Service device, control method of service device, and system including service device

The service device system addresses security vulnerabilities by classifying accounts and managing passwords to prevent unauthorized access and malicious use, enhancing security through method and subject-based access control.

WO2026071554A1PCT designated stage Publication Date: 2026-04-02LS ELECTRIC CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

The security of service devices is compromised due to diverse access methods, leading to potential leaks of confidential information and malicious use, especially through hacking and stolen mobile terminals.

Method used

A service device and system that restricts access based on input method and subject, classifying accounts into levels and managing passwords collectively, using a control unit to determine allowable access levels and provide services accordingly.

Benefits of technology

Prevents malicious use and enhances security by restricting services and changing passwords, ensuring only authorized access levels are granted based on input method and subject.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025013787_02042026_PF_FP_ABST
    Figure KR2025013787_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a service device that provides different services according to accounts. The service device comprises: a server; a communication unit including a wired communication module and a wireless communication module; an input unit including a user input means; a driving unit including a component for executing a function of the service device; a memory storing pieces of account information classified for each account level corresponding to different services, and passwords respectively matching the pieces of account information; and a control unit that determines an input method by which access information is input, determines, according to a result of the determination, an accessible account level range including an account level allowing access, allows access according to whether the account information included in the access information is an account level included in the accessible account level range, and provides, in response to the input of the access information, a service corresponding to the account level included in the access information.
Need to check novelty before this filing date? Find Prior Art

Description

A service device, a method for controlling the service device, and a system including the service device

[0001] The present invention relates to a service device that provides different services depending on the account, and a system including the service device.

[0002] Nowadays, due to advancements in communication technology, there is a trend toward allowing access to service devices in various ways. For example, current service devices may allow access to various mobile terminals that connect to the server via wireless communication through a server, or they may allow access by connecting directly to the mobile terminal via wireless communication. By allowing such diverse accessibility, users of the service device can more easily access the device and receive services.

[0003] However, allowing access from various devices using diverse methods, such as remote access, presents a problem in that the security of the aforementioned service device is weakened. In particular, in the case of remote access using the aforementioned communication connection, connection information such as passwords entered by the operator may be leaked through hacking attacks such as sniffing or spoofing, thereby compromising the operator's confidential information, such as IDs or passwords. Furthermore, if the mobile terminal used by the operator to access the service device is stolen, there is a problem that connection information to the service device via the mobile terminal, including the aforementioned confidential information, may be leaked. Moreover, if such confidential and connection information is leaked, there is a problem that the leaked information could be used for malicious purposes, such as a third party impersonating the operator to control the service of the aforementioned service device.

[0004] Accordingly, various measures are being actively researched to enhance the security of the service device while allowing various methods of access to the service device. Furthermore, measures are being actively researched to prevent the malicious use of the service device even if the worker's mobile terminal or server is hijacked.

[0005] The present invention aims to solve the aforementioned problems and other problems, and aims to provide a service device that allows various methods of access to the service device while preventing malicious use of the service device due to the leakage of confidential information and access information, a method for controlling the service device, and a system including the service device.

[0006] Furthermore, the present invention aims to provide a service device capable of restricting services that can be provided by the service device according to a connection information method in which a connection request to the service device is made or a path in which connection information is input, a control method for the service device, and a system including the service device.

[0007] Furthermore, the present invention aims to provide a service device, a method for controlling a service device, and a system including the service device, which can collectively manage passwords that allow access to a plurality of service devices and maintain high security for passwords set on each service device.

[0008] According to one aspect of the present invention for achieving the above or other purposes, a service device that provides the result of execution of at least one function that is executable or is being executed as a service corresponding to the input of connection information including account information and a password according to an embodiment of the present invention comprises: a communication unit including a wired communication module and a wireless communication module for performing communication connections with a pre-configured server and a worker terminal; an input unit including an input means for receiving user input; a driving unit including a component for executing at least one function of the service device; a memory storing a plurality of account information classified by different account levels corresponding to different services and a password matching each of the plurality of account information; and a control unit that determines an input method in which the connection information is input, determines a range of connectable account levels including at least one account level for which connection is allowed with the input connection information according to the determination result, allows connection based on whether the account information included in the input connection information is an account of an account level included within the range of connectable account levels, and provides a service corresponding to the account level included in the input connection information as a response to the input of the connection information.

[0009] In one embodiment, the control unit determines the input method as either input via a communication connection or direct input depending on whether the connection information is input via a communication connection or input via an input unit, and determines the range of connectable account levels differently according to the determined input method, wherein the range of connectable account levels determined when the input method is direct input includes more account levels than the account levels included in the range of connectable account levels determined when the input method is a communication connection.

