Access authentication method using SNS integration and devices using this method

The described method addresses the slowness and security issues of conventional user authentication methods by using QR codes and SNS integration to expedite and secure user verification.

JP2026085220APending Publication Date: 2026-05-22SUPREMA INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SUPREMA INC
Filing Date
2025-06-13
Publication Date
2026-05-22

AI Technical Summary

Technical Problem

Conventional user authentication methods using user terminals, such as smartphones, are slower and less secure compared to traditional card keys, leading to inconvenience and potential security issues.

Method used

A method involving obtaining identification information from a control device via a QR code, performing login to an authentication server, and generating authentication data using user and device identification information, which is then transmitted to a separate server for verification, enhancing security and reducing authentication time.

Benefits of technology

This method significantly reduces authentication time and improves security by leveraging QR codes and SNS integration for efficient and secure user verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026085220000001_ABST
    Figure 2026085220000001_ABST
Patent Text Reader

Abstract

This provides an access authentication method that uses social networking services (SNS). [Solution] A method for authenticating access to a terminal comprises the steps of: obtaining identification information of a control device from a control device; performing login of the terminal user to an authentication server; obtaining terminal user identification information from the authentication server in response to the login; generating authentication data based on the identification information of the control device and the user identification information; and transmitting the authentication data to a server that performs user authentication for the terminal user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - reference to Related Applications This application claims the benefit of priority under 35 U.S.C. § 119 to Korean Patent Application Nos. 10 - 2024 - 0160240, filed on November 12, 2024, and 10 - 2024 - 0184880, filed on December 12, 2024, with the Korean Intellectual Property Office, the disclosures of which are hereby incorporated by reference in their entirety.

[0002] Field The present invention relates to an access authentication method using SNS linkage and a device using the same.

Background Art

[0003] In the field of performing user authentication to manage access to buildings or specific areas, payment processing, and the use of specific devices, technologies using user terminals are being used to improve convenience. In such technologies, user terminals were conventionally implemented as card keys, but they are gradually expanding to terminals such as smartphones carried by users.

[0004] However, the time required to obtain the information necessary for user authentication on the terminal may be longer compared to conventional card keys, and accordingly, the user may experience a delay feeling inconvenience, and multiple security problems may occur.

[0005] In recent years, efforts have continued to solve these problems.

Summary of the Invention

[0006] An object to be achieved by the present disclosure is to provide a control method for reducing the time required for user authentication.

[0007] Furthermore, another objective to be achieved by this disclosure is to provide control methods for enhancing security during user authentication.

[0008] The objectives to be achieved by this disclosure are not limited to those mentioned above, and other objectives not mentioned above can be clearly understood by those skilled in the art based on the description and accompanying drawings provided below.

[0009] According to one embodiment, a method for authenticating access to a terminal comprises the steps of: obtaining identification information of a control device from a control device; performing login of the terminal user to an authentication server; and obtaining user identification information of the terminal from the authentication server in response to the login; generating authentication data based on the identification information of the control device and the user identification information; and transmitting the authentication data to a server that performs user authentication for the terminal user, wherein the server is different from the authentication server.

[0010] The step of obtaining identification information of the control device from the control device includes the steps of: scanning a QR code (registered trademark) displayed on the control device; obtaining a QR code payload from the QR code; and obtaining the identification information of the control device from the QR code payload.

[0011] The user identification information includes at least one of the following: the mobile phone number of the terminal, the user's name, the user's email address, and the SNS identification information of the user on the terminal.

[0012] The step of obtaining user identification information of the terminal from the authentication server includes the steps of obtaining an access token from the authentication server in response to the login, and obtaining user identification information based on the access token.

[0013] The step of obtaining user identification information of the terminal from the authentication server includes the step of obtaining the user identification information of the terminal from the authentication server through the browser of the terminal, and the step of transmitting the authentication data includes the step of transmitting the authentication data to the server through the browser.

[0014] The method comprises the step of storing at least one of the access token or the user identification information in the browser or access authentication application.

[0015] The step of obtaining the user identification information of the terminal from the authentication server includes the step of obtaining the user identification information of the terminal from the authentication server through the terminal's access authentication application, The step of transmitting the authentication data includes the step of transmitting the authentication data to the server through the access authentication application.

[0016] The method comprises the steps of: receiving an installation prompt message for the access authentication application from the server; and installing the access authentication application on the terminal in response to the installation prompt message.

[0017] According to one embodiment, a method for server access authentication includes the steps of: obtaining authentication data from a terminal, where the authentication data is based on identification information of a control device that controls a specific security area and user identification information of the terminal, the user identification information being obtained by the terminal from an authentication server different from the server; performing user authentication to determine whether the user is permitted to access the specific security area; transmitting the result of the user authentication to the control device; obtaining a re-verification result of the user authentication from the control device; and determining, based on the re-verification result, whether the user is permitted to access the specific security area.

[0018] The step of performing user authentication includes a step of determining the validity of access schedule information, the access schedule information includes the user's accessible area and access time on the terminal.

[0019] The user identification information and access schedule information are stored in the server in association with each other.

[0020] The aforementioned access schedule information is obtained from an external device.

[0021] In another embodiment, the method for authenticating terminal access may include the steps of: receiving connection information from an external source; communicating with a server through a browser according to the connection information; receiving an OTP issuance key from the server; storing the OTP issuance key in the browser; obtaining the OTP issuance key from the browser; generating authentication information using the received OTP issuance key; and performing access authentication based on the authentication information.

[0022] Connection information may include information necessary for communication with the server and connection identification information for identifying the connection information.

[0023] Connection identification information may be generated as a random value.

[0024] The OTP issuance key may be generated once by the server, and the step of receiving the OTP issuance key from the server may include sending an OTP issuance key storage confirmation request to the server and receiving an OTP issuance key storage confirmation response from the server indicating whether the OTP issuance key is stored in the server.

[0025] A method for authenticating terminal access according to another embodiment may further include requiring access authentication for a specific area.

[0026] The step of generating authentication information using the received OTP issuance key may include the step of generating an OTP using the OTP issuance key and the step of generating authentication information using the OTP.

[0027] The step of generating authentication information using the received OTP issuance key may have the step of generating a QR code payload based on the OTP and the step of generating a QR code based on the QR code payload, and the step of performing access authentication based on the authentication information may include the step of displaying the QR code so that the QR code is scanned by the control device.

[0028] The step of generating authentication information using the received OTP issuance key may include the step of updating the OTP according to a predetermined cycle so as to prevent unauthorized use of the QR code in an external device.

[0029] The step of performing access authentication based on the authentication information includes the step of obtaining the OTP issuance key from the QR code through communication with the control device in the server, the step of generating an OTP based on the OTP issuance key, the step of obtaining a QR code validity verification result by comparing the OTP generated by the server with the OTP included in the QR code, the step of obtaining a validity verification result of access schedule information by obtaining access schedule information corresponding to the connection information, and the step of obtaining a response regarding access permission according to the result of user authentication performed by the server from the server through the browser when user authentication is performed based on the QR code validity verification result and the access schedule information validity verification result.

[0030] According to another embodiment, the server access authentication method may include the steps of: obtaining a QR code payload from a control device; a QR code containing the QR code payload being provided by a terminal; obtaining connection identification information from the QR code payload; obtaining an OTP issuance key based on the connection identification information; performing user authentication for the terminal user based on the OTP issuance key; and providing the user authentication result to the control device.

[0031] Another embodiment of the server access authentication method may further include the steps of receiving an OTP issuance key request from a terminal by sending an OTP issuance key request using connection information including connection identification information through a browser on the terminal, and generating an OTP issuance key in response to the OTP issuance key request.

