Access control method, program, and first device
The access control system improves user convenience and security by enabling door operation based on user terminal tokens, addressing server vulnerabilities and enhancing emergency response.
Patent Information
- Application Number
- JP2024039620
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2017-09-05
- Filing Date
- 2024-03-14
- Publication Date
- 2025-09-03
- Estimated Expiration
- 2038-09-04
AI Technical Summary
Conventional access control systems face issues with user convenience and security, requiring separate authentication devices, potential loss of authentication means leading to unauthorized access, and vulnerability due to server communication failures.
An access control method where door operating devices determine door access based on authentication tokens from user terminals without server intervention, allowing doors to open if the token is valid, and enabling token updates during emergencies.
Enhances user convenience and security by allowing authorized access without additional authentication and maintaining access even during server failures, while managing legitimate use and improving evacuation assistance.
Smart Images

Figure 0007733363000001 
Figure 0007733363000002 
Figure 0007733363000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an access control system and an access control method using the same. [Background technology]
[0002] An access control system is a system that recognizes and manages visitors who attempt to enter a specific space through a door. Access control systems are widely used in general offices and residential buildings, as well as in high-security restricted access facilities.
[0003] Conventional authentication methods used by such access control systems include authentication methods using magnetic cards, smart cards, contactless smart cards, etc., and authentication methods using biometric information such as a visitor's fingerprints and iris.
[0004] In such conventional authentication methods, a visitor can only access the door after authenticating through an authentication device installed near the door. As mentioned above, authentication must be performed through a separate authentication device. Therefore, when there are multiple visitors, authentication takes time. Another drawback is that the user must always carry a separate authentication means such as a magnetic card. Furthermore, if such authentication means is lost, an unauthorized visitor who has obtained the separate authentication means illegally can gain access to the door.
[0005] Furthermore, in conventional authentication methods, authentication is performed only by a control server that collectively manages authentication devices installed near the door. Therefore, if communication between the control server and the authentication devices installed near the door is interrupted or if a problem occurs in the control server, the door becomes inaccessible.
[0006] In recent years, in order to eliminate such drawbacks, attempts have been made to improve user convenience and further enhance the security of access control systems. Summary of the Invention [Problem to be solved by the invention]
[0007] An object of the present invention is to provide an access control system and an access control method using the same that can improve user convenience while also enhancing security.
[0008] The technical problems solved by the present invention are not limited to the problems described above, and other technical problems not described in this specification will be clearly understood by those skilled in the art from the following description and the accompanying drawings.
[0009] According to an aspect of the present invention, there is provided an access control method in which a door operating device determines whether to open a door based on an authentication token acquired from a user terminal without intervention of an authentication server, the access control method comprising the steps of: acquiring the authentication token from the user terminal; determining whether the user has authority to access the door based on authentication information included in the authentication token; and controlling the door to open if it is determined that the user has authority to access the door.
[0010] According to another aspect of the present invention, there is provided an access control method, the access control method including: a first door operation device provided on a first door of a plurality of doors acquiring an authentication token from a user terminal; the first door operation device determining, based on authentication information included in the authentication token, whether the user terminal has authority to access the first door; and the first door operation device unlocking the first door if the user terminal has authority to access the first door; a second door operation device provided on a second door of the plurality of doors acquiring an authentication token from the user terminal; the second door operation device determining, based on the authentication information included in the authentication token, whether the user terminal has authority to access the second door; and the second door operation device unlocking the second door if it is determined that the user terminal has authority to access the second door.
[0011] According to yet another aspect of the present invention, there is provided a non-transitory recording medium having a program recorded thereon for executing the above method.
[0012] According to yet another aspect of the present invention, there is provided a door operation device configured to determine whether to open a door based on an authentication token obtained from a user terminal without the intervention of an authentication server, the door operation device comprising: a door communication unit configured to obtain the authentication token from the user terminal; a door drive unit configured to provide power required to open the door; and a door control unit configured to determine whether the user terminal has authority to access the door based on authentication information included in the authentication token, and configured to control the door drive unit to open the door when it is determined that the user terminal has authority to access the door.
[0013] The present invention provides increased user convenience by allowing authorized doors to be opened without additional authentication as long as the authentication token is valid.
[0014] Furthermore, according to the present invention, even if a failure occurs in the authentication server or in communication between the authentication server and the door opening unit, the authorized door can be opened as long as the authentication token is valid, thereby improving user convenience.
[0015] Furthermore, according to the present invention, legitimate use by users can be managed by taking into consideration access status information regarding entry or exit.
[0016] Furthermore, according to the present invention, when a specific event such as a disaster occurs, the authentication token is forcibly updated, thereby enabling quicker and more accurate assistance to the user in evacuating.
[0017] Furthermore, according to the present invention, by allowing the use of electronic devices in consideration of entry into a specific space, it is possible to improve security against unauthorized use of electronic devices.
[0018] The effects of the present invention are not limited to those described above, and other effects not described in this specification will be apparent to those skilled in the art from the following description and the accompanying drawings. [Brief explanation of the drawings]
[0019] [Figure 1] 1 is a block diagram of an access control system according to an embodiment of the present invention.
[0020] [Figure 2] FIG. 2 is a block diagram of an authentication server according to an embodiment of the present invention.
[0021] [Figure 3] FIG. 2 is a block diagram of a terminal according to an embodiment of the present invention.
[0022] [Figure 4] 1 is a block diagram of a door operating device according to an embodiment of the present invention;
[0023] [Figure 5] FIG. 2 is an exemplary diagram of a table illustrating the data structure of information included in an authentication token according to an embodiment of the present invention.
[0024] [Figure 6] 1 is a flowchart of a user registration method according to an embodiment of the present invention.
[0025] [Figure 7] 1 is a flowchart of an authentication token issuing method according to an embodiment of the present invention.
[0026] [Figure 8] 1 is a diagram showing an overall view of a door opening control method according to an embodiment of the present invention;
[0027] [Figure 9] 3 is a flowchart of a door opening control method according to an embodiment of the present invention.
[0028] [Figure 10] 1 is a diagram showing an overview of an access state management method according to an embodiment of the present invention;
[0029] [Figure 11] 1 is a flowchart illustrating an access state management method according to an embodiment of the present invention.
[0030] [Figure 12] FIG. 10 is a sequence diagram showing a first modified example of the access state management method according to the embodiment of the present invention.
[0031] [Figure 13] FIG. 10 is a sequence diagram showing a second modified example of the access state management method according to the embodiment of the present invention.
[0032] [Figure 14] FIG. 10 is a sequence diagram showing a third modified example of the access state management method according to the embodiment of the present invention.
[0033] [Figure 15] FIG. 10 is a sequence diagram showing a fourth modified example of the access state management method according to the embodiment of the present invention.
[0034] [Figure 16] FIG. 10 is a sequence diagram showing a fifth modified example of the access state management method according to the embodiment of the present invention.
[0035] [Figure 17] FIG. 10 is a diagram showing an overall view of a door having a layered structure according to a sixth modified example of the present invention.
[0036] [Figure 18] FIG. 10 is a sequence diagram showing a sixth modified example of the access state management method according to the embodiment of the present invention.
[0037] [Figure 19] 1 is a diagram showing an overview of a method for forcibly changing authority according to an embodiment of the present invention;
[0038] [Figure 20] FIG. 1 is a sequence diagram illustrating a method for forcibly changing authority according to an embodiment of the present invention.
[0039] [Figure 21] 1A to 1C are exemplary diagrams illustrating the operation of a door operating device according to an embodiment of the present invention in a normal situation and in a situation where a special event occurs.
[0040] [Figure 22] 1 is a diagram showing an overview of a coordinated domain security method according to an embodiment of the present invention;
[0041] [Figure 23] FIG. 2 is a sequence diagram showing an area cooperation security method according to an embodiment of the present invention.
[0042] [Figure 24] FIG. 10 is a sequence diagram showing a first modified example of the area cooperation security method according to the embodiment of the present invention.
[0043] [Figure 25] 10 is a flowchart showing a second modified example of the area cooperation security method according to the embodiment of the present invention.
[0044] According to an aspect of the present invention, there is provided an access control method in which a door operating device determines whether to open a door based on an authentication token acquired from a user terminal without intervention of an authentication server, the access control method comprising the steps of: acquiring the authentication token from the user terminal; determining whether the user has authority to access the door based on authentication information included in the authentication token; and controlling the door to open if it is determined that the user has authority to access the door. DETAILED DESCRIPTION OF THE INVENTION
[0045] The above objects, features, and advantages of the present invention will become more apparent from the following detailed description taken in conjunction with the accompanying drawings. However, the present invention is susceptible to various modifications and may have several embodiments. Accordingly, specific embodiments will be shown and described with reference to the accompanying drawings.
[0046] In the drawings, the thickness of layers and regions are exaggerated for clarity. Also, when a component or layer is referred to as being "on" another component or layer, the component or layer may be formed directly on the other component or layer, or a third component or layer may be interposed therebetween. Like reference numerals refer to like components throughout this specification. Also, the same reference numerals are used to designate components having the same scope and function as shown in the drawings of each embodiment.
[0047] In addition, detailed descriptions of well-known functions or configurations related to the present invention will be omitted so as not to unnecessarily obscure the subject matter of the present invention. It should also be noted that although ordinal numbers (such as first and second) are used in the following description, they are merely used to distinguish between similar components.
[0048] The suffixes "module" and "section" used in the following description are used interchangeably solely to facilitate the description of this specification, and therefore no specific meaning or function is assigned to them.
[0049] 1. Definition of Terms The terms used in this specification are defined as follows.
[0050] (1) Door A door may prevent or allow access to an area. A door may include a door frame and a door body. The door frame may be a fixed component that defines an area where passage is prevented or allowed. The door body is a component whose position changes due to an external force. Depending on its position, the location where passage is prevented or allowed may change. The change in position of the door body may have a comprehensive meaning including rotational movement and movement of the entire door body. In this specification, such a door frame and door body are collectively referred to as a door. Therefore, in this specification, the movement and change in position of a door may refer to the movement and change in position of the door body.
[0051] (2) Door Closed / Open State The door closed state may refer to a state in which the door body is in a position that prevents passage through the area defined by the door frame. The door open state may refer to a state in which the door body is in a position that ensures space for passage through the area defined by the door frame. A change in door state as used herein may refer to at least one of a change from an open state to a closed state and a change from a closed state to an open state.
[0052] The door closing operation may refer to the process of moving the door body from an open position to a closed position, and the door opening operation may refer to the process of moving the door body from a closed position to an open position.
[0053] In addition, in this specification, the open and closed states of the door may include a state in which the door can be opened by a change in position corresponding to an unlocking operation and movement of the door body, and a state in which the door cannot be opened. Therefore, in some embodiments of the present invention, the closed state of the door may refer to a state in which the door is locked, and the open state of the door may refer to a state in which the door is unlocked.
[0054] In an embodiment of the present invention, opening and closing the door and locking and unlocking the door may be independent of each other.
[0055] For example, even if the door is not closed, the locking unit may provide an obstacle. As another example, even if the door is unlocked, the door body may be placed in the closed position. Therefore, the closed state of the door is not necessarily limited to the locked state, and the open state of the door is not necessarily limited to the unlocked state.
[0056] (3) Locking / Unlocking Doors Locking and unlocking may relate to whether a door can be opened.
[0057] The locked state of the door may indicate that an external force or an obstacle has been applied, preventing the door from being opened. The unlocked state of the door may indicate that the applied external force or obstacle has been removed, allowing the door to be opened.
[0058] Additionally, a door locking operation may refer to the process of providing an external force and / or an obstacle to prevent the door from being opened, and a door unlocking operation may refer to the process of removing the provided external force and / or an obstacle so that the door can be opened.
[0059] (4) Access: Access may refer to a user passing through a space defined by a door frame. Access may include entry, where a user holding a terminal moves from the outside to the inside of the door, and exit, where a user holding a terminal moves from the inside to the outside of the door.
[0060] (5) Inside / Outside of Door The inside of a door may refer to an area where unauthorized persons are restricted from entering through the door, while the outside of a door may refer to the opposite side of the inside of the door. For example, according to an embodiment of the present disclosure, an authorized user with access to a particular door can enter the door from the outside to the inside. However, according to an embodiment of the present disclosure, an unauthorized person without access cannot enter the door from the outside to the inside.
[0061] (6) Token. As used herein, a token may be data in a predetermined format that contains at least some information used in an access control system. Herein, tokens may be classified into authentication tokens, refresh tokens, and the like, depending on their intended use. Authentication tokens and refresh tokens may be the same type but contain different information. However, authentication tokens and refresh tokens do not necessarily have to always be in the same format. Depending on the embodiment, authentication tokens and refresh tokens may be provided in different formats. Herein, token types may be classified into authentication tokens and refresh tokens, for example, depending on their intended use. The token format may be any format determined by the service provider and may include formats such as JSON Web Token (JWT), Security Assertion Markup Language (SAML), and Extensible Rights Markup Language (XrML).
[0062] (7) User Identification Information The user identification information may be information that allows the access control system 10000 to identify a specific user from among multiple users. For example, the user identification information may be identification information that is uniquely assigned to a user, such as an ID.
[0063] (8) User Information The user information may be information used to generate the user identification information described above. For example, the user information may be personal information of the user, such as a resident registration number, date of birth, address, employee identification number, and telephone number, which are typically required for user authentication.
[0064] (9) Terminal Identification Information The terminal identification information may be information for identifying a specific user terminal among multiple user terminals. For example, the terminal identification information may include at least one of a universally unique identifier (UUID), a unique identifier (UID), an IP address, a MAC address, a CPU (MCU) serial number, a HDD serial number, and a communication number of the terminal.
[0065] (10) Door Identification Information The door identification information may be information used to identify a specific door among multiple doors. For example, the door identification information may be at least one of identification field information assigned to the door and identification field information assigned to the door operating device. The door identification information may be stored in a door storage unit. Also, according to some embodiments of the present invention, the door authentication information may be included in an authentication token.
[0066] 2. System Configuration FIG. 1 is a block diagram of an access control system 10000 according to an embodiment of the present invention.
[0067] Referring to FIG. 1, the access control system 10000 may include an authentication server 1000, a terminal 2000, a door operation device 3000, a door 4000, and a third-party authentication server 5000.
[0068] The authentication server 1000 may be connected to an external electronic device. Hereinafter, a specific device being connected to another device may at least indicate that the specific device is at least physically, electrically, or communicatively connected to another device. In the above example, the authentication server 1000 being connected to the external electronic device indicates that the authentication server 1000 and the external electronic device are communicatively connected to each other. This may mean, for example, that the authentication server 1000 and the external electronic device can send and receive data to and from each other.
[0069] According to some embodiments of the present invention, the authentication server 1000 may be connected to a terminal 2000. Also, according to some embodiments of the present invention, the authentication server 1000 may be connected to a third-party authentication server 5000. Although not shown in Figure 1, according to some embodiments of the present invention, the authentication server 1000 may be connected to an office-specific electronic device 6000, a hotel controller 7000, or the like. According to embodiments of the present invention, the authentication server 1000 may perform authentication.
[0070] The authentication server 1000 may perform authentication on the user of the terminal 2000. Alternatively, the authentication server 1000 may perform authentication on the terminal 2000 itself.
[0071] The terminal 2000 may be connected to the authentication server 1000 and the door operation device 3000. The terminal 2000 may provide the authentication server 1000 with data necessary for user registration and authentication. The terminal 2000 may also transmit data necessary for making a request to open the door to the door operation device 3000, and may obtain data related to the result of the open request from the door operation device 3000. The terminal 2000 may also transmit and receive various types of data to and from the authentication server 1000 and the door operation device 3000.
[0072] The terminal 2000 may also provide applications for executing some embodiments, as described below.
[0073] The terminal 2000 may also be, for example, a smartphone, a tablet, a notebook, a wearable device, etc. As another example, the terminal 2000 may be a smart card, an integrated circuit (IC) card, a magnetic card, and a radio frequency (RF) chip.
[0074] Furthermore, the terminals 2000 may be classified into a user terminal 2000a and an administrator terminal 2000b according to their roles.
[0075] The door operating device 3000 may control the opening and closing of the door 4000 .
[0076] For example, the door operation device 3000 may be installed inside the door 4000 and control the locking or unlocking of the door 4000. The door operation device 3000 does not necessarily have to be installed inside the door, and may be selectively provided in various forms. For example, the door operation device 3000 may be installed on a wall adjacent to the door so as to be or not to be an obstacle to the door. Furthermore, if the door 4000 is an automatic door, the door operation device 3000 may change the position of the door body to open or close the door 4000.
[0077] Door 4000 may also prevent or allow access to an area.
[0078] The state of the door 4000 may also be variable by the door operating device 3000.