[0010] In one embodiment, the control unit further determines whether the input method is a wireless communication connection using the wireless communication module or a wired communication connection using the wired communication module when the input method is a communication connection, and if the communication connection is a wired communication connection, considers the input method of the connection information as the direct input.

[0011] In one embodiment, the account level includes a low level capable of providing a service that can only verify stored data according to the operation of the service device, a middle level capable of providing a service that can not only verify stored data according to the operation of the service device but also set a setting value for a conditional function that allows the service device to execute a specific function, and a high level capable of providing a service that can directly control whether the specific function is executed and the state of execution beyond the execution conditions in which the specific function that the service device can perform is executed, and is characterized in that when the input method is a communication connection, at least one of the account levels is excluded from the range of connectable account levels.

[0012] In one embodiment, the control unit further determines an input subject who inputs the connection information, and limits the range of connectable account levels that can access the service device through the connection information according to the input method of the determined connection information and the input subject of the determined connection information.

[0013] In one embodiment, the input subject of the connection information is any one of the pre-configured server, the worker terminal, and the worker, and the control unit limits the range of connectable account levels to the middle level and the low level when the input method of the connection information is a wireless communication connection, and further limits the range of connectable account levels to the low level when the input method of the connection information is a wireless communication connection and the input subject of the connection information is the worker terminal.

[0014] In one embodiment, the service device is a device capable of providing communication services and is characterized by including a monitoring device capable of viewing recorded or captured images only by authorized operators, a protection relay that performs monitoring, measurement, and protection functions for power equipment, and an intelligent electric device (IED) capable of controlling at least one function of power equipment as well as monitoring, measurement, and protection functions for at least one power equipment.

[0015] In one embodiment, the pre-configured server provides temporary access information including a temporary account and a temporary password that can access the service device at the low level upon a request from an authenticated worker, transmits the temporary access information to at least one service device where the work of the authenticated worker is allowed, grants the low-level account to the worker terminal of the authenticated worker, and is characterized in that the temporary account and the temporary password are an account and password with a limited usage period.

[0016] In addition, the control method of the service device comprises: a step of determining an input method in which the connection information is input; a step of determining a range of connectable account levels including at least one account level that is allowed to be accessed with the input connection information according to the determined input method of the connection information; a step of detecting an account level corresponding to the account information included in the input connection information from a plurality of account information classified by different account levels corresponding to different services stored previously; a step of checking whether the detected account level is included within the determined range of connectable account levels; and a step of checking whether the password included in the input connection information matches a previously stored password according to the check result, and providing a service corresponding to the detected account level as an input of the connection information according to whether the password matches.

[0017] In one embodiment, the step of determining the input method in which the connection information is input is characterized by determining the input method as either input via a communication connection or direct input depending on whether the connection information is input via a communication connection or input via an input unit provided in the service device.

[0018] In one embodiment, the step of determining the input method in which the connection information is input further comprises: a step of determining whether, when the input method is a communication connection, it is a wireless communication connection using a wireless communication module or a wired communication connection using a wired communication module; and a step of considering the input method of the connection information as the direct input when the communication connection is a wired communication connection.

[0019] In one embodiment, the step of determining the input method in which the connection information is input further includes the step of determining the input subject inputting the connection information, and the step of determining the range of accessible account levels further includes the step of further restricting the range of account levels to which access is allowed with the input connection information according to the determined input subject of the connection information within the range of accessible account levels determined according to the determined input method of the connection information.

[0020] In addition, according to one aspect of the present invention, a system according to an embodiment of the present invention comprises: a plurality of service devices that provide the result of execution of at least one function that is executable or is being executed as a service corresponding to the input of connection information including account information and a password, and a plurality of account information classified by different account levels corresponding to each different service, and a server formed to provide a password matching each of the plurality of account information to the plurality of service devices and to transmit connection information input through a user input unit to the service devices in a pre-configured communication connection method. The service device determines the input method in which the connection information is input, determines a range of accessible account levels including at least one account level for which access is allowed with the input connection information according to the determination result, allows access based on whether the account information included in the input connection information is an account of an account level included within the range of accessible account levels, and provides a service corresponding to the account level included in the input connection information as a response to the input of the connection information.

