System for user authentication for industrial control device and authentication code verification device
The system addresses security vulnerabilities in industrial control devices by generating and verifying OTACs within the authentication code verification device, enhancing security and access control without separate OTP devices.
Patent Information
- Application Number
- PCT/KR2025/009555
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-12-26
- Filing Date
- 2025-07-03
- Publication Date
- 2026-01-08
AI Technical Summary
Existing user authentication methods for industrial control devices face security vulnerabilities due to data leaks and the need for separate OTP generation devices, which are inconvenient and prone to seed data leakage.
A system for user authentication using an authentication code verification device that generates and verifies One-Time Authentication Codes (OTACs) without requiring a separate OTP generation device, incorporating a verification module and processor to manage user registration and authentication, with secret data encryption and QR code recognition for secure access control.
Enhances security by preventing seed data leakage and ensuring secure access to industrial control devices through dynamic OTACs, reducing vulnerabilities and enhancing user verification and authority authentication.
Smart Images

Figure KR2025009555_08012026_PF_FP_ABST
Abstract
Description
System and authentication code verification device for user authentication of industrial control devices
[0001] The present disclosure relates to a system for user authentication for industrial control devices and an authentication code verification device.
[0002] Code-based data is used in many areas. Examples of code-based data include card numbers and account numbers used for payment, as well as IPIN numbers and resident registration numbers used for user identification.
[0003] However, there are frequent cases of data leaks during the use of this code. Card numbers are often printed on the card's surface, making them visible to others. Furthermore, card numbers are also leaked when magnetic stripe payments are made, transmitting them directly to the POS device.
[0004] There have been many attempts to use virtual code to prevent the actual code from being leaked, but data to identify the user was needed to search for the actual code corresponding to the virtual code.
[0005] However, in the case of OTP (One Time Password), a separate OTP generation device is required, which is inconvenient, and in particular, in the case of user terminals, there is a security vulnerability due to the leakage of seed data used for OTP generation.
[0006] Therefore, a method is needed to increase security by generating OTP codes, such as generating virtual security codes required for user authentication based on card data held by many users, without requiring a separate OTP generation device, and at the same time preventing seed data from being leaked.
[0007] The purpose of the embodiments disclosed in the present disclosure is to provide a system for user authentication for an industrial control device and an authentication code verification device.
[0008] The problems to be solved by the present disclosure are not limited to the problems mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art from the description below.
[0009] In order to achieve the above-described technical task, an authentication code verification device for user authentication for an industrial control device according to one aspect of the present disclosure includes a verification module that performs user registration based on a user key and verifies an authentication code for user authentication generated by the authentication code generation device, and a processor that receives a user registration request from the authentication code generation device and receives a verification request for the authentication code from the authentication code generation device, wherein the verification of the authentication code may be performed to allow or deny access to the industrial control device.
[0010] In addition, if the authentication code verification device is a server, the verification module generates secret data using the user ID and the user key assigned to the user, and the secret data can be re-encrypted and stored in the authentication code generation device through QR code recognition of the authentication code generation device.
[0011] In addition, when the authentication code verification device is a server, the verification module performs the verification by comparing the secret data included in the authentication code and the previously stored secret data, and when the verification is completed, transmits the user ID together with the verification result to the industrial control device, and the user ID can be used for user verification and authority verification in the industrial control device.
[0012] In addition, when the authentication code verification device is the industrial control device, the verification module generates secret data using the user ID and the user key assigned to the user, and the secret data can be re-encrypted and stored in the authentication code generation device through QR code recognition of the authentication code generation device.
[0013] In addition, when the authentication code verification device is the industrial control device, the verification module performs the verification by comparing the secret data included in the authentication code and the previously stored secret data, and when the verification is completed, transmits the user ID together with the verification result to the processor, and the user ID can be used for user verification and authority verification in the processor.
[0014] In addition, when the authentication code verification device is a server, the verification module generates secret data using the user ID and the user key assigned to the user, and the secret data is re-encrypted and stored in the industrial control device, and can be re-encrypted and stored in the authentication code generation device through QR code recognition of the authentication code generation device.
[0015] In addition, when the authentication code verification device is a server, when communication between the server and the industrial control device is possible, the verification module performs the verification by comparing the secret data included in the authentication code and the previously stored secret data, and when the verification is completed, the user ID is transmitted to the industrial control device together with the verification result, and when communication between the server and the industrial control device is impossible, an alternative module included in the industrial control device performs the verification, and when the verification is completed, the user ID is transmitted to a processor included in the industrial control device together with the verification result, and the user ID can be used for user verification and authority verification in the industrial control device.
[0016] Additionally, when an attempt to access the industrial control device occurs from an input / output device through user input, verification of the authentication code may be performed at the request of a gateway connected to the industrial control device.
[0017] Additionally, only when the gateway determines that the access attempt is a fixed password-based login attempt, verification of the authentication code is requested by the verification module, and when the verification is completed, access to the industrial control device can be permitted through the fixed password.
[0018] In addition, only when the value entered at the time of the access attempt is determined by the gateway to be the authentication code, verification of the authentication code is requested by the verification module, and when the verification is completed, access to the industrial control device may be permitted through a fixed password previously stored in the gateway.
[0019] In addition, if the authentication code verification device is a server, the verification module performs verification of the authentication code requested by the gateway, and when the verification is completed, transmits the user ID assigned to the user along with the verification result to the gateway, and the user ID can be used for user verification at the gateway.
[0020] In addition, when the authentication code verification device is the industrial control device, the verification module performs verification of the authentication code requested by the gateway, and when the verification is completed, transmits the user ID assigned to the user along with the verification result to the gateway, and the user ID can be used for user verification at the gateway.
[0021] In addition, when the authentication code verification device is a server, when communication between the server and the industrial control device is possible, the verification module performs verification of the authentication code requested by the gateway, and when the verification is completed, the user ID assigned to the user is transmitted to the gateway through the industrial control device together with the verification result, and when communication between the server and the industrial control device is impossible, a substitute module included in the industrial control device performs verification of the authentication code requested by the gateway, and when the verification is completed, the substitute module transmits the user ID together with the verification result to the gateway, and the user ID can be used for user verification in the gateway.
[0022] In addition, a computer program stored in a computer-readable recording medium for executing a method for implementing the present disclosure may be further provided.