[0032] The step of generating an OTP issuance key in response to an OTP issuance key request may include not generating an OTP issuance key if an OTP issuance key request has been previously received from the terminal using connection information, or if an OTP issuance key corresponding to the connection identification information exists in the visitor management database.

[0033] The step of obtaining an OTP issuance key based on connection identification information may include the steps of looking up an OTP issuance key corresponding to the connection identification information from the visitor management database, and obtaining the looked-up OTP issuance key.

[0034] A server access authentication method according to another embodiment may further include a step of obtaining an OTP from a QR code payload, and the step of performing user authentication for a terminal user based on the OTP issuance key may include a step of generating an OTP based on the OTP issuance key, a step of comparing the OTP obtained from the QR code payload with the generated OTP, and a step of performing user authentication based on the comparison result.

[0035] A server access authentication method according to another embodiment may further include a step of obtaining access schedule information corresponding to connection information, and the step of performing user authentication for a terminal user based on an OTP issued key may include a step of checking whether the access schedule information is valid, and a step of performing user authentication based on the validity verification result of the access schedule information.

[0036] The means for solving the problems of this invention are not limited to those described above, and those skilled in the art will clearly understand from this specification and the accompanying drawings that other means not mentioned herein are also possible.

[0037] According to this invention, the time required for user authentication can be reduced. Furthermore, according to this invention, security during user authentication can be improved. The effects of this invention are not limited to those described above, and those skilled in the art will clearly understand from this specification and the accompanying drawings that effects not mentioned herein can be clearly understood.

[0038] According to this invention, the time required for user authentication can be reduced.

[0039] Furthermore, according to this invention, security during user authentication can be improved.

[0040] The effects of this invention are not limited to those described above, and effects not mentioned herein will be clearly understood by those skilled in the art from this specification and the accompanying drawings. [Brief explanation of the drawing]

[0041] [Figure 1] This figure shows the environment of a management system according to one embodiment.

[0042] [Figure 2] This is a block diagram of a terminal according to one embodiment.

[0043] [Figure 3] This is a block diagram of a control device according to one embodiment.

[0044] [Figure 4] This is a block diagram of a server according to one embodiment.

[0045] [Figure 5] This is a diagram illustrating an access authentication process according to one embodiment.

[0046] [Figure 6] This is a diagram illustrating an access authentication process according to another embodiment. [Figure 7] This is a diagram illustrating an access authentication process according to another embodiment.

[0047] [Figure 8] This is a diagram illustrating an access authentication process according to another embodiment. [Figure 9] This is a diagram illustrating an access authentication process according to another embodiment.

[0048] [Figure 10] This figure illustrates the management of user identification information and visitor access information according to another embodiment.

[0049] [Figure 11] This is a diagram illustrating an access authentication process according to another embodiment.

[0050] [Figure 12] This is a diagram illustrating the acquisition of an OTP issuance key by a terminal according to another embodiment.

[0051] [Figure 13] This figure illustrates a QR code generation and access authentication process using a QR code according to another embodiment. [Modes for carrying out the invention]

[0052] The embodiments described herein are provided to those skilled in the art to clearly illustrate the technical concepts of the disclosure, and the disclosure is not limited to the embodiments described herein. The scope of the disclosure should be construed as including various modifications or changes without departing from the technical concepts of the disclosure.

[0053] The terms used herein are general terms that are widely used in light of the functions of this disclosure, but these terms may change in accordance with the intent of those skilled in the art, precedents, or the emergence of new technologies. However, where a term is defined and used to have a specific meaning, the meaning of the term shall be defined separately. Accordingly, the terms used herein should be interpreted not on the basis of the name of the term, but on the basis of the substantive meaning of the terms and content described throughout this specification.

[0054] To aid in the easy understanding of this disclosure, drawings are provided herein, and the shapes shown in the drawings may be shown in an extended form for the easy understanding of this disclosure, where necessary, and this disclosure is not limited by the drawings.

[0055] Detailed descriptions of well-known configurations or functions are omitted in this specification because they would unnecessarily obscure the subject matter of this disclosure.

[0056] The following describes an access management method and an access management device using the same according to one embodiment of the present disclosure.

[0057] Figure 1 shows the environment of a management system according to one embodiment.

[0058] Referring to Figure 1, the management system 10 may include a terminal 100, a control device 200, and a server 300.

[0059] Terminal 100 may communicate with at least one of the control device 200 or the server 300 and may send or receive various information. For example, terminal 100 may send or receive information necessary for user authentication to or from the control device 200. Here, user authentication may refer to authentication performed to determine whether a user or user terminal has certain privileges. For example, user authentication may include authentication of various privileges, such as access privilege authentication to determine whether a user or user terminal has the privilege to access a particular area, payment privilege authentication to determine whether a user or user terminal has the privilege to perform payment processing, usage privilege authentication to determine whether a user or user terminal has the privilege to use a particular device, and operation mode setting authentication to determine whether a user or user terminal has the privilege to set the operating mode of a particular device.

[0060] Furthermore, terminal 100 may transmit an access request and / or data necessary for the access request to the control device 200 or server 300. In addition, according to one embodiment, terminal 100 may perform the user authentication described above.

[0061] Furthermore, when user authentication is performed, terminal 100 may request control device 200 or server 300 to process user authentication, and may obtain the result of the request for processing for user authentication from control device 200 or server 300. Furthermore, terminal 100 may obtain information from control device 200 or server 300 regarding whether or not it is possible to perform processing for user authentication, and may perform processing for user authentication based on that information.

[0062] Furthermore, applications for performing some of the embodiments described below may be provided to terminal 100.

[0063] Terminal 100 may be implemented as a smartphone, tablet, personal digital assistant (PDA®), laptop, wearable device, or similar. Alternatively, terminal 100 may be implemented as a smart card, integrated circuit (IC) card, magnetic card, radio frequency (RF) chip capable of recording data, or similar.

[0064] The control device 200 may communicate with at least one of the server 300 or the terminal 100 and may transmit or receive various information. Furthermore, the control device 200 may perform various processing operations depending on the user authentication result described above. For example, depending on the user authentication result, the control device 200 may control the user's access to a specific area, control the user's payment processing, control the user's use of a specific device, or control the operating mode of a specific device.

[0065] Specifically, if user access to a particular area is restricted by a gate, the control device 200 may control the gate to control user access to the particular area according to the user authentication result. Here, the gate may be a device that physically restricts user access and may include access restriction devices (e.g., access bars, access doors, etc.). The control device 200 may provide an unlock signal to the gate according to the user authentication result, thereby controlling the gate to open and allowing user access. Furthermore, the control device 200 may not provide an unlock signal to the gate, or it may provide a lock signal to the gate according to the user authentication result, thereby controlling the gate to close and preventing user access. Furthermore, according to one embodiment, the control device 200 may be located inside or outside the gate.

[0066] Furthermore, if the control device 200 controls the payment process, the control device 200 may execute a payment authentication procedure as a process corresponding to the user authentication result. For example, the control device 200 may receive a payment request from the terminal 100 and accept or reject the payment request based on the user authentication result. Furthermore, according to one embodiment, the payment authentication procedure may be executed at the terminal 100 or the server 300.

[0067] Furthermore, the control device 200 may perform various control operations based on the user authentication result. For example, if the control device 200 controls a gate for accessing public transport, the control device 200 may control the gate based on the payment authentication result. Furthermore, the control device 200 may provide the payment authentication result to at least one of the server 300 or terminal 100. Furthermore, if the control device 200 controls the use of a particular device in accordance with the user authentication result, the control device 200 may control the use of the particular device through software installed on the particular device, or by controlling a restriction device to physically restrict the use of the particular device, based on the user authentication result.