[0021] In one embodiment, the account level is characterized by including a low level that can provide a service capable of only verifying stored data according to the operation of the service device, a middle level that can provide a service capable of not only verifying stored data according to the operation of the service device but also setting a value for a conditional function that allows the service device to execute a specific function, and a high level that can provide a service capable of directly controlling whether the specific function is executed and the state of execution beyond the execution conditions in which the specific function that the service device can perform is executed.

[0022] In one embodiment, the service device determines the range of accessible account levels differently depending on the input subject inputting the access information when the access information is input via the pre-configured communication connection method, wherein if the input subject is the server, the range of accessible account levels includes the middle-level accounts and the low-level accounts, and if the input subject is the terminal of a worker, the range of accessible account levels includes the low-level accounts.

[0023] In one embodiment, the server transmits a password mapping table configured such that a plurality of different passwords are each matched to a different mapping number to the plurality of service devices, provides a specific mapping number corresponding to any one password included in the password mapping table to the plurality of service devices to determine a password matched to a specific account level, and provides a mapping number matching any other password to the plurality of service devices according to a pre-configured password change condition for the specific account level to collectively change the passwords matched to the specific account level.

[0024] In one embodiment, the server transmits to the plurality of service devices a password generation algorithm that defines rules for generating passwords based on at least one password generation key, provides the at least one password generation key to the plurality of service devices so that the plurality of service devices generate the same password that matches a specific account level, changes the at least one password generation key according to a pre-set password change condition for the specific account level, and provides the changed at least one password generation key to the plurality of service devices to collectively change the password that matches the specific account level.

[0025] According to at least one embodiment of the present invention, the present invention has the effect of preventing malicious use of the service device by access information leaked through theft or security vulnerabilities by a server or a worker's terminal (hereinafter referred to as the worker terminal) by restricting the services that can be provided by the service device according to an input method for inputting account information and a password into the service device or by a subject inputting said account information and password.

[0026] In addition, the present invention has the effect of enhancing the security of said passwords by enabling collective changes to passwords that allow access to a specific account level for each service device, and by ensuring that the changed password is not transmitted when the password is changed.

[0027] FIG. 1 is a block diagram illustrating the configuration of a system including a plurality of service devices, a server, and a worker terminal according to an embodiment of the present invention.

[0028] FIG. 2 is a block diagram illustrating the configuration of a service device according to an embodiment of the present invention.

[0029] FIG. 3 is a flowchart illustrating the operation process of a service device limiting the range of accounts allowed to be accessed based on the method of inputting account information and the subject of inputting account information, according to an embodiment of the present invention.

[0030] FIG. 4 is a flowchart illustrating in more detail the operation process of a service device according to an embodiment of the present invention determining an account level that is allowed to connect according to the connection method of a connection request device.

[0031] FIG. 5 is a flowchart illustrating the operation process in which a server of a system according to an embodiment of the present invention grants a low-level account to a worker terminal in response to a request from a worker terminal.

[0032] FIG. 6 is a flowchart illustrating the operation process in which a server of a system according to an embodiment of the present invention collectively changes a specific account level password assigned to a worker terminal using a password mapping table shared among service devices.

[0033] FIG. 7 is a flowchart illustrating the connection process in which a worker terminal of the system illustrated in FIG. 6 connects to a service device.

[0034] FIG. 8 is a flowchart illustrating the operation process in which a server of a system according to an embodiment of the present invention collectively changes a specific account level password assigned to a worker terminal using a password generation algorithm shared among service devices.

[0035] It should be noted that technical terms used in this specification are used merely to describe specific embodiments and are not intended to limit the invention. Additionally, singular expressions used in this specification include plural expressions unless the context clearly indicates otherwise. The suffixes "module" and "part" for components used in the following description are assigned or used interchangeably solely for the ease of drafting the specification and do not inherently possess distinct meanings or roles.

[0036] In this specification, terms such as "composed of" or "comprising" should not be interpreted as necessarily including all of the various components or steps described in the specification, and should be interpreted as potentially excluding some of the components or steps, or including additional components or steps.

[0037] In addition, when describing the technology disclosed in this specification, if it is determined that a detailed description of related prior art could obscure the essence of the technology disclosed in this specification, such detailed description is omitted.

[0038] In addition, the attached drawings are intended only to facilitate understanding of the embodiments disclosed in this specification, and the technical concept disclosed in this specification is not limited by the attached drawings; it should be understood that they include all modifications, equivalents, and substitutions that fall within the concept and technical scope of the present invention. Furthermore, not only each of the embodiments described below, but also combinations of embodiments may fall within the concept and technical scope of the present invention as modifications, equivalents, and substitutions that fall within the concept and technical scope of the present invention.