[0023] In addition, a computer-readable recording medium recording a computer program for executing a method for implementing the present disclosure may be further provided.
[0024] According to the aforementioned problem solving means of the present disclosure, user and device authentication is possible through an OTAC verification module mounted on an industrial control device or server.
[0025] In addition, the security of the industrial control device can be enhanced by connecting a gateway to the industrial control device, having the gateway process access to the industrial control device and transmit the processing result to the industrial control device.
[0026] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.
[0027] FIG. 1 is a schematic diagram illustrating a system for user authentication for an industrial control device according to one embodiment of the present disclosure.
[0028] FIG. 2 is a block diagram of an authentication code verification device for user authentication for an industrial control device according to one embodiment of the present disclosure.
[0029] FIG. 3 is a flowchart of a user registration method for user authentication for an industrial control device according to one embodiment of the present disclosure.
[0030] Figure 4 is a drawing for explaining the type-specific user registration process for industrial control devices.
[0031] FIG. 5 is a flowchart of an authentication code verification method for user authentication for an industrial control device according to one embodiment of the present disclosure.
[0032] FIG. 6 is a diagram for explaining a type-specific user authentication process according to one embodiment of the present disclosure.
[0033] FIG. 7 is a diagram for explaining a user registration process for each type of case including a gateway according to one embodiment of the present disclosure.
[0034] FIG. 8 is a diagram for explaining a user authentication process for each type of case including a gateway according to one embodiment of the present disclosure.
[0035] Throughout this disclosure, the same reference numerals denote the same components. This disclosure does not describe all elements of the embodiments, and any content that is common in the technical field to which this disclosure pertains or that overlaps between embodiments is omitted. The terms "part, module, element, block" used in the specification may be implemented in software or hardware, and depending on the embodiments, multiple "parts, modules, elements, blocks" may be implemented as a single component, or a single "part, module, element, block" may include multiple components.
[0036] Throughout the specification, when a part is said to be "connected" to another part, this includes not only direct connection but also indirect connection, and indirect connection includes connection via a wireless communication network.
[0037] Additionally, when a part is said to "include" a component, this does not mean that it excludes other components, but rather that it may include other components, unless otherwise specifically stated.
[0038] Throughout the specification, when we say that an element is "on" another element, this includes not only cases where the element is in contact with the other element, but also cases where another element exists between the two elements.
[0039] The terms first, second, etc. are used to distinguish one component from another, and the components are not limited by the aforementioned terms.
[0040] Singular expressions include plural expressions unless the context clearly indicates otherwise.
[0041] The identification codes for each step are used for convenience of explanation and do not describe the order of each step. Each step may be performed in a different order than specified unless the context clearly indicates a specific order.
[0042] The operating principle and embodiments of the present disclosure are described below with reference to the attached drawings.
[0043] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.
[0044] Before proceeding, the meanings of terms used in this specification will be briefly explained. However, it should be noted that the explanation of terms is intended to aid understanding of this specification, and therefore, unless explicitly stated to limit the disclosure, they are not intended to limit the technical concepts of this disclosure.
[0045] As used herein, the term "device" encompasses a variety of devices capable of performing computational processing and providing results to a user. For example, a device may include a computer, a server, or a mobile terminal, or may be any one of these.
[0046] Here, the computer may include, for example, a notebook, desktop, laptop, tablet PC, slate PC, etc. equipped with a web browser.
[0047] The above server device is a server that processes information by communicating with an external device, and may include an application server, a computing server, a database server, a file server, a game server, a mail server, a proxy server, and a web server.
[0048] The above portable terminal may include, for example, a wireless communication device that ensures portability and mobility, and may include all kinds of handheld-based wireless communication devices such as a PCS (Personal Communication System), GSM (Global System for Mobile communications), PDC (Personal Digital Cellular), PHS (Personal Handyphone System), PDA (Personal Digital Assistant), IMT (International Mobile Telecommunication)-2000, CDMA (Code Division Multiple Access)-2000, W-CDMA (W-Code Division Multiple Access), WiBro (Wireless Broadband Internet) terminal, a smart phone, and a wearable device such as a watch, a ring, a bracelet, an anklet, a necklace, glasses, contact lenses, or a head-mounted device (HMD).
[0049] In this specification, “character” is a component that constitutes a code, and includes all or part of uppercase alphabets, lowercase alphabets, numbers, and special characters.
[0050] In this specification, “code” means a string of characters.
[0051] In this specification, “authentication code” may mean an OTAC (One Time Authentication Code) temporarily generated for authentication of at least one of a user and a device.
[0052] In this specification, "authentication code generation function" refers to a function that generates an authentication code. Examples include, but are not limited to, a One Time Password (OTP).
[0053] In this specification, “detail code generation function” means a function that generates each detail code that constitutes an authentication code.
[0054] In this specification, “detail code combination function” means a function that generates a virtual code by combining or combining multiple detail codes.
[0055] In this specification, a "unit count" is defined as a unit set at a specific time interval and changed as the time interval elapses. For example, 1 count may be set and used at a specific time interval (e.g., 1.5 seconds).
[0056] In this specification, “storage location” means the point (count) on the track corresponding to the time when user or device registration is requested.
[0057] In this specification, “industrial control device” may include, but is not limited to, a PLC (Programmable Logic Controller), a DCS (Distributed Control System), an RTU (Remote Terminal Unit), an HMI (Human-Machine Interface), a SCADA (Supervisory Control And Data Acquisition), and an ICS (Industrial Control Systems). Here, the HMI may also be used as an input window for entering information necessary for controlling the industrial control device.
[0058] Cyberattacks targeting industrial control systems have been on the rise recently. Among the components of industrial control systems, industrial control devices are a core component. A cyberattack targeting these devices could potentially cause damage to the entire industrial control system.
[0059] Accordingly, in the present disclosure, an industrial control device can be protected from hacking risks by using an authentication method using a dynamic authentication code (One-Time Authentication Code, OTAC).
[0060] Hereinafter, a system for user authentication for an industrial control device will be described with reference to FIG. 1.
[0061] FIG. 1 is a schematic diagram illustrating a system for user authentication for an industrial control device according to one embodiment of the present disclosure.
[0062] Referring to FIG. 1, a system for user authentication for an industrial control device (hereinafter, “system”) may include an authentication code generation device (10) and an authentication code verification device (20). However, in some embodiments, the system may include fewer or more components than the components illustrated in FIG. 1.
