Control method based on user authentication using a detection sensor and device using the same

The control method enhances user authentication efficiency and security by using a detection sensor to manage communication modes and process identification information via a server, addressing inefficiencies in conventional mobile terminal authentication.

JP7777312B2Active Publication Date: 2025-11-28MOCA SYST INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024014418
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-08-23
Filing Date
2024-02-01
Publication Date
2025-11-28
Estimated Expiration
2041-08-25

AI Technical Summary

Technical Problem

Conventional user authentication methods using mobile terminals are inefficient due to longer communication times and varying performance based on the operating system, causing delays and inconvenience.

Method used

A control method utilizing a detection sensor to activate different operation modes based on the location of a mobile object, allowing for accurate and secure user authentication by communicating with terminals in specific areas through dedicated communication units, and processing user identification information via a server.

Benefits of technology

This approach reduces authentication time and improves accuracy and security by optimizing communication based on location, independent of terminal performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007777312000001
    Figure 0007777312000001
  • Figure 0007777312000002
    Figure 0007777312000002
  • Figure 0007777312000003
    Figure 0007777312000003
Patent Text Reader

Abstract

To provide a control method, a program, and a control device that improve accuracy and security of user authentication regardless of performance of a terminal.SOLUTION: A control method for a control device comprises the steps of: determining, using a detection sensor, whether or not a moving object is located in a first area; activating, when determining that the moving object is located in the first area, a first mode of the control device; and acquiring, when the first mode is active, user authentication information from a terminal. The user authentication information corresponds to user-specific information stored in the terminal and is provided to the terminal by the server before the terminal provides the user authentication information to the control device. The method also comprises the steps of: transmitting processing request information based on the user authentication information to the server so that the server performs processing on the user authentication information; obtaining a processing result for the user authentication information from the server; and providing the processing result for the user authentication information to the terminal.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application claims priority to and the benefit of Korean Patent Application No. 10-2020-0107374, filed on August 25, 2020, and Korean Patent Application No. 10-2021-0111298, filed on August 23, 2021, the disclosures of which are incorporated herein by reference in their entireties.

[0002] 1. Field of the Invention The present invention relates to a user authentication based control method using a detection sensor and a device using the same.

[0003] 2. Consideration of related technologies In the field of performing user authentication and controlling access to buildings or specific areas, a technology is used to improve convenience of payment processing, use of specific devices, etc. In this technology, the user terminal is implemented as a card key in related technologies, and in recent years has gradually been extended to mobile terminals such as smartphones carried by users.

[0004] However, it may take a long time for the mobile terminal to obtain the information necessary for user authentication compared to a conventional card key, which causes inconvenience to the user in that the user feels a delay.

[0005] Furthermore, with conventional BLE communication, there are issues such as the required communication time varying depending on the operating system of the mobile device, or the time it takes to transmit and receive data being longer than expected. Summary of the Invention

[0006] The present disclosure aims to provide a control method that can improve the accuracy and security of user authentication regardless of the performance of the terminal.

[0007] Another object of the present disclosure is to provide a control method that can reduce the time required for user authentication and processing corresponding to the user authentication.

[0008] The technical solutions of the present disclosure are not limited to the solutions described above, and other solutions not described in this specification may be clearly understood by those skilled in the art from the following description and the accompanying drawings.

[0009] According to an aspect of the present disclosure, a control method for a control device is provided, the control method including the steps of: using a detection sensor to determine whether a mobile object is located in a first area; activating a first mode among operation modes of the control device when it is determined that the mobile object is located in the first area; and, when the first mode is activated, acquiring user identification information from a terminal, the user identification information corresponding to user-specific information stored in the terminal and being provided to the terminal by a server before the terminal provides the user identification information to the control device; transmitting processing request information to a server based on the user identification information so that the server performs processing on the user identification information; acquiring a processing result on the user identification information from the server; and providing the processing result on the user identification information to the terminal.

[0010] Furthermore, if it is not determined that the moving object is located in the first area, the operation mode of the control device is set to the second mode.

[0011] The first mode also includes an active mode in which the control device is permitted to communicate with terminals present in the first area, and the second mode includes an inactive mode in which the control device is not permitted to communicate with terminals present in the first area.

[0012] Furthermore, when the first mode is activated, the control device communicates with terminals present in the first area and terminals present in a second area indicating a predetermined communication area other than the first area, and when the second mode is activated, the control device communicates with terminals present in the second area without communicating with terminals in the first area.

[0013] The control device also has a first communication unit configured to communicate with a terminal present in the first area and a second communication unit configured to communicate with a terminal present in the second area, and the control unit executes control to drive the first communication unit and the second communication unit when the first mode is activated, and executes control to drive the second communication unit without driving the first communication unit when the second mode is activated.

[0014] The user-specific information includes at least one of identification information of the terminal, identification information of the user of the terminal, and information required for user authentication.

[0015] The first mode also includes a central mode in which the control device receives an advertising signal from a terminal and scans for the terminal in response to receiving the advertising signal, and the second mode includes a peripheral mode in which the control device transmits an advertising signal to the terminal and is scanned by the terminal in response to transmitting the advertising signal.

[0016] Furthermore, the first communication unit operates in a central mode in which the control device receives an advertising signal from the terminal and scans for the terminal in response to receiving the advertising signal, and the second communication unit operates in a peripheral mode in which the control device transmits an advertising signal to the terminal and is scanned by the terminal in response to transmitting the advertising signal.

[0017] In addition, the step of determining whether or not the moving body is located in the first area using the detection sensor includes a step of acquiring a detection signal from the detection sensor if the moving body is located in the first area, and a step of determining that the moving body is located in the first area if the detection signal is acquired.

[0018] The user verification information includes a result of user authentication performed by the server based on the user-specific information, and the processing request information based on the user verification information includes a processing request for the result of the user authentication.

[0019] In addition, the user verification information includes information for verifying that the terminal is in the first area, the processing request information based on the user verification information includes a user authentication request requesting the server to perform user authentication based on the user verification information, and the processing result for the user verification information includes the result of the user authentication.

[0020] According to another aspect of the present disclosure, a method for controlling a terminal is provided, the control method including the steps of providing user-specific information of the terminal to a server, obtaining user identification information from the server based on the user-specific information, providing the user identification information to a control device, wherein the user identification information is received by the control device when the terminal is located in a first area and the control device confirms that a moving object is located in the first area through a detection sensor arranged inside or near the control device, and obtaining a processing result for the user identification information from the control device when processing request information based on the user identification information is provided from the control device to the server so that processing of the user identification information is performed by the server.

[0021] Further, the step of providing the terminal user-specific information to the server includes a step of transmitting the terminal user-specific information from the control device to a server in a second area indicating a predetermined communication area other than the first area.

[0022] Also, providing the terminal user specific information to the server may include transmitting the terminal user specific information to the control device so that the terminal user specific information is transmitted to the server.

[0023] In addition, the step of providing the server with information specific to the user of the terminal includes a step of determining whether the terminal is located in the second area, and a step of providing the server with information specific to the user of the terminal if it is determined that the terminal is located in the second area.

[0024] In addition, the step of transmitting user-specific information of the terminal to the server includes a step of confirming the location of the terminal using at least one of a signal received from the control device, a signal received from an external device, or a signal obtained from a Global Positioning System (GPS) sensor included in the terminal, and a step of determining whether the terminal is located in the second area based on the confirmed location of the terminal.

[0025] The technical solutions of the present disclosure are not limited to the solutions described above, and other solutions not described in this specification may be clearly understood by those skilled in the art from the following description and the accompanying drawings. [Brief explanation of the drawings]

[0026] The above and other objects, features, and advantages of the present disclosure will become more apparent to those skilled in the art from the following detailed description of illustrative embodiments thereof, taken in conjunction with the accompanying drawings. [Figure 1] FIG. 1 is a block diagram of a management system according to an embodiment. [Figure 2] FIG. 2 is a block diagram of a server according to an embodiment. [Figure 3] FIG. 2 is a block diagram of a terminal according to the embodiment. [Figure 4] FIG. 2 is a block diagram of a control device according to an embodiment. [Figure 5] 1 is a schematic diagram illustrating a control device according to an embodiment. [Figure 6]1 is a schematic diagram illustrating an environment in which a control method for a control device according to an embodiment is implemented. [Figure 7] 1 is a flowchart illustrating a control method for a control device according to an embodiment. [Figure 8] 10 is a flowchart illustrating a control method for a control device according to another embodiment. [Figure 9] FIG. 4 is a sequence diagram showing the operation of the management system according to the embodiment. [Figure 10] FIG. 10 is a sequence diagram illustrating an operation of a management system according to another embodiment. [Figure 11] 10 is a flowchart illustrating a method for controlling a terminal according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0027] The embodiments described in this disclosure clearly explain the concept of the present disclosure to those skilled in the art, and therefore the present disclosure is not limited to the embodiments described in this disclosure, and the scope of the present disclosure should be interpreted as including variations and modifications within the spirit and scope of the present disclosure.