[0039] Hereinafter, embodiments disclosed in this specification will be described in detail with reference to the attached drawings.

[0040] FIG. 1 is a block diagram illustrating the configuration of a system (1) including a plurality of service devices (10-1, 10-2, ... 10-n), a server (20), and a worker terminal (30) according to an embodiment of the present invention.

[0041] Referring to FIG. 1, a system (1) according to an embodiment of the present invention may be configured to include a plurality of service devices (10-1, 10-2, ... 10-n), a server (20) that communicates with the plurality of service devices, and a worker terminal (30) that can communicate with the plurality of service devices and the server.

[0042] Here, the service device (10) may be a device that provides the result of execution of at least one function that is executable or is being executed as a service according to the input of the connection information, corresponding to the input of connection information including pre-set account information and password.

[0043] The above service device (10) is a device capable of providing communication services and may include a monitoring device, such as a CCTV, which allows only authorized workers to view recorded or captured images, or a protection device, such as a protection relay, which performs monitoring, measurement, and protection functions for power facilities. In addition, the above service device (10) may include an Intelligent Electric Device (IED) capable of controlling at least one function of power facilities as well as monitoring, measurement, and protection functions for at least one power facility.

[0044] Such a service device (10) may be equipped with at least one of a display unit, such as a display capable of outputting visual information capable of displaying information, or an audio output unit capable of outputting audio information. It may also be equipped with a light sensor capable of acquiring visual information, such as a camera. In this case, the service device (10) may be equipped with a function capable of scanning and recognizing visual information, i.e., an image, acquired through the light sensor.

[0045] In addition, the service device (10) may be configured to have a plurality of accounts that can be accessed and a password corresponding to each account pre-assigned, and may be configured to allow access only when a password matching the pre-assigned password is entered for each account.

[0046] The above service device (10) may be connected via wired or wireless communication to a device that wishes to connect to the service device (10), such as a worker terminal (30) or a server (20). When a communication connection is established, the service device (10) may receive account information and a password input through the connected device. Alternatively, the service device (10) may receive account information and a password through an input unit capable of receiving direct user input. In this case, the service device (10) may determine the method by which the account information and password are entered, such as whether the account information and password are entered via wireless communication or wired communication, and whether they are entered via an input unit provided in the service device (10). Additionally, the service device (10) may determine whether the connection request device, which is the input subject that enters the account information and password into the service device (10), is a worker terminal (30) or a server (20).

[0047] And the service device (10) can restrict the accounts allowed to access based on the input method in which the account information and password are entered and the result of determining the input subject. For example, if the input of the account information and password is made via a wireless communication method from the worker terminal (30), the service device (10) can restrict access to accounts corresponding to the first level.

[0048] On the other hand, if the input of the above account information and password is made via a wireless communication method from the server (20), the service device (10) may restrict access to accounts corresponding to the first level and the second level.

[0049] In addition, if the input of the above account information and password is performed through a direct input method via the input section of the service device (10), the service device (10) may restrict access to accounts corresponding to the first level, the second level, and the third level. In this case, the services that the service device (10) can provide may differ depending on the level of each account.

[0050] For example, the above-mentioned first-level account may be an account that can receive a service that allows only verification of stored data according to the operation of the service device (10).

[0051] For example, if the service device (10) is an IED or a protection device, the account of the first level above may be an account capable of receiving a service that allows only verification of measurement values ​​or monitoring values ​​related to the power equipment protected by the service device (10). Additionally, if the service device (10) is a CCTV or a surveillance camera, the account may be an account capable of receiving a service that allows only verification of the current surveillance video or surveillance status of the service device (10), that is, the video currently being recorded.

[0052] On the other hand, the second level account may be an account that can receive a service that can not only verify data stored according to the operation of the service device (10), but also set a setting value for a conditional function that allows the service device (10) to execute a specific function.

[0053] For example, the second level account may be an account capable of receiving a service that allows setting execution conditions for specific functions to be performed on power facilities protected by the service device (10), such as a measurement value at which a cutoff function is activated, when the service device (10) is an IED or a protection device. Additionally, when the service device (10) is a CCTV or a surveillance camera, it may be an account capable of receiving a service that allows checking the surveillance history of the service device (10) or previously recorded surveillance footage (e.g., setting a specific point in time as a condition).

[0054] Meanwhile, the above-mentioned third-level account may be an account capable of receiving a service that can directly control whether a specific function is executed and the state of execution of the specific function, beyond the execution conditions in which a specific function that the service device (10) can perform is executed.