[0063] The authentication code generation device (10) may be a user's mobile terminal, or a smart card for identification or access (entry). However, it is not limited thereto, and any device that includes an authentication code generation module may be applied.
[0064] The authentication code verification device (20) may be a server connected to an industrial control device, or may be the industrial control device itself. However, it is not limited thereto, and any device that includes an authentication code verification module may be applied.
[0065] When the authentication code generated by the authentication code generation device (10) is transmitted to the authentication code verification device (20), the authentication code verification device (20) can verify the authentication code. Based on the verification result, the industrial control device can allow or deny access.
[0066] At this time, the transmission of the authentication code can be performed via an input / output device (not shown). The input / output device may include, but is not limited to, a human-machine interface (HMI) device, a PC or laptop remotely connected to an industrial control device, or a PC or laptop wired to an industrial control device for maintenance. Any input or communication means for transmitting information may be applied.
[0067] Specifically, transmission of the authentication code can be performed through any one of the keyboard, camera, scanner, and NFC of the input / output device.
[0068] According to an embodiment, a user may transmit an authentication code generated by an authentication code generation device (10) to an authentication code verification device (20) by directly entering the authentication code through a keyboard of an input / output device connected to an industrial control device. In this case, the authentication code may be in the form of a character string composed of a combination of alphabets, numbers, and special characters.
[0069] According to an embodiment, a user may transmit an authentication code generated by an authentication code generation device (10) to an authentication code verification device (20) by taking a picture of the authentication code with a camera or scanner of an input / output device connected to an industrial control device. In this case, the authentication code may be in the form of a QR code.
[0070] Hereinafter, the authentication code verification device (20) will be described with reference to FIG. 2.
[0071] FIG. 2 is a block diagram of an authentication code verification device for user authentication for an industrial control device according to one embodiment of the present disclosure.
[0072] Referring to FIG. 2, the authentication code verification device (20) may include a communication unit (21), a memory (22), a verification module (23), and a processor (24). However, in some embodiments, the authentication code verification device (20) may include fewer or more components than the components illustrated in FIG. 2.
[0073] The communication unit (21) may include one or more modules that enable wireless or wired communication between the authentication code verification device (20) and another device, or between the authentication code verification device (20) and a communication network. For example, it may include at least one of a wired communication module, a wireless communication module, a short-range communication module, and a location information module.
[0074] The communication network can use various types of communication networks, for example, wireless communication methods such as WLAN (Wireless LAN), Wi-Fi, Wibro, WiMAX, and HSDPA (High Speed Downlink Packet Access), or wired communication methods such as Ethernet, xDSL (ADSL, VDSL), HFC (Hybrid Fiber Coax), FTTC (Fiber to The Curb), and FTTH (Fiber to The Home) can be used.
[0075] Meanwhile, the communication network is not limited to the communication methods presented above, and may include all other widely known or future-developed communication methods in addition to the above-described communication methods.
[0076] The wired communication module may include various wired communication modules such as a Local Area Network (LAN) module, a Wide Area Network (WAN) module, or a Value Added Network (VAN) module, as well as various cable communication modules such as a Universal Serial Bus (USB), a High Definition Multimedia Interface (HDMI), a Digital Visual Interface (DVI), RS-232 (recommended standard 232), power line communication, or plain old telephone service (POTS).
[0077] The wireless communication module may include a wireless communication module that supports various wireless communication methods such as GSM (global System for Mobile Communication), CDMA (Code Division Multiple Access), WCDMA (Wideband Code Division Multiple Access), UMTS (universal mobile telecommunications system), TDMA (Time Division Multiple Access), LTE (Long Term Evolution), 4G, 5G, and 6G, in addition to a WiFi module and a Wireless Broadband module.
[0078] The short-range communication module is for short-range communication, and can support short-range communication using at least one of Bluetooth™, RFID (Radio Frequency Identification), Infrared Data Association (IrDA), UWB (Ultra Wideband), ZigBee, NFC (Near Field Communication), Wi-Fi (Wireless-Fidelity), Wi-Fi Direct, and Wireless USB (Wireless Universal Serial Bus) technologies.
[0079] The memory (22) may store at least one process related to authentication code verification for user authentication for an industrial control device.
[0080] The memory (22) can store data supporting various functions of the authentication code verification device (20), a program for the operation of the processor (24), can store input / output data (e.g., music files, still images, moving images, etc.), and can store a plurality of application programs (or applications) run by the authentication code verification device (20), data for the operation of the authentication code verification device (20), and commands. At least some of these application programs can be downloaded from an external server via wireless communication.
[0081] The memory (22) may include at least one type of storage medium among a flash memory type, a hard disk type, an SSD (Solid State Disk type), an SDD (Silicon Disk Drive type), a multimedia card micro type, a card type memory (e.g., SD or XD memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, and an optical disk. In addition, the memory (22) is separate from the authentication code verification device (20), but may be a database connected by wire or wirelessly.
[0082] The verification module (23) can verify the authentication code generated by the authentication code generation device (10). The generation and verification of the authentication code will be described later.
[0083] The processor (24) can perform the aforementioned operations using a memory that stores data regarding an algorithm for controlling the operation of components within the authentication code verification device (20) or a program that reproduces the algorithm, and the data stored in the memory. In this case, the memory (22) and the processor (24) may be implemented as separate chips. Alternatively, the memory (22) and the processor (24) may be implemented as a single chip.
[0084] In addition, the processor (24) can control one or a combination of the components discussed above to implement various embodiments according to the present disclosure described in FIGS. 3 to 8 below on the authentication code verification device (20).
[0085] Hereinafter, with reference to FIGS. 3 and 4, the user registration process of the OTAC solution for strengthening the security of industrial control devices in the OT (Operational Technology) field will be described.
[0086] FIG. 3 is a flowchart of a user registration method for user authentication for an industrial control device according to one embodiment of the present disclosure.
[0087] Figure 4 is a drawing for explaining the type-specific user registration process for industrial control devices.
[0088] Referring to FIG. 3, the processor (24) of the authentication code verification device (20) can receive a user registration request from the authentication code generation device (10) (S310).
[0089] The processor (24) of the authentication code verification device (20) can perform user registration based on the user key (UserKey) (S320).