[0028] The terms used in this disclosure are selected from common terms currently widely used based on the functions in this disclosure, and may change according to the intentions of those skilled in the art, precedents in related art, or the development of new technology. When a specific term is defined and used in any sense, the meaning of the term will be explained separately. Therefore, the terms used in this disclosure should be interpreted based on the true meaning of the term and the entire description of this disclosure, rather than the simple name of such term.

[0029] The accompanying drawings in this disclosure are intended to facilitate explanation of the present disclosure. The shapes shown in the drawings may be exaggerated for the convenience of explanation, and the present disclosure is not limited to the drawings.

[0030] In the present disclosure, detailed descriptions of relevant known functions or structures incorporated herein will be omitted as necessary if they would otherwise obscure the subject matter of the disclosure.

[0031] An access management method and an access management device using the same according to an embodiment of the present disclosure are described below.

[0032] FIG. 1 is a block diagram of a management system according to an embodiment.

[0033] Referring to FIG. 1, a management system 10000 may include a server 1000 , a terminal 2000 and a control device 3000 .

[0034] The server 1000 may communicate with at least one of the control device 3000 or the terminal 2000 to transmit or receive various pieces of information.

[0035] According to an embodiment, the server 1000 may provide information necessary for user authentication to at least one of the control device 3000 or the terminal 2000. Here, user authentication may refer to authentication regarding whether a user or user terminal has specific authority. For example, user authentication may include authentication of various privileges, such as access authority authentication regarding whether a user or user terminal has authority to access a specific area, payment authority authentication regarding whether a user or user terminal has authority to perform payment processing, use authority authentication regarding whether a user or user terminal has authority to use a specific device, and operation mode setting authentication regarding whether a user or user terminal has authority to set the operation mode of a specific device. The server 1000 may also perform user authentication and provide the authentication result to at least one of the control device 3000 or the terminal 2000. If user authentication is performed by at least one of the control device 3000 or the terminal 2000, the server 1000 may obtain the user authentication result from at least one of the control device 3000 or the terminal 2000.

[0036] Furthermore, the server 1000 may execute a process corresponding to the user authentication. For example, when the server 1000 receives a processing request for user authentication from the terminal 2000 or the control device 3000, the server 1000 may execute a process corresponding to the user request, or may determine whether the process corresponding to the user request is to be executed by the terminal 2000 or the control device 3000, and may provide the determination result to the terminal 2000 or the control device 3000. Here, the process related to user authentication may refer to a subsequent operation executed based on the user authentication, such as controlling the user's access to a specific area, controlling the user's payment processing, controlling the user's use of a specific device, or controlling the operation mode of a specific device depending on the user authentication result.

[0037] The terminal 2000 may also communicate with at least one of the control device 3000 or the server 1000 to transmit or receive various pieces of information. For example, the terminal 2000 may transmit or receive information necessary for user authentication from or to the control device 3000. The terminal 2000 may also transmit data necessary for an access request and / or a setting change request to the control device 3000 or the server 1000. In some embodiments, the terminal 2000 may also perform the user authentication described above.

[0038] Furthermore, when user authentication is to be performed, the terminal 2000 may make a processing request for user authentication from the control device 3000 or the server 1000, and obtain a result of the processing request from the control device 3000 or the server 1000. Furthermore, the terminal 2000 may obtain a result of whether or not processing for user authentication can be performed from the control device 3000 or the server 1000, and perform processing for user authentication based on the result.

[0039] Additionally, applications for executing some of the embodiments described below may be provided to the terminal 2000.

[0040] Furthermore, the terminal 2000 may be implemented as a smartphone, a tablet, a personal digital assistant (PDA), a notebook, a wearable device, etc. Alternatively, the terminal 2000 may be implemented as a smart card, an integrated circuit (IC) card, a magnetic card, a radio frequency (RF) chip, etc., capable of recording data.

[0041] The control device 3000 may communicate with at least one of the server 1000 and the terminal 2000 to transmit or receive various pieces of information. The control device 3000 may also perform various processes described above in response to the user authentication result. For example, the control device 3000 may control the user's access to a specific area, control the user's payment processing, control the user's use of a specific device, or control the operating mode of a specific device depending on the user authentication result.

[0042] As a specific example, if a user's access to a specific area is restricted by a gate, the control device 3000 may control the gate to restrict the user's access to the specific area according to the user authentication result. Here, the gate is a device that physically restricts the user's access and may include an access restriction device (e.g., an access bar, an access door, etc.). The control device 3000 may allow the user's access by providing an unlock signal to the gate according to the user authentication result and controlling the gate to open. The control device 3000 may also not allow the user's access by preventing the unlock signal from being provided to the gate or by providing a lock signal to the gate and controlling the gate to close depending on the user authentication result. In some embodiments, the control device 3000 may be located inside or near the gate.

[0043] Furthermore, when the control device 3000 controls the payment processing, the control device 3000 may execute a payment authorization procedure. For example, the control device 3000 may receive a payment request from the terminal 2000 and may or may not approve the payment request based on the user authentication result. In some embodiments, the payment authorization procedure may be executed by the server 1000. In this case, the control device 3000 may send the payment request received from the terminal 2000 to the server 1000 and may receive a payment authorization result from the server 1000. The control device 3000 may also execute various control operations based on the payment authorization result. For example, when the control device 3000 controls a gate for access to public transportation, the control device 3000 may control the gate based on the payment authorization result. The control device 3000 may also provide the payment authorization result to at least one of the server 1000 and the terminal 2000. Furthermore, when controlling the use of a specific device according to the user authentication result, the control device 3000 may control the use of the specific device through software installed on the specific device, or may control the use of the specific device by controlling a restriction device to physically restrict the use of the specific device based on the user authentication result.

[0044] Furthermore, when controlling the operation mode of a specific device, the control device 3000 may set the operation mode of the specific device based on the user authentication result. For example, when the control device 3000 controls an access control device to manage access to a specific area, the control device 3000 may control the access control device in a security mode that increases the security level in the specific area, or in a normal mode in which the security mode is released based on the user authentication result. Furthermore, in some embodiments, the access control device may be included in the control device 3000.

[0045] The process for user authentication may be performed by the server 1000 or the terminal 2000.

[0046] In some embodiments, the control device 3000 may also perform the operations for user authentication described above, which are described in more detail below.

[0047] Furthermore, when user authentication is performed, the control device 3000 may make a processing request for user authentication from the terminal 2000 or the server 1000, and obtain a result of the processing request from the terminal 2000 or the server 1000. Furthermore, the control device 3000 may obtain a result of whether or not user authentication can be processed from the terminal 2000 or the server 1000, and perform processing for user authentication based on the result.

[0048] However, the block diagram shown in Figure 1 is merely an example for convenience of explanation, and the present invention is not limited thereto. According to some embodiments, any element may be added to the block diagram of Figure 1, and elements shown in Figure 1 may be removed or subdivided.

[0049] FIG. 2 is a block diagram of a server according to the embodiment.

[0050] Referring to FIG. 2, the server 1000 may include a server communication unit 1100 , a server input unit 1200 , a server storage unit 1300 , a server display unit 1400 and a server control unit 1500 .

[0051] The server communication unit 1100 may communicate with at least one of the terminal 2000 or the control device 3000. As another example, the server communication unit 1100 may transmit biometric information stored in the control device 3000 to the terminal 2000.

[0052] The server communication unit 1100 may also include mobile communication modules such as Bluetooth® low energy (BLE), Bluetooth®, Wireless Local Area Network (WLAN), Wireless Fidelity (WiFi®), WiFi® Direct, Near Field Communication (NFC), Infrared Data Association (IrDA), Ultra Wideband (UWB), Zigbee®, 3G, 4G and 5G, and other wired or wireless modules capable of transmitting data through various communication standards.

[0053] The server input unit 1200 may acquire electrical signals corresponding to user inputs and may include a keypad, a keyboard, a switch, a button, and a touch screen.

[0054] The server storage unit 1300 may store various types of data. For example, the server storage unit 1300 may store information necessary for user authentication (e.g., user authority information, user-specific information (or user or terminal identification information, and identification information necessary for payment processing (e.g., user card information, authentication information corresponding to card information, etc.), user biometric authentication information, password information, etc.)) or information related to user authentication results.

[0055] The server storage unit 1300 may also store information obtained from the terminal 2000 or the control device 3000. The server storage unit 1300 may also store programs required for the operation of the server 1000.

[0056] The server storage unit 1300 may include at least one type of storage medium selected from flash memory type memory, hard disk type memory, multimedia card micro type memory, card type memory (e.g., SD or XD memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, and optical disk. The memory may store information temporarily, permanently, or semi-permanently, and may be provided as built-in or removable type memory.