[0055] For example, if the service device (10) is an IED or a protection device, the account of the third level above may be an account that can receive a service to turn the blocking function itself on or off, or to turn on or off the output of a blocking control signal for controlling the blocking device, whereas the account of the second level above is limited to setting the measurement value at which the blocking function of the service device (10) is operated. Additionally, if the service device (10) is a CCTV or a surveillance camera, the account may be an account that can receive a service to turn the service device (10) on or off, or an editing function of the surveillance video recorded on the service device (10), that is, to copy or delete a part of the recorded surveillance video.

[0056] In this case, the services provided at the higher level account may include services that can be provided at the lower level. That is, the services that the service device (10) can provide at the third level (High Lv) account may include the services that can be provided at the second level (Middle Lv) account and the services that can be provided at the first level (Low Lv) account. And the services that the service device (10) can provide at the second level (Middle Lv) account may include the services that can be provided at the first level (Low Lv) account.

[0057] Here, the service device (10) can determine the range of accounts that are allowed to connect based on the determination result of the input method and the input subject in which the account information and password are entered. Then, based on the determination result, it checks whether the entered account information is included among the accounts within the range that are allowed to connect, and if the entered account information is included among the accounts within the range that are allowed to connect, it can allow the connection. And it can provide a service according to the account level of the connected account.

[0058] For example, the service device (10) can determine that access to accounts up to the third level is permitted when account information and passwords are entered via a direct input method through its input unit as described above. Accordingly, among the first level accounts, second level accounts, and third level accounts, it can detect the account and password corresponding to the account information entered via the direct input method. And if the password entered via the direct input method matches the detected password, it can provide an account level service according to the entered account information.

[0059] For example, if the account information and password entered via the above direct input method match any one of the second-level accounts stored in the service device (10), the service device (10) may allow access according to the second-level account. And it may provide a service according to the second-level account.

[0060] That is, even if account information is entered using an input method that enables a third level of service, if the entered account information and password match a lower level account, the control unit (100) can provide a service according to the level of the account that matches the account information and password.

[0061] Therefore, as described above, if account information and password are entered via a direct input method through the input section of the service device (10), it may be possible to access the service device (10) with any one of the accounts of the second level and the first level, as well as the accounts of the third level.

[0062] On the other hand, the service device (10) may not allow access even if the account information and password match a specific level of account that has been stored, if the account information and password fall outside the range of the account based on the input method and the determination result of the input subject.

[0063] For example, when the account information and password are entered into the service device (10) via wireless communication through a worker terminal (30), the service device (10) can determine that only first-level accounts are allowed to access based on the method (wireless communication) and the input subject (worker terminal (30)) in which the account information and password were entered. That is, the range of allowable accounts can be limited to first-level accounts.

[0064] In this case, if the account information and password input from the worker terminal (30) via the wireless communication match any of the second-level accounts stored in the service device (10), the service device (10) can determine that the account information input from the worker terminal (30) is outside the acceptable account range. Then, the service device (10) may not allow the connection request from the worker terminal (30), that is, the connection based on the input of the account information and password.

[0065] To this end, each service device (10) according to an embodiment of the present invention can store account information for accounts of different levels and password information corresponding to each account, and can store information on different service levels that can be provided for each account level.

[0066] With reference to FIG. 2 of the present invention, we will examine the configuration of the service device (10) in more detail below.

[0067] And the system (1) according to an embodiment of the present invention may have a server (20) that can be wirelessly or wiredly connected to the plurality of service devices.

[0068] The above server (20) can create accounts for multiple different account levels and generate password information corresponding to the created accounts. It can then transmit the generated account information and password information for each different account level to multiple service devices (10-1, 10-2, ... 10-n). For example, the server (20) can receive account information to be used according to each level from the user of each worker terminal, i.e., the worker, and store it. It can then transmit the account information for each level to each of the multiple service devices as the account information of the worker corresponding to each account level. Accordingly, multiple account information for each different account level for each worker can be stored in each service device.

[0069] In this case, at least one account-level password transmitted to the plurality of service devices may be the same for each account level. That is, the passwords corresponding to the third level transmitted to the plurality of service devices may all be the same, and the passwords corresponding to the second level may all be the same. In this case, the account information may differ for each worker terminal, but the passwords may all be the same.

[0070] Therefore, although the account information of each worker differs by account level, the passwords for each level may be the same for each level. For example, a pre-set first password may be used as the password for multiple accounts that allow access to multiple service devices at the second account level. Additionally, a pre-set second password may be used as the password for multiple accounts that allow access to multiple service devices at the third account level. Furthermore, the password for accessing the second account level (first password) and the password for accessing the third account level (second password) may be managed by the server (20).