[0090] Here, the user key may refer to a value assigned to a user when registering to generate an OTAC. The user key may be generated on a server and transmitted to an authentication code generation device (10), or may be generated by the authentication code generation device (10).
[0091] The authentication code generation device (10) can transmit a user registration request together with the provided or generated user key to the authentication code verification device (20).
[0092] The processor (24) of the authentication code verification device (20) can set the user's access rights according to the user registration request.
[0093] The processor (24) of the authentication code verification device (20) can request user registration while transmitting a user key and user ID (UserID) to the verification module (23).
[0094] Here, the user ID is information for identifying the user generated by the authentication code verification device (20), and can be mapped to the user's access rights.
[0095] The verification module (23) of the authentication code verification device (20) can generate secret data using a user key and user ID.
[0096] Here, secret data can be encrypted and stored in the authentication code verification device (20) and transmitted to the authentication code generation device (10) in the form of a QR code.
[0097] The authentication code generation device (10) can recognize a QR code to obtain secret data, and re-encrypt and store the obtained secret data.
[0098] This user registration process may vary depending on the type of OTAC solution.
[0099] Here, the types of OTAC solutions may include the first type, the second type, and the third type.
[0100] The first type is when the OTAC solution is implemented via an OTAC server connected to (or included in) a central server.
[0101] The second type is when the OTAC solution is implemented via an OTAC verification module connected to (or embedded in) the industrial control device.
[0102] The third type is where the OTAC solution is primarily implemented through an OTAC server connected to (or included in) a central server, but in cases where communication with the central server is not possible, through an OTAC verification module connected to (or included in) an industrial control device.
[0103] - Type 1 User Registration Process -
[0104] As described above, the first type is when the authentication code verification device (20) is a server.
[0105] Referring to the server type illustrated in FIG. 4, when the authentication code verification device (20) is a server, the OTAC server (verification module (23)) can generate secret data using the user key and user ID assigned to the user according to the user registration request, and encrypt and store the generated secret data.
[0106] At this time, the user key is shown as being provided to the central server through an input / output device, but it may also be provided directly to the central server from the user terminal (authentication code generation device (10)) without going through the input / output device.
[0107] The OTAC server (verification module (23)) can generate the generated secret data in the form of a QR code and provide it to the user terminal (authentication code generation device (10)). At this time, the QR code can be sent to the user's email or output through the screen of the input / output device.
[0108] The user terminal (authentication code generation device (10)) can recognize the QR code and obtain secret data. The obtained secret data can be re-encrypted and stored in the user terminal (authentication code generation device (10)).
[0109] - Type 2 User Registration Process -
[0110] As described above, the second type is when the authentication code verification device (20) is an industrial control device.
[0111] Referring to the modular configuration illustrated in FIG. 4, when the authentication code verification device (20) is an industrial control device, the OTAC verification module (verification module (23)) can generate secret data using the user key and user ID assigned to the user according to a user registration request, and encrypt and store the generated secret data.
[0112] At this time, the user key is shown as being provided to the central server through an input / output device, but it may also be provided directly to the central server from the user terminal (authentication code generation device (10)) without going through the input / output device.
[0113] An industrial control device (specifically, a processor (23)) can generate secret data in the form of a QR code and provide it to a user terminal (authentication code generation device (10)). At this time, the QR code can be sent to the user's email or output through the screen of an input / output device.
[0114] The user terminal (authentication code generation device (10)) can recognize the QR code and obtain secret data. The obtained secret data can be re-encrypted and stored in the user terminal (authentication code generation device (10)).
[0115] - Third type of user registration process -
[0116] As described above, the third type is a case where the authentication code verification device (20) is a server, but in a situation where communication is impossible, the role of the authentication code verification device (20) is replaced by an industrial control device.
[0117] Referring to the hybrid type illustrated in FIG. 4, when the authentication code verification device (20) is a server, a user registration request is transmitted to the central server via an industrial control device, and the OTAC server (verification module (23)) can generate secret data using the user key and user ID assigned to the user according to the user registration request, and encrypt and store the generated secret data.
[0118] At this time, the user key is shown as being provided to the central server through an input / output device, but it may also be provided to the central server through an industrial control device directly from the user terminal (authentication code generation device (10)) without going through the input / output device.
[0119] The central server can provide secret data generated by the OTAC server (verification module (23)) to an industrial control device. The provided secret data can be re-encrypted and stored in the industrial control device (specifically, the OTAC verification module (replacement module)).
[0120] An industrial control device can generate the provided secret data in the form of a QR code and provide it to a user terminal (authentication code generation device (10)). At this time, the QR code can be sent to the user's email or output through the screen of an input / output device.
[0121] The user terminal (authentication code generation device (10)) can recognize the QR code and obtain secret data. The obtained secret data can be re-encrypted and stored in the user terminal (authentication code generation device (10)).
[0122] Hereinafter, with reference to FIGS. 5 and 6, the user authentication process of the OTAC solution for strengthening the security of industrial control devices in the OT (Operational Technology) field will be described.
[0123] FIG. 5 is a flowchart of an authentication code verification method for user authentication for an industrial control device according to one embodiment of the present disclosure.
[0124] FIG. 6 is a diagram for explaining a type-specific user authentication process according to one embodiment of the present disclosure.
[0125] Referring to FIG. 5, the processor (24) of the authentication code verification device (20) can receive a request for verification of an authentication code from the authentication code generation device (10) (S510).
[0126] The verification module (23) of the authentication code verification device (20) can perform verification of the authentication code for user authentication (S520).
[0127] The processor (24) of the authentication code verification device (20) can request user registration while transmitting an authentication code to the verification module (23). Here, the authentication code can be generated based on secret data stored in the authentication code generation device (10).
[0128] The verification module (23) of the authentication code verification device (20) performs a comparison between the secret data included in the authentication code and the previously stored secret data, and can determine whether the authentication code was generated from a normal user terminal at the current time based on whether the two values match.
[0129] The verification module (23) of the authentication code verification device (20) can extract the user ID included in or mapped to the secret data if the two values above match.
[0130] The processor (24) of the authentication code verification device (20) can transmit the user ID and verification result to an industrial control device.
[0131] Here, the user ID can be used for user authentication and authorization verification on industrial control devices. That is, the industrial control device can use the transmitted user ID to identify the user corresponding to the user ID and verify the user's access rights.