[0068] Furthermore, if the control device 200 controls the operating mode of a specific device, the control device 200 may configure the operating mode of the specific device based on the user authentication result. For example, if the control device 200 controls an access control device for managing access to a specific area, the control device 200 may control the access control device in a security mode to enhance the security level in the specific area, or in a normal mode where the security mode is disabled, depending on the user authentication result. Furthermore, according to one embodiment, the access control device may be included in the control device 200.

[0069] Various processing operations performed in response to user authentication results may be executed on the server 300 or the terminal 100.

[0070] Furthermore, according to one embodiment, the control device 200 may perform the operations described above for user authentication. When user authentication is performed, the control device 200 may request the terminal 100 or server 300 to process the user authentication and may obtain the result of the processing request from the terminal 100 or server 300. Furthermore, the control device 200 may obtain a result from the terminal 100 or server 300 regarding whether or not it is possible to perform the processing for user authentication and may perform the processing for user authentication based on the result.

[0071] The server 300 may communicate with at least one of the control device 200 or terminal 100 and may transmit or receive various information.

[0072] According to one embodiment, the server 300 may provide information necessary for user authentication to at least one of the control device 200 or terminal 100. Furthermore, the server 300 may perform user authentication and provide the result of user authentication to at least one of the control device 200 or terminal 100. Furthermore, if user authentication is performed on at least one of the control device 200 or terminal 100, the server 300 may obtain the result of user authentication from at least one of the control device 200 or terminal 100.

[0073] The server 300 may perform processing in response to user authentication. For example, when the server 300 receives a request for processing for user authentication from the terminal 100 or the control device 200, it may perform processing in response to the user request, or it may determine whether processing in response to the user request is performed by the terminal 100 or the control device 200, and may provide the terminal 100 or the control device 200 with the result of the determination. Here, processing for user authentication may refer to follow-up operations performed based on user authentication, such as controlling the user's access to a specific area, controlling the user's payment processing, controlling the user's use of a specific device, or controlling the operating mode of a specific device, in accordance with the user authentication result.

[0074] However, the environmental diagram shown in Figure 1 is merely an example for illustrative purposes, and the disclosure is not limited thereto. According to some embodiments, components may be added to, omitted from, or divided from the environmental diagram in Figure 1.

[0075] Figure 2 is a block diagram of a terminal according to one embodiment.

[0076] Referring to Figure 2, the terminal 100 may include a communication module 110, a display module 120, an input module 130, a location information collection module 140, a storage module 150, a processor 160, and a biometric authentication data input module 170.

[0077] The communication module 110 may communicate with at least one of the server 300 or the control device 200. For example, the communication module 110 may send or receive information necessary for user authentication or information about the user authentication result to or from at least one of the server 300 or the control device 200.

[0078] Furthermore, the communication module 110 may include a mobile communication module that supports wired or wireless modules for transmitting or receiving data through Bluetooth® Low Energy (BLE), Bluetooth, Wireless Local Area Network (WLAN), Wireless Fidelity (WiFi®), WiFi Direct, Near Field Communication (NFC), Infrared Data Group (IrDA), Ultra Wideband (UWB), ZigBee®, 3G, 4G, or 5G, and various other communication standards.

[0079] The display module 120 may output various visual information. For example, when the control device 200 is detected and a communication connection is established through communication with the control device 200, the display module 120 may output relevant information. Furthermore, the display module 120 may visually output the user authentication result. Furthermore, the display module 120 may visually output messages received from the server 300. Furthermore, the display module 120 may output various authentication information such as QR codes.

[0080] The display module 120 may be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic LED (AMOLED) display, or similar. If the display module 120 is provided as a touchscreen, it may perform the functions of the input module 130. In this case, a separate input module 130 may not be provided depending on the choice, and an input module 130 that performs limited functions such as volume control, power button, and home button may be provided.

[0081] The input module 130 may acquire signals corresponding to user input. For example, the input module 130 may acquire input to request user authentication from the server 300 or control device 200. Furthermore, the input module 130 may acquire input to acquire information necessary for user authentication (e.g., user authorization information, user personal information (or user or terminal identification information, identification information necessary for payment processing (e.g., user card information, authentication information corresponding to card information), user biometric authentication data, encryption information, etc.)).

[0082] Furthermore, the input module 130 may be implemented by a keyboard, keypad, buttons, jog shuttle, wheel, or similar. User input may also be, for example, button presses, touches, and drags. If the display module 120 is implemented by a touchscreen, the display module 120 may function as the input module 130. Furthermore, the input module 130 may function as a camera. For example, the input module 130 may scan a QR code displayed by an external device (e.g., a control device).

[0083] The location information collection module 140 may acquire location information to identify the location of the terminal 100. For example, the location information collection module 140 may acquire coordinate information to determine the location, such as a Global Positioning System (GPS) sensor. In another example, the location information collection module 140 may determine the location of the terminal 100 based on a signal received from an external device. For example, if the terminal 100 receives a signal from the control device 200 indicating a specific area, the terminal 100 may, in response to receiving the signal, identify that the terminal 100 is within that specific area.

[0084] Furthermore, the memory module 150 may store various types of data. For example, the memory module 150 may store data necessary for operating the terminal 100 (for example, information necessary for user authentication (for example, user permission information, user personal information (or user or terminal identification information, identification information necessary for payment processing (for example, user card information, authentication information corresponding to card information), user biometric authentication data, encryption information, etc.))).

[0085] The memory module 150 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card micro, card type memory (e.g., SD or XD memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, or optical disk. The memory may store information temporarily, permanently, or semi-permanently, and may be provided in an embedded or removable form.

[0086] The processor 160 may control each component of the terminal 100, or process or calculate various information. Furthermore, the processor 160 may acquire signals from some of the components included in the terminal 100. Furthermore, the processor 160 may control operations for performing some of the steps of the method described below that are performed in the terminal 100, or perform the calculations necessary to perform the steps.

[0087] The processor 160 may be implemented by software, hardware, or a combination thereof. For example, with respect to hardware, the processor 160 may be implemented by a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a semiconductor chip, and various other types of electronic chips. In another example, with respect to software, the processor 160 may be implemented by a logic program or various computer languages ​​that are executed in accordance with the hardware described above.

[0088] The biometric data input module 170 may receive the user's biometric data. The biometric data may refer to at least one of the user's voice, fingerprint, iris, face, and vein information. The biometric data input module 170 may be performed by at least one of the following: a microphone into which the user's voice information is input, a screen scanner into which the user's fingerprint information is input, and a camera into which the user's iris, face, and vein information is input.

[0089] Terminal 100 does not necessarily have to include all of the components described above, and some components may be omitted depending on the choice. For example, if terminal 100 does not receive biometric authentication data, terminal 100 does not need to be provided with the biometric authentication data input module 170. Furthermore, terminal 100 may be provided with additional components that perform additional functions and operations depending on the choice.

[0090] Figure 3 is a block diagram of a control device according to one embodiment.

[0091] Referring to Figure 3, the control device 200 may include a communication module 210, a display module 220, an output module 230, a sensing module 240, a storage module 250, a power module 260, a processor 270, a biometric authentication data input module 280, and an input module 290.

[0092] The communication module 210 may communicate with at least one of the server 300 or the terminal 100. For example, the communication module 210 may send or receive information necessary for user authentication or user authentication result information to or from at least one of the server 300 or the terminal 100.

[0093] The communication module 210 may generally perform communication according to wireless communication standards and may include mobile communication modules that support BLE, Bluetooth, WLAN, WiFi, WiFi Direct, NFC, IrDA, UWB, ZigBee, 3G, 4G, or 5G, as well as wired or wireless modules for transmitting data through various other communication standards. Furthermore, the communication module 210 may include a short-range wireless module that supports NFC and radio frequency identification (RFID).