[0079] According to some embodiments of the present invention, multiple door operation devices 3000 may be connected to each other. For example, as shown in FIG. 1, a first door operation device 3000a and a second door operation device 3000b may be connected to each other. Also, a greater number of door operation devices 3000 than the number shown in FIG. 1 may be connected to each other. All of the multiple door operation devices 3000 do not necessarily need to be connected to each other, and may be connected in series. For example, the first door operation device 3000a may be connected to the second door operation device 3000b, and the second door operation device 3000b may be connected to a third door operation device (not shown). In some cases, multiple door operation devices 3000 may be connected in parallel to one door operation device 3000. The connection between the multiple door operation devices 3000 is not limited to the above example, and may be selectively provided in various forms.
[0080] Also, the connection between the multiple door operating devices 3000 is not essential. According to some embodiments of the present invention, the multiple door operating devices 3000 may not be connected to each other.
[0081] However, the block diagram shown in Figure 1 is intended to be an example for ease of explanation only, and is not intended to be limiting. According to some embodiments of the present invention, elements may be added to the block diagram of Figure 1, or elements shown in Figure 1 may be omitted or divided.
[0082] FIG. 2 is a block diagram of an authentication server 1000 according to an embodiment of the present invention.
[0083] Referring to FIG. 2, the authentication server 1000 may include a server communication unit 1100, a server input unit 1200, a server storage unit 1300, a server display unit 1400, and a server control unit 1500.
[0084] The server communication unit 1100 may connect the authentication server 1000 to an external electronic device. That is, the server communication unit 1100 may transmit or receive data to or from the external electronic device. Furthermore, the server communication unit 1100 may maintain or disconnect a communication connection with the terminal 2000 as necessary. Furthermore, depending on the embodiment, the server communication unit 1100 may be configured to periodically maintain a connection to the terminal 2000.
[0085] The server communication unit 1100 may also be a communication module for supporting at least one of a wired communication method and a wireless communication method.
[0086] The server input unit 1200 may acquire electrical signals corresponding to user inputs. For example, the server input unit 1200 may include a keypad, a keyboard, a switch, a button, and a touch screen.
[0087] The server storage unit 1300 may store data.
[0088] For example, the server storage unit 1300 may store data acquired from the terminal 2000. As another example, the server storage unit 1300 may store a program necessary for the authentication server 1000 to operate.
[0089] The server display unit 1400 may output visual information.
[0090] For example, server display 1400 may be a liquid crystal display (LCD), an organic light emitting diode (OLED) display, an active matrix organic light emitting diode (AMOLED) device, or the like.
[0091] The server control unit 1500 may process the operations of the authentication server 1000 collectively.
[0092] The authentication server 1000 according to the present invention does not necessarily have all of the above-described elements, and some of the elements may be selectively omitted. For example, if the authentication server 1000 does not provide direct visual information, the server display unit 1400 may be omitted from the authentication server 1000. Furthermore, elements that perform additional functions or operations may be selectively provided in the authentication server 1000.
[0093] FIG. 3 is a block diagram of a terminal 2000 according to an embodiment of the present invention.
[0094] Referring to FIG. 3, the terminal 2000 may include a terminal communication unit 2100 , a terminal display unit 2200 , a terminal input unit 2300 , a location information collection unit 2400 , a terminal storage unit 2500 , and a terminal control unit 2600 .
[0095] The terminal communication unit 2100 may connect the terminal to external electronic devices. For example, the terminal communication unit 2100 may connect the user terminal 2000a to external electronic devices such as the authentication server 1000, the door operation device 3000, and the third-party authentication server 5000. The terminal communication unit 2100 may also be a communication module for supporting wired and / or wireless communication.
[0096] The terminal display unit 2200 may output visual information.
[0097] When the terminal display unit 2200 may be provided as a touch screen, the terminal display unit 2200 may function as the terminal input unit 2300. In this case, a separate terminal input unit 2300 may not be selectively provided, and the terminal input unit 2300 may be configured to perform limited functions using buttons such as a volume control button, a power button, and a home button.
[0098] The terminal input unit 2300 may acquire a signal corresponding to a user input.
[0099] The terminal input unit 2300 may be implemented as, for example, a keyboard, a keypad, a button, a jog dial, or a wheel.
[0100] The user input may also be, for example, a button press, a touch, or a drag.
[0101] If the terminal display unit 2200 is provided as a touch screen, the terminal display unit 2200 may function as the terminal input unit 2300 .
[0102] The location information collector 2400 may obtain location information that it uses to determine the location of the terminal 2000. For example, the location information collector 2400 may be a module configured to obtain coordinate information for performing location determination, such as a GPS module.
[0103] The terminal storage unit 2500 may store data.
[0104] The terminal storage unit 2500 may be implemented as, for example, a flash memory, a random access memory (RAM), a read-only memory (ROM), a solid-state drive (SSD), a secure digital (SD) card, or an optical disk.
[0105] The terminal storage unit 2500 may store data necessary for the operation of the terminal 2000 .
[0106] The terminal control unit 2600 may process the operations of the terminal 2000 collectively.
[0107] FIG. 4 is a block diagram of a door operating device 3000 according to an embodiment of the present invention.
[0108] Referring to FIG. 4, the door operation device 3000 may include a door communication unit 3100, a door display unit 3200, a door audio output unit 3300, a door sensor unit 3400, a door memory unit 3500, a door drive unit 3600, and a door control unit 3700.
[0109] The door communication unit 3100 may be a communication module capable of communicating with an external electronic device.
[0110] The door communication unit 3100 may connect the door operation device 3000 to the terminal 2000 .
[0111] The door communication unit 3100 may establish communication via a wireless communication method. For example, the door communication unit 3100 may be a communication module configured to support wireless Internet interfaces such as Wireless LAN (WLAN), Wireless Fidelity (WiFi), and WiFi Direct, as well as wireless communication methods such as Bluetooth (registered trademark), Bluetooth (registered trademark) Low Energy (BLE), and Infrared Data Association (IrDA). The door communication unit 3100 may also be a reader capable of reading information from an external electronic device, such as an RF reader, an IC reader, and a magnetic reader.
[0112] The door display unit 3200 may output visual information.
[0113] The door display unit 3200 may output information that is visually provided to the user. If the door display unit 3200 includes a touch panel, the door display unit 3200 may operate as a touch input device.
[0114] The door audio output unit 3300 may output information that is provided audibly to the user.
[0115] For example, the door audio output unit 3300 may be a speaker and a buzzer configured to output a sound.
[0116] The door sensor unit 3400 may acquire an external environmental signal necessary for the door operation device 3000. For example, the door sensor unit 3400 may acquire a signal related to the distance from a user or an object, etc. As another example, the door sensor unit 3400 may acquire a signal necessary to determine the position of the door body.
[0117] The door memory unit 3500 may store a program for executing the control operation of the door control unit 3700, and may also store data received from an external source, data generated by the door control unit 3700, etc.
[0118] The door drive unit 3600 may provide the power required to lock or unlock the door body. Also, if the door 4000 is implemented as an automatic door, the door drive unit 3600 may provide the power required to open and close the door body.
[0119] The door drive 3600 may be provided as a motor, a solenoid, or an actuator.
[0120] When the door drive unit 3600 provides the power necessary to lock or unlock the door body, the door drive unit 3600 may also provide power to a lock (not shown) to maintain the lock or unlock state and / or change from the locked state to the unlocked state. The lock may be provided as a deadbolt, a latchbolt, or a combination thereof. Also, the lock is not limited to the deadbolt and latchbolt described above, and a typical lock may be used as the lock.
[0121] The door control unit 3700 controls the overall operation of the door operating device 3000 .
[0122] The door control unit 3700 may control the operations of some of the elements included in the door operation device 3000. The door control unit 3700 may also acquire signals from some of the elements included in the door operation device 3000. The door control unit 3700 may also control the operations for executing some of the steps executed by the door operation device 3000 among the steps described in the following methods, or may perform calculations necessary to execute the steps.
[0123] The access control system 10000 corresponding to various embodiments of the present invention, and the elements, operations, terminology, etc. included in the access control system 10000 have been described. The above-described access control system 10000, the elements, operations, terminology, etc. included in the access control system 10000 are applied to various methods and embodiments described below. However, it should be understood that the access control system 10000 described below does not necessarily have to be configured to have the above-described elements and functions, and may also be applied to access control systems with configurations different from the above-described access control system 10000.
[0124] 3. Authentication Token and Refresh Token Overview of Authentication Token An authentication token is data issued to an issue target by the authentication server 1000, and may be data that can be used to determine the authority granted to the issue target. Here, the issue target may include at least one of a user and a terminal 2000. The issue target may be classified into a user and a terminal 2000, but the authentication token may be issued by transmitting the authentication token to the terminal 2000.
[0125] The authentication token may contain various information, the information contained in the authentication token will be described in more detail below with reference to FIG.
[0126] FIG. 5 is an exemplary diagram of a table illustrating the data structure of information included in an authentication token according to an embodiment of the present invention.
[0127] Referring to Figure 5, an authentication token according to some embodiments of the present invention may include at least one of authentication information indicating the authority granted to the issuer, validity conditions, issuer information, and recipient information. However, Figure 5 is merely an example for ease of explanation, and the authentication token of the present invention is not limited thereto. Optionally, some of the information may be omitted, or various additional information may be added.
[0128] The various types of information that may be included in an authentication token are described in more detail below.
[0129] According to some embodiments of the present invention, the authentication token may include authentication information.
[0130] According to some embodiments of the present invention, the authentication information may be information used to determine whether the person to whom it is issued has access rights to a particular door among at least one or more doors 4000.
[0131] Additionally, in some embodiments of the present invention, the authentication information may be information used to determine whether the subject has access to a particular space among at least one or more spaces, and thus, if the subject is authorized for a space, the subject may also be authorized for anything provided within the space.
[0132] Additionally, according to some embodiments of the present invention, the authentication information may be information used to determine whether the issued subject has authorization to use a function or electronic device. Here, the function may relate to a service provided by the electronic device, and may include, for example, an email function, a web surfing function, and a function to use and edit a universal serial bus (USB) device. If authorization for this function is included in the authentication information, the authentication information may be used to determine whether the issued subject is authorized to view email, whether the issued subject is authorized to send email, whether the issued subject is authorized to use a USB port, etc. Additionally, the electronic device may be an office-specific electronic device such as a personal computer (PC), printer, or fax machine, or an electronic device such as a light, air conditioner, heater, or television used in a hotel room or residential room.
[0133] According to an embodiment, the authentication information may be generated based on the authority set for the issue target.
[0134] According to some embodiments of the present invention, the authentication server 1000 may store in advance the permissions set for the issuance target. The authentication server 1000 may acquire permission setting information indicating which permissions have been set for the issuance target from the administrator terminal 2000b, and set the permissions for the issuance target based on the acquired permission setting information. The permission setting information does not necessarily have to be acquired through the administrator terminal 2000b, but may be acquired in various ways depending on the embodiment. For example, the authentication server 1000 may acquire the permission setting information from the administrator via the server input unit 1200.
[0135] When the issuance target is a user, the authentication server 1000 may set authority for each pre-registered user and store the set authority. When the issuance target is a terminal 2000, the authentication server 1000 may set and store authority for each pre-registered terminal 2000.
[0136] The authority setting does not necessarily have to be performed individually for each issuance target, but may be selectively performed for each issuance target group. For example, if the issuance targets are grouped according to grade, a first type of authority may be set for all issuance targets grouped into grade A, and a second type of authority may be set for all issuance targets grouped into grade B.
[0137] The authentication information included in the authentication token may be determined based on the set permissions.
[0138] The authentication information according to some embodiments of the present invention may include information regarding authorization to access the door and / or authorization to use a function or electronic device.
[0139] When the authentication information is information regarding authority to access a door, the authentication information may include at least one of door identification information and an authority value.
[0140] The door identification information may include at least a portion of the door identification information included in a pre-stored door identification information list.
[0141] The authentication information may include authorized door identification information, or may include all door identification information registered with the authentication server 1000.
[0142] The authentication information may include an authorization value corresponding to the door identification information. The authorization value may be classified into a value indicating authorization and a value indicating no authorization. For example, as shown in FIG. 5, the authentication token may include "first door" which is the identification information of the first door, and an authorization value of "1" which indicates that authorization for the first door has been granted. As another example, as shown in FIG. 5, the authentication token may include "second door" which is the identification information of the second door, and an authorization value of "0" which indicates no authorization.
[0143] In some embodiments, the authority value of the authentication token may be omitted. In this case, when the door operation device 3000 receives the authentication token, the door operation device 3000 may determine whether the authorization token is authorized based on whether the authentication token includes identification information of the door operation device 3000 or the door 4000. For example, if the authentication token includes identification information of the door operation device 3000 that received the authentication token or identification information of the door 4000, the door operation device 3000 may determine that the authentication token is authorized.
[0144] The authentication information according to some embodiments may be information about the authority to use a function.
[0145] The authentication information may include authorized functions and electronic devices, or may include functions and electronic devices registered with the authentication server 1000.
[0146] In this case, as in the embodiment of the door operation device 3000, the authentication information may include identification information that identifies the function and the electronic device. The authentication information may also include an authorization value that indicates whether the function and the electronic device are authorized.
[0147] The authentication token may also include authentication validity conditions.
[0148] An authentication token may have a limited time period during which it is considered valid after it is issued. The time period until which the authentication token is valid may vary depending on authentication validity conditions.
[0149] According to some embodiments of the present invention, at least one of the terminal 2000 and the door operation device 3000 may determine whether the authentication token is valid. Furthermore, whether the authentication token is valid may be determined based on a validity condition.
[0150] The authentication token may further include authentication token status information indicating whether the authentication token is valid or expired. The authentication token status information may be changed depending on whether the authentication token is valid or expired.
[0151] According to some embodiments of the present invention, if it is determined that the authentication token has expired, the terminal 2000 may set the authentication token status information to expired. Also, according to some embodiments of the present invention, if it is determined that the authentication token has expired, the terminal 2000 may refuse to transmit the authentication token to the door operation device 3000.
[0152] The authentication validity conditions of an authentication token according to some embodiments of the present invention are described below as an example.
[0153] The authentication token validity conditions are conditions used to determine whether the authentication token is valid. The authentication validity conditions may include at least one of a validity period, a location of the user terminal, a number of uses, and a request from the authentication server. The authentication validity conditions may be provided as a combination of various conditions. In this case, the authentication token may be determined to be valid when all of the conditions are met. Alternatively, the authentication token may be determined to be valid when at least one of the conditions is met.
[0154] The validity conditions may be applied equally to all authentication tokens, or, depending on the selection, the validity conditions may be assigned differently to each issuer or grade.
[0155] The validity condition of an authentication token according to some embodiments of the present invention may be a validity period, which may indicate a predetermined period during which the authentication token may be valid. As an example, the validity period may start when the token is issued. The predetermined period may also be preset by the authentication server.
[0156] For example, an authentication token may include a validity period indicating that the authentication token has been valid for six hours from the time of issuance. The authentication token may also include time information regarding the time of issuance and information indicating how long the authentication token is valid from the time of issuance. The entity that determines the validity of the authentication token may determine whether the authentication token is valid based on whether the validity period has elapsed since the time of issuance relative to the current time at which the authentication token is determined to be valid. More specifically, assume that the authentication token was issued at midnight and the validity condition is that the current time is within six hours of the time of issuance. In this case, if the current time at which the authentication token is determined to be valid is 5:00 AM, the door operation device 3000 may determine that the authentication token is valid. If the current time at which the authentication token is determined to be valid is 7:00 AM, the door operation device 3000 may determine that the authentication token is invalid. Here, the validity determination entity is an element that determines whether the authentication token is valid, and may be at least one of the authentication server 1000, the terminal 2000, and the door operation device 3000.
[0157] As another example, an authentication token may include age information to determine how much time has passed since its issuance. A value corresponding to the age information may increase over time until a threshold indicating expiration is reached, at which point the authentication token is determined to have expired. Optionally, a value corresponding to the age information may decrease over time until a threshold is reached, at which point the authentication token is determined to have expired.
[0158] According to some embodiments of the present invention, a validity condition of an authentication token may be location.
[0159] If the validity condition is location, the authentication token may be valid only in a predetermined location. That is, if the user terminal is outside the predetermined location, the authentication token may be determined to have expired. If the validity condition is location, it may be determined whether the authentication token is valid based on location information acquired from the location information collection unit 2400.
[0160] If the determining entity is the authentication server 1000 and the door operation device 3000, rather than the terminal 2000, the terminal 2000 may provide location information to the determining entity, allowing the determining entity to determine whether the authentication token is valid based on the location information of the terminal 2000. The location information may be at least one of the location of the terminal at the time the authentication token was issued and the current location of the terminal.