[0071] And at least one of the first password and the second password may be changed collectively by the server (20) depending on whether the pre-set password change condition is satisfied.

[0072] For example, the server (20) can send a password mapping table configured such that multiple different passwords are each matched to different mapping numbers to the multiple service devices, and send a specific mapping number matching a specific password to each of the multiple service devices depending on whether the password change condition is satisfied. Accordingly, a specific password corresponding to the specific mapping number can be set as a password corresponding to the specific account level in the multiple service devices. That is, by transmitting a specific mapping number depending on whether the password change condition is satisfied, the server (20) can collectively change the passwords that allow access to the specific account level in each of the multiple service devices.

[0073] Alternatively, the server (20) may send the same password generation algorithm capable of generating a password to the plurality of service devices and send at least one key capable of generating a password through the password generation algorithm to each of the plurality of service devices. Accordingly, the password generated according to the transmitted key may be set to the plurality of service devices as a password corresponding to the specific account level. Therefore, by transmitting the at least one key depending on whether the password change condition is satisfied, the server (20) can collectively change the passwords that allow access to the specific account level for each of the plurality of service devices.

[0074] Meanwhile, the server (20) can generate a password for each account that can access a specific account level, and transmit the generated password to each of the multiple service devices.

[0075] The above server (20) may have a different password setting method for each account level. For example, in the case of a password corresponding to account information at the first account level, the above server (20) may temporarily generate a password upon the request of the worker terminal (30) and distribute the generated password to each service device. To do this, the worker terminal (30) may transmit a connection request and authentication information for worker authentication to the server (20), and the server (20) may transmit the password (low-level password (Password, PW)) of the first account level in response. Then, the worker terminal (30) can input the low-level password into the service device and connect to each service device at the first account level (low level) and receive services according to the first account level (low level).

[0076] On the other hand, the server (20) may determine the password according to the password mapping table or the password generation algorithm sharing method for the second account level and the third account level.

[0077] For example, the server (20) may determine a password that allows access to each service device at the second account level by sharing the password mapping table. In this case, a user who wishes to access each service device through the user input unit (21) provided in the server (20) must enter a password corresponding to the password mapping number currently used in each service device so that they can access any one of the plurality of service devices at the second account level and receive services corresponding to the second account level. In this case, information regarding the password mapping number currently used in each service device may be provided (e.g., provided via the mobile terminal of the authenticated user) only when the user using the user input unit (21) is authenticated. In this case, the password mapping table stored in the server (20) may be used to detect a password that matches the provided password mapping table.

[0078] Additionally, for example, the server (20) may determine a password that allows access to each service device at the third account level by sharing the password generation algorithm. In this case, access to any one of the multiple service devices at the third account level and the service according to the third account level can be provided by directly inputting the password generated according to at least one key provided by the server (20) through the input unit of the service device. In this case, the server (20) may share the password generation algorithm with the worker terminal (30) of a pre-registered worker, and only when the worker is authenticated, at least one password generation key currently provided to each service device may be provided to the authenticated worker terminal (30). Then, the worker terminal (30) can generate and display a password based on the password generation key provided by the server (20), and access to the third account level can be achieved by the worker verifying the generated password and directly inputting it through the input unit of the service device.

[0079] Meanwhile, in the above description, for the convenience of explanation, an example was described in which a password for accessing the first account level is provided in the form of a temporary password distributed to each of the multiple service devices, the second account level is provided in the form of a password matching one of the password mapping tables, and the third account level is provided in the form of a password generated according to at least one key and a password generation algorithm provided by the server (20); however, it is obvious that the present invention is not limited thereto.

[0080] Furthermore, although the above description provides examples of first, second, and third account levels, this is merely an example to facilitate the explanation of the present invention, and it goes without saying that the present invention is not limited thereto. That is, there may be as many or as few account levels, and different services may be provided for each account level. However, for the sake of convenience of explanation, the following description will assume a case where account levels are classified into a first account level (low level), a second account level (middle level), and a third account level (high level).

[0081] Meanwhile, the worker terminal (30) can receive various information from the server (20) for performing access to a service device according to a specific account level. For example, the worker terminal (30) may directly receive a password that allows access to a service device at a specific account level from the server (20), or receive a password mapping table configured such that multiple different passwords are each matched to different mapping numbers and a mapping number that matches a specific password, and detect a password that matches the received mapping number. Alternatively, it may generate a password for accessing a service device at a specific account level based on a password generation algorithm provided by the server (20) and at least one password generation key provided by the server (20).