[0094] The display module 220 may output information that will be provided to the user visually. For example, when a door open signal is received, the display module 220 may output visual information indicating the reception of the door open signal. Furthermore, the display module 220 may output various authentication information, such as a QR code.

[0095] The display module 220 may be an LCD, OLED, or AMOLED display. If the display module 220 includes a touch panel, it may operate as a touch-based input device.

[0096] The output module 230 may output information that will be provided to the user audibly. For example, when a door open signal is received, the output module 230 may output auditory information indicating the reception of the door open signal. Furthermore, when a setting change signal is received, the output module 230 may output auditory information indicating the reception of the setting change signal.

[0097] The output module 230 may be a speaker or a buzzer to output sound.

[0098] The sensing module 240 may acquire signals related to the external environment necessary for the control device 200. For example, the sensing module 240 may identify whether or not a movable object (e.g., a user) is present in the vicinity of the control device 200. Furthermore, the sensing module 240 may be located on or near the control device 200. According to one embodiment, the sensing module 240 does not need to be included in the control device 200. In this case, a separate sensor may be located near the control device 200.

[0099] Various types of information may be stored in the memory module 250. For example, the memory module 250 may store a program for executing control operations of the processor 270, and may store data received from an external source and data generated by the processor 270. Furthermore, the memory module 250 may store information necessary for operating the control device 200 (for example, information necessary for user authentication (for example, user authority information, user identification information (for example, user or user terminal identifier information, user biometric authentication data encryption information))), and user authentication result information.

[0100] The memory module 250 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card micro, card type memory (e.g., SD or XD memory), RAM, SRAM, ROM, EEPROM, PROM magnetic memory, magnetic disk, or optical disk. The memory may store information temporarily, permanently, or semi-permanently, and may be provided in an embedded or removable form.

[0101] The power module 260 may provide the power necessary to lock or unlock the gate. Furthermore, the power module 260 may provide the power necessary to open or close the gate. The power module 260 may be provided as a motor, solenoid, or actuator.

[0102] If the power module 260 provides the power necessary to lock or unlock the gate, the power module 260 may also provide power to change and / or maintain a locking unit (not shown) for locking or unlocking the gate to a locked or unlocked state. The locking unit may be provided as a deadbolt, a latch bolt, or a combination thereof. Furthermore, the locking unit is not limited to deadbolts and latch bolts, and typical locking units may be used.

[0103] According to one embodiment, the power module 260 may or may not be included in the control device 200. Furthermore, the power module 260 may be located near the control device 200 in the form of a separate device. In this case, the control device 200 may provide the power module 260 with signals for controlling the power module 260. Furthermore, the lock unit described above may be included in the control device 200, or it may be located near the control device 200 to receive control from the control device 200.

[0104] The processor 270 may control each component of the control device 200, or it may process and calculate various information. The processor 270 may obtain signals from some of the components included in the control device 200. Furthermore, the processor 270 may control operations to perform some of the steps of the method described below that are performed in the control device 200, or it may perform the calculations necessary to perform the steps.

[0105] The processor 270 may be implemented by software, hardware, or a combination thereof. For example, with respect to hardware, the processor 270 may be implemented by an FPGA, ASIC, semiconductor chip, or various types of electronic circuits. For example, with respect to software, the processor 270 may be implemented by a logic program executed in accordance with the hardware described above or by various computer languages.

[0106] The biometric data input module 280 may receive biometric data input from the user. For example, the biometric data input module 280 may receive at least one of the user's voice, fingerprint, iris, face, and vein information. The biometric data input module 280 may be implemented using at least one of the following: a microphone into which the user's voice information is input, a screen scanner into which the user's fingerprint information is input, or a camera into which the user's iris, face, and vein information is input.

[0107] The input module 290 may be configured to receive various inputs. For example, the input module 290 may receive an input to request user authentication from the server 300 or terminal 100. Furthermore, the input module 290 may receive an input to obtain information necessary for user authentication (e.g., user or user terminal identification information, encryption information, biometric authentication data). In addition, the input module 290 may receive an input of configuration change information to change the settings of the control device 200.

[0108] Furthermore, the input module 290 may receive user authentication requests from the user. For example, if user authentication is authentication of the user's access to a specific area, the control device 200 may receive an input to open a door, open the door by activating the power module 260, or send an access authentication request signal to the server 300 or terminal 100. For example, the input module 290 may be performed by a keyboard, keypad, buttons, switches, jog shuttle, wheel, or similar. Furthermore, user input may be, for example, pressing a switch, pressing a button, touching, and dragging. If the display module 220 is performed by a touchscreen, the display module 220 may perform the role of the input module 290.

[0109] Furthermore, the input module 290 may function as a camera. For example, the input module 290 may scan a QR code displayed by an external device (e.g., a terminal).

[0110] A control device 200 according to one embodiment of the present disclosure does not necessarily include all of the components described above, and some components may be omitted at will.

[0111] For example, the control device 200 may include a control device 200 having a communication module 210 and a processor 270. More specifically, the control device 200 may receive information obtained from the terminal 100 through the communication module 210 which performs the functions of a reader, analyze the information obtained through the processor 270 which performs the functions of a controller, and perform functions to control operations such as access management, attendance management, and system mode changes.

[0112] Furthermore, the control device 200 may be provided with additional components that perform additional functions and operations depending on the selection.

[0113] Figure 4 is a block diagram of a server according to one embodiment.

[0114] Referring to Figure 4, the server 300 may include a communication module 310, an input module 320, a storage module 330, a display module 340, and a processor 350.

[0115] The communication module 310 may communicate with at least one of the terminal 100 or the control device 200. In another example, the communication module 310 may transmit biometric authentication data to the terminal 100, which will be stored in the control device 200.

[0116] Furthermore, the communication module 310 may include a mobile communication module that supports wired or wireless modules for transmitting data through BLE, Bluetooth, WLAN, WiFi, WiFi Direct, NFC, IrDA, UWB, ZigBee, 3G, 4G, or 5G, and various other communication standards.

[0117] The input module 320 may acquire electrical signals corresponding to user input. The input module 320 may include a keypad, keyboard, switches, buttons, and a touchscreen.

[0118] The memory module 330 may store various types of data. For example, the memory module 330 may store information necessary for user authentication (e.g., user authorization information, user personal information (or user or terminal identification information, identification information necessary for payment processing (e.g., user's card information, authentication information corresponding to card information), user's biometric authentication data, encryption information)), or information about the user authentication result.

[0119] Furthermore, the memory module 330 may store information obtained from the terminal 100 or the control device 200. In addition, the memory module 330 may store programs necessary for the operation of the server 300.

[0120] Furthermore, the memory module 330 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card micro, card type memory (e.g., SD or XD memory), RAM, SRAM, ROM, EEPROM, PROM magnetic memory, magnetic disk, or optical disk. In addition, the memory may store information temporarily, permanently, or semi-permanently, and may be provided in an embedded or removable form.

[0121] The display module 340 may output visual information. For example, the display module 340 may be an LCD, OLED, or AMOLED display.

[0122] Furthermore, the processor 350 may control each component of the server 300, or process and calculate various information. Additionally, the processor 350 may control operations for performing some of the steps of the method described below that are performed in the server 300, or perform the calculations necessary to perform those steps.

[0123] The processor 350 may be implemented by software, hardware, or a combination thereof. For example, with respect to hardware, the processor 350 may be implemented by an FPGA, ASIC, semiconductor chip, or various types of electronic circuits. For example, with respect to software, the processor 350 may be implemented by a logic program executed according to the hardware described above or by various computer languages.

[0124] Server 300 does not necessarily include all of the components described above, and some components may be omitted depending on the selection. For example, if server 300 does not directly provide visual information, server 300 does not need to be provided with a display module 340. Furthermore, server 300 may be provided with additional components to perform additional functions and operations depending on the selection.