[0057] The server display unit 1400 may also output visual information, for example, the server display unit 1400 may be a liquid crystal display (LCD), an organic light emitting diode (OLED) display, an active matrix organic light emitting diode (AMOLED) display, etc.

[0058] Server control unit 1500 may also control each element of server 1000, or process and calculate various types of information, and may also control operations for executing some of the steps performed by server 1000 among the steps described in the following methods, or may perform calculations necessary to execute the steps.

[0059] Server control unit 1500 may be implemented in software, hardware, or a combination thereof. For example, in hardware, server control unit 1500 may be implemented in a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a semiconductor chip, and various other types of electronic circuitry. As another example, in software, server control unit 1500 may be implemented in a logic program or various types of computer languages ​​executed by hardware.

[0060] The server 1000 does not necessarily have to include all of the above-described elements, and some of the elements may be selectively excluded. For example, if the server 1000 does not directly provide visual information, the server display unit 1400 may be omitted from the server 1000. Additionally, elements for performing additional functions and operations may be selectively added to the server 1000.

[0061] FIG. 3 is a block diagram of a terminal according to the embodiment.

[0062] Referring to FIG. 3 , the terminal 2000 may include a terminal communication unit 2100, a terminal display unit 2200, a terminal input unit 2300, a location information collection unit 2400, a terminal storage unit 2500, a terminal control unit 2600, and a terminal biometric information input unit 2700.

[0063] The terminal communication unit 2100 may communicate with at least one of the server 1000 or the control device 3000. For example, the terminal communication unit 2100 may transmit or receive information required for user authentication or user authentication result information to or from at least one of the server 1000 or the control device 3000.

[0064] The terminal communication unit 2100 may also include a mobile communication module such as BLE, Bluetooth, WLAN, WiFi, WiFi Direct, NFC, IrDA, UWB, Zigbee, 3G, 4G and 5G, and other wired or wireless modules capable of transmitting data through various communication standards.

[0065] The terminal display unit 2200 may output various types of visual information. For example, the terminal display unit 2200 may output information when the control device 3000 is detected through communication with the control device 3000 and communication is established. The terminal display unit 2200 may also visually output a user authentication result. The terminal display unit 2200 may also visually output a message received from the server 1000. The terminal display unit 2200 may also visually output a screen for inputting setting change information to change the settings of the control device 3000.

[0066] The terminal display unit 2200 may be an LCD display, an OLED display, an AMOLED display, etc. When the terminal display unit 2200 is provided as a touch screen, the terminal display unit 2200 may function as the terminal input unit 2300. In this case, a separate terminal input unit 2300 may not be provided selectively, and a terminal input unit 2300 configured to perform limited functions such as a volume control function, a power button function, and a home button function may be provided.

[0067] The terminal input unit 2300 may acquire a signal corresponding to a user input. For example, the terminal input unit 2300 may acquire an input for requesting user authentication from the server 1000 or the control device 3000. The terminal input unit 2300 may also acquire an input for acquiring information necessary for user authentication (e.g., user authority information, user-specific information (or user or terminal identification information, identification information necessary for payment processing (e.g., user card information, authentication information corresponding to the card information, etc.), user biometric authentication information, password information, etc.)). The terminal input unit 2300 may also receive setting change information to change the settings of the control device 3000.

[0068] The terminal input unit 2300 may be implemented, for example, by a keyboard, a keypad, a button, a jog dial, or a wheel. The user input may be, for example, a button press, a touch, or a drag. If the terminal display unit 2200 is implemented as a touch screen, the terminal display unit 2200 may function as the terminal input unit 2300.

[0069] The location information collecting unit 2400 may acquire location information of the terminal 2000 and determine its location. For example, the location information collecting unit 2400 may acquire coordinate information for determining the location, such as from a GPS sensor. As another example, the location information collecting unit 2400 may determine the location of the terminal 2000 based on a signal received from an external device. For example, when the terminal 2000 receives a signal indicating a specific area from the control device 3000, the terminal 2000 may confirm the specific area in response to receiving the signal.

[0070] The terminal storage unit 2500 may also store various types of data. For example, the terminal storage unit 2500 may store information necessary for the operation of the terminal 2000 (for example, information necessary for user authentication (for example, user authority information, user-specific information (or user or terminal identification information, identification information necessary for payment processing (for example, user card information, authentication information corresponding to card information, etc.), user biometric authentication information, password information, etc.))).

[0071] The terminal storage unit 2500 may include at least one type of storage medium selected from flash memory type memory, hard disk type memory, multimedia card micro type memory, card type memory (e.g., SD or XD memory), RAM, SRAM, ROM, EEPROM, PROM, magnetic memory, magnetic disk, and optical disk. The memory may store information temporarily, permanently, or semi-permanently, and may be provided as a built-in or removable type memory.

[0072] The terminal control unit 2600 may control each element of the terminal 2000, or may process and calculate various types of information. The terminal control unit 2600 may also acquire signals from several elements included in the terminal 2000. The terminal control unit 2600 may also control operations for executing several steps performed by the terminal 2000 among the steps described in the following methods, or may perform calculations necessary to execute the steps.

[0073] The terminal control unit 2600 may be implemented in software, hardware, or a combination thereof. For example, in hardware, the terminal control unit 2600 may be implemented in an FPGA, an ASIC, a semiconductor chip, and various other types of electronic circuits. As another example, in software, the terminal control unit 2600 may be implemented in various types of computer languages ​​or logic programs executed by hardware.

[0074] The terminal biometric information input unit 2700 may receive a user's biometric information. The biometric information may refer to at least one of the user's voice information, fingerprint information, iris information, face information, and vein information. The terminal biometric information input unit 2700 may be implemented by at least one of a microphone through which the user's voice information is input, a screen scanner through which the user's fingerprint information is input, and a camera through which the user's iris information, face information, and vein information is input.

[0075] The terminal 2000 does not necessarily have to include all of the above-mentioned elements, and some of the elements may be selectively excluded. For example, if the terminal 2000 does not receive biometric information, the terminal biometric information input unit 2700 may be excluded from the terminal 2000. In addition, elements for performing additional functions and operations may be selectively added to the terminal 2000.

[0076] FIG. 4 is a block diagram of a control device according to an embodiment.

[0077] Referring to FIG. 4 , the control device 3000 may include a communication unit 3100, a display unit 3200, an audio output unit 3300, a sensor unit 3400, a storage unit 3500, a power supply unit 3600, a control unit 3700, a biometric information input unit 3800, and an input unit 3900.

[0078] The communication unit 3100 may communicate with at least one of the server 1000 or the terminal 2000. For example, the communication unit 3100 may transmit or receive information required for user authentication or user authentication result information to or from at least one of the server 1000 or the terminal 2000.

[0079] As another example, the communication unit 3100 may receive a setting change signal from the terminal 2000. The communication unit 3100 may also transmit to the terminal 2000 result information obtained by performing the setting change.

[0080] The communication unit 3100 may primarily communicate according to wireless communication standards, but may also include mobile communication modules such as BLE, Bluetooth, WLAN, WiFi, WiFi Direct, NFC, IrDA, UWB, Zigbee, 3G, 4G, and 5G, and other wired or wireless modules capable of transmitting data through various communication standards. The communication unit 3100 may also include a short-range wireless module supporting NFC or RFID, etc.

[0081] In an embodiment, the communication unit 3100 may include a first communication unit (not shown) and a second communication unit (not shown).

[0082] In an embodiment, the first communication unit (not shown) and the second communication unit (not shown) may be configured to have different communication areas. For example, the first communication unit (not shown) may be configured to communicate with an area relatively close to the control device 3000 or the sensor unit 3400 (e.g., a first area described with reference to FIGS. 6 to 11), and the second communication unit (not shown) may be configured to communicate with an area relatively far from the control device 3000 or the sensor unit 3400 or the remaining area (e.g., a second area described with reference to FIGS. 6 to 11) excluding the communication area of ​​the first communication unit (not shown).

[0083] For example, the first communication unit (not shown) and the second communication unit (not shown) may be configured to have different communication ranges. As an example, the first communication unit (not shown) may be configured to have a communication range that is the same as the sensing range of the sensor unit 3400, or a communication range that differs from the sensing range of the sensor unit 3400 by a predetermined distance or shorter, and the second communication unit (not shown) may be configured to have a communication range that is longer than the first communication unit (not shown). In this case, the second communication unit (not shown) may be configured not to communicate over a communication range over which the first communication unit (not shown) can communicate. For example, the second communication unit (not shown) may filter out signals received over a communication range over which the first communication unit (not shown) can communicate.

