is a control screen for operation authority = general use, and it displays the display name = UserLV1. Similar to the general operation authority in the permission table 21T, operation authority is not given to some of the operation buttons provided by the PLC 21 (control robotic arm, change tank temperature), so each operation button is made invalid.
[0099] The authentication system 100 of the present embodiment described above includes the PLC 21, the authentication server 40, and the directory server 50, and has the following features.
[0100] · The PLC 21 writes the input authentication input information into its own memory 21m.
[0101] · The authentication server 40 detects and reads the authentication input information written in the memory 21m, and sends an authentication request including the authentication input information to the directory server 50.
[0102] · The directory server 50 generates an authentication result for the authentication input information by comparing the authentication input information included in the authentication request with the account information registered in the user DB 51, and returns it to the authentication server 40.
[0103] · The authentication server 40 writes the authentication result for the authentication input information into the memory 21m.
[0104] · The PLC 21 determines whether control processing can be performed. Whether control processing can be performed depends on the authentication result read from the memory 21m.
[0105] According to this authentication system 100, the following effects can be obtained.
[0106] · Instead of the PLC 21, the authentication server 40 requests external authentication from the user DB 51 of the directory server 50, thereby enabling the unified management of users to be extended to the PLCs 21 - 23 that do not have authentication protocol functions such as LDAP.
[0107] · Since there is no need to have local authentication inside the PLC 21, account management can be centralized at the directory server 50. Therefore, even if the number of PLCs 21 - 23 increases, the maintenance workload of account management can be reduced.
[0108] · Since there is no need to have an authentication protocol function inside the PLC 21, the existing old - type PLCs 21 - 23 that are already in operation can be directly adopted, and at the same time, a network authentication function can be added to the authentication system 100.
[0109] Furthermore, the present invention is not limited to the above - mentioned embodiments. As long as it does not deviate from the gist of the present invention described in the claimed scope of rights, various other application examples and modification examples can be adopted. For example, in order to explain the present invention easily and understandably, the structure of the authentication system 100 has been described in detail and specifically in the above - mentioned embodiments, and it is not limited to having all the constituent elements described. In addition, a part of the structure of a certain embodiment can be replaced with the constituent elements of other embodiments. In addition, the constituent elements of other embodiments can be added to the structure of a certain embodiment. In addition, for a part of the structure of each embodiment, other constituent elements can also be added, replaced, or deleted.
[0110] In addition, for the above - mentioned various structures, functions, processing units, etc., for example, a part or all of them can be implemented in hardware by designing in an integrated circuit. As hardware, general - purpose processor devices such as FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit) can be used.
[0111] In addition, regarding the constituent elements of the authentication system 100 in the above - mentioned embodiments, as long as each hardware can send and receive information to and from each other via a network, they can be implemented in any hardware. In addition, the processing executed by a certain processing unit can be implemented by one hardware or by distributed processing performed by multiple hardwares.
[0112] Explanation of reference numerals
[0113] 11 Terminal
[0114] 21 PLC (Control Device)
[0115] 21m Memory
[0116] 31 Workbench
[0117] 40 Authentication Server
[0118] 41 Authentication Status DB
[0119] 50 Directory Server
[0120] 51 User DB
[0121] 100 Authentication System.
Claims
1. An authentication server capable of accessing data in a memory within a control device, characterized in that: By monitoring access to the memory, it detects and reads authentication input information written in the memory, By comparing the authentication input information with account information registered in a user DB, it generates an authentication result for the authentication input information, By writing the authentication result for the authentication input information into the memory within the control device, it notifies the control device whether control processing can be performed, where whether control processing can be performed depends on the authentication result.
2. The authentication server according to claim 1, characterized in that: The account information registered in the user DB is associated with the ID of the control device in addition to the authentication input information, The authentication server generates the authentication result indicating successful authentication when the ID of the control device that detected the authentication input information is also registered in the user DB based on the authentication input information.
3. The authentication server according to claim 1, characterized in that: The account information registered in the user DB is associated with information indicating the operation authority among the functions provided by the control device in addition to the authentication input information, When writing the authentication result into the memory within the control device, the authentication server notifies the control device whether control processing within the scope of the operation authority can be performed by writing the information indicating the operation authority together, where whether control processing within the scope of the operation authority can be performed depends on the authentication result.
4. The authentication server according to claim 1, characterized in that: After writing the authentication result into the memory within the control device, the authentication server receives a notification from the control device indicating that it has been forced to log out due to no operation input to the control device within a specified time, and deletes the authentication result from the memory within the control device.
5. An authentication system having a control device, an authentication server, and a directory server, characterized in that: The control device writes the input authentication input information into its own memory, The authentication server detects and reads the authentication input information written into the memory by monitoring access to the memory, and sends an authentication request including the authentication input information to the directory server, The directory server generates an authentication result for the authentication input information by comparing the authentication input information included in the authentication request with account information registered in a user DB, and returns the authentication result to the authentication server, The authentication server writes the authentication result for the authentication input information into the memory, The control device determines whether control processing can be performed, where whether control processing can be performed depends on the authentication result read from the memory.
6. The authentication system according to claim 5, characterized in that: When there is no response to the authentication request sent to the directory server within a specified time, the authentication server writes the authentication result indicating the failure of the authentication process into the memory.
7. The authentication system according to claim 5, wherein: The control device writes encrypted information into the memory. The authentication server decrypts the information read from the memory.
8. An authentication method, wherein: An authentication server capable of accessing the data in the memory within the control device Performs access monitoring of the memory to detect and read the authentication input information written in the memory, Compares the authentication input information with the account information registered in the user DB to generate an authentication result for the authentication input information, Writes the authentication result for the authentication input information into the memory within the control device to notify the control device whether control processing can be performed, where whether control processing can be performed depends on the authentication result.
Citation Information
Patent Citations
Authentication server and authentication system
JP2021096512A