[0125] Figure 5 is a diagram illustrating the access authentication process according to one embodiment.

[0126] Referring to Figure 5, the control device 200 may provide authentication information to the terminal 100 for access authentication. Here, the authentication information is information necessary for user authentication, and may be composed of various forms such as QR codes, barcodes, ultrasonic signals, RF signals, BLE signals, NFC signals, etc. For the sake of explanation, the following description will focus on one embodiment in which the authentication information is composed of a QR code, but it is not limited to this, and the authentication information may be composed of various forms such as barcodes, ultrasonic signals, RF signals, BLE signals, NFC signals, etc.

[0127] The control device 200 may display a QR code. In this case, the QR code payload may include identification information for the control device 200. The terminal 100 may scan the QR code, obtain the QR code payload from the QR code, and obtain the identification information for the control device 200 from the QR code payload.

[0128] Terminal 100 may then obtain user identification information. For example, the user identification information may include the mobile phone number of terminal 100, the SNS identification information of the user of terminal 100 (e.g., SNS account), the user's name, the user's email address, etc. Terminal 100 may then generate authentication data using the identification information of the control device 200 and the user identification information, and send the authentication data to the server 300.

[0129] The server 300 may perform user authentication based on the authentication data and send the user authentication result to the control device 200. The control device 200 may then re-verify the user authentication result performed by the server 300. The control device 200 may send the re-verification result to the server 300, and the server 300 may decide whether or not to open the gate based on the re-verification result.

[0130] The server 300 may then send a response regarding access permission to the control device 200 based on whether or not to open the gate. For example, the response regarding access permission may include an access permission message or an access denial message. The control device 200 may or may not open the gate based on the response regarding access permission. In this case, the terminal 100 may perform access authentication through a browser without using a separate application, and in this case, user identification information does not need to be stored in the browser. Accordingly, the terminal 100 may not need to obtain user identification information through a predetermined procedure. Various embodiments including predetermined procedures will be described in detail with reference to Figures 6 to 10.

[0131] Figures 6 and 7 illustrate an access authentication process according to another embodiment.

[0132] Referring to Figure 6, the control device 200 may display a QR code. In this case, the QR code payload may include identification information of the control device 200. The terminal 100 may scan the QR code according to a predetermined procedure. The terminal 100 may obtain the QR code payload from the QR code. Then, the terminal 100 may obtain the identification information of the control device 200 from the QR code payload.

[0133] Furthermore, terminal 100 may log in to the authentication server 400 using the SNS identification information of terminal 100's user. Here, unlike the server 300 described above, the authentication server 400 may be a server that performs authentication of terminal 100's user in various services such as SNS. Terminal 100 may communicate with the authentication server 400 using a browser and may log in using the SNS identification information of terminal 100's user using the browser.

[0134] When terminal 100 attempts to log in using the user's SNS identification information, the authentication server 400 may provide terminal 100 with user identification information. For example, user identification information may include terminal 100's mobile phone number, SNS identification information, and user identification information (e.g., the user's name). As an example, terminal 100 may obtain an access token from the authentication server 400 using the OAuth (Open Authorization) method through a browser. Terminal 100 may obtain user identification information from the access token. Terminal 100 may store the access token and / or user identification information in its browser. In this case, terminal 100 may encrypt the access token and / or user identification information and store the encrypted access token and / or user identification information in its browser.

[0135] Terminal 100 may generate authentication data using the identification information and user identification information of the control device 200. Terminal 100 may send the authentication data to the server 300 using a browser. The server 300 may perform user authentication using the authentication data. As an example, the authentication data and / or user identification information may be encrypted, and terminal 100 may encrypt the authentication data and / or user identification information. Furthermore, terminal 100 may encrypt the user identification information and generate and send authentication data using the encrypted user identification information.

[0136] Server 300 may, as part of user authentication, use the identification information of the control device 200 and the user identification information included in the authentication data to determine whether the user of terminal 100 has the authority to access the control device 200. For example, the user identification information and access schedule information (such as the accessible area (or the identification information of the control device that controls the accessible area), and the accessible time (start time, end time)) may be matched and stored in Server 300. Server 300 may obtain the access schedule information corresponding to the user identification information and verify the validity of the access schedule information. For example, Server 300 may verify the validity of the access schedule information by determining whether the accessible area in the access schedule information corresponds to the control device 200 displaying the QR code, and whether the accessible time in the access schedule information corresponds to the current time.

[0137] Server 300 may send the user authentication result to control device 200. Control device 200 may then re-verify the user authentication result performed by server 300. For example, control device 200 may determine whether the accessible area authenticated by server 300 (or the identification information of the control device that controls the accessible area) is an accessible area controlled by the corresponding control device 200 (or whether the control device authenticated by server 300 is the corresponding control device 200). If the re-verification is determined to be abnormal, control device 200 may send information to server 300 indicating that there is an abnormality in the re-verification result. In this case, server 300 may decide not to open the gate to control device 200. On the other hand, if the re-verification is determined to be normal, control device 200 may send information to server 300 indicating that there is no abnormality in the re-verification result. In this case, the server 300 may decide to open the gate for the control device 200 and may instruct the control device 200 to open the gate.

[0138] Furthermore, Figure 7 is a diagram illustrating the access authentication process after the access authentication process shown in Figure 6 has been executed.

[0139] Referring to Figure 7, the control device 200 may display a QR code. Terminal 100 may scan the QR code and obtain a QR code payload from it. Terminal 100 may then obtain the identification information of the control device 200 from the QR code payload. Furthermore, terminal 100 may obtain user identification information. For example, terminal 100 may obtain user identification information from a browser, or from an access token stored in the browser. Since the access token and / or user identification information is already stored in the browser, terminal 100 does not need to obtain user identification information through the authentication server 400.

[0140] The terminal 100 may generate authentication data using the identification information and user identification information of the control device 200, the server 300 may perform user authentication, the server 300 may send the user authentication result to the control device 200, the control device 200 may perform re-verification, the control device 200 may send the re-verification result to the server 300, and the server 300 may decide whether or not to open the gate based on the re-verification result. The contents described in Figure 6 can be applied here, so a detailed explanation is omitted.

[0141] Figures 8 and 9 illustrate an access authentication process according to another embodiment.

[0142] Referring to Figure 8, the server 300 may prompt the terminal 100 to install the access authentication application. At this time, while the server 300 is sending a response regarding access permission to the terminal 100 in accordance with the procedure described in Figure 10 and / or Figure 11, or thereafter, the terminal 100 may receive an installation prompt message about the access authentication application as an prompt to install the access authentication application.

[0143] Furthermore, terminal 100 may install the access authentication application in response to receiving an installation prompt message for the access authentication application. In this case, the access authentication application does not need to be able to obtain user identification information from the browser described in Figures 6 and 7. Accordingly, terminal 100 may obtain user identification information from the authentication server 400 and store the obtained user identification information in the access authentication application.

[0144] Specifically, terminal 100 may initiate signup to server 300 through an access authentication application. At this time, server 300 may guide the signup through the OAuth method, and terminal 100 may perform login to authentication server 400 while performing signup according to the OAuth method. At this time, terminal 100 may communicate with authentication server 400 through the access authentication application. Then, in response to the login to authentication server 400, authentication server 400 may provide terminal 100 with an access token.

[0145] Terminal 100 may obtain an access token from the authentication server 400 through an access authentication application, and may obtain user identification information from the access token. Terminal 100 may store the access token and / or user identification information in the access authentication application. At this time, terminal 100 may encrypt the access token and / or user identification information, and store the encrypted access token and / or encrypted user identification information in the access authentication application.