[0084] Also, the first communication unit (not shown) may operate in a central mode described below, and the second communication unit (not shown) may communicate in a peripheral mode. Thus, the first communication unit (not shown) may communicate with a terminal communicating in a peripheral mode, and the second communication unit (not shown) may communicate with a terminal operating in a central mode. For example, when a terminal in the second area operates in a central mode, the second communication unit (not shown) may communicate with the terminal, and the first communication unit (not shown) may not communicate with the terminal. Also, when a terminal in the first area operates in a peripheral mode, the first communication unit (not shown) may communicate with the terminal, and the second communication unit (not shown) may not communicate with the terminal. It will be understood that in some cases, the first communication unit (not shown) may communicate in a peripheral mode, and the second communication unit (not shown) may communicate in a central mode.

[0085] The display unit 3200 may output information that is visually presented to a user.

[0086] For example, when a door open signal is received, the display unit 3200 may output visual information indicating the reception. Also, when a setting change signal is received, the display unit 3200 may output visual information indicating the reception.

[0087] The display unit 3200 may be an LCD display, an OLED display, an AMOLED display, etc. If the display unit 3200 includes a touch panel, the display unit 3200 may operate as a touch-based input device.

[0088] The audio output unit 3300 may output information to be provided to the user audibly. For example, when a door open signal is received, the display unit 3200 may output audio information indicating the reception. When a setting change signal is received, the display unit 3200 may output audio information indicating the reception.

[0089] The audio output unit 3300 may be a speaker or a buzzer that outputs audio.

[0090] The sensor unit 3400 may acquire an external environmental signal required for the control device 3000. For example, the sensor unit 3400 may check whether a moving object (e.g., a user) is present near the control device 3000. The sensor unit 3400 may be disposed inside or near the control device 3000. In some embodiments, the sensor unit 3400 may not be included in the control device 3000. In this case, a separate sensor may be disposed near the control device 3000.

[0091] The sensor unit 3400 may be implemented based on various structures. For example, the sensor unit 3400 may be implemented based on various devices such as an infrared sensor, a camera, and a wireless communication device (e.g., a Bluetooth communication device). For example, if the sensor unit 3400 includes an infrared sensor, an output signal of the sensor unit 3400 may be changed or output when a user passes through a gate. Based on the change or output of the output signal, the sensor unit 3400 may determine whether the user is located near the gate. For another example, if the sensor unit 3400 includes a camera, the sensor unit 3400 may track the user's movement based on images acquired by the camera and detect whether the user is located near the gate based on the tracking result. For another example, if the sensor unit 3400 includes a wireless communication device, the wireless communication device and the user's terminal may communicate, and the sensor unit 3400 may detect whether the user is located near the gate based on a received signal strength indicator at the wireless communication device or a received signal strength indicator at the terminal.

[0092] For example, according to an embodiment, the sensor unit 3400 may obtain signals related to the distance between a user and an object, etc. As another example, the sensor unit 3400 may obtain signals necessary for a control device to determine its position.

[0093] Various types of information may be stored in the storage unit 3500. For example, the storage unit 3500 may store a program for executing operation control of the control unit 3700, and may store data received from the outside, data generated by the control unit 3700, etc. The storage unit 3500 may also store information necessary for the operation of the control device 3000 (for example, information necessary for user authentication (for example, user authority information, user identification information (for example, user or terminal identification information, user biometric authentication information, password information, etc.)))) and user authentication result information.

[0094] The storage unit 3500 may include at least one type of storage medium selected from flash memory type memory, hard disk type memory, multimedia card micro type memory, card type memory (e.g., SD or XD memory), RAM, SRAM, ROM, EEPROM, PROM, magnetic memory, magnetic disk, and optical disk. The memory may store information temporarily, permanently, or semi-permanently, and may be provided as a built-in or removable type memory.

[0095] The power supply unit 3600 may provide the power necessary to lock or unlock the gate. The power supply unit 3600 may also provide the power necessary to open and close the gate. The power supply unit 3600 may be provided as a motor, a solenoid, an actuator, or the like.

[0096] When the power supply unit 3600 provides the power necessary to lock or unlock the gate, the power supply unit 3600 may provide power so that a lock unit (not shown) for locking or unlocking the gate is in a locked or unlocked state or changes to a locked or unlocked state. The lock unit may be provided as, for example, a deadbolt, a latch bolt, or a combination thereof. Furthermore, the lock unit is not limited to the deadbolt and latch bolt described as examples, and any typical lock unit may be used.

[0097] In some embodiments, the power supply unit 3600 may or may not be included in the control device 3000. Alternatively, the power supply unit 3600 may be in the form of a separate device and located near the control device 3000. In this case, the control device 3000 may provide signals to the power supply unit 3600 for controlling the power supply unit 3600. Also, the locking unit described above may not be included in the control device 3000, but may be located near the control device 3000 or may be controlled by the control device 3000.

[0098] The control unit 3700 may control each element of the control device 3000, or may process and calculate various types of information. The control unit 3700 may also acquire signals from some elements included in the control device 3000. The control unit 3700 may also control operations for executing some steps performed by the control device 3000 among the steps described in the following methods, or may perform calculations necessary to execute the steps.

[0099] The control unit 3700 may be implemented in software, hardware, or a combination thereof. For example, in hardware, the control unit 3700 may be implemented in an FPGA, an ASIC, a semiconductor chip, and various other types of electronic circuits. As another example, in software, the control unit 3700 may be implemented in a logic program or various types of computer languages ​​executed by hardware.

[0100] The biometric information input unit 3800 may receive biometric information of a user. For example, the biometric information input unit 3800 may receive at least one of the user's voice information, fingerprint information, iris information, face information, and vein information. The biometric information input unit 3800 may be implemented by at least one of a microphone through which the user's voice information is input, a screen scanner through which the user's fingerprint information is input, and a camera through which the user's iris information, face information, and vein information is input.

[0101] The input unit 3900 may be configured to receive various inputs. For example, the input unit 3900 may acquire an input for requesting user authentication from the server 1000 or the terminal 2000. The input unit 3900 may also acquire an input for acquiring information necessary for user authentication (e.g., identification information of a user or a user terminal, password information, biometric authentication information, etc.). The input unit 3900 may also receive setting change information for changing the settings of the control device 3000.

[0102] The input unit 3900 may also receive a user authentication request from a user. For example, if the user authentication is authentication of a user's access to a specific area, the control device 3000 may receive an input to open a door and drive the power supply unit 3600 to open the door, or may allow an access authentication request signal to be transmitted to the server 1000 or the terminal 2000. For example, the control device 3000 may be implemented with a keyboard, a keypad, a button, a switch, a jog dial, or a wheel. The user input may be, for example, a switch press, a button press, a touch, or a drag. If the display unit 3200 is implemented with a touch screen, the display unit 3200 may function as the input unit 3900.

[0103] The control device 3000 according to the embodiment of the present disclosure does not necessarily have to include all of the above elements, and some of the elements may be selectively excluded.

[0104] A management system 10000 according to an embodiment of the present disclosure may be implemented to include at least one control device 3000. As an example, the management system 10000 may include a control device 3000 including a communication unit 3100 and a control unit 3700. As a specific example, the control device 3000 may receive information obtained from the terminal 2000 through the communication unit 3100, may function as a reader and analyze the information obtained through the control unit 3700, and may function as a controller and perform functions of control operations such as access management, time and attendance management, and system mode change.

[0105] Additionally, elements may be selectively provided in the control device 3000 to perform additional functions and operations.

[0106] FIG. 5 is a schematic diagram illustrating a control device according to an embodiment.

[0107] 5, in some embodiments, the control device 3000 may include multiple devices. For example, the control device 3000 may include a first control device 4000 and a second control device 5000.

[0108] As a specific example, the first controlling device 4000 may be useful for communicating with external devices, and the second controlling device 5000 may be useful for controlling the first controlling device 4000. For example, the first controlling device 4000 may receive acquired information from at least one of the server 1000 or the terminal 2000 through a communication unit functioning as a reader, and may transmit the acquired information to the second controlling device 5000 through a communication unit connected to the second controlling device 5000 in a wired or wireless communication manner. In this case, when the second controlling device 5000 receives information from the first controlling device 4000, the second controlling device 5000 may perform functions of control operations, such as access management, time and attendance management, and system mode change, based on the information received through the control unit.

[0109] Furthermore, as another example, the first control device 4000 may include the first communication unit described above, and the second control device 5000 may include the second communication unit described above, or vice versa.

[0110] As another example, the first control device 4000 and the second control device 5000 may perform the same function. For example, if there are two gates, the first control device 4000 may be located at the first gate, and the second control device 5000 may be located at the second gate. Operations related to user authentication may be performed at the gates where the first control device 4000 and the second control device 5000 are located.

[0111] As another example, the first control device 4000 and the second control device 5000 may each include a communication unit, and the communication standards supported by the communication units may be different. For example, the second control device 5000 may support a communication scheme not supported by the first control device 4000 as well as a communication scheme supported by the first control device 4000. For example, if the first control device 4000 and the second control device 5000 are in the form of readers, the second control device 5000 may support a communication scheme not supported by the first control device 4000. Therefore, the first control device 4000 may be referred to as a legacy reader, and the second control device 5000 may be referred to as a sub-reader.