[0161] For example, if the location range included in the validity conditions is within 100 m from the company building and the location at which the authentication token was issued is outside the location range included in the validity conditions, the door operation device 3000 may determine that the authentication token is not valid.
[0162] As another example, if the location range included in the validity condition is within 100 m from the company building, the door operation device 3000 may compare the location information acquired from the terminal 2000 with the location range included in the validity condition. If the acquired location information is outside the location range included in the validity condition, the door operation device 3000 may determine that the authentication token is invalid.
[0163] As yet another example, if it is determined that the current location information is outside the location range included in the validity conditions, the terminal 2000 may determine that the authentication token has expired and change the state of the authentication token to an expired state.
[0164] The location range included in the validity condition may be assigned differently for each issuance object or each grade.
[0165] The predetermined location may refer to a single point, or may refer to a specific area based on the predetermined location. For example, as shown in Figure 5, if the validity condition is a location, the validity condition may include a range of location information.
[0166] According to some embodiments of the present invention, the validity condition of an authentication token may be a number of uses. Here, using an authentication token may indicate that the authentication token is sent to a service provider. Alternatively, using an authentication token may indicate that the authentication token is sent to a service provider and then authorization is received. If the validity condition is a number of uses, the authentication token may be valid for a predetermined number of uses. That is, the authentication token may be determined to have expired when the predetermined number of uses is exceeded or reached. Furthermore, the authentication token may include information for determining the number of uses. The information for determining the number of uses is not necessarily included in the authentication token, but may be provided as separate information.
[0167] For example, it is assumed that the validity condition is set to five uses. If the authentication token is transmitted to the door operation device 3000 five times, the authentication token may be determined to have expired.
[0168] As another example, assume a validity condition is seven uses: if the authentication token is transmitted to the door operation device 3000 seven times, the authentication token may be determined to have expired.
[0169] As yet another example, assume a validity condition is three uses: If an authentication token is sent to the door operation device 3000 but access authentication fails (e.g., a rejection message is received three times), the authentication token may be determined to have expired.
[0170] According to some embodiments of the present invention, the authentication token may include access state information.
[0171] The access state information may be information for determining whether a user has entered or exited. Various embodiments relating to access state information are described in detail in Section 4.2 entitled "Access State Management Method."
[0172] According to some embodiments of the present invention, the authentication token may include issuer information.
[0173] The issuer information may be identification information for identifying the authentication server 1000 that issued the authentication token. The issuer information may be identification information for identifying the service provider that operates the authentication server 1000 that issued the authentication token. The issuer information may be used to determine whether the authentication token was issued by an authorized issuer.
[0174] According to some embodiments of the present invention, the authentication token may include recipient information.
[0175] The authentication token may be issued to the user and / or the terminal 2000 .
[0176] Therefore, the recipient information may be information for identifying the person who issued the authentication token. Here, the recipient information may include at least one of user identification information and terminal identification information.
[0177] According to some embodiments of the present invention, the authentication token may include authentication token state information.
[0178] The authentication token status information may be information indicating whether the authentication token is valid or has expired.
[0179] 3.2 Issuing an Authentication Token 3.2.1 User Registration (User Registration and Authority Setting) A user registration method according to an embodiment of the present invention will be described below with reference to FIG.
[0180] User registration, which will be explained below, involves registering in the authentication server 1000 information about at least one of the user who uses the access control system 10000 and the user terminal 2000a that the user intends to use.
[0181] FIG. 6 is a flowchart of a user registration method according to an embodiment of the present invention.
[0182] Referring to FIG. 6, a user registration method according to an embodiment of the present invention may include a step of acquiring user information (S100), a step of registering the user information (S110), and a step of setting authority for the user information (S120).
[0183] According to some embodiments of the present invention, registration of user information may be performed (S110). The acquisition of user information may be performed by the authentication server 1000 acquiring at least one of user information and terminal identification information.
[0184] The authentication server 1000 may obtain user information in various ways.
[0185] The authentication server 1000 may acquire the user information from the user terminal 2000a. Alternatively, the authentication server 1000 may acquire the user information from the third-party authentication server 5000.
[0186] When the authentication server 1000 acquires user information from the user terminal 2000a, the authentication server 1000 may receive and acquire the user information from the user terminal 2000a. For example, the user terminal 2000a may receive and acquire user information from the user of the user terminal 2000a, and may transmit the acquired user information to the authentication server 1000.
[0187] When the authentication server 1000 acquires user information from a third-party authentication server 5000 designated by a user, the authentication server 1000 may acquire information about the third-party authentication server 5000 to which the user information is provided from the user terminal 2000a. The authentication server 1000 may acquire the user information by requesting the third-party authentication server 5000 to provide the user information.
[0188] The above-described user information acquisition is merely an example for the purpose of simplifying the explanation, and various typical methods for providing user information may be used.
[0189] Additionally, according to some embodiments of the present invention, registration of the obtained user information may be performed (S110). The registration of the user information may be initiated by the authentication server 1000. The registration of the user information may include assigning a unique user identification to the issue target, matching the user identification information to the user information, and storing the user identification information matched to the user information.
[0190] The user information assigned to the user information issuance target registration may be arbitrarily determined by the authentication server 1000. Furthermore, the authentication server 1000 may assign user identification information requested by the user terminal 2000a to the issuance target.
[0191] The authentication server 1000 may transmit the user identification information to the user terminal 2000a so that the user can recognize the user identification information.
[0192] The authentication server 1000 may also set a security key corresponding to the user identification information. The security key corresponding to the user identification information may be acquired from the user terminal 2000a. The security key corresponding to the user identification information may also be generated and acquired by the authentication server 1000. When the security key is generated and set by the authentication server 1000, the authentication server 1000 may also transmit the set security key to the user terminal 2000a so that the user can recognize the security key.
[0193] According to some embodiments of the present invention, the setting of authority for the registered user information may be performed (S120). The setting of authority for the user information may be initiated by the authentication server 1000.
[0194] The authorization may be based on authorization setting information, such as the authentication token outlined above.
[0195] The authentication server 1000 may store user information and authentication information corresponding to the user information.
[0196] 3.2.2 User Authentication and Token Issuance With reference to FIG. 7, a user authentication and token issuance method according to an embodiment of the present invention will now be described.
[0197] FIG. 7 is a flowchart of an authentication token issuing method according to an embodiment of the present invention.
[0198] Referring to FIG. 7, the authentication token issuance method may include a step of obtaining authentication token issuance request information (S200), a step of performing user authentication (S210), a step of generating an authentication token (S220), and a step of sending the authentication token to a user terminal (S230).
[0199] According to some embodiments of the present invention, obtaining authentication token issuance request information may be performed (S200). The obtaining of the authentication token issuance request information may include the authentication server 1000 obtaining the authentication token issuance request information from the user terminal 2000a.
[0200] The authentication token issuance request information may include user identification information and a security key.
[0201] Therefore, the authentication server 1000 may obtain the user identification information and the security key from the user terminal 2000a.
[0202] According to some embodiments of the present invention, user authentication may be performed (S210).
[0203] The authentication server 1000 may determine whether the user of the user terminal 2000a requesting the issuance of an authentication token is authorized.
[0204] The authentication server 1000 may determine whether the user is authorized based on whether the acquired user identification information and the security key corresponding to the user identification information are valid.
[0205] The authentication server 1000 may determine whether the user identification information acquired from the user terminal 2000a and the security key corresponding to the user identification information are valid.
[0206] If the user identification information acquired from the user terminal 2000a has been registered in advance, the authentication server 1000 may determine that the acquired user identification information is valid.
[0207] Additionally, if the acquired security key corresponds to a security key that has been stored and matched to the user identification information, the authentication server 1000 may determine that the security key is valid.
[0208] If the acquired user identification information and security key are valid, the authentication server 1000 may determine that the user is authorized.
[0209] Additionally, the authentication server 1000 may obtain at least one of user information, user identification information, and a security key from the third-party authentication server 5000 to determine whether the user is authorized.
[0210] Additionally, the authentication server 1000 may obtain an authentication result from a third-party authentication server 5000 to determine whether the user is authorized.
[0211] If it is determined that the user is not authorized, the authentication server 1000 may send a message to the user terminal 2000a indicating that the authentication has failed.
[0212] According to some embodiments of the present invention, generation of an authentication token may be performed (S220).
[0213] If the user is authorized, the authentication server 1000 may generate an authentication token to be sent to the user terminal 2000a. The authentication server 1000 may generate the authentication token based on the authentication information assigned to the user identification information.
[0214] According to some embodiments of the present invention, sending of an authentication token to the user terminal 2000a may be performed (S230).
[0215] The authentication server 1000 may transmit the generated authentication token to the user terminal 2000a. Alternatively, the authentication server 1000 may generate an update token corresponding to the authentication token and transmit the generated update token to the user terminal 2000a.
[0216] 3.3 Refreshing Tokens 3.3.1 Refresh Tokens As mentioned above, an authentication token may be determined to be valid or expired depending on predetermined conditions.
[0217] That is, conditions may be placed on an authentication token as to how long or under what conditions it is valid, and if the validity conditions are not met, the authentication token will need to be renewed or reissued.
[0218] According to some embodiments of the present invention, a refresh token may be used to refresh an authentication token. A refresh token may be used to refresh an authentication token with a new authentication token at or before its expiration. If there is no refresh token and the authentication token has expired, the authentication token may need to be regenerated to reissue the authentication token. To eliminate this inconvenience, a refresh token may be used to issue a new authentication token. As long as the refresh token is valid, a separate authentication is not required. This improves user convenience.
[0219] The refresh token may include a refresh token identification, a refresh condition, an authentication token identification for a corresponding authentication token, and a validity condition for the refresh token.
[0220] The update token identification information may be information for identifying a plurality of issued update tokens.
[0221] The renewal conditions may be the conditions for renewing the authentication token. Renewal conditions are described in more detail in Section 3.3.2 entitled "Renewing an Authentication Token."
[0222] The corresponding authentication token identification information may be the identification information of the authentication token that is updated via the update token.
[0223] The refresh token may include validity conditions.
[0224] For example, a refresh token may have a limited time period during which the refresh token is issued and is considered valid. The time at which the refresh token is valid may vary depending on the validity conditions.
[0225] The validity conditions for the update token may be the time elapsed since issuance, the number of updates, the location of the user terminal, a request from the authentication server, or the like.
[0226] The validity conditions of the refresh token may be applied to the validity conditions of the authentication token.
[0227] According to some embodiments of the present invention, the validity condition of the refresh token may be the amount of time that has elapsed since the time of issuance.
[0228] For example, the refresh token may include a validity period indicating that the refresh token has been valid for six hours from the time of issuance. The refresh token may include time information regarding the time of issuance and information regarding how long the refresh token is valid from the time of issuance. The entity that determines the validity of the refresh token may determine whether the refresh token is valid based on whether the validity period has elapsed since the time of issuance at the current time at which the validity of the refresh token is determined. More specifically, assume that the refresh token was issued at midnight and the validity condition is that the current time is within six hours from the time of issuance. In this case, if the current time at which the validity of the refresh token is determined is 5:00 AM, the terminal 2000 may determine that the refresh token is valid. If the current time at which the validity of the refresh token is determined is 7:00 AM, the terminal 2000 may determine that the refresh token is invalid. Here, the validity determination entity is an element that determines whether the refresh token is valid and may be at least one of the authentication server 1000, the terminal 2000, and the door operation device 3000.
[0229] As another example, the refresh token may include age information to determine how much time has passed since it was issued. The value corresponding to the age information may increase over time until a threshold indicating expiration is reached, at which point the refresh token is determined to have expired. Optionally, the value corresponding to the age information may decrease over time until a threshold is reached, at which point the refresh token is determined to have expired.
[0230] According to some embodiments of the present invention, the validity condition of the refresh token may be the number of refreshes.
[0231] For example, assume that the validity condition is five refreshes. If the refresh token has been sent to the authentication server 1000 five times, the refresh token may be determined to have expired.
[0232] As another example, assume the validity condition is seven refreshes: If the refresh token is sent to authentication server 1000 seven times, and thus the authentication token is refreshed seven times, the refresh token may be determined to have expired.
[0233] As yet another example, assume a validity condition is three refreshes. If the refresh token is sent to authentication server 1000 three times and a rejection message is therefore received three times, the refresh token may be determined to have expired. According to some embodiments of the present invention, the validity condition for the refresh token may be the location of terminal 2000.
[0234] If the terminal 2000 is placed in a predetermined location, the refresh token may be determined to be valid. If the terminal 2000 is placed outside the predetermined location, the refresh token may be determined to be invalid.
[0235] If the determination entity is the authentication server 1000 rather than the terminal 2000, the terminal 2000 may provide location information to the authentication server 1000 so that the authentication server 1000 can determine whether the refresh token is valid based on the location information of the terminal 2000. The location information may be at least one of the location of the terminal at the time the refresh token was issued and the current location of the terminal. A refresh token is also issued when an authentication token is initially issued. Therefore, the location information at the time the authentication token was issued may be the same as the location information at the time the refresh token was issued. Therefore, the location information at the time the refresh token was issued may be replaced with the location information at the time the authentication token is issued.
[0236] For example, if the location range included in the validity conditions is within 100 m from the company building and the location at which the update token was issued is outside the location range included in the validity conditions, the door operation device 3000 may determine that the update token is not valid.
[0237] As another example, if the location range included in the validity condition is within 100 m from the company building, the door operation device 3000 may compare the location information acquired from the terminal 2000 with the location range included in the validity condition. If the acquired location information is outside the location range included in the validity condition, the door operation device 3000 may determine that the update token is invalid.
[0238] As yet another example, if it is determined that the current location information is outside the location range included in the validity condition, the terminal 2000 may determine that the refresh token has expired and change the state of the refresh token to an expired state. If it is determined that the refresh token is invalid, the authentication server 1000 may refuse to refresh the authentication token.
[0239] 3.3.2 Refreshing an Authentication Token (Refresh Token Embodiment) According to some embodiments of the present invention, an authentication token may be refreshed.
[0240] An authentication token update may indicate that a new authentication token has been issued by the authentication server. The new authentication token may have the same authentication information as the previously issued authentication token. However, if permissions have changed, the new authentication token may have different authentication information than the previously issued authentication token.
[0241] Additionally, the new authentication token may have a different validity period than the previously issued authentication token.
[0242] The terminal 2000 may send an update token to the authentication server 1000 to request an update of the authentication token.
[0243] The authentication server 1000 may send an authentication token corresponding to the update token sent to the terminal 2000.
[0244] According to some embodiments of the present invention, a renewal condition may be set on the refresh token.
[0245] According to some embodiments of the present invention, if the authentication token has expired, the terminal 2000 may send a refresh token to the authentication server 1000 to request a refresh of the authentication token.
[0246] For example, when it is determined that the authentication token has expired, the terminal 2000 may request an update of the authentication token by transmitting an update token to the authentication server 1000. As another example, when an expiration message indicating that the authentication token has expired is received from the door operation device 3000, the terminal 2000 may request an update of the authentication token by transmitting an update token to the authentication server 1000.
[0247] According to some embodiments of the present invention, a predetermined period may be set as a renewal condition for the refresh token.
[0248] When a predetermined period of time has elapsed since the update token was issued, the terminal 2000 may transmit the update token to the authentication server 1000 to request an update of the authentication token.
[0249] When the update time is reached, the terminal 2000 may transmit the authentication token to the authentication server 1000 to request an update of the authentication token.
[0250] The refresh token may include information about the remaining time until the refresh time. When the remaining time included in the refresh token is subtracted from the predetermined refresh time, the terminal 2000 may send the refresh token to the authentication server 1000 to request a refresh of the authentication token.
[0251] For example, if the remaining period information in the update token is set to 1000 seconds, when the time is reduced from 1000 seconds to 0 seconds during the update, the terminal 2000 may send the update token to the authentication server 1000 to request an update of the authentication token.
[0252] As another example, if the refresh token is set to 1000 seconds, the terminal 2000 may transmit the refresh token to the authentication server 1000 every 100 seconds to request a refresh of the authentication token.
[0253] According to some embodiments of the present invention, the authentication token may be updated after determining whether to update the authentication token based on the location.
[0254] When the user terminal 2000 reaches a predetermined position, the user terminal 2000 may transmit an update token to the authentication server 1000 to request an update of the authentication token.
[0255] According to some embodiments of the present invention, the authentication token may be updated after determining whether to update the authentication token based on a user request.
[0256] When a user input is made to request an update, the terminal 2000 may transmit an update token to the authentication server 1000 to request an update of the authentication token.