[0146] Furthermore, terminal 100 may optionally acquire the user's biometric authentication information and register it. This may be because terminal 100 uses an access authentication application to perform biometric authentication of the user using the user's biometric authentication information.

[0147] Furthermore, Figure 9 is a diagram illustrating the access authentication process after the access authentication process shown in Figure 8 has been executed.

[0148] Referring to Figure 9, the control device 200 may display a QR code. Terminal 100 may scan the QR code and obtain a QR code payload from it. Terminal 100 may then obtain identification information of the control device 200 from the QR code payload. Furthermore, terminal 100 may obtain user identification information. For example, terminal 100 may obtain user identification information from an access token stored in the access authentication application, or obtain user identification information stored in the access authentication application. Since the access token and / or user identification information is already stored in the access authentication application, terminal 100 does not need to obtain the access token and / or user identification information through the authentication server 400.

[0149] Optionally, terminal 100 may receive the user's biometric information and perform biometric authentication by comparing the received biometric information with previously stored biometric information. If the previously stored biometric information and the received biometric information do not match, the access authentication process may be terminated. If the previously stored biometric information and the received biometric information do match, terminal 100 may generate authentication data using the identification information of control device 200 and user identification information, and may transmit the authentication data of control device 200 to server 300 through the access authentication application.

[0150] The server 300 may perform user authentication based on the authentication data and send the user authentication result to the control device 200. The control device 200 may then re-verify the user authentication result performed by the server 300. The control device 200 may send the re-verification result to the server 300, and the server 300 may decide whether or not to open the gate based on the re-verification result. The contents described in Figure 6 can be applied here, so a detailed explanation is omitted.

[0151] Figure 10 is a diagram illustrating the management of user identification information and visitor access information according to another embodiment.

[0152] Referring to Figure 10, the server 300 may obtain access configuration information from the external device 500. Here, the external device 500 may be an administrator's terminal or an external server (for example, a client company's server) that can set or modify access permissions. The access configuration information is information for setting access permissions or access levels for a specific visitor, and may include user identification information of the terminal of the user who is permitted access, and access schedule information for the user (such as the accessible area (or identification information of the control device that controls the accessible area), and the accessible time (start time, end time)).

[0153] Server 300 may store access configuration information. Specifically, Server 300 may store and match user identification information and access schedule information for users whose terminals are permitted access.

[0154] According to the procedure described in Figures 5 to 9, when the server 300 obtains user identification information stored in the browser or access authentication application (or user identification information obtained from an access token stored in the browser or access authentication application) and the identification information of the control device 200 from the terminal 100, it can verify the previously stored user identification information that matches the obtained user identification information and obtain access schedule information that matches the verified user identification information. Then, as user authentication, the server 300 may use the user identification information and / or the identification information of the control device 200 to determine the validity of the access schedule information.

[0155] The server 300 may send the user authentication result to the control device 200. The control device 200 may then re-verify the user authentication result performed by the server 300. The control device 200 may send the re-verification result to the server 300, and the server 300 may decide whether or not to open the gate based on the re-verification result. The contents described in Figure 6 can be applied here, so a detailed explanation is omitted.

[0156] According to these embodiments, cost and procedural simplification may be possible through the access authentication process described herein. Furthermore, security can be enhanced, and visitors do not need to manage additional separate authentication means, so the access authentication process described herein can be effectively integrated with services targeting a large number of people, such as contactless facility reservation management services.

[0157] Figure 11 is a diagram illustrating an access authentication process according to another embodiment.

[0158] Referring to Figure 11, terminal 100 may provide authentication information to control device 200 for access authentication. Here, the authentication information is information necessary for user authentication, and may be composed of various forms such as QR codes, barcodes, ultrasonic signals, RF signals, BLE signals, NFC signals, etc. For the sake of explanation, the following description focuses on one embodiment in which the authentication information is composed of a QR code, but is not limited to this, and the authentication information may be composed of various forms such as barcodes, ultrasonic signals, RF signals, BLE signals, NFC signals, etc. In this case, terminal 100 may perform access authentication using a browser that can connect to the internet without using a dedicated application. Accordingly, terminal 100 may provide authentication information to control device 200 using a browser. Furthermore, by performing access authentication using a browser without using a dedicated application, the access authentication processor according to one embodiment can have high versatility by being applicable to various applications while enhancing security.

[0159] To explain in more detail, first, terminal 100 may receive connection information from an external source. For example, terminal 100 may receive messages from an external source, such as email, SNS messages, or text messages, and may obtain a link as connection information from the received message.

[0160] Here, connection information may be sent only to the terminals of users who have permission to access a specific area. For example, server 300 may obtain identification information (e.g., email address, SNS ID, mobile phone number, etc.) of users who have permission to access a specific area from the outside, and may send connection information to users who have permission to access a specific area based on the obtained identification information.

[0161] As an example, connection information may include information necessary for communication with server 300 and connection identification information. Connection identification information is for identifying connection information and may be a UUID (Universally Unique Identifier). Connection identification information may be in the form of a unique random value. For example, if the connection information is a link, the connection identification information may be displayed in the link as "qid=ba4a3906-4a9f-4332-9c52-580f546aa151". Server 300 may match the connection identification information with the identification information of a user who has the authority to access it. Link: http: / / visitor-frontend-host / qr?qid=ba4a3906-4a9f-4332-9c52-580f546aa151

[0162] Terminal 100 may communicate with server 300 through a browser using connection information, and may generate or receive a QR code through communication with server 300. Terminal 100 may display a QR code, and control device 200 may scan the QR code displayed on terminal 100 through its camera. Control device 200 may obtain a QR code payload by scanning the QR code and send the QR code payload to server 300. Server 300 may perform user authentication using the QR code payload and send the user authentication result to control device 200. Control device 200 may determine whether or not to open the gate based on the user authentication result from server 300.

[0163] In a particular embodiment, for user A to authorize user B to access area A, user A's terminal may send a request to server 300 authorizing user B to access area A. At this time, the access permission request may include additional information such as user B's access schedule information (accessible area (or identification information of the control device that controls the accessible area), accessable time (start time, end time), etc.) and user B's message account (e.g., user B's email account, SNS account, mobile phone number, etc.). Server 300 may generate connection identification information according to the access permission request and / or additional information. Server 300 may then match the connection identification information with the access schedule information. Server 300 may then generate connection information (e.g., a link) including the connection identification information and send a message (e.g., user B's email) including the connection information to user B's message account (e.g., user B's email account).

[0164] User B's terminal may obtain connection information through User B's message account, communicate with Server 300 through the connection information, and generate or receive a QR code through communication with Server 300. User B's terminal 100 may display a QR code, and the control device 200 may determine whether or not to open the gate controlling area A by scanning the QR code displayed on terminal 100 through its camera.

[0165] An access authentication process according to one embodiment will be described in detail with reference to Figures 6 and 7.

[0166] Figure 12 illustrates the acquisition of an OTP issuance key by a terminal according to another embodiment.

[0167] Referring to Figure 12, terminal 100 may receive connection information from an external source and communicate with the control server 610 through that connection information. Here, terminal 100 may be the web front end (FE) of terminal 100. Furthermore, the control server 610 and the visitor management database 620 may be included in the server 300 described above. In one embodiment, the visitor management database 620 may be included in the control server 610. In another embodiment, the visitor management database 620 may be included in the visitor management server 630, which will be described later.

[0168] Furthermore, the control server 610 may be represented as a visitor management backend (BE) server. The terminal 100 may transmit connection identification information included in the connection information while communicating with the control server 610 through a connection request, and the control server 610 may verify which connection information the terminal 100's communication connection is based on through the connection identification information.

[0169] Specifically, terminal 100 may request an OTP issuance key from control server 610. For example, terminal 100 may request an OTP issuance key from control server 610 using the REST API method.