[0112] As a specific example, the communication unit of the first control device 4000 may support a short-range wireless communication standard such as NFC and RFID, and the communication unit of the second control device 5000 may support a wireless communication standard such as BLE or Bluetooth. In this case, if the communication unit 2100 of the terminal 2000 supports BLE communication, the first control device 4000 and the terminal 2000 may not be able to communicate with each other. Currently, if the wireless communication standard is supported by the second control device 5000 and the terminal 2000 is compatible with each other, the second control device 5000 may receive data from the terminal 2000 and transmit the received data to the first control device 4000. For example, the second control device 5000 may receive BLE-formatted data used in BLE from the terminal 2000, convert the BLE-formatted data into RFID-formatted data used in RFID and understandable by the first control device 4000, and transmit the converted data to the first control device 4000. Similarly, in the opposite case, after the second control device 5000 receives RFID-formatted data from the first control device 4000, the second control device 5000 may convert the RFID-formatted data into BLE-formatted data and transmit the converted data to the terminal 2000. In other words, the second control device 5000 helps the first control device 4000 to communicate with the terminal 2000 in a communication scheme not supported by the first control device 4000.

[0113] The management system 10000 associated with various embodiments, and the elements, operations, and terminology included in the management system 10000, are described above. The above-described management system 10000, and the elements, operations, and terminology included in the management system 10000 may be applied to various methods and embodiments described below. However, it should be noted that the management system 10000 described below does not necessarily have to be configured to have the above-described elements and functions, and may also be applied to a management system having a structure different from the above-described management system 10000.

[0114] FIG. 6 is a schematic diagram illustrating an environment in which a control method for a control device according to an embodiment is implemented.

[0115] 6 , the control device 3000 may be located inside or near the gate 6000. The control device 3000 may control the gate according to a user authentication result and / or a process corresponding to the user authentication result. For example, when the gate 6000 is used to control access to the inside of the gate, the control device 3000 may control the opening and closing of the gate 6000 based on the user authentication result so that a user can enter or exit through the gate 6000. Furthermore, when a payment for a product purchase, public transportation, boarding, or the like occurs simultaneously to enter or exit through the gate 6000, the control device 3000 may control the gate 6000 based on a payment processing result corresponding to the user authentication.

[0116] In a specific embodiment, the control device 3000 may acquire information necessary for user authentication from the terminal 2000 and perform user authentication based on the acquired information, or may transmit the acquired information to a server (not shown) so that user authentication is performed on the server. Furthermore, when the control device 3000 acquires a user authentication result, the control device 3000 may execute a process corresponding to the user authentication result, or may transmit a processing request corresponding to the user authentication result to the server 1000.

[0117] For example, when the control device 3000 communicates with the terminal 2000 using a wireless communication scheme and the terminal 2000 is located in the first area 100, the control device 3000 may determine that the user of the terminal 2000 plans to perform user authentication and obtain information necessary for user authentication from the terminal 2000, or to perform user authentication or provide information necessary for user authentication to a server (not shown). Also, when user authentication has been previously performed and the terminal 2000 is located in the first area 100, the control device 3000 may determine that the user of the terminal 2000 plans to perform user authentication according to the user authentication result, and obtain a processing request corresponding to the user authentication result from the terminal 2000 and / or provide the processing request corresponding to the user authentication result to the server 1000.

[0118] For example, the control device 3000 may determine whether the terminal 2000 is located in the first area 100 using a received signal strength indicator (e.g., RSSI) of a signal received from the terminal 2000. However, if only the received signal strength indicator of the received signal is used, the accuracy of the positioning of the terminal 2000 may be reduced. Therefore, if the terminal 2000 is not accurately located, user authentication may be performed on the user of the terminal 2000. If the terminal 2000 is not located in the first area 100 but is located in the second area 2000 that is farther from the gate 6000 than the first area 100, or is outside the first area 100 and the second area 200, further processing corresponding to the user authentication result may be performed. Therefore, an error such as the gate 6000 being opened erroneously may occur.

[0119] To prevent such errors, the control device 3000 may use the detection sensor 7000 to accurately determine whether the user of the terminal 2000 is located in the first area 100, and if it is determined that the user of the terminal 2000 is located in the first area 100, may perform an operation to authenticate the user or to perform a process corresponding to the user authentication result. In some embodiments, the detection sensor 7000 may be located inside or near the control device 3000 or the gate 6000. The detection sensor 7000 may also refer to the sensor unit 3400 described above. When the detection sensor 7000 is located near the control device 3000 or the gate 6000, the detection sensor 7000 and the control device 3000 may perform wired communication in a wired manner or wireless communication using various communication schemes.

[0120] FIG. 7 is a flowchart showing a control method for a control device according to the embodiment.

[0121] Referring to Figure 7, the control method for the control device may include a step (S100) of using a detection sensor to determine whether a mobile object is located in a first area, a step (S200) of changing the operating mode of the control device if it is determined that the mobile object is located in the first area, a step (S300) of acquiring information necessary for user authentication from a terminal, and a step (S400) of acquiring a result of user authentication based on the information necessary for user authentication.

[0122] In operation S100, the control device may acquire a detection signal from a detection sensor, where the detection sensor may be disposed inside or near the control device. The above description of the sensor unit 3400 of the control device and the description with reference to FIG. 6 may apply to the detection sensor, and therefore detailed description thereof will be omitted.

[0123] In an embodiment, the detection sensor may transmit a detection signal to the control device when the moving object is located within the detection range. When the detection signal is received from the detection sensor, the control device may determine that the moving object is located within the detection range of the detection sensor.

[0124] For example, the detection range of the detection sensor may be shorter than the wireless communication distance between the user's terminal and the control device. For example, the detection range of the detection sensor may be shorter than the communication range of Bluetooth or BLE between the user's terminal and the control device. When the user plans to perform user authentication or to perform a process corresponding to user authentication on the control device, the user is approaching the control device and therefore may be likely to be located within the detection range of the detection sensor. On the other hand, when the user does not plan to perform user authentication or to perform a process corresponding to user authentication, the user may be away from the control device and therefore may be unlikely to be located within the detection range of the detection sensor, even if the control device and the user's terminal are located in a place where they can communicate with each other.

[0125] For convenience of explanation, hereinafter, the detection range of the detection sensor is referred to as a first area, and an area other than the first area is referred to as a second area. However, in some cases, the second area may refer to an area where the control device and the user terminal can perform wireless communication.

[0126] Also, in operation S200, the control device may change the operation mode depending on whether or not the moving object is located in the first area, i.e., the operation mode of the control device when the moving object is present in the first area may be different from the operation mode of the control device when the moving object is not present in the first area.

[0127] In an embodiment, when a mobile object is located in a first area, the communication mode of the control device may be changed. Through the change of the communication mode, the control device may activate or disable communication between the control device and a terminal in the first area. For example, when it is determined that no mobile object is located in the first area, the control device may set the communication mode to an inactive mode. Thus, the control device and the terminal do not communicate with each other, and therefore, user authentication or processing corresponding to the user authentication result may not be performed. For example, when a user is located in a second area rather than the first area, or in another area, the communication mode of the control device may be set to an inactive mode, and therefore, the control device and the user's terminal do not communicate.

[0128] Furthermore, when it is determined that a mobile object exists in the first area, the control device may set the communication mode to an active mode. Thus, the control device and the terminal may communicate with each other, and when the control device receives a user authentication request from the terminal, user authentication or a process corresponding to the user authentication result may be performed. For example, when a user is located in the first area and the communication mode of the control device is set to an active mode, the control device and the user's terminal may communicate.

[0129] As another example, when it is determined that a mobile object is present in the first area, the control device may set its communication mode to a first area active mode in which the control device can communicate with terminals present in the first area. Thus, the control device may communicate with terminals present in the first area, and user authentication or processing corresponding to the user authentication result may be performed. In this case, in some embodiments, the control device may communicate with another terminal present in a second area. For example, in the first area active mode, the control device may activate both a first communication unit that communicates with terminals present in the first area and a second communication unit that communicates with terminals present in the second area.

[0130] Furthermore, if it is determined that no mobile object is present in the first area, the control device may set its communication mode to a first-area inactive mode, in which it cannot communicate with terminals present in the first area but can communicate with terminals present in the second area. Thus, rather than communicating with terminals present in the first area, the control device may communicate with terminals present in the second area. For example, when the terminal is located in the second area, the control device may acquire information necessary for user authentication from the terminal, and thus user authentication may be performed by the control device or the server. However, if a processing request corresponding to the user authentication result is configured to be acquired by the control device when the terminal is located in the first area, the processing request corresponding to the user authentication result may not be acquired when the terminal is located in the second area, and therefore the processing corresponding to the user authentication result may not be performed.