[0257] According to some embodiments of the present invention, whether the authentication token is updated may be determined depending on whether a connection is established between the terminal 2000 and the door operating device 3000.
[0258] In an embodiment, the authentication token may be updated when communication is established between the terminal 2000 and the door operation device 3000. In this case, the updated authentication token may be sent to the door operation device 3000.
[0259] When communication with the door operation device 3000 is established, the terminal 2000 may transmit an update token to the authentication server 1000 to request an update of the authentication token.
[0260] The terminal 2000 may transmit the updated authentication token to the door operation device 3000.
[0261] According to some embodiments of the present invention, the authentication token may be updated when a determination result on whether to open the door is received from the door operating device 3000. For example, the terminal 2000 may send an authentication token to the door operating device 3000 to receive a determination result on whether to open the door.
[0262] When the determination result obtained on whether to open the door is received from the door operating device 3000, the terminal 2000 may transmit an update token to the authentication server 1000 to request an update of the authentication token.
[0263] According to some embodiments of the present invention, the refresh token may be refreshed according to predetermined conditions. According to some embodiments of the present invention, both the authentication token and the refresh token may be revoked according to the above-mentioned validity conditions. If both the authentication token and the refresh token are revoked, the authentication token and the refresh token may need to be reissued by re-authentication. If both the authentication token and the refresh token are revoked, the authentication server 1000 may perform user authentication and then issue the authentication token and the refresh token to the terminal 2000.
[0264] According to some embodiments of the present invention, the refresh token may be refreshed.
[0265] If the validity period of the refresh token is within a predetermined period, the refresh token may be refreshed.
[0266] For example, the authentication server 1000 may obtain a refresh token from the terminal 2000 to refresh the authentication token. In this case, if the remaining time until the refresh token expires is within a predetermined period, the authentication server 1000 may refresh the refresh token and transmit the refresh token to the terminal 2000. The refresh token of the authentication server 1000 may be refreshed by initializing the remaining time until the expiration.
[0267] As another example, if the remaining time until the refresh token expires is within a predetermined period, the terminal 2000 may transmit the refresh token to the authentication server 1000 to request that the refresh token be refreshed.
[0268] According to some embodiments of the present invention, the refresh token may be refreshed when the terminal 2000 is placed in a predetermined location.
[0269] According to some embodiments of the present invention, the refresh token may be updated after determining whether to update the refresh token based on a user request.
[0270] When a user input is made to request updating of the update token, the terminal 2000 may transmit the update token to the authentication server 1000 to request updating of the authentication token.
[0271] The authentication server 1000 may determine whether the transmitted refresh token is valid. If the refresh token is valid, the authentication server 1000 may transmit an authentication token corresponding to the refresh token to the terminal 2000. If the transmitted refresh token is invalid, the authentication server 1000 may determine that the refresh is not possible and transmit a message to the terminal 2000 indicating that the refresh is not possible.
[0272] The authentication server 1000 may determine whether the update token is valid based on the time elapsed since issuance, the location of the terminal 2000, the number of times the update token has been updated, and the like.
[0273] Furthermore, the authentication server 1000 may acquire location information of the terminal 2000 from the terminal 2000 to determine whether the update token is valid based on the location of the terminal 2000 .
[0274] 4. Use of Authentication Token The access control system 10000 of the present invention may use the acquired authentication token to perform various operations.
[0275] Various detailed embodiments of the access control system 10000 are described in more detail below.
[0276] However, for the sake of convenience, the following describes the processing that occurs after the user terminal 2000a acquires the authentication token from the authentication server 1000. The processing that occurs when the user terminal 2000a acquires the authentication token from the authentication server 1000 was explained in Section 3 entitled "Authentication Token and Update Token," and therefore a detailed explanation of this processing will be omitted.
[0277] 4.1. Door Opening Management Method A conventional access control system includes an access control server and an access control device. When a user requests access, the access control server and the access control device work together to determine whether to permit the access.
[0278] Such conventional systems may determine whether to grant access only if the access control server and the access controller can communicate with each other and perform their respective roles. Therefore, if the access control server fails or if there is a problem with communication between the access control server and the access controller, user access will not be granted.
[0279] A door opening control method according to an embodiment of the present invention will now be described with reference to FIGS.
[0280] FIG. 8 is a diagram showing an overview of a door opening control method according to an embodiment of the present invention.
[0281] 8 , according to the door opening control method according to the embodiment of the present invention, the user terminal 2000a transmits an authentication token to the door operation device 3000, and the door operation device 3000 determines whether to open the door 4000 based on the authentication token, and opens the door 4000 if the authentication token indicates the authority to open the door 4000. Thus, the user of the user terminal 2000a can access the door 4000.
[0282] As explained in Section 3 entitled "Authentication Tokens and Refresh Tokens," the user terminal 2000a obtains an authentication token by having the authentication server issue the authentication token to the user terminal 2000a.
[0283] In the door opening control method according to the embodiment of the present invention, the authentication server 1000 does not need to be involved in the series of processes in which the user terminal 2000a requests the door to be opened using an authentication token and the door operating device 3000 determines whether to open the door.
[0284] Therefore, unlike conventional access control systems, the door opening control method according to the embodiment of the present invention can allow access without any problems if the authentication token is valid, even if the authentication token becomes unavailable.
[0285] The basic concept of the door opening control method according to the embodiment of the present invention can be applied to the following various embodiments.
[0286] A door opening control method according to a first detailed embodiment of the present invention will be described below with reference to FIG.
[0287] FIG. 9 is a flowchart of a door opening control method according to an embodiment of the present invention.
[0288] Referring to FIG. 9, the door opening control method may include a step of the user terminal 2000a transmitting an authentication token to the first door operation device 3000a (S300), a step of the first door operation device 3000a determining whether to open the door (S310), a step of the first door operation device 3000a transmitting a result of the determination whether to open (S320), the first door operation device 3000a opening the door (S330), a step of the user terminal 2000a transmitting the authentication token to the second door operation device 3000b (S340), a step of the second door operation device 3000b determining whether to open the door (S350), a step of the second door operation device 3000b transmitting a result of the determination whether to open (S360), and a step of the second door operation device 3000b opening the door (S370).
[0289] According to some embodiments of the present invention, the user terminal 2000a may transmit an authentication token to the first door operation device 3000a (S300).
[0290] When communication with the first door operating device 3000a is established, the user terminal 2000a may transmit a pre-stored authentication token to the first door operating device 3000a. As an example, the user terminal 2000a may automatically transmit the pre-stored authentication token to the first door operating device 3000a without a separate user request.
[0291] Alternatively, when a user request is input, the user terminal 2000a may transmit a pre-stored authentication token to the first door operation device 3000a. For example, the user terminal 2000a may notify the user that communication with the first door operation device 3000a has been established. When a user inputs an authentication token transmission request while communication with the first door operation device 3000a has been established, the user terminal 2000a may transmit the authentication token to the first door operation device 3000a. As another example, when a user inputs an authentication token transmission request while communication with the first door operation device 3000a has been established, the user terminal 2000a may transmit a pre-stored authentication token to the first door operation device 3000a. However, to determine whether the user intends to cancel due to input errors or changes in circumstances, if the user terminal 2000a does not connect to the first door operation device 3000a within a predetermined amount of time from the time the authentication token transmission request is input, the user terminal 2000a may determine that the user intends to cancel and cancel the authentication token transmission request. If the authentication token transmission request is canceled, the user terminal 2000a may not transmit the pre-stored authentication token to the first door operation device 3000a even if the user terminal 2000a connects to the first door operation device 3000a.
[0292] The above-mentioned pre-stored authentication token to be transmitted may refer to at least one authentication token stored in the user terminal 2000a.
[0293] If a valid authentication token exists among the pre-stored authentication tokens, the user terminal 2000a does not need to transmit the authentication token to the first door operation device 3000a.
[0294] Furthermore, according to some embodiments of the present invention, the first door operating device 3000a may perform a determination as to whether to open the door (S310).
[0295] A decision as to whether to open the door may be made based on the authority contained in the authentication information.
[0296] The determination of authority by the door operating device 3000 may be provided in various ways.
[0297] First, authorization may be determined if the authentication token includes door identification information for an authorized door.
[0298] In a first method, the first door operating device 3000a may determine whether the authentication token includes door identification information corresponding to the first door operating device 3000a. If the authentication token includes door identification information corresponding to the first door operating device 3000a, the first door operating device 3000a may determine whether the authentication token is authorized.
[0299] Second, authorization may be determined when the authentication token includes at least one of authorized and unauthorized door identifications and further includes authentication information therefor.
[0300] In a second method, the first door operating device 3000a may determine whether the authentication token includes authority for the door corresponding to the first door operating device 3000a.
[0301] The first door operating device 3000a may determine whether the authentication token includes first door identification information corresponding to the first door operating device 3000a. The first door operating device 3000a may also determine whether the authority corresponding to the first door identification information is the authority to pass through the door.
[0302] The first door operating device 3000a may further consider whether the authentication token is valid when determining whether to open the door. If the validity period included in the authentication token has expired, the first door operating device 3000a may determine that the authentication token does not have the authority to open the door.
[0303] Furthermore, according to some embodiments of the present invention, the first door operating device 3000a may transmit the result of the determination as to whether to open (S320).
[0304] The first door operating device 3000a may transmit the result of the determination as to whether to open the door to the user terminal 2000a.
[0305] If the determination result indicates that the authentication token has the authority to open the door 4000, the first door operating device 3000a may transmit permission information indicating that the authentication token has been determined to have the authority to the user terminal 2000a. The first door operating device 3000a may also issue a notification indicating that the authentication token has been determined to have the authority by outputting at least one of auditory information and visual information through a separate output unit.
[0306] Furthermore, if the result of the determination as to whether to open indicates that the authentication token does not have the authority to open the door 4000, the first door operating device 3000a may send a message to the user terminal 2000a indicating that opening the door 4000 is not permitted.
[0307] The above-mentioned step S320 is not necessarily required and may be omitted in some embodiments, and step S320 does not necessarily precede step S330, but may in some embodiments be performed during or after step S330.
[0308] Also, according to some embodiments of the present invention, opening the door may be performed by the first door operating device 3000a (S330).
[0309] If it is determined that the authentication token includes authority to open the door 4000, the first door operating device 3000a may provide power through the door drive unit 3600 so that the door body can be unlocked. If the door 4000 is an automatic door, the first door operating device 3000a may provide power through the door drive unit 3600 so that the door body can be opened.
[0310] After the door body is unlocked, the first door operation device 3000a may provide power through the door drive unit 3600 so that the door body is locked based on the locking condition. The first door operation device 3000a may determine whether to close the door body again based on a signal obtained from the door sensor unit 3400. If the door body is closed again, the first door operation device 3000a may provide power through the door drive unit 3600 so that the door body can be locked. In addition, the first door operation device 3000a may provide power through the door drive unit 3600 in consideration of a locking standby time so that the door body can be locked after the locking standby time even if the door body is closed again.
[0311] Additionally, according to some embodiments of the present invention, the user terminal 2000a may transmit an authentication token to the second door operation device 3000b (S340).
[0312] When communication with the second door operation device 3000b is established, the user terminal 2000a may transmit a pre-stored authentication token to the second door operation device 3000b.
[0313] Additionally, according to some embodiments of the present invention, a determination as to whether to open the door may be performed by the second door operating device 3000b (S350).
[0314] The second door operating device 3000b may determine whether the authentication token includes door identification information corresponding to the second door operating device 3000b. If the authentication token includes door identification information corresponding to the second door operating device 3000b, the second door operating device 3000b may determine whether the authentication token has authority to open the door 4000.
[0315] The second door operating device 3000b may determine whether the authentication token includes authority to open the door 4000 corresponding to the second door operating device 3000b.
[0316] The second door operating device 3000b may determine whether the authentication token includes second door identification information corresponding to the second door operating device 3000b. The second door operating device 3000b may also determine whether the authority corresponding to the second door identification information is the authority to open the door 4000.
[0317] Furthermore, according to some embodiments of the present invention, the second door operating device 3000b may transmit the result of the decision to open (S360).
[0318] The second door operating device 3000b may transmit the result of the determination as to whether to open the door to the user terminal 2000a.
[0319] If the determination result indicates that the authentication token has the authority to open the door 4000, the second door operation device 3000b may transmit permission information indicating that it has been determined that the authentication token has the authority to open the door 4000 to the user terminal 2000a. Furthermore, the second door operation device 3000b may notify the user terminal 2000a that it has been determined that the authentication token has the authority to open the door 4000 by outputting at least one of auditory information and visual information through a separate output unit.
[0320] Furthermore, if the result of the determination as to whether to open indicates that the authentication token does not have the authority to open the door 4000, the second door operating device 3000b may send a message to the user terminal 2000a indicating that opening the door 4000 is not permitted.
[0321] Also, according to some embodiments of the present invention, opening the door may be performed by the second door operating device 3000b (S370).
[0322] If it is determined that the authentication token includes the authority to open the door 4000, the second door operating device 3000b may provide power through the door drive unit 3600 so that the door body can be unlocked. Also, if the door 4000 is an automatic door, the second door operating device 3000b may provide power through the door drive unit 3600 so that the door body can be opened.
[0323] After the door body is unlocked, the second door operation device 3000b may provide power through the door drive unit 3600 so that the door body is locked based on the locking condition. The second door operation device 3000b may determine whether to close the door body again based on a signal obtained from the door sensor unit 3400. If the door body is closed again, the second door operation device 3000b may provide power through the door drive unit 3600 so that the door body can be locked. In addition, the second door operation device 3000b may provide power through the door drive unit 3600 in consideration of a locking standby time so that the door body can be locked after the locking standby time even if the door body is closed again.
[0324] Therefore, with regard to the access request and authorization according to the first detailed embodiment of the present invention, the user terminal 2000a may use the authentication token obtained from the authentication server 1000 to open the authorized door 4000. Therefore, if the pre-stored authentication token is valid, the user terminal 2000a does not perform additional authentication with the authentication server 1000, and the user may freely access the authorized door among the multiple doors 4000.
[0325] 4.2. Access State Management Method An access state management method according to an embodiment of the present invention will now be described with reference to FIGS.
[0326] The following describes an access status management method according to an embodiment of the present invention, but the same content as the door opening control method according to an embodiment of the present invention, such as opening the door, will be omitted or only briefly described.
[0327] FIG. 10 is a diagram showing an overview of an access state management method according to an embodiment of the present invention.
[0328] As shown in FIG. 10, a first door communication unit 3110 may be provided on the inside of a door 4000, and a second door communication unit 3120 may be provided on the outside of the door 4000.
[0329] As shown in FIG. 10, the first door communication unit 3110 and the second door communication unit 3120 may be connected to a door control unit 3700.
[0330] 10 is merely an example for the convenience of explanation, and the present invention is not limited thereto. Depending on the selection, the positions of the first door communication unit 3110 and the second door communication unit 3120 may be changed, only one of the first door communication unit 3110 and the second door communication unit 3120 may be provided, or an additional element such as a third door communication unit may be further provided.
[0331] Depending on the operating environment, separate door operation devices 3000 may be provided on the inside and outside. For example, a first door operation device 3000a may be provided on the outside, and a second door operation device 3000b may be provided on the inside.
[0332] Also, depending on the operating environment, a single door communication unit 3100 may be provided that handles both the inside and outside. In this case, the door communication unit 3100 may detect the distance from the user terminal 2000a and the direction of the user terminal 2000a, and determine whether the user is entering from the outside to the inside or exiting from the inside to the outside.
[0333] For convenience of explanation, the access state management method of the present invention and its variations will be described below with reference to the installation environment of FIG.
[0334] In the following discussion with reference to FIG. 10, the management of authorized users' use of the access control system is a crucial issue.
[0335] For example, when multiple users attempt to pass through a door 4000 in an automated access control system, a user of a first user terminal 2000a′ may be authorized using an authentication token and may then pass through the door 4000, while a user of a second user terminal 2000a″ may pass through the door 4000 opened by the user of the first user terminal 2000a′ without determining access authorization. In this case, a history of the user of the second user terminal 2000a″ passing through the door 4000 may not be maintained.
[0336] To avoid such problems, the access status management method according to an embodiment of the present invention may further include access status information. Therefore, it is possible to determine whether there is an abnormal access based on the access status information and further deny the abnormal access. For example, when a user passes through a door after access authentication, the user's access status is changed from an entry status to an exit status. When the user attempts to exit, the user's access status is normal, so as long as the user has authorization, the door operating device 3000 may open the door 4000 to allow the user to pass through.
[0337] On the other hand, if a user passes through without access authentication, the user's access status is maintained as an entering status. If this user attempts to exit, the door operating device 3000 may refuse to open the door 4000 even if the user has authorization, because the user's access status is abnormal. According to some embodiments of the present invention, the user needs to request the authentication server 1000 to reissue the access status, so that the authentication server 1000 can manage the access status independently.