[0132] Specifically, the industrial control device can verify that the transmitted user ID matches the information in the database (i.e., verify that the transmitted user ID corresponds to the information of an actual registered user). The industrial control device can verify the user's authority through the access rights mapped to the verified user ID.
[0133] In some embodiments, the industrial control device can determine whether a user has access rights to the industrial control device by checking the access rights of the user corresponding to the transmitted user ID.
[0134] Once user verification and access authorization are completed, the industrial control device can grant or deny access based on the verification results. If the verification results indicate an abnormal user access, access can be denied immediately, without the need for user ID verification or access authorization verification, as described above.
[0135] This user authentication process may vary depending on the type of OTAC solution.
[0136] - Type 1 user authentication process -
[0137] As described above, the first type is when the authentication code verification device (20) is a server.
[0138] Referring to the server type illustrated in FIG. 6, when the authentication code verification device (20) is a server, the authentication code generated in the user terminal (authentication code generation device (10)) is input through an input / output device and transmitted to the industrial control device, and the industrial control device can transmit an authentication code verification request together with the authentication code to the OTAC server (verification module (23)).
[0139] The OTAC server (verification module (23)) performs the verification by comparing the secret data included in the authentication code with the previously stored secret data, and when the verification is completed, the user ID can be transmitted to the industrial control device along with the verification result.
[0140] Industrial control devices can use user IDs to perform user authentication and user authorization verification, and grant or deny access based on the verification results.
[0141] The input / output device can output the verification results.
[0142] - Type 2 User Authentication Process -
[0143] As described above, the second type is when the authentication code verification device (20) is an industrial control device.
[0144] Referring to the modular configuration illustrated in FIG. 6, when the authentication code verification device (20) is an industrial control device, the authentication code generated in the user terminal (authentication code generation device (10)) is input through an input / output device and transmitted to the industrial control device (specifically, the processor (24)), and the industrial control device (specifically, the processor (24)) can transmit an authentication code verification request together with the authentication code to the OTAC verification module (verification module (23)).
[0145] The OTAC verification module (verification module (23)) performs the verification by comparing the secret data included in the authentication code with the previously stored secret data, and when the verification is completed, the user ID can be transmitted together with the verification result to an industrial control device (specifically, a processor (24)).
[0146] An industrial control device (specifically, a processor (24)) can perform user authentication and user authority verification using a user ID, and allow or deny access based on the verification result.
[0147] The input / output device can output the verification results.
[0148] - Third type of user authentication process -
[0149] As described above, the third type is a case where the authentication code verification device (20) is a server, but in a situation where communication is impossible, the role of the authentication code verification device (20) is replaced by an industrial control device.
[0150] Referring to the hybrid type illustrated in FIG. 6, when the authentication code verification device (20) is a server, the authentication code generated in the user terminal (authentication code generation device (10)) is input through an input / output device and transmitted to the industrial control device, and the industrial control device can transmit an authentication code verification request together with the authentication code to the OTAC server (verification module (23)).
[0151] When communication between the server and the industrial control device is possible, the OTAC server (verification module (23)) performs the verification by comparing the secret data included in the authentication code with the previously stored secret data, and when the verification is completed, the user ID can be transmitted to the industrial control device together with the verification result.
[0152] When communication between the server and the industrial control device is not possible, the OTAC verification module (alternative module) performs the verification by comparing the secret data included in the authentication code with the previously stored secret data, and when the verification is completed, the user ID can be transmitted to the industrial control device along with the verification result.
[0153] An industrial control device (specifically, a processor (24)) can perform user authentication and user authority verification using a user ID, and allow or deny access based on the verification result.
[0154] The input / output device can output the verification results.
[0155] The reason why authentication code verification is possible even though the entity performing verification is different for each type is because the secret data is stored identically for each user when registering.
[0156] Hereinafter, with reference to FIGS. 7 and 8, an embodiment including a gateway that must be passed through to access an industrial control device will be described.
[0157] FIG. 7 is a diagram for explaining a user registration process for each type of case including a gateway according to one embodiment of the present disclosure.
[0158] FIG. 8 is a diagram for explaining a user authentication process for each type of case including a gateway according to one embodiment of the present disclosure.
[0159] The gateway (30) is a device connected by wire to an industrial control device. The industrial control device sets or operates terminals other than the terminal to which the gateway (30) is connected as locks so that other devices must access the industrial control device through the gateway (30) in order to control it.
[0160] Although the gateway (30) is described above as being wired to the industrial control device, the gateway (30) is not limited thereto and may be wirelessly connected to the industrial control device, in which case all terminals of the industrial control device may be set to lock or manipulated.
[0161] Below, with reference to Fig. 7, the user registration process for each type of case including a gateway (30) will be described.
[0162] - User registration process for the first type of case with a gateway -
[0163] As described above, the first type is when the authentication code verification device (20) is a server.
[0164] Referring to the server type illustrated in FIG. 7, when the authentication code verification device (20) is a server, the OTAC server (verification module (23)) can generate secret data using the user key and user ID assigned to the user according to the user registration request transmitted through the gateway (30), and encrypt and store the generated secret data.
[0165] At this time, the user key is transmitted to the gateway (30) through the input / output device, and the gateway (30) can transmit a user registration request together with the user key to the central server.
[0166] The OTAC server (verification module (23)) can generate the generated secret data in the form of a QR code and provide it to the user terminal (authentication code generation device (10)). At this time, the QR code can be sent to the user's email or output through the screen of the input / output device.
[0167] The user terminal (authentication code generation device (10)) can recognize the QR code and obtain secret data. The obtained secret data can be re-encrypted and stored in the user terminal (authentication code generation device (10)).
[0168] - Second type of user registration process for cases with gateways -
[0169] As described above, the second type is when the authentication code verification device (20) is an industrial control device.
[0170] Referring to the modular configuration illustrated in FIG. 7, when the authentication code verification device (20) is an industrial control device, the OTAC verification module (verification module (23)) can generate secret data using the user key and user ID assigned to the user according to the user registration request transmitted through the gateway (30), and encrypt and store the generated secret data.
[0171] At this time, the user key is transmitted to the gateway (30) through the input / output device, and the gateway (30) can transmit a user registration request together with the user key to an industrial control device (specifically, a processor (23)).