[0131] As another example, if it is determined that no mobile object is located in the first area, the control device may set the communication module to a receive mode. Thus, if the terminal is not located in the first area, the control device may receive information from the terminal but may not transmit information to the terminal. In some cases, the control device may communicate with a server.

[0132] However, even if the control device is in the receive mode, the control device may transmit to the terminal information necessary to establish or maintain communication with the terminal, but may not transmit other information (e.g., information having a data size greater than or equal to a predetermined size, information necessary for user authentication, information related to the user authentication result, etc.) to the terminal. Also, in some cases, the control device may transmit specific information to the terminal when necessary, even if the control device is in the receive mode. For example, when specific information to be transmitted to the terminal is received from the server, the control device may transmit the corresponding information to the terminal.

[0133] Furthermore, when it is determined that a mobile object is present in the first area, the control device may set the communication mode to a transmission mode. Thus, the control device may transmit or receive information to or from the terminal. For example, in the transmission mode, the control device may transmit a user authentication result or a result of processing the user authentication result to the terminal.

[0134] In another embodiment, when the control device and the terminal perform Bluetooth or BLE communication or other wireless communication, the control device may include a central mode or a peripheral mode as a communication mode through a change of the communication mode.

[0135] When the control device is in the central mode, the terminal may transmit an advertising signal, and the control device may scan for the advertising signal to establish communication between the control device and the terminal. In this case, the terminal may communicate in the peripheral mode.

[0136] Furthermore, when the control device is in peripheral mode, the control device may transmit an advertising signal, and the control device may scan for the advertising signal to establish communication between the control device and the terminal. In this case, the terminal may communicate in central mode. More specifically, when the terminal communicates only in central mode, the Bluetooth signal strength received from the terminal is the criterion for communication connection recognition, but the deviation of corresponding signal strength may be significant between terminal manufacturers or between terminals. That is, in this case, although connection and data transfer between the control device and the terminal are fast, signal reception may be delayed, and the signal may be received beyond a certain distance. Therefore, failures may occur, and as a result, it may be difficult to precisely control the timing.

[0137] To solve this problem, the control device and the terminal may communicate while changing the communication mode between a central mode and a peripheral mode depending on the location of the terminal.

[0138] Furthermore, the control device may communicate using a first communication unit and a second communication unit. For example, the first communication unit may communicate in a central mode, and the second communication unit may communicate in a peripheral mode. When it is determined that a mobile object is present in a first area, the control device may activate the first communication unit to communicate with a terminal present in the first area. In this case, the control device according to the embodiment may activate the second communication unit. Thus, the control device may communicate with a terminal present in the first area while communicating with another terminal present in the second area. Furthermore, when it is determined that a mobile object is not present in the first area, the control device may disable the first communication unit so as not to communicate with the terminal present in the first area. It will be understood that in this case, the second communication unit may be activated.

[0139] This is explained in more detail with reference to FIG.

[0140] In addition, in operation S300, the control device may acquire information necessary for user authentication from the terminal. Here, the information necessary for user authentication may include user authentication request information, user-specific information (or user or terminal identification information, identification information necessary for payment processing (e.g., user card information, authentication information corresponding to the card information, etc.), user biometric authentication information, password information, etc.), etc.

[0141] If the terminal is located in a first area close to the control device, the control device may confirm that the user of the terminal intends to request user authentication by obtaining information necessary for user authentication.

[0142] In another embodiment, the control device may obtain some of the information necessary for user authentication when the terminal is located in the second area, and may obtain the remaining part of the information necessary for user authentication to confirm all of the information necessary for user authentication in the first area when the terminal is located in the first area. For example, when the control device and the terminal communicate via Bluetooth and the terminal is located in the second area, the control device may communicate in a peripheral mode and the terminal may communicate in a central mode. In this case, the control device may obtain some of the information necessary for user authentication from the terminal. Then, when the terminal is located in the first area, the operation modes of the terminal and the control device may be switched so that the control device may communicate in the central mode and the terminal may communicate in the peripheral mode. In this case, by obtaining the remaining part of the information necessary for user authentication from the terminal, the control device may obtain all of the information necessary for user authentication when the terminal is located in the second area. Thus, when the terminal is located in the first area close to the control device, the control device may confirm that the user of the terminal intends to request user authentication by obtaining all of the information necessary for user authentication.

[0143] In another embodiment, when the terminal is located in the second area, the control device may obtain all of the information necessary for user authentication. However, the user authentication result may not be obtained by the control device at this time. Later, when it is determined that the terminal is located in the first area, the control device may obtain the user authentication result using the information necessary for user authentication previously obtained.

[0144] Also, in operation S400, the control device may obtain a result of user authentication based on the information necessary for user authentication. In an embodiment, the user authentication may be performed by the control device. In this case, the control device may perform the user authentication and compare the information necessary for user authentication pre-stored in the control device with the information necessary for user authentication acquired from the terminal to obtain the result of the user authentication. Also, in another embodiment, when the user authentication is performed by a server, the control device may transmit the information necessary for user authentication acquired from the terminal and at least some of the information corresponding to the information necessary for user authentication acquired from the terminal to the server to perform the user authentication, and may obtain the result of the user authentication from the server.

[0145] In another embodiment, when the terminal is located in the second area, the control device may obtain information necessary for user authentication. However, the user authentication result may not be obtained until the operation mode of the control device is changed in operation S200. Also, when the operation mode of the control device is changed in operation S200, it may be determined that the user of the terminal plans to request user authentication, and therefore, no user authentication result may be obtained. Also, in this case, the control device may obtain the information necessary for user authentication from the user terminal before the terminal is located in the first area, and when the terminal is located in the first area, may obtain the user authentication result based on the information necessary for user authentication previously obtained from the terminal. Therefore, the user authentication result can be obtained more quickly.

[0146] The control device may also transmit the user authentication result to the user terminal and perform processing corresponding to the user authentication result, such as controlling the user's access to a particular area, controlling the user's payment processing, controlling the user's use of a particular device, or controlling the operation mode of a particular device depending on the user authentication result.

[0147] FIG. 8 is a schematic diagram illustrating the operation of a management system according to another embodiment.

[0148] Referring to FIG. 8, the control method for the control device may include a step of determining whether a moving object is located in a first area using a detection sensor (S1000), a step of changing the operation mode of the control device if it is determined that the moving object is located in the first area (S2000), a step of acquiring user confirmation information (S3000), a step of transmitting processing request information based on the user confirmation information to a server (S4000), and a step of acquiring a processing result for the user confirmation information (S5000).

[0149] The above description of operations S100 and S200 in FIG. 7 can be applied to operations S1000 and S2000, and therefore detailed description thereof will be omitted.

[0150] In operation S300, the control device may obtain user authentication information from a server or a terminal. Here, the user authentication information may include a user authentication result. Specifically, the server may obtain information necessary for user authentication from the control device or the terminal. The server may also perform user authentication based on the information necessary for user authentication, generate user authentication information including the user authentication result, and transmit the generated user authentication information to the terminal or the control device. If the user authentication information is transmitted to the terminal, the terminal may transmit the user authentication information to the control device.

[0151] Additionally, user authorization information (e.g., information about security areas the user can access, information about products for which the user can process payments, information about devices available to the user, information about operating modes the user can control, etc.) may be included in the user verification information.

[0152] In some embodiments, the user challenge information may be generated in the form of a token. By way of example, the user challenge information may include at least one of user-specific information, user authorization information, validity conditions (such as validity period and validity area), issuer information, or recipient information.

[0153] In another embodiment, the user authentication result may not be included in the user challenge information, in which case the control device may verify that the user is located in the first area based on the user-specific information, and may add the verification result information to the user challenge information.

[0154] Also, in operation S4000, the control device may transmit processing request information based on the user authentication information to the server.

[0155] In an embodiment, when a user authentication result is included in the user challenge information, the processing request information based on the user challenge information may include a processing request for the user authentication result. Here, the processing related to the user authentication may refer to a subsequent action performed based on the user authentication, such as controlling the user's access to a specific area, controlling the user's payment processing, controlling the user's use of a specific device, or controlling the operation mode of a specific device depending on the user authentication result. The processing request information based on the user challenge information may also include the user authentication result. The server may perform a processing for the user authentication result based on the user authentication result in accordance with the processing request information based on the user challenge information.

[0156] Furthermore, the processing request information based on the user confirmation information may include a request for determining whether to permit the control device to execute processing corresponding to the user authentication request result, in which case the server may determine whether to permit the control device to execute processing for the user authentication request result based on the user authentication result.

[0157] In another embodiment, the user challenge information may not include a user authentication result, but may include information for confirming that the terminal is in the first area. The processing request information based on the user challenge information may include a user authentication request for performing user authentication on the basic user challenge information. The control device may transmit the information required for user authentication to the server, and the server may perform user authentication based on the information required for user authentication in accordance with the user authentication request.