[0338] An access state management method according to an embodiment of the present invention and its variations will be described below with reference to FIGS.
[0339] FIG. 11 is a flowchart showing an access state management method according to an embodiment of the present invention.
[0340] Referring to FIG. 11, the access status management method may include a step of transmitting an authentication token and access status information (S400), a step of determining whether to open the door (S410), a step of changing the access status information (S420), a step of sending the changed access status information (S430), a step of opening the door (S440), and a step of sending a denial message (S450).
[0341] According to some embodiments of the present invention, the user terminal 2000a may transmit the authentication token and the first access state information to the first door communication unit 3110 (S400).
[0342] When communication is established between the user terminal 2000a and the first door communication unit 3110, the user terminal 2000a may transmit a pre-stored authentication token and first access state information to the first door communication unit 3110. The establishment of communication between the user terminal 2000a and the first door communication unit 3110 may indicate that the user terminal 2000a will establish communication with the door operation device 3000.
[0343] The user terminal 2000a may automatically transmit the pre-stored authentication token and the first access state information to the first door communication unit 3110 without a separate user request.
[0344] Alternatively, the user terminal 2000a may transmit a pre-stored authentication token and first access state information to the first door communication unit 3110 even when a user request is input. For example, the user terminal 2000a may issue a notification indicating that communication with the first door communication unit 3110 has been established. When a user inputs an authentication token transmission request while communication with the first door communication unit 3110 has been established, the user terminal 2000a may transmit a pre-stored authentication token and first access state information to the first door communication unit 3110. As another example, when a user inputs an authentication token transmission request while communication with the first door communication unit 3110 has been established, the user terminal 2000a may transmit a pre-stored authentication token and first access state information to the first door communication unit 3110. However, to determine whether the user intends to cancel due to an input error or a change in circumstances, if the user terminal 2000a does not connect to the first door communication unit 3110 within a predetermined amount of time from the time the authentication token transmission request is input, the user terminal 2000a may determine that the user intends to cancel and cancel the authentication token transmission request. If the authentication token transmission request is canceled, the user terminal 2000a may not transmit the pre-stored authentication token to the first door communication unit 3110 even if the user terminal 2000a connects to the first door communication unit 3110.
[0345] The above-mentioned pre-stored authentication token to be transmitted may refer to at least one authentication token stored in the user terminal 2000a.
[0346] Also, according to some embodiments of the present invention, a determination may be made as to whether to open the door (S410).
[0347] The door control unit 3700 may acquire the authentication token and the access state information through the first door communication unit 3110.
[0348] The door control unit 3700 may determine whether to open the door based on the access state information and authority included in the authentication token.
[0349] The door control unit 3700 may determine whether the authentication token includes door identification information corresponding to the door operating device 3000 and / or the door 4000. If the authentication token includes door identification information corresponding to the door operating device 3000 and / or the door 4000, the door control unit 3700 may determine whether the authentication is authorized.
[0350] The door control 3700 may determine whether the authentication token is authorized by taking into account the door identification information and the authorization value.
[0351] The door control unit 3700 may determine whether the authentication token includes door authority corresponding to the door operation device 3000 and / or the door 4000.
[0352] The door control unit 3700 may determine whether the authentication token includes door identification information corresponding to the door operation device 3000 and / or the door 4000. The door control unit 3700 may also determine whether the authority included in the authentication information corresponding to the door identification information is the authority to pass through the door.
[0353] The door control unit 3700 may determine whether the access status information included in the authentication information is normal.
[0354] In the embodiment, the door control unit 3700 may determine whether the access state included in the access state information corresponds to the first door communication unit 3110.
[0355] The door control unit 3700 may determine to open the door if the authentication token is authorized and the access status information included in the authentication information corresponds to the first door communication unit 3110. For example, if the first door communication unit 3110 is installed outside the door and the access status information indicates an entry status, the door control unit 3700 may determine that the access status information corresponds to the first door communication unit 3110.
[0356] The door control unit 3700 may determine whether to open the door based on various additional criteria in addition to determining the authority based on the authentication token and whether the access status information is normal.
[0357] According to some embodiments of the present invention, the door control 3700 may further consider the number of users allowed into the space when determining whether to open the door.
[0358] The door control unit 3700 may calculate the current number of users entering the space. The door control unit 3700 may calculate the current number of users entering the space, which is equal to the number of users who entered minus the number of users who exited. For example, the door control unit 3700 may calculate the number of entering users by subtracting the number of users whose access status was in the exiting state when the door opened from the number of users whose access status was in the entering state when the door opened.
[0359] If the number of entering users is greater than or equal to a predetermined maximum allowable number of users, the door control unit 3700 may determine that the door is not allowed to open.
[0360] Also, according to some embodiments of the present invention, a modification of the access state information may be performed (S420).
[0361] If it is determined that the door is to be opened, the door control section 3700 may change the access state information.
[0362] For example, if the authentication token includes authority to pass through the door and the access status information is determined to be normal, the door control unit 3700 may change the access status information. As a more detailed example, if the access status information indicates an entry status, the door control unit 3700 may change the access status information to an exit status.
[0363] Also, according to some embodiments of the present invention, transmission of the modified access state information may be performed (S430).
[0364] The door control unit 3700 may execute control so that the access status information can be transmitted to the user terminal 2000a.
[0365] The door control unit 3700 may also execute control so that the result of the determination as to whether to open the door can be transmitted to the user terminal 2000a.
[0366] If the authorization determination result indicates that the authentication is authorized, the door control unit 3700 may transmit permission information indicating that the authentication token is determined to be authorized to the user terminal 2000a. The door control unit 3700 may also notify the user terminal 2000a that the authentication token is determined to be authorized by outputting at least one of auditory information and visual information through a separate output unit.
[0367] Furthermore, if the result of the determination as to whether to open indicates that the authentication token does not have the authority to open the door 4000, the door control unit 3700 may perform control so that a message indicating that opening the door 4000 is not permitted is sent to the user terminal 2000a.
[0368] Also, according to some embodiments of the present invention, opening the door may be performed (S440).
[0369] If it is determined that the authentication token includes the authority to open the door 4000, the door control unit 3700 may control the door drive unit 3600 so that the door body can be unlocked.
[0370] The door driving unit 3600 may provide power to unlock the door body. If the door 4000 is an automatic door, the door control unit 3700 may control the door driving unit 3600 to open the door body. In this case, the door driving unit 3600 may provide power to open the door body.
[0371] After the door body is unlocked, the door control unit 3700 may control the door driving unit 3600 to lock the door body based on the locking condition. The door control unit 3700 may determine whether to close the door body again based on a signal obtained from the door sensor unit 3400. If the door body is closed again, the door control unit 3700 may control the door driving unit 3600 to provide power so that the door body can be locked. The door control unit 3700 may also control the door driving unit 3600 to further take into account a locking standby time, thereby allowing the door body to be locked after the locking standby time, even if the door body is closed again.
[0372] Also, according to some embodiments of the present invention, if the result of determining whether to open the door indicates refusal, sending a refusal message may be performed (S450).
[0373] If the result of determining whether to open the door indicates denial, the door control unit 3700 may execute control so that an opening denial message can be sent to the user terminal 2000a.
[0374] The open denial message may be a message indicating that the door is not permitted to be opened.
[0375] The open denial message may additionally include a reason for the open denial, such as no authorization, invalid authentication token, expired authentication token, abnormal access state, or exceeding the maximum number of allowed users.
[0376] In the access state management method according to the embodiment of the present invention described above, the user terminal 2000a may provide unaltered access state information to the door operation device 3000, and the door operation device 3000 may determine whether to open the door and, if it is determined that the door should be opened, open the door. In this case, if the user terminal 2000a may transmit the altered access state information to the first door communication unit 3110 without passing through the open door, the door control unit 3700 may refuse to open the door based on the unaltered access state information, unlike when opening the door is permitted.
[0377] For convenience of explanation, it has been described that, when it is assumed that the device is in the entering state, the authentication token is transmitted through the first door communication unit 3110. However, the present invention is not limited to this, and may be implemented in various ways depending on the installation environment. For example, when it is in the exiting state, the access state management method may be implemented by transmitting the authentication token through the second door communication unit 3120.
[0378] The access state management method according to the embodiment of the present invention may be provided in various modified forms.
[0379] A variant of the access state management method will now be described with reference to FIGS.
[0380] A modified example of the access state management method will be described below, but the same elements and steps as those in the above-described access state management method will be designated by the same reference numerals, and steps that are the same as those in the above-described access state management method will be omitted.
[0381] 4.2.1. Access State Management Method - First Modification FIG. 12 is a sequence diagram showing a first modification of the access state management method according to an embodiment of the present invention.
[0382] Referring to FIG. 12, a first variant of the access state management method may include a step of transmitting an authentication token (S400), a step of determining whether to open the door (S410), a step of transmitting information on the determination result of whether to open the door (S500), a step of opening the door (S440), a step of requesting an update of the access state information (S510), a step of the authentication server 1000 changing the access state information (S520), and a step of transmitting the updated access state information (S530).
[0383] According to some embodiments of the present invention, the user terminal 2000a may transmit an authentication token to the first door communication unit 3110 (S400).
[0384] Furthermore, according to some embodiments of the present invention, the door control unit 3700 may perform a determination as to whether to open the door (S410).
[0385] Furthermore, according to some embodiments of the present invention, the door control unit 3700 may execute control so as to transmit information on the result of the determination as to whether or not to open the door (S500).
[0386] If it is determined that the authentication token contains authority, and if the access status is normal, the door control unit 3700 may execute control so that information indicating that opening the door is permitted is sent to the user terminal 2000a.
[0387] Alternatively, if it is determined that the authentication token does not contain authority or the access status is not normal, the door control unit 3700 may perform control so that information indicating that opening the door has been denied is sent to the user terminal 2000a.
[0388] The door control unit 3700 may also execute control so that access status information can be transmitted to the user terminal 2000a.
[0389] The door control unit 3700 may also execute control so that an authentication token can be transmitted to the user terminal 2000a.
[0390] Also, according to some embodiments of the present invention, opening the door may be performed (S440).
[0391] Furthermore, according to some embodiments of the present invention, the user terminal 2000a may request the authentication server 1000 to update the access state information (S510).
[0392] When the user terminal 2000a receives information from the door operation device 3000 indicating that the door is permitted to be opened, the user terminal 2000a may request the authentication server 1000 to update the access status information.
[0393] The user terminal 2000a may send to the authentication server 1000 the identification information of the door that is permitted to be opened, information indicating that the door is permitted to be opened, and the access status information in order to request the authentication server 1000 to update the access status information.
[0394] Furthermore, according to some embodiments of the present invention, the authentication server 1000 may change the access status of the received access status information (S520).
[0395] The authentication server 1000 may update the access status included in the received access status information.
[0396] The authentication server 1000 may transmit the updated access status to the user terminal 2000a. For example, if the access status indicates an entering status, the authentication server 1000 may update the access status to an exiting status. As another example, if the access status indicates an exiting status, the authentication server 1000 may update the access status to an entering status.
[0397] Additionally, according to some embodiments of the present invention, the authentication server 1000 may transmit updated access status information to the user terminal 2000a (S530).
[0398] Depending on the situation, various additional functions may be added to the above-described first modified example of the access status management method. The above-described first modified example of the access status management method may determine whether a user has entered a specific space based on identification information of a door that the user is permitted to open, which is acquired from the user terminal 2000a.
[0399] According to some embodiments of the present invention, the authentication server 1000 may determine whether all users have evacuated to a meeting place in the event of an emergency such as a fire. The authentication server 1000 may determine whether a user has entered a predetermined meeting place based on identification information of a door that the user is authorized to open, obtained from the user terminal 2000a.
[0400] Furthermore, the authentication server 1000 may transmit an evacuation notification to the user terminal 2000a of a user who has not entered the predetermined meeting place among the registered users or the users who have received the authentication token. Furthermore, the authentication server 1000 may transmit information guiding the user to the location of the predetermined meeting place among the registered users or the users who have received the authentication token among the users who have not entered the predetermined meeting place among the user terminal 2000a.
[0401] 4.2.2. Access State Management Method - Second Modification FIG. 13 is a sequence diagram showing a second modification of the access state management method according to an embodiment of the present invention.
[0402] Referring to FIG. 13, a second variant of the access status management method may include a step of transmitting an authentication token (S400), a step of determining whether to open the door (S410), a step of transmitting information on the determination result of whether to open the door (S500), a step of requesting an update of the access status information (S510), a step of the authentication server 1000 changing the timestamp record and the access status information (S520), a step of transmitting the updated access status information (S530), a step of transmitting the timestamp (S540), a step of checking the timestamp (S550), and a step of opening the door (S440).
[0403] According to some embodiments of the present invention, an authentication token may be transmitted (S400).
[0404] According to some embodiments of the present invention, a determination may be made whether to open the door (S410).
[0405] According to some embodiments of the present invention, transmission of the opening determination result information may be performed (S500).
[0406] According to some embodiments of the present invention, requesting an update of the access state information may be performed (S510).
[0407] According to some embodiments of the present invention, the authentication server 1000 may perform timestamp recording and modification of the access state information (S520).
[0408] The authentication server 1000 may record a timestamp in the authentication token and / or the access state information.
[0409] The authentication server 1000 may record a timestamp based on at least one of the time when information indicating that the door is permitted to be opened is obtained, the time when an update of the access status information is requested, and the current time.
[0410] According to some embodiments of the present invention, sending of updated access state information may be performed (S530).
[0411] The authentication server 1000 may transmit the updated access state information to the user terminal 2000a. Also, if an authentication token is acquired from the user terminal 2000a, the authentication server 1000 may transmit the authentication token to the user terminal 2000a. Also, if a timestamp is recorded in the authentication token, the authentication server 1000 may transmit the updated authentication token with the timestamp recorded to the user terminal 2000a.
[0412] Alternatively, the authentication server 1000 may transmit the access status information and the timestamp separately and individually.
[0413] According to some embodiments of the present invention, a timestamp transmission may be performed (S540).
[0414] The user terminal 2000a may transmit the timestamp to the door operation device 3000. For example, the user terminal 2000a may transmit the timestamp to the first door communication unit 3110, as shown in FIG.
[0415] The user terminal 2000a may transmit an individually provided timestamp to the door operation device 3000.
[0416] Alternatively, if a timestamp is included in the access state information, the user terminal 2000a may transmit the timestamp to the door operation device 3000 by transmitting the access state information to the door operation device 3000.
[0417] Alternatively, if the timestamp is included in the authentication token, the user terminal 2000a may transmit the timestamp to the door operation device 3000 by transmitting the authentication token to the door operation device 3000.
[0418] According to some embodiments of the present invention, a timestamp check may be performed (S550).
[0419] The door control unit 3700 may check the timestamp.
[0420] The door control unit 3700 may check whether a timestamp has been acquired from the user terminal 2000a. For example, the door control unit 3700 may check whether an individual timestamp has been acquired from the user terminal 2000a. As another example, the door control unit 3700 may check whether a timestamp is included in at least one of the authentication token and the access state information acquired from the user terminal 2000a.
[0421] The door control 3700 may check whether the time period in the timestamp is valid.
[0422] For example, the door control unit 3700 may check whether the time stamp is at or after the time when the opening determination result was transmitted. If the time stamp is at or after the time when the opening determination result was transmitted, the door control unit 3700 may determine whether the time stamp is valid.
[0423] If the timestamp check result shows no error, the door control unit 3700 may execute control to allow the door to open.
[0424] According to some embodiments of the present invention, opening the door may be performed (S440).
[0425] The timestamp described above may be transformed into various forms, for example, the timestamp may be provided as a certificate, a digital signature, or a security key.
[0426] 4.2.3. Access State Management Method - Third Modification FIG. 14 is a sequence diagram showing a third modification of the access state management method according to an embodiment of the present invention.
[0427] Referring to FIG. 14, a third variant of the access status management method may include a step of transmitting an authentication token (S400), a step of determining whether to open the door (S410), a step of transmitting the result of the determination as to whether to open the door by the door operating device 3000 (S500), a step of opening the door (S440), and a step of changing the access status information by the user terminal 2000a (S600).
[0428] According to some embodiments of the present invention, the user terminal 2000a may transmit an authentication token to the first door communication unit 3110 (S400).
[0429] Also, according to some embodiments of the present invention, a determination may be made as to whether to open the door (S410).
[0430] According to some embodiments of the present invention, a transmission of the opening determination result may also be performed (S500).
[0431] The door control unit 3700 may execute control so that information indicating that the door is permitted to be opened can be transmitted to the user terminal 2000a.