[0172] An industrial control device (specifically, a processor (23)) transmits the generated secret data to a gateway (30), and the gateway (30) can generate the transmitted secret data in the form of a QR code and provide it to a user terminal (authentication code generation device (10)). At this time, the QR code can be sent to the user's email or output through the screen of an input / output device.
[0173] The user terminal (authentication code generation device (10)) can recognize the QR code and obtain secret data. The obtained secret data can be re-encrypted and stored in the user terminal (authentication code generation device (10)).
[0174] - Third type of user registration process for cases with gateways -
[0175] As described above, the third type is a case where the authentication code verification device (20) is a server, but in a situation where communication is impossible, the role of the authentication code verification device (20) is replaced by an industrial control device.
[0176] Referring to the hybrid type illustrated in FIG. 4, when the authentication code verification device (20) is a server, a user registration request is transmitted to the central server via a gateway (30) and an industrial control device, and the OTAC server (verification module (23)) can generate secret data using the user key and user ID assigned to the user according to the user registration request, and encrypt and store the generated secret data.
[0177] At this time, the user key is transmitted to the gateway (30) through the input / output device, and the gateway (30) can transmit a user registration request together with the user key to the industrial control device and the central server.
[0178] The central server can provide secret data generated by the OTAC server (verification module (23)) to an industrial control device. The provided secret data can be re-encrypted and stored in the industrial control device (specifically, the OTAC verification module (replacement module)).
[0179] The gateway (30) can generate secret data transmitted from an industrial control device in the form of a QR code and provide it to a user terminal (authentication code generation device (10)). At this time, the QR code can be sent to the user's email or output through the screen of an input / output device.
[0180] The user terminal (authentication code generation device (10)) can recognize the QR code and obtain secret data. The obtained secret data can be re-encrypted and stored in the user terminal (authentication code generation device (10)).
[0181] Below, with reference to Fig. 8, the user authentication process for each type of case including a gateway (30) will be described.
[0182] In the user authentication process, the gateway (30) can first determine whether the access to the industrial control device is a login attempt.
[0183] A user may attempt access by entering a fixed password or authentication code into an input / output device. If the gateway (30) determines that the access is a login attempt, it may request authentication code verification from the authentication code verification device (20) and transmit the verification result to the industrial control device.
[0184] According to an embodiment, the gateway (30) requests verification of an authentication code to the verification module (23) of the authentication code verification device (20) only when it is determined that an access attempt through an input / output device is a login attempt based on a fixed password, and when the verification is completed, access to the industrial control device can be permitted through the fixed password.
[0185] Specifically, the gateway (30) can determine that an access attempt from an input / output device is a login attempt through communication packet analysis.
[0186] If the gateway (30) determines that it is a login attempt, it can keep the access attempt in a hold state to prevent it from accessing the industrial control device.
[0187] If the gateway (30) determines that it is a login attempt, it can request the input of an authentication code by executing a web or agent capable of inputting an authentication code into an input / output device.
[0188] When an authentication code is input through an input / output device, the gateway (30) can request verification of the authentication code to the verification module (23) of the authentication code verification device (20).
[0189] When the authentication code verification is completed, the gateway (30) transmits the held access attempt to the industrial control device, allowing the user to access the industrial control device using a fixed password.
[0190] According to an embodiment, the gateway (30) requests verification of the authentication code to the verification module (23) of the authentication code verification device (20) only when it is determined that the value entered upon an access attempt is an authentication code, and when verification is completed, access to the industrial control device can be permitted through a fixed password previously stored in the gateway (30).
[0191] Specifically, when a user attempts to log in to an industrial control device through the manufacturer's software and enters an authentication code generated by an authentication code generation device (10) (user terminal) instead of a fixed password in the password input window, the gateway (30) can determine through communication packet analysis that the entered value includes OTAC or that the access is a login attempt. At this time, the fixed password and the authentication code may be composed of the same number of digits or may be composed of different numbers of digits.
[0192] After extracting an authentication code value from a communication packet, the gateway (30) can request verification of the authentication code by transmitting the authentication code to the verification module (23) of the authentication code verification device (20).
[0193] Once verification is complete, access to the industrial control device can be permitted through a fixed password stored in the gateway (30).
[0194] - First type of user authentication process for cases involving gateways -
[0195] As described above, the first type is when the authentication code verification device (20) is a server.
[0196] Referring to the server type illustrated in FIG. 8, when the authentication code verification device (20) is a server, the OTAC server (verification module (23)) performs verification of the authentication code requested by the gateway (30), and when verification is completed, the user ID assigned to the user can be transmitted to the gateway (30) along with the verification result. The verification method is the same as the authentication code verification method of the first type described above.
[0197] - Second type of user authentication process for cases with gateways -
[0198] As described above, the second type is when the authentication code verification device (20) is an industrial control device.
[0199] Referring to the modular configuration illustrated in FIG. 8, when the authentication code verification device (20) is a server, the OTAC verification module (verification module (23)) performs verification of the authentication code requested by the gateway (30), and when verification is completed, the user ID assigned to the user can be transmitted to the gateway (30) along with the verification result.
[0200] - Third type of user authentication process for cases involving gateways -
[0201] As described above, the third type is a case where the authentication code verification device (20) is a server, but in a situation where communication is impossible, the role of the authentication code verification device (20) is replaced by an industrial control device.
[0202] Referring to the hybrid type illustrated in FIG. 6, when the authentication code verification device (20) is a server, when communication between the server and the industrial control device is possible, the OTAC server (verification module (23)) performs verification of the authentication code requested by the gateway (30), and when verification is completed, the user ID assigned to the user can be transmitted to the gateway (30) along with the verification result through the industrial control device.
[0203] When communication between the server and the industrial control device is impossible, a replacement module (OTAC verification module) included in the industrial control device performs verification of the authentication code requested by the gateway (30), and when verification is completed, the replacement module can transmit the user ID together with the verification result to the gateway.
[0204] In all of the above types, the user ID can be used for user verification at the gateway (30). Specifically, when a user logs in through authentication code verification, the gateway (30) can analyze packets regarding the user's access attempt based on the user ID to perform user management. Based on the user ID, the gateway (30) can recognize and block attempts by the user to gain control beyond their authorized level.
[0205] Meanwhile, the response methods to error situations may also differ depending on Type 1, Type 2, and Type 3.
[0206] In the first type, since the authentication code verification device (20) is a server, in the event of a network disconnection or server failure, an attempt can be made to log in to the industrial control device using a preset emergency password. Accessing the device using this emergency password allows control of the industrial control device with limited authority.