[0170] The control server 610 may generate an OTP issuance key in response to an OTP issuance key request from the terminal 100. In this case, if the terminal 100 requests an OTP issuance key from the control server 610 through the corresponding connection information, the control server 610 may generate the OTP issuance key only once. This enhances security. For example, if the terminal 100 requests an OTP issuance key from the control server 610 through a first link as connection information, the control server 610 may issue a first OTP issuance key. Later, if the terminal 100 requests an OTP issuance key from the control server 610 again through the first link, the control server 610 does not need to issue the first OTP issuance key. Furthermore, if the terminal 100 requests an OTP issuance key from the control server 610 through a second link different from the first link, the control server 610 may issue a second OTP issuance key different from the first OTP issuance key.

[0171] Furthermore, as will be explained later, according to one embodiment, the OTP issuance key may be stored in the visitor management database 620 together with the connection identification information included in the connection information. In this case, the control server 610 may check whether an OTP issuance key corresponding to the connection identification information provided by the terminal 100 that made the OTP issuance key request exists in the visitor management database 620. If an OTP issuance key corresponding to the connection identification information provided by the terminal 100 that made the OTP issuance key request does not exist in the visitor management database 620, the control server 610 may issue a first OTP issuance key. However, if an OTP issuance key corresponding to the connection identification information provided by the terminal 100 that made the OTP issuance key request exists in the visitor management database 620, the control server 610 does not need to issue a first OTP issuance key.

[0172] Furthermore, the control server 610 may generate an OTP issuance key and store it in the visitor management database 620. For example, the control server 610 may store in the visitor management database 620, along with the generated OTP issuance key, information about the terminal 100's identification information and / or connection information (e.g., connection identification information), access schedule information (accessible area (or identification information of the control device that controls the accessible area), accessible time (start time, end time), etc.), and identification information of users who have permission to access the corresponding area (e.g., email address, SNS ID, mobile phone number, etc.). Furthermore, information about authentication information (e.g., information about the type of authentication information such as QR code, RF signal, or face) may be stored in the visitor management database 620 along with the OTP issuance key. Furthermore, according to one embodiment, an OTP issuance key storage confirmation flag, described below, may also be stored along with the OTP issuance key.

[0173] Furthermore, the control server 610 may send an OTP issuance key to the terminal 100. For example, the control server 610 may send the OTP issuance key to the terminal 100 using a REST API method. The terminal 100 may then encrypt the OTP issuance key and store the encrypted OTP issuance key in its browser. Accordingly, both the terminal 100 and the control server 610 can store the same OTP issuance key.

[0174] Furthermore, terminal 100 may send an OTP issuance key storage confirmation request to control server 610.

[0175] The OTP issuance key storage confirmation request may be a handshake process indicating that terminal 100 has received an OTP issuance key from the control server 610. From the control server 610's perspective, since the control server 610 generates an OTP issuance key only once according to the corresponding connection information, it may be necessary to confirm whether the OTP issuance key, which was generated only once, was sent to terminal 100 without errors. Accordingly, the control server 610 may receive an OTP issuance key storage confirmation request from terminal 100 to confirm that the OTP issuance key was sent to terminal 100 without errors. In response to the OTP issuance key storage confirmation request from terminal 100, the control server 610 may store an OTP issuance key storage confirmation flag in the visitor management database 620. In the visitor management database 620, the OTP issuance key storage confirmation flag may be stored in association with the corresponding OTP issuance key. The control server 610 may then send an OTP issuance key storage confirmation response to terminal 100.

[0176] For example, if terminal 100 requests an OTP issuance key from control server 610 according to connection information, control server 610 may check whether an OTP issuance key has been previously generated according to the corresponding connection information. For example, control server 610 may check whether an OTP issuance key storage confirmation flag corresponding to the OTP issuance key exists, and if the OTP issuance key storage confirmation flag does not exist in the visitor management database 620, control server 610 may generate an OTP issuance key. However, if an OTP issuance key storage confirmation flag corresponding to the OTP issuance key exists in the visitor management database 620, control server 610 may confirm that an OTP issuance key has been previously generated and may send an error message regarding the OTP issuance key request to terminal 100 without generating an OTP issuance key.

[0177] Figure 13 is a diagram illustrating a QR code generation and access authentication process using a QR code according to another embodiment.

[0178] Referring to Figure 13, terminal 100 may perform an operation based on connection information as a request for authentication to access a specific area. Terminal 100 may check whether or not an OTP issuance key is stored in the browser.

[0179] If the OTP issuance key is not stored in the browser, terminal 100 may obtain the OTP issuance key as described in Figure 12. If the OTP issuance key is stored in the browser, terminal 100 may obtain the OTP issuance key.

[0180] Furthermore, terminal 100 may generate an OTP (One Time Password) using an OTP issuance key. Then, terminal 100 may generate a QR code payload using the generated OTP. Specifically, terminal 100 may generate a QR code payload using the connection identification information contained in the connection information and the generated OTP. For example, the QR code payload may be expressed as follows, in the QR code payload below, the connection identification information may appear as "a4a3906-4a9f-4332-9c52-580f546aa151", and the OTP may appear as "882351". Furthermore, terminal 100 may generate a QR code using the QR code payload and display the QR code.

[0181] In one embodiment, the generation of the OTP, the generation of the QR code payload, and the generation of the QR code may be repeated at relatively short predetermined time intervals (e.g., 5 seconds). That is, the QR code may change at predetermined time intervals. This is for security purposes. For example, user C's terminal may generate a QR code and send the generated QR code to user D's terminal, and user D's terminal may display the QR code and tag it to the control device 200. However, there may be a time lag between the generation of the QR code on user C's terminal and the display of the QR code on user D's terminal. On the other hand, since the generation of the QR code on user C's terminal is repeated over a relatively short predetermined time, when the QR code is displayed on user D's terminal, a different QR code may be generated on user C's terminal than the one sent to user D's terminal. Accordingly, even if the QR code displayed on user D's terminal is tagged to the control device 200, access by user D's terminal to the area managed by the control device 200 may be denied because the QR code displayed on user D's terminal is already an invalid QR code.

[0182] Furthermore, after the QR code is displayed on terminal 100, the camera of control device 200 may scan the QR code. Control device 200 may obtain a QR code payload from the scanned QR code. Then, control device 200 may send the QR code payload to control server 610. Control server 610 may be included in server 300 as a server for controlling control device 200. Control server 610, visitor management server 630, and visitor management database 620 may be included in server 300 as described above, and they may be configured as a single physical entity or as separate physical entities. Furthermore, as described above, visitor management database 620 may be included in control server 610.

[0183] Furthermore, the control server 610 may perform user authentication based on the QR code payload. User authentication is described in detail below.

[0184] Specifically, first, the control server 610 may obtain connection identification information from the QR code payload. Then, the control server 610 may look up the OTP issuance key corresponding to the connection identification information in the visitor management database 620. The control server 610 may obtain the OTP issuance key from the visitor management database 620 and generate an OTP based on the OTP issuance key. Then, the control server 610 may obtain the OTP from the QR code payload and compare the OTP from the QR code payload with the OTP generated based on the OTP issuance key. If the OTP from the QR code payload and the OTP generated based on the OTP issuance key do not match, the control server 610 may determine that the QR code is not valid. In the example described above, when the control server 610 obtains the QR code payload of the QR code displayed on user D's terminal, there may be cases where the OTP from the QR code payload and the OTP generated based on the OTP issuance key do not match. Specifically, while the OTP and QR code are updated on user C's terminal over a short period of time, the process of user D's terminal acquiring the QR code from user C's terminal takes time. Therefore, at the time the control device 200 scans the QR code from user D's terminal, the OTP included in the QR code payload of the QR code displayed on user D's terminal and the OTP updated on user C's terminal may be different. That is, the OTP generated on user C's terminal and the OTP generated on the control server 610 are synchronized, and the OTP generated on the control server 610 may match only the OTP updated on user C's terminal, but not the OTP included in the QR code payload of the QR code displayed on user D's terminal. However, since the QR code is displayed directly on user C's terminal without the QR code duplication process on user D's terminal, if the control device 200 scans the QR code shortly after it is generated on user C's terminal, the OTP generated on the control server 610 and the OTP updated on user C's terminal may match.In this case, the control server 610 may determine that the QR code is valid.