[0432] Alternatively, the door control unit 3700 may execute control so that information indicating that opening of the door has been denied is transmitted.
[0433] The door control unit 3700 may also execute control so that access status information can be transmitted to the user terminal 2000a.
[0434] Also, according to some embodiments of the present invention, opening the door may be performed (S440).
[0435] Furthermore, according to some embodiments of the present invention, the user terminal 2000a may update the access state information (S600).
[0436] The user terminal 2000a may receive the access state information and update the received access state information.
[0437] The user terminal 2000a may update the received access state information and store the updated access state information. For example, if the access state indicates an entering state, the user terminal 2000a may update the access state to an exiting state and store the updated access state. As another example, if the access state is an exiting state, the user terminal 2000a may update the access state to an entering state and store the updated access state.
[0438] 4.2.4. Access State Management Method - Fourth Modification A fourth modification of the access state management method according to the embodiment of the present invention will be described below with reference to FIG.
[0439] A fourth variant of the access status management method according to an embodiment of the present invention may be an embodiment in which, if opening the door is refused because the access status information is abnormal, the authentication server 1000 is requested to reissue the access status information.
[0440] FIG. 15 is a sequence diagram showing a fourth modified example of the access state management method according to the embodiment of the present invention.
[0441] Referring to FIG. 15, a fourth variant of the access state management method may include a step of sending an authentication token (S400), a step of determining whether to open the door (S410), a step of sending an opening refusal message (S450), a step of the user terminal 2000a sending authentication information and access state information to the authentication server 1000 to request the authentication server 1000 to update the access state information (S700), a step of the authentication server 1000 updating the access state information (S710), and a step of the authentication server 1000 reissuing the access state information to the user terminal 2000a (S720).
[0442] According to some embodiments of the present invention, the user terminal 2000a may transmit an authentication token to the first door communication unit 3110 (S400).
[0443] Furthermore, according to some embodiments of the present invention, the door operating device 3000 may perform a determination as to whether to open the door (S410).
[0444] According to some embodiments of the present invention, the door operation device 3000 may also transmit an opening refusal message (S450).
[0445] If the access state information does not correspond to the first door communication unit 3110, the door control unit 3700 may determine that the access state is abnormal, and may transmit an opening refusal message to the user terminal 2000a.
[0446] Also, according to some embodiments of the present invention, the user terminal 2000a may transmit the authentication information and the access state information to the authentication server 1000 to request the authentication server 1000 to reissue the access state information (S700).
[0447] The user terminal 2000a may transmit the authentication information and the access state information to the authentication server 1000. Here, the authentication information may include at least one of user information, user identification information, a security key, and an authentication token.
[0448] Furthermore, the user terminal 2000a does not necessarily need to transmit the authentication information and the access state information to the authentication server 1000 in order to request the authentication server 1000 to reissue the access state information. The user terminal 2000a may transmit at least one of the authentication information and the access state information to the authentication server 1000 in order to request the authentication server 1000 to reissue the access state information.
[0449] Furthermore, if the authentication token includes access state information, the transmission of the access state information by the user terminal 2000 a to the authentication server 1000 may indicate that the user terminal 2000 a transmits the authentication token to the authentication server 1000 .
[0450] Also, if the access state information is carried separately from the authentication token, the transmission of the access state information by the user terminal 2000a to the authentication server 1000 may indicate that only the access state information is being sent.
[0451] Additionally, according to some embodiments of the present invention, the authentication server 1000 may perform regeneration of the access state information (S710).
[0452] The authentication server 1000 may change the access state information after performing authentication based on the acquired authentication information.
[0453] If the result of user authentication indicates that the user is authorized, the authentication server 1000 may regenerate the access state information by modifying the access state information. For example, if the access state of the received access state information is an entering state, the authentication server 1000 may change the access state to an exiting state.
[0454] Furthermore, the authentication server 1000 may change the access status to a status requested by the user terminal 2000a. For example, when the user terminal 2000a requests that the access status be changed to an entering status, the authentication server 1000 may change the access status in the access status information to an entering status.
[0455] Furthermore, according to some embodiments of the present invention, the authentication server 1000 may reissue the access state information to the user terminal 2000a (S720).
[0456] The authentication server 1000 may reissue the access state information to the user terminal 2000a by transmitting the regenerated access state information. The authentication server 1000 may also store a change history.
[0457] 4.2.5. Access State Management Method - Fifth Modification A fifth modification of the access state management method according to the embodiment of the present invention will be described below with reference to FIG.
[0458] The fifth modification of the access state management method according to the embodiment of the present invention may be an embodiment in which management is performed to determine whether a user has actually passed through.
[0459] For example, a user entering the facility may transmit an authentication token to the first door communication unit 3110 installed on the outside, enter the facility after the door opens, and obtain access status information having the changed access status from the second door communication unit 3120 installed on the inside. Therefore, only users who actually pass through the facility can obtain access status information having the changed access status.
[0460] FIG. 16 is a sequence diagram showing a fifth modified example of the access state management method according to the embodiment of the present invention.
[0461] Referring to FIG. 16, a fifth variant of the access status management method may include a step of transmitting an authentication token (S400), a step of determining whether to open the door (S410), a step of changing the access status (S420), a step of opening the door (S440), and a step of the second door communication unit 3120 transmitting access status information (S800).
[0462] According to some embodiments of the present invention, the user terminal 2000a may transmit an authentication token to the first door communication unit 3110 (S400).
[0463] Furthermore, according to some embodiments of the present invention, the door control unit 3700 may determine whether to open the door (S410).
[0464] Also, according to some embodiments of the present invention, a modification of the access state information may be performed (S420).
[0465] Also, according to some embodiments of the present invention, opening the door may be performed (S440).
[0466] Furthermore, according to some embodiments of the present invention, the second door communication unit 3120 may transmit access status information (S800).
[0467] Furthermore, the door control unit 3700 may execute control so that the second door communication unit 3120 can transmit access status information to the user terminal 2000a.
[0468] When communication is established between the second door communication unit 3120 and the user terminal 2000a, the door control unit 3700 may execute control so that the second door communication unit 3120 transmits access status information to the user terminal 2000a.
[0469] If communication between the second door communication unit 3120 and the user terminal 2000a is not established within a predetermined time from at least one of the time the authentication token is received, the time of determining whether to open the door, the time of changing the access status, and the time the door is opened, the door control unit 3700 may cancel the transmission of the access status information.
[0470] 4.2.6. Access State Management Method - Sixth Modification A sixth modification of the access state management method according to the embodiment of the present invention will be described below with reference to FIGS.
[0471] A sixth variant may be an embodiment in which the doors are arranged in a tiered structure.
[0472] FIG. 17 is a diagram showing an overall view of a door having a hierarchical structure according to a sixth modified example of the present invention.
[0473] As shown in Fig. 17, a space separated by a single door includes separate interior spaces. In Fig. 17, a first door operating device 3000a may be provided on a first door 4000a that separates the first interior space from the exterior space, and a second door operating device 3000b may be provided on a second door 4000b that separates the second interior space from the first interior space.
[0474] Therefore, it is preferable that the state information of the internal space and the high-rank space be managed separately.
[0475] A sixth modification of the access state management method according to the embodiment of the present invention will be described below with reference to FIG.
[0476] FIG. 18 is a sequence diagram showing a sixth modified example of the access state management method according to the embodiment of the present invention.
[0477] Referring to FIG. 18, the sixth modified example of the access state management method includes a step in which the user terminal 2000a transmits an authentication token to the first door operation device 3000a (S900), a step in which the first door operation device 3000a determines whether to open the door (S910), a step in which the first door operation device 3000a changes the access state information (S920), a step in which the first door operation device 3000a transmits the access state information (S930), and a step in which the first door 4000a opens the first door 4000a. The method may include a step of the first door operating device 3000a transmitting an authentication token to the second door operating device 3000b (S940), a step of the second door operating device 3000b determining whether to open the door (S950), a step of the second door operating device 3000b changing the access status information (S960), a step of the second door operating device 3000b transmitting the access status information (S970), and a step of opening the second door 4000b (S440).
[0478] According to some embodiments of the present invention, the user terminal 2000a may transmit an authentication token to the first door operation device 3000a (S900).
[0479] Furthermore, according to some embodiments of the present invention, the first door operating device 3000a may perform a determination as to whether to open the door (S910).
[0480] The first door operating device 3000a may determine whether to open the door based on the access state information and authority included in the authentication token.
[0481] The first door operating device 3000a may determine whether the authentication token includes door identification information corresponding to the first door operating device 3000a. If the authentication token includes door identification information corresponding to the first door operating device 3000a, the first door operating device 3000a may determine whether the authentication token is authorized.
[0482] The first door operating device 3000a may determine whether the authentication token includes an authority value for the door corresponding to the first door operating device 3000a.
[0483] The first door operating device 3000a may determine whether the authentication token includes door identification information corresponding to the first door operating device 3000a. The first door operating device 3000a may also determine whether the authority value corresponding to the door identification information is an authority value for passing through the door.
[0484] The first door operating device 3000a may determine whether the access status information included in the authentication information is normal.
[0485] The first door operation device 3000a may determine whether the access state for the first door operation device 3000a included in the access state information corresponds to the door communication unit 3100 that has acquired the authentication token. In the following embodiment, it is assumed that the authentication token is acquired through the first door communication unit 3110 of the first door operation device 3000a. The first door operation device 3000a may determine whether the access state corresponds to the first door communication unit 3110 of the first door operation device 3000a.
[0486] If the authentication token is authorized and the access status for the first door operating device 3000a included in the authentication information corresponds to the first door communication unit 3110 of the first door operating device 3000a, the first door operating device 3000a may determine to open the door.
[0487] Furthermore, according to some embodiments of the present invention, the first door operation device 3000a may execute a change of the access status information (S920).
[0488] The first door operation device 3000a may change the access state to the next stage. For example, if the access state is an entry state, the first door operation device 3000a may change the access state to an exit state.
[0489] Also, according to some embodiments of the present invention, the first door operation device 3000a may transmit access status information (S930).
[0490] The first door operation device 3000a may transmit access state information including the changed access state for the first door operation device 3000a to the user terminal 2000a.
[0491] The user terminal 2000a may update the access state of the authentication token with the access state information acquired from the first door operation device 3000a, or may discard the access state information stored in advance and store the access state information acquired from the first door operation device 3000a.
[0492] Also, according to some embodiments of the present invention, opening of the first door 4000a may be performed by the first door operating device 3000a (S440).
[0493] Additionally, according to some embodiments of the present invention, the user terminal 2000a may transmit an authentication token to the second door operation device 3000b (S940).
[0494] Also, according to some embodiments of the present invention, determining whether to open the door may be performed by the second door operating device 3000b (S950).
[0495] The second door operating device 3000b may determine whether to open the door based on the access status information and authority included in the authentication token.
[0496] The second door operating device 3000b may determine whether the authentication token includes door identification information corresponding to the second door operating device 3000b. If the authentication token includes door identification information corresponding to the second door operating device 3000b, the second door operating device 3000b may determine whether the authentication token has an authorization value.
[0497] The second door operating device 3000b may determine whether the authentication token includes an authority value for the door corresponding to the second door operating device 3000b.
[0498] The second door operating device 3000b may determine whether the authentication token includes door identification information corresponding to the second door operating device 3000b. The second door operating device 3000b may also determine whether the authority value corresponding to the door identification information is an authority value for passing through the door.
[0499] The second door operating device 3000b may determine whether the access status information included in the authentication information is normal.
[0500] The second door operation device 3000b may determine whether the access state for the second door operation device 3000b included in the access state information corresponds to the door communication unit 3100 that has acquired the authentication token. In the following embodiment, it is assumed that the authentication token is acquired through the first door communication unit 3110 of the second door operation device 3000b. The second door operation device 3000b may determine whether the access state corresponds to the state corresponding to the first door communication unit 3110 of the second door operation device 3000b.
[0501] If the authentication token is authorized and the access status for the second door operating device 3000b included in the authentication information corresponds to the first door communication unit 3110 of the first door operating device 3000a, the second door operating device 3000b may determine to open the door.
[0502] Furthermore, the second door operating device 3000b may determine whether to open the door by further considering the access status of the first door operating device 3000a, which is in a higher rank.
[0503] If the access status for the first door operation device 3000a is abnormal, the second door operation device 3000b may refuse to open the door. For example, the abnormal access status for the first door operation device 3000a may indicate that the user terminal 2000a has determined not to have passed through the first door operation device 3000a. As a more detailed example, if the user terminal 2000a has passed through the first door operation device 3000a in a higher rank, the access status for the first door operation device 3000a must be an exit status. If the access status for the first door operation device 3000a is an entry status, the second door operation device 3000b may determine that the user terminal 2000a has abnormally passed through the first door operation device 3000a and may refuse to open the door.
[0504] Also, according to some embodiments of the present invention, modifying the access status information may be performed by the second door operation device 3000b (S960).
[0505] If it is determined that the door should be opened, the second door operating device 3000b may change the access state information.
[0506] The second door operation device 3000b may change the access state to the next stage. For example, if the access state for the second door operation device 3000b is an entering state, the second door operation device 3000b may change the access state to an exiting state.
[0507] Also, according to some embodiments of the present invention, transmitting access status information may be performed by the second door operation device 3000b (S970).
[0508] Also, according to some embodiments of the present invention, opening of the second door 4000b may be performed by the second door operating device 3000b (S440).
[0509] Although the above description illustrates an example of access control through a hierarchical structure among multiple door operation devices, the present invention is not limited thereto. A sixth modification of the access status management method according to the present embodiment may be implemented as a hierarchical structure between the door operation device 3000 and the electronic device. For example, when a request to use the electronic device is made using an authentication token, the electronic device may determine, based on the access status information, whether the user terminal 2000a has entered through an entrance door of the space in which the electronic device is located. If the determination result indicates that the user terminal 2000a has entered through the entrance door of the space in which the electronic device is located, use of the electronic device may be permitted. In this embodiment, the second door operation device 3000b of the sixth modification of the access status management method according to the present embodiment may be replaced by an electronic device, and the determination of whether to open the door performed by the second door operation device 3000b may be replaced by a determination of whether to permit use of the electronic device.
[0510] 4.3. Method for Forcibly Changing Authority A method for forcibly changing authority according to an embodiment of the present invention will now be described with reference to FIGS.
[0511] FIG. 19 shows an overview of a method for forcibly changing authority according to an embodiment of the present invention.
[0512] When the access control system 10000 is installed in a building or the like, authentication tokens are typically issued according to the granted authority, thereby limiting the accessible area and allowing only authorized doors to be opened. However, in the event of a special event such as a fire or earthquake, it is preferable to grant authority to open all doors or to open doors necessary for evacuation as an exception. In the event of a fire or earthquake, if a problem occurs in the communication established between the access control server and the access control device, conventional access control systems may be unable to open evacuation doors. However, the access control system 10000 of the present invention solves this problem by having the authentication server 1000 forcibly issue authorized authentication tokens.
[0513] The method for forcibly changing authority according to the embodiment of the present invention can also be applied to cases where access by authorized users is temporarily restricted due to a security conference or the like.
[0514] FIG. 20 is a sequence diagram showing a method for forcibly changing authority according to an embodiment of the present invention.
[0515] Referring to FIG. 20, the method for forcibly changing authority includes a step of obtaining a request to change authority (S1000), a step of extracting a target whose authority is to be changed (S1010), and a step of sending an authentication token having updated authority to the extracted target (S1020).
[0516] According to some embodiments of the present invention, obtaining a request to change the authority may be performed (S1000). The request to change the authority may be provided by a user terminal 2000a.
[0517] The user terminal 2000a may acquire the permission change request information.
[0518] The permission change request information may be information for requesting a change in the user's permission. Changing the permission in accordance with the permission change request information may indicate a continuous change in the permission, but the present invention is not limited thereto. Changing the permission may indicate a temporary change in which at least one of a time limit and a condition is fixed.
[0519] Here, the object of the permission change may be at least one of a user and the door 4000. If the object of the permission change is a user, the permission change may indicate a change in the permission granted to the user. Also, if the object of the permission change is a door, the permission change may indicate a change in the permission performed by updating an authentication token including the permission of the corresponding door.
[0520] The user terminal 2000a may output a permission change graphical user interface (GUI) for acquiring permission change request information through a display unit.
[0521] The user terminal 2000a may acquire information about the object whose authority is to be changed. If the object whose authority is to be changed is a user, the user terminal 2000a acquires information about the object whose authority is to be changed through at least one of selecting a user whose authority is to be acquired and inputting user identification information. If the object whose authority is to be changed is a door, the user terminal 2000a acquires information about the object whose authority is to be changed through at least one of selecting a door whose authority is to be acquired and inputting door identification information.