[0207] In the second type, since the authentication code verification device (20) is an industrial control device, if an error occurs in the OTAC verification module included or connected to the industrial control device, an attempt can be made to log in to the industrial control device using a preset emergency password. Accessing the device using the emergency password allows control of the industrial control device with limited authority.
[0208] In the third type, since the authentication code verification device (20) is a server, login is possible through the OTAC verification module included in or connected to the industrial control device when the network connection is disconnected or the server fails. However, if the network connection is disconnected or a server failure occurs, and an error occurs in the OTAC verification module included in or connected to the industrial control device, login to the industrial control device can be attempted using a preset emergency password. Accessing the industrial control device using the emergency password allows control of the industrial control device with limited authority.
[0209] Meanwhile, when the system of the present disclosure is linked with an access control system, user registration management is different from the above-described method.
[0210] When linked to an access control system, access to industrial control devices must first be approved by the access control server.
[0211] The access control server can set a usage period for the user key assigned to the user.
[0212] The access control server can send a user registration request along with a user key, user ID, and usage period to the authentication code verification device (20).
[0213] Additionally, as described above, the authentication code generation device (10) may be a user's mobile terminal, or a smart card for identification or access (entry). The operation method of the authentication code generation device (10) can be divided into cases of using a mobile terminal, using a smart card, and using a mobile terminal and an ID card.
[0214] In the case of mobile terminal use, the authentication code generation device (10) is the user's terminal. A dedicated app can be downloaded and used on the user's terminal. In this case, the app cannot access the OT (Operational Technology) internal network, and both internal and external personnel within the industrial site can use the app.
[0215] In the case of smart card use, the authentication code generation device (10) may be a smart card manufactured exclusively for external users. That is, an external user visiting an industrial site may be given a smart card with an IC chip, allowing access to the industrial site for a limited period of time.
[0216] Additionally, in the case of smart card use, the authentication code generation device (10) may be an ID card (e.g., an employee ID card) containing an IC chip. In this case, internal employees visiting an industrial site may use the ID card to control access and industrial control devices.
[0217] In the case of using a mobile terminal and ID card, the authentication code generation device (10) is the user's terminal. A dedicated app can be downloaded and used on the user's terminal. In this case, internal users can use their own ID card by linking it with the app, while external users can use their own dedicated ID card by linking it with the app. In this case, the app cannot access the OT (Operational Technology) internal network, and both internal and external users of the industrial site can use the app.
[0218] Below, we will specifically explain how the OTAC generation module (authentication code generation device) generates an authentication code.
[0219] The OTAC generation module can generate one or more subcodes. A subcode is a portion of the code that constitutes the authentication code. The authentication code may consist solely of the subcodes, or it may be formed by combining one or more subcodes with a virtual security code generated by the OTP function to form the final authentication code (OTAC).
[0220] The OTAC generation module includes a code generation function that generates an authentication code, and the code generation function includes a detail code generation function that generates one or more detail codes, and a detail code combination function that combines the detail codes to generate a virtual code (i.e., a rule for combining multiple detail codes).
[0221] That is, when the authentication code includes multiple detailed codes, the code generation function generates multiple detailed codes using multiple detailed code generation functions, and generates an authentication code by combining the multiple detailed codes into a preset combination using the detailed code combination function.
[0222] A correlation exists between a plurality of detailed codes, which is used by the OTAC verification module (verification module (23)) to search for a storage location of information that can identify a user or a device. That is, the OTAC verification module has a search algorithm, and the search algorithm extracts a plurality of detailed codes included in the authentication code, and searches for a storage location of identification information of a user or a device (a value assigned to a user (e.g., a user key, a user ID, etc.)) based on the correlation of the plurality of detailed codes. As an embodiment of the correlation of the plurality of detailed codes, the search algorithm can search for the storage location by calculating the correlation between the plurality of detailed codes from a transit point corresponding to one or more of the plurality of detailed codes. At this time, the transit points may be one or more, and there is no limitation on the number and order.
[0223] In addition, as an embodiment of a plurality of detailed codes, the plurality of detailed codes may include a first code and a second code, and the OTAC generation module includes a first function and a second function as detailed code generation functions to generate the first code and the second code. The first code and the second code have a correlation for searching the storage location within the OTAC verification module, but the OTAC generation module may not include data on the correlation between the first code and the second code, but may only include a first function for generating the first code and a second function for generating the second code as detailed code generation functions to enhance security.
[0224] As a specific example of the correlation between the first and second codes, the first and second codes may each perform a role in searching for the storage location. That is, the first code may include information about the transit point, and the second code may include information necessary for an operation to reach the storage location from the transit point.
[0225] Meanwhile, in one embodiment of the present disclosure, the first code may be generated based on the first count, and the second code may be generated based on the second count. In this case, the first count may be the number of unit counts that have elapsed from the initial time point at which the code generation function is executed in the OTAC generation module or the OTAC verification module to the time point at which the authentication code is generated, and the second count may include the number of unit counts that have elapsed from the time point at which the identification information is stored in the OTAC verification module.
[0226] That is, the first function that generates the first code is a function that provides a specific code value corresponding to the first count, and the second function that generates the second code is a function that provides a specific code value corresponding to the second count.
[0227] Below, the method by which the OTAC verification module (verification module (23)) verifies the authentication code will be described in detail.
[0228] In one embodiment of the present disclosure, the OTAC verification module can verify the authentication code by comparing the time data at which the authentication code was received with the time data included in the authentication code.
[0229] Specifically, the OTAC verification module verifies whether the authentication code was normally generated. That is, after receiving the authentication code, the OTAC verification module determines whether the received authentication code is normally generated at the current time based on the information stored in the OTAC verification module (i.e., the code generation function and seed data (secret data)). The OTAC verification module applies the inverse function of the code generation function to the authentication code to find the count corresponding to the time at which the authentication code was generated. Since there is a difference between the time at which the authentication code is generated and the time at which the OTAC verification module receives the authentication code due to the transmission time or delay of the authentication code, the count at which the OTAC verification module receives the authentication code and the count at which the OTP number for authentication is generated may not match. Therefore, the OTAC verification module allows a margin of error from the count at which the authentication code is received.