[0158] In operation S5000, the control device may obtain a processing result for the user confirmation information. The processing result for the user confirmation information may vary depending on processing request information based on the user confirmation information. For example, the processing result for the user confirmation information may include a result of processing the user authentication result, a result of determining whether the control device is permitted to perform the processing for the user authentication request result, a user authentication result, etc.

[0159] FIG. 9 is a sequence diagram showing the operation of the management system according to the embodiment.

[0160] Referring to FIG. 9 , when the terminal is located in the second area, the user of the terminal may not be located within the detection range of the detection sensor. Therefore, the control device may activate the second mode. For example, the second mode may include one of the inactive mode, the first area inactive mode, the receive mode, and the vicinity mode described above. The terminal may then determine whether the terminal is located in the second area. For example, assume that the control device is in the vicinity mode. If the terminal is located within a range where it can receive an advertising signal from the control device, the terminal may acquire the advertising signal from the control device, and in response to acquiring the advertising signal, the terminal may confirm that it is located in the second area. As another example, the terminal may acquire a signal from a device that can transmit a signal to the first area rather than the control device, and if the signal is acquired, it may confirm that the terminal is located in the second area. As another example, the terminal may include a global positioning system (GPS) sensor and use the GPS sensor to determine whether the terminal is located in the first area. In addition, the terminal may acquire a user authentication request from a user through an input unit of the terminal, and may determine that the terminal is located in the first area when the user authentication request is acquired from the user. For example, a user authentication application may be installed on the terminal, and the terminal may determine that the terminal is located in the first area when the user is running the application or when the user authentication request is input through the application.

[0161] However, if it is determined that the terminal is located in the second area, the terminal may transmit user-specific information to the server, where the user-specific information may refer to information for identifying the user to perform user authentication, such as identification information of the user or the terminal (such as a unique identifier (UID) or a device identifier (DID)), and identification information required for payment processing (such as the user's card information, authentication information corresponding to the card information, etc.).

[0162] In this case, the terminal may transmit the user-specific information to the server directly or via the control device. For example, when the second mode of the control device is an inactive mode, the control device is not performing communication, so the terminal may transmit the user-specific information to the server directly.

[0163] As another example, when the operating mode of the control device, which is the second mode, is the first area inactive mode, the receiving mode, or the surrounding mode, the control device may receive user-specific information from the terminal and transmit the user-specific information to the server.

[0164] The server may generate user verification information based on the acquired user-specific information. The user verification information may include information for verifying that the user is in the first area. The user verification information may also include a user authentication result and authorization information indicating that the user has unique authorization. For example, the server may determine whether the user has unique authorization using the user-specific information and the user authorization information (e.g., information about security areas the user can access, information about devices the user can use, information about products the user can process payments for, information about operation modes the user can control, etc.). If the determination result is that the user has unique authorization, the server may generate user verification information. That is, user authentication may be performed by the server.

[0165] The server may also provide user challenge information to the terminal. As mentioned above, the server may transmit the user challenge information to the terminal directly or via a control device.

[0166] Also, when the terminal is located in the first area, the user of the terminal may be located within the detection range of the detection sensor, and therefore the control device may activate the first mode. For example, the first mode may include one of the above-mentioned active mode, first area active mode, transmission mode, and peripheral mode.

[0167] The terminal may also determine whether the terminal is located in the first area. For example, the terminal may receive a signal indicating the first area from a control device or another device and may confirm that the terminal is located in the first area in response to the corresponding signal. The terminal may also determine whether the terminal is located in the first area using a GPS sensor of the terminal. The terminal may also determine whether the terminal is located in the first area based on input from a user.

[0168] Also, if the terminal communicates via Bluetooth and the terminal is located in a second area, the controlling device may be set to be in peripheral mode, the terminal may be set to be in central mode, and a communication connection may be established between them. If the controlling device subsequently determines that the terminal is located in a first area, the controlling device may be set to be in central mode, and thus the previously established communication connection may be terminated. Since the communication connection with the controlling device is terminated, the terminal may determine that the terminal is located in the first area, and thus the operating mode may be set to peripheral mode.

[0169] Also, in some embodiments, the terminal may not need to determine whether the terminal is located in the first area. In this case, in response to obtaining the user challenge information, the terminal may broadcast the user challenge information or transmit the user challenge information to the control device and communicate with the control device. Also, if the terminal communicates via Bluetooth, the terminal may change its operating mode to an ambient mode after obtaining the user challenge information and therefore may broadcast an advertising signal to communicate with the control device.

[0170] The terminal may also transmit the user challenge to the control device. It will be understood that the terminal may transmit the user challenge information or some of the information obtained by processing the user challenge information to the control device. However, for convenience of explanation, the following description will focus on the terminal transmitting the user challenge information to the control device. However, the present invention is not limited thereto.

[0171] The control device may obtain user verification information from the terminal and obtain a user authentication result.

[0172] In an embodiment, user authentication may be performed by a server. In this case, the control device may transmit processing request information for user authentication information to the server. Here, the processing request information for user authentication information may refer to processing request information for user authentication or processing request information based on user authentication information. It will be understood that the control device may transmit only user authentication information to the server. However, for convenience of explanation, the following description focuses on a control device transmitting processing request information for user authentication information to a server, but the present invention is not limited thereto.

[0173] The server may determine whether the processing request information for the user challenge information obtained from the control device is valid. This may enhance security. For example, the user challenge information may be included in the processing request information for the user challenge information, and the validation information may be included in the user challenge information. The server may determine whether the user challenge information obtained from the control device is valid based on the validation information. For example, the validation information may be generated by the server according to a predetermined rule when the server generates the user challenge information. For example, the validation information may be a one-time password (OTP). The server may determine that the user challenge information is validated using the predetermined rule.

[0174] As another example, the server may determine whether the user challenge information obtained from the control device is identical to the user challenge information previously transmitted to the terminal, and may determine that the user challenge is valid if the two pieces of information are identical to each other. For example, the server may determine whether the identification information of the user challenge information included in the user challenge information obtained from the control device is identical to the identification information of the user challenge information included in the user challenge information transmitted to the terminal.

[0175] If the processing request information for the user verification information is determined to be valid, the server may execute a process corresponding to the processing request information for the user verification information, where the process corresponding to the processing request information for the user verification information may include the above-described process corresponding to the user authentication result.

[0176] For example, if the process corresponding to the processing request information for user authentication information is a payment process, the payment process may be performed by a payment module. Here, the payment module may be included in the server or another server. In this case, identification information required for the payment process (e.g., the user's card information, authentication information corresponding to the card information, etc.) may be included in the processing request information for user authentication information, or the identification information required for the payment process may be pre-stored in the server. The server may provide the identification information required for the payment process to the payment module. The payment module may perform authentication for the payment process, and the server may obtain the authentication result for the payment process from the payment module.

[0177] In another embodiment, when the processing request information for user verification information includes a user authentication request, the server may perform user authentication by determining whether the user has inherent authority. For example, the user-specific information may be included in the processing request information for user verification information, and the server may perform user authentication by determining whether the user has inherent authority using the user-specific information and user authority information pre-stored in the server (e.g., information on security areas the user can access, information on products for which the user can process payments, information on devices the user can use, information on operation modes the user can control, etc.).

[0178] The server may transmit a processing result for the user confirmation information to the control device, and the control device may perform an operation corresponding to the processing result for the user confirmation information and transmit the processing result for the user confirmation information to the terminal.

[0179] In another embodiment, user authentication may be performed by the control device. The control device may check whether the user challenge information received from the terminal is generated by the server. This may be to increase the security of the user authentication. For example, validity information may be included in the user challenge information received from the terminal, and the control device may determine whether the user challenge information is valid based on the validity information. If the server generates the user challenge information, the validity information may be generated by the server according to a predetermined rule. For example, the validity information may be an OTP. The control device may obtain information about the predetermined rule from the server and determine whether the user challenge information was validated using the predetermined rule.

[0180] The control device may also perform user authentication by determining whether the user has specific authority. For example, user-specific information may be included in the user confirmation information, and the control device may perform user authentication by determining whether the user has specific authority using the user-specific information and user authority information pre-stored in the control device (e.g., information on security areas the user can access, information on devices the user can use, information on whether the user can process payments, information on operation modes the user can control, etc.).

[0181] Also, if the inherent authority is a payment authority that allows a user to process payments, user authentication for the payment authority may be performed by a payment module. Here, the payment module may be included in the control device or another device (e.g., a server, another server, another payment device, etc.). In this case, identification information required for payment processing (e.g., user card information, authentication information corresponding to the card information, etc.) may be included in the user verification information or may be stored in the control device. The control device may provide the identification information required for payment processing to the payment module. The payment module may perform user authentication for the payment authority, and the control device may obtain the user authentication result for the payment authority from the payment module.

[0182] The control device may perform processing corresponding to the user authentication result, and may transmit the user authentication result to the terminal.