[0185] If the control server 610 determines that the QR code is valid, the control server 610 may request the visitor management server 630 to verify the validity of the access schedule information. In response to the request from the control server 610 to verify the validity of the access schedule information, the visitor management server 630 may obtain access schedule information (such as the accessible area (or identification information of the control device that controls the accessible area), and the accessible time (start time, end time)) corresponding to the connection identification information from the visitor management database 620. Furthermore, the visitor management server 630 may verify the validity of the obtained access schedule information. For example, the visitor management server 630 may verify the validity of the access schedule information by determining whether the accessible area of ​​the access schedule information corresponds to the control device 200 that scanned the QR code, whether the accessible time of the access schedule information corresponds to the current time, and whether the information about the authentication information stored in the visitor management database 620 along with the OTP issuance key (for example, information about the type of authentication information such as a QR code, RF signal, or face) corresponds to the type of authentication information scanned by the control device 200 (for example, a QR code).

[0186] The visitor management server 630 may send the results of verifying the validity of the access schedule information to the control server 610. The control server 610 may receive the results of verifying the validity of the access schedule information from the visitor management server 630 and generate the user authentication result, i.e., a response regarding permission to access, by combining the results of verifying the validity of the QR code and the validity of the access schedule information. The control server 610 may send the response regarding permission to access to the control device 200, and the control device 200 may determine whether or not to open the gate according to the received response. For example, if the QR code (or OTP) and / or access schedule information are not valid, the control server 610 may send a response to the control device 200 indicating that access is denied, and the control device 200 does not have to open the gate according to the received response. If the QR code (or OTP) and access schedule information are valid, the control server 610 may send a response to the control device 200 indicating that access is permitted, and the control device 200 may open the gate according to the received response.

[0187] Various embodiments of this specification can be implemented as software including instructions stored in a machine-readable storage medium. A machine as a device capable of calling instructions stored from a storage medium and operating in accordance with the called instructions may include an electronic device according to the disclosed embodiments. When instructions are executed by a processor, the processor may perform the function corresponding to the instructions directly or by using other components under the control of the processor. Instructions may include code generated or executed by a compiler or interpreter. The machine-readable storage medium may be provided in the form of a non-temporary storage medium, where “non-temporary storage medium” means that it does not contain signals and is tangible, but does not distinguish whether data is stored permanently or temporarily in the storage medium. For example, a non-temporary storage medium may include a buffer in which data is temporarily stored.

[0188] According to one embodiment, the methods according to the various embodiments disclosed herein may be provided as part of a computer program product. The computer program product may be sold as a commodity between a seller and a buyer. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., a compact disk read-only memory, a CD-ROM) or online through an application store (e.g., the Play Store®). In the case of online distribution, at least a portion of the computer program product, e.g., a downloadable app, may be at least temporarily stored or temporarily created in a storage medium such as the memory of a manufacturer's server, an application store server, or an intermediary server.

[0189] Although embodiments have been described with limited embodiments and drawings, those skilled in the art can make various modifications and variations from the above description. For example, the described techniques may be performed in a different order than the described methods, and / or the described components such as systems, structures, devices, and circuits may be combined or joined in a different manner than the described methods, or replaced or substituted by other components or equivalents, and satisfactory results may still be achieved.

[0190] Therefore, other embodiments, other forms, and equivalents to the claims also fall within the scope of the following claims.

Claims

1. A method for authenticating access to a device, A step of obtaining identification information of the control device from the control device; The steps of: executing the user login of the terminal to the authentication server; and obtaining user identification information of the terminal from the authentication server in response to the login; A step of generating authentication data based on the identification information and user identification information of the control device; and The step of sending the authentication data to the server that performs user authentication for the user of the terminal. Equipped with, The aforementioned server is different from the authentication server. method.

2. The step of obtaining the identification information of the control device from the control device is, The step of scanning the QR code displayed on the control device; The step of obtaining a QR code payload from the aforementioned QR code; and Step of obtaining the identification information of the control device from the QR code payload. The method according to claim 1, comprising:

3. The method according to claim 1, wherein the user identification information includes at least one of the following: the mobile phone number of the terminal, the name of the user, the email address of the user, and the SNS identification information of the terminal of the user.

4. The step of obtaining user identification information of the terminal from the authentication server is: The step of obtaining an access token from the authentication server in response to the aforementioned login; and Steps to acquire the user identification information based on the access token. The method according to claim 1, comprising:

5. The step of obtaining user identification information of the terminal from the authentication server includes the step of obtaining the user identification information of the terminal from the authentication server through the browser of the terminal, The step of transmitting the authentication data includes the step of transmitting the authentication data to the server through the browser. The method according to claim 4.

6. Steps include storing at least one of the access token or user identification information in the browser or access authentication application. The method according to claim 5, further comprising:

7. The step of obtaining user identification information of the terminal from the authentication server includes the step of obtaining the user identification information of the terminal from the authentication server through the terminal's access authentication application, The step of transmitting the authentication data includes the step of transmitting the authentication data to the server through the access authentication application. The method according to claim 4.

8. The step of receiving an installation prompt message for the access authentication application from the server; and Steps to install the access authentication application on the terminal in response to the installation prompt message. The method according to claim 7, further comprising:

9. A method for server access authentication, In the step of obtaining authentication data from the terminal, the authentication data is based on the identification information of a control device that controls a specific security area and the user identification information of the terminal, and the user identification information is obtained by the terminal from an authentication server different from the server; A step in which user authentication is performed to determine whether the user is permitted to access the aforementioned specific security area; A step of transmitting the user authentication result to the control device; The step of obtaining the re-verification result of the user authentication result from the control device; and Based on the results of the re-verification, the step of determining whether the user is permitted to access the specific security area. A method for providing this.

10. The step of performing user authentication includes a step of determining the validity of access schedule information. The access schedule information includes the user's accessible area and access time on the terminal. The method according to claim 9.

11. The method according to claim 10, wherein the user identification information and access schedule information are stored in the server in association with each other.

12. The method according to claim 11, wherein the access schedule information is obtained from an external device.

13. A program for causing a computer to perform the method described in claim 1.

14. A program for causing a computer to perform the method described in claim 9.

15. Communication module; and at least one processor A terminal equipped with, The aforementioned at least one processor is The control device acquires identification information of the control device from the control device, The user of the terminal logs in to the authentication server, and in response to the login, the user identification information of the terminal is obtained from the authentication server. Authentication data is generated based on the identification information and user identification information of the control device. The authentication data is sent to the server that performs user authentication for the user of the terminal. The aforementioned server is different from the authentication server. Terminal.

16. Communication module; and at least one processor A server equipped with, The aforementioned at least one processor is Authentication data is obtained from the terminal, and here, the authentication data is based on the identification information of a control device that controls a specific security area and the user identification information of the terminal, and the user identification information is obtained by the terminal from an authentication server different from the server. Perform user authentication to determine whether the user is permitted to access the aforementioned specific security area. The user authentication result is transmitted to the control device. The re-verification result of the user authentication is obtained from the control device. Based on the results of the re-verification, it is determined whether the user is permitted to access the specific security area. server.