[0082] Here, various devices may be used as the worker terminal (30). For example, the worker terminal (30) may include a smartphone, a laptop computer, a PDA (personal digital assistant), a slate PC, a tablet PC, an ultrabook, or a wearable device, such as a smartwatch, equipped with at least one display such as a display.

[0083] FIG. 2 is a block diagram illustrating the configuration of a service device (10) according to an embodiment of the present invention.

[0084] Referring to FIG. 2, the service device (10) may be configured to include a communication unit (110), an input unit (120), a driving unit (130), a memory (150), a control unit (100), and a light sensor (140). Since the components shown in FIG. 2 are not essential for implementing the service device (10), the service device (10) described herein may have more or fewer components than those listed above.

[0085] More specifically, the communication unit (110) among the above components may include one or more modules that enable wireless or wired communication connections between the service device (10) and the server (20), and between the service device (10) and at least one worker terminal (30).

[0086] And the input unit (120) may include at least one input means for receiving user input. The input means may include mechanical input means (or mechanical keys, e.g., buttons, dome switches, jog wheels, jog switches, etc.) and touch input means. As an example, the touch input means may consist of a virtual key, soft key, or visual key displayed on a touch screen (not shown) of a service device (10) through software processing, or a touch key placed on a part other than the touch screen. The input unit (120) may be embedded in the service device (10) and may be opened or activated to enable user input using the input means when there is a request such as a communication connection of a worker terminal (30), and may be displayed on the touch screen.

[0087] Additionally, the driving unit (130) may include a component for performing at least one function to perform a service that the service device (10) can provide. For example, if the service device (10) is a surveillance device such as a CCTV, a camera or the like may be further included as the driving unit (130) to perform the surveillance function. Also, if the service device (10) is a protection relay, components such as a current sensor or a voltage sensor may be included as the driving unit (130) to perform monitoring, measurement, and protection functions for power equipment. Additionally, if the service device is an intelligent electronic device (IED), a component capable of controlling at least one function of the power equipment according to the measurement results of the power equipment may be included as the driving unit (130).

[0088] Meanwhile, the memory (150) can store data that supports functions that the service device (10) can perform. The memory (150) can store instructions or data for the execution of a program or application that can execute functions provided by the service device (10). It can also temporarily store data that is input / output for the execution of a program or application.

[0089] As data supporting functions that the service device (10) can perform, the memory (130) can store information about accounts of different account levels. For example, each worker may have accounts corresponding to each of different account levels. That is, the memory (150) may be equipped with an account information storage unit (160) that stores information about accounts corresponding to different account levels for the worker 'Hong Gil-dong'. In addition, information about passwords corresponding to each account may be stored in the account information storage unit (160). In this case, the passwords corresponding to each account may be different for each account level.

[0090] For example, account information for a low-level account, 'Hong Gil-dong LV1', for the worker 'Hong Gil-dong' may be stored in memory (150). Additionally, account information for a middle-level account, 'Hong Gil-dong LV2', for the worker 'Hong Gil-dong' may be stored in memory (150). Furthermore, account information for a high-level account, 'Hong Gil-dong LV3', for the worker 'Hong Gil-dong' may be stored in memory (150). In this case, the passwords corresponding to each of the 'Hong Gil-dong LV1', 'Hong Gil-dong LV2', and 'Hong Gil-dong LV3' accounts may be different from each other. Also, 'Hong Gil-dong LV1', 'Hong Gil-dong LV2', and 'Hong Gil-dong LV3' are account information having different account levels, and different services may be provided depending on the account information being accessed. That is, even if the worker is the same ('Hong Gil-dong'), the service provided may differ depending on which account information is used to access the service device (10).

[0091] To this end, the account information storage unit (160) can manage the account information of low-level accounts, the account information of middle-level accounts, and the account information of high-level accounts separately. Accordingly, as shown in FIG. 2, the account information storage unit (160) may each be equipped with a low-level account information storage unit (161) in which the account information of low-level accounts is stored, a middle-level account information storage unit (162) in which the account information of middle-level accounts is stored, and a high-level account information storage unit (163) in which the account information of high-level accounts is stored, and each account information may be stored in a storage unit of a different memory (150) according to the account level of the account information.