[0522] The user terminal 2000a may acquire information related to the change history.
[0523] When the subject of the change of authority is a user, the user terminal 2000a may acquire a change history regarding at least a portion of the granted authority. For example, when authority to the first door is granted to the user, the change history may include information regarding the revocation of authority to the first door. As another example, when the user does not have authority to the first door, the change history may include information regarding the authority to the first door. As another example, the change history may include information regarding the granting of authority to the first door only to a specific user.
[0524] As mentioned above, the change history may include information regarding changes to at least some of the previously granted permissions or permissions that have not been granted.
[0525] If the target for changing permissions is a door, the change history may include information on whether access to the door for which permissions are changed is forcibly restricted or permitted. For example, if the target for changing permissions is a door, the change history may include information on a request to restrict permissions for the door for which permissions are changed. As another example, the change history may include information on a request to forcibly grant permissions for the door for which permissions are changed.
[0526] Additionally, according to some embodiments of the present invention, the change history may include the occurrence of a predetermined special event. For example, the change history may include a fire.
[0527] In this case, the change history may include opening all doors.
[0528] The user terminal 2000a may acquire information about the change conditions.
[0529] The change conditions may be conditions under which the change becomes effective.
[0530] The change conditions may include a change time and a target grade.
[0531] The change time may be information regarding the time period during which the change in the permission is valid. For example, the changed permission may be valid only for a limited time period depending on the change time. As another example, the validity of the changed permission may be limited depending on the target grade.
[0532] The user terminal 2000a may transmit permission change request information to the authentication server 1000 to request the authentication server 1000 to change the permission.
[0533] Also, according to some embodiments of the present invention, if the change history is the occurrence of a specific event, such as a fire, the change condition may be omitted.
[0534] Also, according to some embodiments of the present invention, extracting a target for changing the permission may be performed (S1010).
[0535] The authentication server 1000 may extract the target included in the authority change request information.
[0536] In the following description, as an example, the target included in the authority change request information is a user. In this case, the authentication server 1000 may extract the user whose authority is to be changed. The authentication server 1000 may extract, as the user whose authority is to be changed, a user corresponding to user identification information included in the target whose authority is to be changed. Furthermore, the authentication server 1000 may extract, as the user whose authority is to be changed, a user corresponding to a grade included in the target whose authority is to be changed.
[0537] In the following description, as an example, the object included in the authority change request information is a door. In this case, different operations may be executed depending on whether the change history includes blocking passage through the door or allowing passage through the door.
[0538] If the change history includes blocking of passage through a door, the authentication server 1000 may extract users who have been granted permission for the door whose permission is to be changed.
[0539] Furthermore, if the change history includes permission to pass through a door, the authentication server 1000 may extract users who do not have the authority to access the door for which the authority is to be changed.
[0540] Also, in some embodiments of the present invention, if the change history includes the occurrence of a particular event, such as a fire, the permissions to be changed may be for all registered users or all users who have received an authentication token.
[0541] Also, according to some embodiments of the present invention, sending the authentication token with the updated authorization to the extraction target may be performed (S1020).
[0542] The authentication server 1000 may transmit an authentication token with changed privileges based on the privilege change history for each extracted user. For example, assume that an authentication token with privileges for the first door is issued to user A, who is a target included in the privilege change request information. In this case, if the privilege change history includes a request to revoke privileges for the first door, the authentication server 1000 may transmit a new authentication token that does not include privileges for the first door to user A's user terminal 2000a. After receiving the new authentication token, user A's user terminal 2000a may discard the original authentication token and replace it with the new authentication token.
[0543] If the deadline and / or conditions for the permission change are revoked, the authentication server 1000 may restore the original authentication token.
[0544] For example, the authentication server 1000 may transmit the authentication token before the authority change to the user terminal 2000a in order to update the new authentication token with the transmitted authentication token.
[0545] As another example, the authentication server 1000 may send a command to the user terminal 2000a so that the authentication token before the authority change can be used.
[0546] The request to change the authority does not necessarily have to be acquired through the user terminal 2000a, but may be acquired from the administrator terminal 2000b.
[0547] The authentication server 1000 may also acquire authority change request information in relation to separate systems such as a fire alarm system and a disaster response system.
[0548] In addition, when it is determined that a special event such as a fire or disaster has occurred in connection with separate systems such as a fire alarm system and a disaster prevention system, the authentication server 1000 may determine that a request to change authority has been received, extract the target for which authority is to be changed, and send updated authentication information.
[0549] When it is determined that such a special event has occurred, the target to which the authentication information is sent may be preset by the authentication server 1000.
[0550] In addition, when a special event occurs, the door operation device 3000 may receive a notification from the terminal 2000 indicating that a special event has occurred, and may determine whether a special event has occurred based on information contained in the authentication token.
[0551] According to some embodiments of the present invention, when it is determined that a special event has occurred, the door operating device 3000 may notify all connected door operating devices 3000 that the special event has occurred. Upon receiving the notification, all door operating devices 3000 may change the state of the door so that the door can remain open.
[0552] The door operation device 3000 may operate in different ways when a special event occurs and when it is in a normal situation.
[0553] FIG. 21 is an exemplary diagram showing the operation of the door operation device 3000 according to the embodiment of the present invention in a normal situation and in a situation where a special event occurs.
[0554] As shown in FIG. 21 , under normal circumstances, the door operation device 3000 may determine that only a signal acquired within a first communication range is a normal signal. Specifically, the door control unit 3700 may acquire a signal transmitted by the terminal 2000 through the door communication unit 3100. If the signal acquired through the door communication unit 3100 is within the first communication range, the door control unit 3700 may determine that the acquired signal is a normal signal. The door control unit 3700 may determine whether the acquired signal is within the first communication range based on the strength of the signal. If the signal acquired through the door communication unit 3100 is within a second communication range outside the first communication range, the door control unit 3700 may ignore the acquired signal.
[0555] Even if the acquired signal is within the second communication range, if a special event occurs, the door control unit 3700 may determine that the acquired signal is a normal signal.
[0556] When a signal occurs, the terminal 2000 may add an event occurrence notification indicating that a special event has occurred to the signal and transmit the signal.
[0557] When an event occurrence notification indicating that a special event has occurred is included in a signal acquired within the second communication range, the door control unit 3700 may determine the acquired signal as a normal signal without ignoring the signal. Furthermore, when an event occurrence notification indicating that a special event has occurred is included in the acquired signal, the door control unit 3700 may execute a predetermined special event action. For example, the door control unit 3700 may execute a special event action to keep the door open. As another example, the door control unit 3700 may execute a special event action to open the door regardless of conditions such as authorization.
[0558] Furthermore, according to some embodiments of the present invention, the authentication server 1000 may issue an authentication token for registering a specific user requested by the terminal 2000 for the door operation device 3000 so that only the specific user is permitted to enter. The terminal 2000 may transmit the authentication token for registering the specific user to the door operation device 3000, and the door operation device 3000 may determine that only the specific user included in the authentication token has the authority to open the door.
[0559] 4.4. Domain Cooperation Security Method A domain cooperation security method according to an embodiment of the present invention will now be described with reference to FIGS.
[0560] FIG. 22 is a diagram showing an overview of the area cooperation security method according to the embodiment of the present invention.
[0561] Referring to FIG. 22, the area collaboration security method is an embodiment in which the use of electronic devices such as an office-specific electronic device 6000 or a hotel-specific electronic device located in a position accessible to a user is permitted taking into consideration at least one of the user's authority and the user's access.
[0562] An office-specific electronic device 6000 installed in an office, or electronic devices such as lighting devices and air conditioners installed in a hotel room, must be restricted so that only specific users can use these devices.
[0563] However, if a user forgets the password to their PC or loses their hotel room key, an unauthorized user may use the office-specific electronic device or the hotel-specific electronic device.
[0564] Therefore, the area linkage security method according to an embodiment of the present invention can enhance security by having the authentication server 1000 determine whether a user has actually entered the space in which the electronic device is located, and allowing use of the electronic device only if the user has entered the space.
[0565] FIG. 23 is a sequence diagram showing a cooperative area security method according to an embodiment of the present invention.
[0566] Referring to FIG. 23, the area cooperation security method may include a step in which the user terminal 2000a sends entry history information to the authentication server 1000 (S1100), a step in which the user terminal 2000a requests the office-specific electronic device 6000 to be permitted to use the office-specific electronic device 6000 (S1110), a step in which the office-specific electronic device 6000 requests user authentication from the authentication server 1000 (S1120), a step in which the authentication server 1000 performs user authentication (S1130), a step in which the authentication server 1000 sends the authentication result to the office-specific electronic device 6000 (S1140), a step in which the user terminal 2000a permits use of the office-specific electronic device 6000 (S1150), a step in which the user terminal 2000a sends exit history information (S1160), and a step in which the authentication server 1000 sends an exit command to the office-specific electronic device 6000 (S1170).
[0567] According to some embodiments of the present invention, the user terminal 2000a may transmit the entry history information to the authentication server 1000 (S1100). Here, the authentication server 1000 may be the authentication server 1000 that issued the authentication token, or may be a separate authentication server different from the authentication server 1000 that issued the authentication token.
[0568] If the authorization information indicates that the user terminal 2000a is determined to be authorized, the user terminal 2000a may transmit the authorization information and door identification information for the authorized door.
[0569] The authentication server 1000 may acquire the permission information and the door identification information from the user terminal 2000a, and may store the acquired permission information and door identification information.
[0570] The authentication server 1000 may determine the space into which the user has entered based on the permission information and the door identification information.
[0571] Furthermore, according to some embodiments of the present invention, the user terminal 2000a may execute a request to the office-specific electronic device 6000 to allow use of the office-specific electronic device 6000 (S1110).
[0572] The user terminal 2000a may send an authentication token to the office-specific electronic device 6000 to request use of the office-specific electronic device 6000. For this purpose, the office-specific electronic device 6000 may be provided with a communication means for communicating with the user terminal 2000a.
[0573] Alternatively, the office-specific electronic device 6000 may acquire a usage request input directly from a user without going through the user terminal 2000a. For this purpose, the office-specific electronic device 6000 may include an input means for acquiring a user input.
[0574] When the office-specific electronic device 6000 obtains a user request through user input, the office-specific electronic device 6000 may obtain at least one of user information, user identification information, and a security key corresponding to the user identification information through the user input.
[0575] Additionally, according to some embodiments of the present invention, the office-specific electronic device 6000 may request user authentication from the authentication server 1000 (S1120).
[0576] The office-specific electronic device 6000 may send the obtained authentication token to the authentication server 1000 to request user authentication.
[0577] The office-specific electronic device 6000 may determine whether the acquired authentication token includes authority for the office-specific electronic device 6000. If the determination result shows that authority for the office-specific electronic device 6000 is included, the office-specific electronic device 6000 may send the authentication token to the authentication server 1000 to request user authentication. If the determination result shows that authority for the office-specific electronic device 6000 is not included, the office-specific electronic device 6000 may output a denial message to deny use.
[0578] Furthermore, the office-specific electronic device 6000 may transmit at least one of the acquired user information, the user identification information, and the security key corresponding to the user identification information to the authentication server 1000 to request user authentication.
[0579] Additionally, according to some embodiments of the present invention, the authentication server 1000 may perform user authentication (S1130).
[0580] The authentication server 1000 may determine whether a user corresponding to the authentication token obtained from the office-specific electronic device 6000 has passed through a door. The authentication server 1000 may determine whether a user corresponding to the authentication token has entered the space in which the office-specific electronic device 6000 is located through the corresponding door 4000, based on at least one of the stored permission information, the door identification information, and the access status information.
[0581] The authentication server 1000 may also determine the authority corresponding to the user identification information obtained from the office-specific electronic device 6000 .
[0582] Additionally, according to some embodiments of the present invention, the authentication server 1000 may transmit the result of the authentication to the office-specific electronic device 6000 (S1140).
[0583] If it is determined that the user corresponding to the authentication token has entered the space in which the office-specific electronic device 6000 is located through the corresponding door, the authentication server 1000 may request permission from the office-specific electronic device 6000 to use the office-specific electronic device 6000.
[0584] The authentication server 1000 may transmit authentication information corresponding to the user identification information to the office-specific electronic device 6000 to request permission to use the function included in the authentication information from the office-specific electronic device 6000.
[0585] If it is determined that a user corresponding to the user identification information has entered the space in which the office-specific electronic device 6000 is located through the corresponding door, the authentication server 1000 may request permission to use the office-specific electronic device 6000.
[0586] Furthermore, according to some embodiments of the present invention, the office-specific electronic device 6000 may execute usage authorization based on the authentication result (S1150).
[0587] If the user authentication result is permission, the office-specific electronic device 6000 may permit use of the office-specific electronic device 6000.
[0588] Furthermore, according to some embodiments of the present invention, the user terminal 2000a may transmit the exit history information (S1160).
[0589] The authentication server 1000 may obtain, from the user terminal 2000a, information indicating that the user has passed through a door that exits the space in which the office-specific electronic device 6000 is located.
[0590] According to some embodiments of the present invention, the authentication server 1000 may also send an end command to the office-specific electronic device 6000 (S1170).
[0591] When the authentication server 1000 acquires information from the user terminal 2000a indicating that the user has passed through the door and moved out of the space in which the office-specific electronic device 6000 is located, the authentication server 1000 may request shutdown from the office-specific electronic device 6000. The shutdown of the office-specific electronic device 6000 may be at least one of a power-off operation, a screen saver operation, and a log-off operation.
[0592] 4.4.1. Area Cooperation Security Method - First Modification The above-described area cooperation security method may be modified in various ways depending on the application.
[0593] In a first modified example of the area cooperation security method, the authentication server 1000 may acquire door access information from the user terminal 2000a, and transmit a control command to an external controller based on the acquired door access information.
[0594] For convenience of explanation, operation in a hotel room will be described as an example below. Conventionally, physical keys have been used to control access to hotel rooms and to control room functions in the hotel room. However, when such physical keys are used, users have the inconvenience of having to carry the physical key. Furthermore, a user may want to activate a hotel room function when they are outside the hotel room. For example, the air conditioner or washing machine may need to operate even when the user is away from the hotel room. In this case, the physical key must be inside the hotel room to activate the hotel room function, thus preventing the user from leaving the hotel room. However, when the domain linkage security method according to an embodiment of the present invention is applied to operation in a hotel room, the above-mentioned physical key may be replaced by a user terminal, thereby solving the above-mentioned problems caused by the use of a physical key. An embodiment in which the domain linkage security method according to an embodiment of the present invention is applied to operation in a hotel room will be described in detail below.
[0595] A first variant of the domain cooperation security method will now be described with reference to FIG.
[0596] FIG. 24 is a sequence diagram showing a first modified example of the area cooperation security method according to the embodiment of the present invention.
[0597] Referring to Figure 24, in the description of the first variant of the area cooperation security method, the operation between the user terminal and the door operation device 3000 may be performed by either the first or second detailed embodiment, and therefore, detailed description thereof will be omitted.
[0598] Referring to FIG. 24, the first modified example of the area cooperation security method includes a step in which the user terminal 2000a transmits entry history information to the authentication server 1000 (S1100), a step in which the authentication server 1000 transmits a room function activation command to the hotel controller 7000 (S1200), a step in which the hotel controller 7000 activates the room function (S1205), a step in which the user terminal 2000a transmits exit history information to the authentication server 1000 (S1210), a step in which the authentication server 1000 transmits a room function deactivation command to the hotel controller 7000 (S1215), and a step in which the hotel controller deactivates the room function (S1220). The method may include a step of requesting activation of a function by the user terminal 2000a (S1225), a step of the authentication server 1000 sending a command to the hotel controller 7000 to activate the requested function (S1230), a step of the hotel controller 7000 activating the requested function for the corresponding room (S1235), a step of the authentication server 1000 determining whether entry history information has been acquired within a predetermined amount of time (S1240), a step of the authentication server 1000 sending a command to deactivate the requested function (S1245), and a step of the hotel controller 7000 sending a command to deactivate the requested function (S1250).
[0599] According to some embodiments of the present invention, the user terminal 2000a may transmit the entry history information to the authentication server 1000 (S1100).
[0600] The entry history information may include at least one of information indicating that a door is permitted to be opened, door identification information of the permitted door, and access status information.
[0601] When permission information indicating that the user terminal 2000a has been determined to have the authority to open the door is received from the door operation device 3000, the user terminal 2000a may transmit entry history information to the authentication server 1000.
[0602] The authentication server 1000 may acquire the entry history information from the user terminal 2000a and store the acquired entry history information.
[0603] Furthermore, the authentication server 1000 may determine the current location of the user terminal 2000a based on the entry history information and store the current location.