[0183] FIG. 10 is a sequence diagram showing the operation of a management system according to another embodiment.

[0184] Referring to FIG. 10 , the control device and the terminal may communicate with each other via a wireless communication method, such as via Bluetooth (or BLE). When the terminal is located in the second area, the user of the terminal may not be located within the detection range of the detection sensor. Therefore, the operation mode of the control device may be set to a peripheral mode, and the operation mode of the terminal may be set to a central mode. Therefore, the control device may broadcast an advertisement signal. The terminal may perform a scanning operation and transmit a connection request signal to the control device. Thereafter, the control device and the terminal may recognize each other so that a communication connection can be established between the control device and the terminal.

[0185] Also, since the operation mode of the control device is the peripheral mode, there is no user authentication result that can be obtained by the control device. However, the control device may obtain at least some of the information necessary for user authentication from the terminal. This may be to improve the speed of obtaining the user authentication result that is performed later.

[0186] As another example, the control device may include the first communication unit and the second communication unit described above. Here, the first communication unit may operate in a central mode, and the second communication unit may operate in a peripheral mode. Therefore, when it is determined that the user of the terminal is not located within the detection range of the detection sensor, the control device may operate the second communication unit without operating the first communication unit. Therefore, the control device can communicate with a terminal located in the second area and operating in the central mode through the second communication unit, but cannot communicate with a terminal located in the first area and operating in the peripheral mode.

[0187] Also, when the terminal is located in the first area and the user of the terminal is located within the detection range of the detection sensor, the operation mode of the control device may be set to the central mode and the operation mode of the terminal may be set to the peripheral mode, that is, the operation modes of the control device and the terminal may be switched according to the location of the terminal.

[0188] As a particular example, the control device may terminate a previously established communication connection by changing the operating mode to a central mode. Accordingly, the terminal may determine that it is located in a first location and change its operating mode to a peripheral mode.

[0189] The terminal may broadcast an advertising signal, and the control device may perform a scanning operation and transmit a connection request signal to the control device, after which the control device and the terminal may recognize each other so that a communication connection can be established between the control device and the terminal.

[0190] In addition, in an embodiment, the control device may determine whether a terminal with which communication is established when the control device is in peripheral mode is the same as a terminal from which an advertising signal is received when the control device is in central mode. For example, the control device may obtain user or terminal identification information (e.g., UID, DID, etc.) from the terminal when the control device is in peripheral mode, and may further obtain user or terminal identification information from the terminal when the control device is in central mode. The control device may determine whether two pieces of identification information about a user or terminal received at different times are identical, and may establish a communication connection if the two pieces of information are identical and the control device is also in central mode.

[0191] As another example, when the user of the terminal is located within the detection range of the detection sensor, the control device may activate both the first communication unit and the second communication unit described above.

[0192] Thus, the control device can communicate with terminals located in the second area and operating in central mode through the second communication unit, and can communicate with terminals located in the first area and operating in peripheral mode through the first communication unit.

[0193] The descriptions with reference to FIGS. 6 to 9 can be applied to the subsequent operations, and therefore detailed descriptions thereof will be omitted.

[0194] FIG. 11 is a flowchart showing a method for controlling a terminal according to the embodiment.

[0195] 11, the method for controlling a terminal may include providing user-specific information of the terminal to a server (S10000), obtaining user authentication information from the server based on the user-specific information (S20000), providing the user authentication information to a control device (S30000), and obtaining a result of processing the user authentication information from the control device (S40000). The descriptions with reference to FIGS. 6 to 10 can be applied to operations S10000 to S40000, and therefore detailed descriptions thereof will be omitted.

[0196] According to the present disclosure, it is possible to improve the accuracy and security of user authentication regardless of the performance of the terminal.

[0197] Furthermore, according to the present disclosure, it is possible to reduce the time required to perform user authentication and processing corresponding to the user authentication.

[0198] The advantageous effects of the present invention are not limited to the above-mentioned effects, and other advantageous effects not described in this specification will be clearly understood by those skilled in the art from the following description and the accompanying drawings.

[0199] The various embodiments described above may be implemented as a software program including instructions stored on a machine-readable (e.g., computer-readable) storage medium. A machine is a device that can retrieve and operate according to instructions stored on the storage medium, and may include an electronic device according to the above-described embodiments. When instructions are executed by a processor, the processor may perform the functions corresponding to the instructions directly or using other components under the control of the processor. The instructions may include code generated or executed by a compiler or an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. In this specification, the term "non-transitory" simply means that the storage medium does not include a signal but is tangible, and does not distinguish between data stored permanently on the storage medium and data stored temporarily on the storage medium.

[0200] According to embodiments of the present disclosure, the methods according to the various embodiments described above may be provided to be included in a computer program product. The computer program product may be traded as a commodity between a seller and a consumer. The computer program product may be distributed online, in the form of a machine-readable storage medium (e.g., a compact disc read-only memory (CD-ROM)), or through an application store (e.g., the Play Store®). For online distribution, at least a portion of the computer program product may be at least temporarily stored on a manufacturer's server, an application store's server, or a storage medium such as a memory, or may be temporarily generated.

[0201] While the present disclosure has been described with reference to particular embodiments and drawings, it will be understood that various modifications and variations from this disclosure may be made by those skilled in the art. For example, the described techniques may be performed in a different order than described and / or the described components, such as systems, structures, devices or circuits, may be combined in a different manner than described and / or replaced or supplemented with other components or their equivalents, although suitable results may still be achieved.

[0202] Accordingly, other implementations, embodiments and equivalents are within the scope of the following claims.

Claims

1. 1. A control method for a control device, the control method comprising: determining whether a moving object is located in a first area using a detection sensor; activating a first mode of the operation modes of the control device when it is determined that the moving object is located in the first area; obtaining user authentication information from a terminal if the first mode is activated; obtaining a result of the user authentication based on the information of the user authentication; providing the result of the user authentication to the terminal; Equipped with If it is determined that the moving object is not located in the first area, the operation mode of the control device is activated in a second mode; A control method, wherein a communication area of ​​the control device when the first mode is activated is at least partially different from the communication area of ​​the control device when the second mode is activated.

2. the first mode includes an active mode in which the control device is permitted to communicate with the terminals present in the first area; The control method of claim 1 , wherein the second mode comprises an inactive mode in which the control device is not permitted to communicate with the terminals present in the first area.

3. When the first mode is activated, the communication area of ​​the control device is set so as to include the first area and a second area indicating that the communication area is a predetermined communication area other than the first area; When the second mode is activated, the communication area of ​​the control device is set so that the communication area includes the second area such that the control device communicates with the terminal located in the second area without communicating with the terminal located in the first area; The control device a first communication unit configured to communicate with the terminal present in the first area; a second communication unit configured to communicate with the terminal present in the second area; and the control device performs control to drive the first communication unit and the second communication unit when the first mode is activated; The control method according to claim 1 , wherein the control device executes control to drive the second communication unit without driving the first communication unit when the second mode is activated.

4. the first mode includes a central mode in which the control device receives an advertising signal from the terminal and scans for the terminal in response to receiving the advertising signal; The control method according to claim 1 , wherein the second mode includes a peripheral mode in which the control device transmits an advertising signal to the terminal and is scanned by the terminal in response to transmitting the advertising signal.

5. the first communication unit operates in a central mode in which the control device receives an advertising signal from the terminal and scans for the terminal in response to receiving the advertising signal; 4. The control method of claim 3, wherein the second communication unit operates in a peripheral mode in which the control device transmits an advertising signal to the terminal and is scanned by the terminal in response to transmitting the advertising signal.

6. 2. The control method of claim 1, wherein the step of determining whether a moving body is located in a first area using a detection sensor includes a step of acquiring a detection signal from the detection sensor if the moving body is located in the first area, and a step of determining that the moving body is located in the first area if the detection signal is acquired.

7. the information for the user authentication corresponds to user-specific information stored in the terminal; The control method according to claim 1 , wherein the user specific information includes at least one of identification information of the terminal and identification information of a user of the terminal.

8. A program for causing a processor to execute the control method according to any one of claims 1 to 7.

9. A control device comprising: A storage unit; at least one processor operatively connected to said storage unit; Equipped with The processor: Using a detection sensor, determine whether or not the moving object is located in a first area; When it is determined that the moving object is located in the first area, activating a first mode of the operation modes of the control device; If the first mode is activated, obtaining user authentication information from the terminal; obtaining a result of the user authentication based on the information of the user authentication; providing the result of the user authentication to the terminal; It is configured as If it is determined that the moving object is not located in the first area, the operation mode of the control device is activated in a second mode; A control device, wherein a communication area of ​​the control device when the first mode is activated is at least partially different from the communication area of ​​the control device when the second mode is activated.

Citation Information

Patent Citations

  • Gate control system

    JP2016136352A

  • JPP7440011B

  • Biometric solution enabling high throughput fare payments and system access

    US20150227923A1