[0230] Meanwhile, in one embodiment of the present disclosure, the OTAC verification module can search for a storage location of user or device identification information based on the authentication code, extract the identification information, and perform user or device authentication based on the extracted identification information.
[0231] Although FIGS. 3 and 5 describe the steps as being executed sequentially, this is merely an example of the technical idea of the present embodiment, and a person having ordinary skill in the technical field to which the present embodiment pertains can modify and apply various modifications and variations by changing the order described in FIGS. 3 and 5 or executing them in parallel without departing from the essential characteristics of the present embodiment, and therefore FIG. 3 is not limited to a chronological order.
[0232] Meanwhile, in the above description, the steps described in FIGS. 3 and 5 may be further divided into additional steps or combined into fewer steps, depending on the implementation of the present disclosure. Furthermore, some steps may be omitted as needed, and the order of the steps may be changed.
[0233] Meanwhile, the disclosed embodiments may be implemented in the form of a recording medium storing computer-executable instructions. The instructions may be stored in the form of program code, and when executed by a processor, may generate program modules to perform the operations of the disclosed embodiments. The recording medium may be implemented as a computer-readable recording medium.
[0234] Computer-readable storage media include all types of storage media that store instructions that can be deciphered by a computer. Examples include read-only memory (ROM), random access memory (RAM), magnetic tape, magnetic disks, flash memory, and optical data storage devices.
[0235] The disclosed embodiments have been described with reference to the attached drawings as described above. Those skilled in the art will understand that the present disclosure can be implemented in forms other than the disclosed embodiments without altering the technical spirit or essential features of the present disclosure. The disclosed embodiments are illustrative and should not be construed as limiting.
Claims
1. A verification module that performs user registration based on a user key and verifies the authentication code for user authentication generated by the authentication code generation device; and A processor that receives a user registration request from the authentication code generation device and receives a verification request of the authentication code from the authentication code generation device, Verification of the above authentication code is performed to allow or deny access to the industrial control device. Authentication code verification device for user authentication for industrial control devices.
2. In paragraph 1, If the above authentication code verification device is a server, The above verification module creates secret data using the user ID and the user key assigned to the user, The above secret data is re-encrypted and stored in the authentication code generation device through QR code recognition of the authentication code generation device. Authentication code verification device for user authentication for industrial control devices.
3. In paragraph 2, If the above authentication code verification device is a server, The above verification module performs the verification by comparing the secret data included in the authentication code and the previously stored secret data, and when the verification is completed, transmits the user ID together with the verification result to the industrial control device. The above user ID is used for user verification and authorization verification in the industrial control device. Authentication code verification device for user authentication for industrial control devices.
4. In paragraph 1, If the above authentication code verification device is the above industrial control device, The above verification module generates secret data using the user ID and the user key assigned to the user, The above secret data is re-encrypted and stored in the authentication code generation device through QR code recognition of the authentication code generation device. Authentication code verification device for user authentication for industrial control devices.
5. In paragraph 4, If the above authentication code verification device is the above industrial control device, The above verification module performs the verification by comparing the secret data included in the authentication code and the previously stored secret data, and when the verification is completed, transmits the user ID together with the verification result to the processor. The above user ID is used for user verification and authorization verification in the processor. Authentication code verification device for user authentication for industrial control devices.
6. In paragraph 1, If the above authentication code verification device is a server, The above verification module generates secret data using the user ID and the user key assigned to the user, The above secret data is re-encrypted and stored in the industrial control device, and is re-encrypted and stored in the authentication code generation device through QR code recognition of the authentication code generation device. Authentication code verification device for user authentication for industrial control devices.
7. In paragraph 6, If the above authentication code verification device is a server, When communication between the server and the industrial control device is possible, the verification module performs the verification by comparing the secret data included in the authentication code and the previously stored secret data, and when the verification is completed, the user ID is transmitted to the industrial control device along with the verification result. When communication between the server and the industrial control device is impossible, a substitute module included in the industrial control device performs the verification, and when the verification is completed, the user ID is transmitted together with the verification result to the processor included in the industrial control device. The above user ID is used for user verification and authorization verification in the industrial control device. Authentication code verification device for user authentication for industrial control devices.
8. In paragraph 1, When an attempt to access the industrial control device occurs from an input / output device through user input, verification of the authentication code is performed at the request of a gateway connected to the industrial control device. Authentication code verification device for user authentication for industrial control devices.
9. In paragraph 8, Only when the access attempt is determined by the gateway to be a fixed password-based login attempt, verification of the authentication code is requested by the verification module, and when the verification is completed, access to the industrial control device is permitted through the fixed password. Authentication code verification device for user authentication for industrial control devices.
10. In paragraph 8, Only when the value entered at the time of the access attempt is determined to be the authentication code by the gateway, verification of the authentication code is requested by the verification module, and when the verification is completed, access to the industrial control device is permitted through the fixed password previously stored in the gateway. Authentication code verification device for user authentication for industrial control devices.
11. In paragraph 8, If the above authentication code verification device is a server, The above verification module performs verification of the authentication code requested by the gateway, and when the verification is completed, transmits the user ID assigned to the user along with the verification result to the gateway. The above user ID is used for user verification at the gateway. Authentication code verification device for user authentication for industrial control devices.
12. In paragraph 8, If the above authentication code verification device is the above industrial control device, The above verification module performs verification of the authentication code requested by the gateway, and when the verification is completed, transmits the user ID assigned to the user along with the verification result to the gateway. The above user ID is used for user verification at the gateway. Authentication code verification device for user authentication for industrial control devices.
13. In paragraph 8, If the above authentication code verification device is a server, When communication between the server and the industrial control device is possible, the verification module performs verification of the authentication code requested by the gateway, and when the verification is completed, transmits the user ID assigned to the user along with the verification result to the gateway through the industrial control device. When communication between the server and the industrial control device is impossible, a substitute module included in the industrial control device performs verification of the authentication code requested by the gateway, and when the verification is completed, the substitute module transmits the user ID together with the verification result to the gateway. The above user ID is used for user verification at the gateway. Authentication code verification device for user authentication for industrial control devices.
Citation Information
Patent Citations
System and method for security of information
KR1020060118247A
System and method for public terminal security
KR1020140127987A
Vehicle access control system and method through code display
KR1020180125729A
Method for manufacturing heat-resistant pottery pot with ceramic coating layer
KR1020230017379A
KR20210027072A