[0604] According to some embodiments of the present invention, the sending of a room function activation command to the hotel controller 7000 may be performed by the authentication server 1000 (S1200).
[0605] The authentication server 1000 may send a control command to the hotel controller 7000 based on the entry history information.
[0606] The authentication server 1000 may determine which room the user has entered after passing through the door 4000, based on the entry history information acquired from the user terminal 2000a.
[0607] If it is determined that the user has entered the room, the authentication server may send a room function activation command to the hotel controller 7000 so that operation of a specific electronic device among multiple electronic devices in the room can be activated.
[0608] Activating and deactivating the electronic device may involve turning the power of the electronic device on and off, or alternatively, supplying and cutting off power to the electronic device.
[0609] In some embodiments, the room activation command may be a command to provide power to the corresponding room, and the room shutdown command may be a command to cut off power to the corresponding room. Also, exceptional electronic devices that require constant power, such as refrigerators, may be exempt from the room activation and shutdown commands.
[0610] According to some embodiments of the present invention, activation of the room function may be performed by the hotel controller 7000 (S1205).
[0611] The hotel controller 7000 may execute control to activate the operation of a specified electronic device among a plurality of electronic devices in a room determined to have been entered by a user based on a room function activation command obtained from the authentication server 1000.
[0612] According to some embodiments of the present invention, the user terminal 2000a may transmit the exit history information to the authentication server 1000 (S1210).
[0613] The authentication server 1000 may acquire, from the user terminal 2000a, exit history information indicating that the user has passed through a door and exited.
[0614] The exit history information may include at least one of information indicating that a door is permitted to be opened, door identification information of the permitted door, and access status information.
[0615] Here, the entry history information and the exit history information may have different access status information.
[0616] When permission information indicating that the user terminal 2000a has been determined to have the authority to open the door is received from the door operation device 3000, the user terminal 2000a may transmit exit history information to the authentication server 1000.
[0617] The authentication server 1000 may acquire the exit history information from the user terminal 2000a and store the acquired exit history information.
[0618] Furthermore, the authentication server 1000 may determine that the user terminal 2000a is outside the corresponding room based on the exit history information, and store the determination.
[0619] According to some embodiments of the present invention, the authentication server 1000 may perform sending of a room shutdown command to the hotel controller 7000 (S1215).
[0620] If it is determined that the user has left the room, the authentication server 1000 may send a room shutdown command to the hotel controller 7000 so that the devices in the room can be shut down.
[0621] According to some embodiments of the present invention, a hotel controller may execute a room shutdown (S1220).
[0622] The hotel controller 7000 may execute control based on the room function shutdown command so as to shut down the function of the corresponding room.
[0623] According to some embodiments of the present invention, a request for activation of a room function may be executed by the user terminal 2000a (S1225).
[0624] The authentication server 1000 may be requested by the user terminal 2000a to activate functions of at least some of the electronic devices included in the room from the user terminal.
[0625] For example, the authentication server 1000 may be requested by the user terminal 2000a to start an air conditioner among multiple electronic devices included in a room.
[0626] The user terminal 2000a may output an authority change graphical user interface (GUI) for receiving the function selected to be activated, outputting selectable functions or all functions, and receiving approval for the function activation request from the user.
[0627] According to some embodiments of the present invention, the authentication server 1000 may send a command to the hotel controller 7000 to activate the requested function (S1230).
[0628] Based on the function activation request received from the user terminal 2000a, the authentication server 1000 may transmit a command to activate the requested function to the hotel controller 7000.
[0629] The authentication server 1000 may also determine whether the user has permission for the function included in the request. If it is determined that the user has permission for the function included in the request, the authentication server 1000 may send a command to the hotel controller 7000 to activate the requested function.
[0630] Furthermore, if it is determined that the user does not have the authority for the function included in the request, the authentication server 1000 may send a rejection message to the user terminal 2000a.
[0631] According to some embodiments of the present invention, activation of the requested room functionality may be performed by the hotel controller 7000 (S1235).
[0632] The hotel controller 7000 may activate electronic devices included in the room based on the acquired requested function activation command. For example, if the request included in the requested function activation is to activate an air conditioner, the hotel controller 7000 may execute control to activate the air conditioner. Furthermore, if the requested function activation command includes detailed requests such as a desired temperature, the hotel controller may execute control to execute the detailed requests. For example, if the detailed command includes a request that the room temperature be 24°C, the hotel controller 7000 may control the air conditioner or heater included in the room to maintain the room temperature at 24°C.
[0633] According to some embodiments of the present invention, the authentication server 1000 may determine whether entry history information has been acquired (S1240).
[0634] For example, if the user terminal 2000a makes a request to turn on a light in a room, the authentication server 1000 may send a control command to the hotel controller 7000 to turn on the light even if the user is outside the room.
[0635] After receiving the function activation request, the authentication server 1000 may determine whether or not the access history information has been received.
[0636] More specifically, the authentication server 1000 may determine whether the entry history information corresponding to the door installed in the room has been obtained from the user terminal 2000a within a predetermined amount of time from the time the function activation request was obtained and from the time the command to activate the requested function was sent to the hotel controller 7000.
[0637] According to some embodiments of the present invention, the sending of a command to deactivate the requested function may be performed by the authentication server 1000 (S1245).
[0638] If the determination result of whether entry history information has been acquired indicates that entry history information corresponding to the door installed in the room has not been acquired from the user terminal 2000a within a predetermined amount of time, the authentication server 1000 may send a command to disable the requested function to the hotel controller 7000. The command to disable the requested function may be a command to cancel a requested function activation command previously sent to the hotel controller 7000 in accordance with a request from the user terminal 2000a.
[0639] According to some embodiments of the present invention, sending a command to deactivate the requested function may be performed by the hotel controller 7000 (S1250).
[0640] The hotel controller 7000 may execute control so as to stop the function activated in S1235.
[0641] As another example, the hotel controller 7000 may cancel the command of S1235 based on a command to disable the requested function.
[0642] 4.4.2. Area Cooperative Security Method - Second Modification A second modification of the area cooperative security method will be described below with reference to FIG.
[0643] FIG. 25 is a flowchart showing a second modified example of the area cooperation security method according to the embodiment of the present invention.
[0644] Referring to FIG. 25 , a second variant of the area cooperation security method may include a step of acquiring first door access history information (S1300), activating a room function (S1310), a step of determining whether second door access history information has been acquired (S1320), a step of maintaining the activation of the room function (S1330), a step of stopping the room function (S1340), a step of acquiring second door access history information (S1350), and a step of activating the room function (S1360).
[0645] According to some embodiments of the present invention, obtaining first door access history information may be performed (S1300).
[0646] When the user terminal 2000a receives permission information from the first door operation device 3000a indicating that it has been determined that the user terminal 2000a has the authority to open the first door, the user terminal 2000a may transmit the first door access history information to the authentication server 1000.
[0647] The first door may be a predetermined door other than the door of the room where the user is staying. For example, the first door may be at least one door in a hotel lobby. As another example, the first door may be a door leading to a hallway leading to the room where the user is staying.
[0648] The authentication server 1000 may acquire the first door access history information from the user terminal 2000a and store the acquired first door access history information.
[0649] Furthermore, the authentication server 1000 may determine, based on the entry history information, that the user of the user terminal 2000a has entered through the first door, and store the determination.
[0650] Also, according to some embodiments of the present invention, activation of a room function may be performed (S1310).
[0651] The authentication server 1000 may send a control command to the hotel controller 7000 based on the first door access history information.
[0652] Based on the first entry history information acquired from the user terminal 2000a, the authentication server 1000 may send a room function activation command to the hotel controller 7000 so that the user terminal 2000a can activate the operation of an identified electronic device among multiple electronic devices in the room where the user is staying.
[0653] Activating and deactivating the electronic device may involve turning the power of the electronic device on and off, or alternatively, supplying and cutting off power to the electronic device.
[0654] In some embodiments, the room activation command may be a command to provide power to the corresponding room, and the room shutdown command may be a command to cut off power to the corresponding room. Also, exceptional electronic devices that require constant power, such as refrigerators, may be exempt from the room activation and shutdown commands.
[0655] Additionally, according to some embodiments of the present invention, a determination may be made as to whether second door access history information has been obtained (S1320).
[0656] The authentication server 1000 may determine whether second door access history information related to a second door provided in the room where the user is staying has been acquired.
[0657] More specifically, the authentication server 1000 may determine whether the second door access history information is obtained from the user terminal 2000a within a predetermined amount of time from the time the first door access history information is obtained or from the time the room function activation command is sent to the hotel controller 7000.
[0658] Also, according to some embodiments of the present invention, maintaining activation of room functions may be performed (S1330).
[0659] When the second door access history information is acquired, the authentication server 1000 may maintain the activation of the room function. More specifically, when the second door access history information is acquired from the user terminal 2000a within a predetermined time from the time when the first door access history information is acquired or the time when the room function activation command is sent to the hotel controller 7000, the authentication server 1000 may maintain the activation of the room function.
[0660] Maintaining activation of a room function may involve not sending a cancel command for the room function activation command or a room function deactivation command to the hotel controller 7000.
[0661] Also, according to some embodiments of the present invention, a shutdown of the room's functions may be performed (S1340).
[0662] If the second door access history information is not acquired, the authentication server 1000 may send a room function stop command to the hotel controller 7000 so that the room function can be stopped. More specifically, if the second door access history information is not acquired from the user terminal 2000a within a predetermined time from the time when the first door access history information is acquired or the time when the room function activation command is sent to the hotel controller 7000, the authentication server 1000 may send a room function stop command to the hotel controller 7000.
[0663] Additionally, according to some embodiments of the present invention, obtaining second door access history information may be performed (S1350).
[0664] When the user terminal 2000a receives permission information from the second door operation device 3000b indicating that it has been determined that the user terminal 2000a has the authority to open the second door, the user terminal 2000a may transmit the second door access history information to the authentication server 1000.
[0665] The second door may be a door to a room where the user is staying. For example, the second door may be an access door to the room where the user is staying.
[0666] The authentication server 1000 may acquire the second door access history information from the user terminal 2000a and store the acquired second door access history information.
[0667] Furthermore, the authentication server 1000 may determine that the user of the user terminal 2000a has entered the second door based on the second door access history information, and store the determination.
[0668] Also, according to some embodiments of the present invention, activation of a room function may be performed (S1340).
[0669] Based on the second entry history information acquired from the user terminal 2000a, the authentication server 1000 may send a room function activation command to the hotel controller 7000 so that the user terminal 2000a can activate the operation of an identified electronic device among multiple electronic devices in the room where the user is staying.
[0670] Therefore, the modified area-linked security method according to the embodiment of the present invention can prevent unauthorized persons from using electronic devices in a room, because the electronic devices will not be activated if the user has not confirmed that they have entered the room, even if the door key or door card is lost. Furthermore, the modified area-linked security method according to the embodiment of the present invention can improve user convenience by allowing the user to request activation of some functions even when the user is outside.
[0671] The present invention provides increased user convenience by utilizing an authentication token to open authorized doors without additional authentication as long as the authentication token is valid.
[0672] Furthermore, according to the present invention, even if a failure occurs in the authentication server or communication between the authentication token and the door operating device is interrupted, as long as the authentication token is valid, the authorized door can be opened, thereby improving user convenience.
[0673] Furthermore, according to the present invention, by taking into consideration access status information regarding entry or exit, it is possible to manage use based on the authorization given to the user.
[0674] Furthermore, according to the present invention, when a special event such as a disaster occurs, the authentication token is forcibly updated, thereby making it possible to assist users in evacuating more quickly and accurately.
[0675] Furthermore, according to the present invention, by allowing the use of an electronic device in consideration of whether or not there has been an intrusion into the corresponding space, security against the use of the electronic device by an unauthorized intruder can be enhanced.
[0676] The effects of the present invention are not limited to those described above, and other effects not described in this specification will be apparent to those skilled in the art from the following description and the accompanying drawings.
[0677] While elements and features of the present invention have been described with reference to embodiments thereof, the present invention is not limited thereto. It will be apparent to those skilled in the art that various modifications and variations may be made without departing from the spirit and scope of the present invention. Accordingly, such modifications and variations are intended to be included within the scope of the appended claims.
Claims
1. An access control method in which a first device determines whether to open a first door to enter or exit a first area based on an authentication token obtained from a second device, obtaining the authentication token from the second device; determining whether the second device is authorized to access the first door based on authentication information included in the authentication token; controlling the first door to open when determining that the second device has authority to access the first door; Equipped with the authentication information includes identification information of at least one of the first door, the first device, or the first area; at least a portion of the authentication information included in the authentication token of the second device is changed by the authentication server when the authentication server is requested to change the authentication information; When the changed authentication information is compared with the authentication information before the change, the changed authentication information includes identification information of at least one of a second door, a third device that determines whether to open the second door to enter or exit the second area, or the second area, the authentication token containing the modified authentication information is used by the first device to determine whether the second device is authorized to access the first door; and If the third device obtains the authentication token from the second device, the authentication token including the modified authentication information is used by the third device to determine whether the second device is authorized to access the second door. Access control methods.
2. If the authentication information is changed by the authentication server so that the second device does not have authority to access the first door, the first device determines that the second device does not have authority to access the first door based on the changed authentication information, and controls the first door to be closed. The access control method according to claim 1 .
3. the authentication information includes an identity of the authorized first device; 2. The access control method of claim 1, wherein if the authentication information includes identification information of at least one of the first device and the first door, the first device determines that the second device has the authority to access the first door.
4. the authentication information includes at least one of the identification information of the first device and the identification information of the first door stored in the authentication server, and includes an authority value corresponding to the identification information; 4. The access control method of claim 3, wherein the authentication information includes identification information of at least one of the first device and the first door, and when the authority value corresponding to the identification information is a predetermined value indicating authority, the first device determines that the second device has the authority to access the first door.
5. The access control method according to claim 1 , wherein the authentication token includes at least one of authentication information, authentication validity conditions, authentication token status information, issuer information, and recipient information.
6. 6. The access control method of claim 5, wherein the first device determines whether the authentication token is valid, and refuses to open the first door if it determines that the second device has the authority to access the first door but the authentication token is not valid.
7. The access control method according to claim 6 , wherein if it is determined based on the authentication token status information that the authentication token has expired, the first device determines that the authentication token is not valid.
8. The first device determines whether the authentication token is valid based on the authentication validity condition; The access control method according to claim 6 or 7, wherein the authentication validity conditions include at least one of a validity period, a validity location, and a number of uses.
9. The validity period is a validity period value corresponding to the remaining time until a time limit at which the authentication token is determined to be invalid or the time elapsed since the authentication token was issued; The access control method of claim 8 , wherein the first device determines that the authentication token is not valid if the validity period value is equal to a predetermined threshold value.
10. the authentication token includes information about the second device at the time the authentication token was issued; 10. The access control method of claim 8, wherein the first device determines that the authentication token is not valid if the information about the second device at the time the authentication token is issued is not included in a location information range included in the valid location.
11. The access control method according to claim 8 , wherein the first device determines that the authentication token is not valid if the number of uses is greater than or equal to a predetermined number.
12. 12. The access control method according to claim 1, further comprising a step in which the first device transmits to the second device a result of determining whether the second device has the authority to access the first door.
13. 13. The method of claim 1, wherein the authentication token is updated by the second device sending a pre-stored update token that matches the authentication token to the authentication server.
14. The access control method according to claim 1 , wherein the authentication information included in the authentication token includes at least one of authority for a space, authority for a first door, and authority for an electronic device.
15. 1. A method of access control for a first device, comprising: obtaining an authentication token from an authentication server; providing the authentication token to a second device that determines whether to open a first door to enter or exit a first area, whereby the second device determines whether the first device is authorized to access the first door based on authentication information contained in the authentication token; Equipped with the authentication information includes identification information of at least one of the first door, the second device, or the first area; At least a portion of the authentication information included in the authentication token of the first device is changed by the authentication server when the authentication server is requested to change the authentication information; When the changed authentication information is compared with the authentication information before the change, the changed authentication information includes identification information of at least one of a second door, a third device that determines whether to open the second door to enter or exit the second area, or the second area, the authentication token containing the modified authentication information is used by the second device to determine whether the first device is authorized to access the first door; and If the third device obtains the authentication token from the first device, the authentication token including the modified authentication information is used by the third device to determine whether the first device is authorized to access the second door. Access control methods.
16. A program for causing a computer in the first device to execute the access control method according to any one of claims 1 to 14.
17. A program for causing a computer in the first device to execute the access control method according to claim 15.
Citation Information
Patent Citations
Portable electronic key
JP2004086547A
Access management system
JP2004287991A
Copyright management system that uses legal expression language
JP2006501536A
Electric lock control system
JP2011012511A
Door security system and control device for the same
JP2011149204A