[0092] Meanwhile, as described above, the service device (10) according to an embodiment of the present invention can provide different services depending on the account level of the account information input for connection. To this end, the memory (150) can store information defining the services that can be provided according to each account level among the functions that the service device (10) can provide. Hereinafter, a portion of the memory (150) where information on the services that can be provided according to each account level is stored will be referred to as the account level information storage portion (170).

[0093] Additionally, the memory (150) may store data that can change a password according to a request from the server (20). For example, the data for changing the password may include a password mapping table configured such that a plurality of different passwords are matched to different mapping numbers. Additionally, the data for changing the password may include data for a password generation algorithm capable of generating a password with at least one given key, and data for at least one key capable of generating a password by inputting it into the password generation algorithm.

[0094] Meanwhile, according to the above description, the service device (10) according to an embodiment of the present invention can determine the range of accounts that may be allowed to access the service device (10) depending on the method of inputting account information and the subject inputting said account information. To this end, the account information storage unit (160) may include information defining the account level that is allowed to access depending on the method of inputting account information and the subject inputting said account information, and the control unit (100) can determine the range of accounts that are allowed to access depending on the method of inputting said account information and the subject inputting said account information, depending on the information of the method of inputting said account information and the subject inputting said account information that is allowed to access said account level, according to the information of the method of inputting said account information and the subject inputting said account information that is allowed to access said account level, which is stored in the account level information storage unit (170).

[0095] And the control unit (100) typically controls the overall operation of the service device (10). The control unit (100) can perform functions that the service device (10) can provide, such as monitoring functions or measurement functions, by processing signals, data, and information that are input or output through the components described above, or by running an application program stored in the memory (150), and can provide the results of the performance of said functions to the worker terminal (30) as a service provided according to the worker's request.

[0096] Meanwhile, as described above, the service device (10) according to the embodiment of the present invention may provide different services depending on the account level of the account information input for connection. To this end, the control unit (100) determines the method of inputting account information into the service device (10) and the subject inputting said account information, and based on the information of the account information input method and the subject inputting each account level defined in the account level information storage unit (170), it may determine the account range in which connection to the service device (10) may be allowed according to the currently input account information. And within the determined account range, connection to the service device (10) according to the account level of the input account information may be allowed only when the input account information and a password matching said account information are input.

[0097] For example, when current account information is input from a worker terminal (30) (the entity inputting account information) via wireless communication (account information input method), the control unit (100) may limit the range of accounts that are allowed to be accessed according to the account information to a first account level, depending on the account information input method and the entity inputting the account information. Accordingly, if the worker 'Hong Gil-dong' inputs 'Hong Gil-dong LV2' corresponding to account level 2 or 'Hong Gil-dong LV3' corresponding to account level 3, the connection request of the worker terminal (30) may be rejected. However, if the worker inputs account information corresponding to account level 1, 'Hong Gil-dong LV1', and inputs a password that matches the input account information, the connection of the corresponding worker terminal (30) may be allowed, and a service corresponding to account level 1 may be provided.

[0098] Alternatively, if the control unit (100) receives current account information from the server (20), it can determine the range of accounts that are allowed to access according to the account information as a second account level based on the method of input and the subject of input of the account information. Therefore, access to all account levels below the second account level may be allowed. Thus, if the worker 'Hong Gil-dong' inputs 'Hong Gil-dong LV1' corresponding to account level 1 or 'Hong Gil-dong LV2' corresponding to account level 2, access according to account level 1 or account level 2 may be allowed. In this case, it is obvious that if accessed via account level 1, services corresponding to account level 1 can be provided, and if accessed via account level 2, services corresponding to account level 2 can be provided.

[0099] Meanwhile, if the current account information is directly input through the input unit (120) provided in the service device (10), the control unit (100) can determine the range of accounts that are allowed to be accessed according to the account information based on the input method and the input subject of the account information as a third account level. Therefore, access to all account levels below the third account level may be allowed. Thus, within the range of 'Hong Gil-dong LV1' (Account Level 1), 'Hong Gil-dong LV2' (Account Level 2), and 'Hong Gil-dong LV3' (Account Level 3), access according to the account information entered by the operator may be allowed. In this case, the control unit (100) may allow access according to the account information when a password matching the account information of a specific account level is entered, and may provide only the service according to the account level of the account information for which access is allowed.

[0100] Meanwhile, the control unit (100) can change the password corresponding to at least one account information when there is a request from the server (20). For example, the control unit (100) can collectively change the passwords of all account information corresponding to a specific account level in accordance with the request from the server (20).

[0101] For example, the control unit (100) may receive a mapping number from the server (20) to specify one of the passwords included in a password mapping table configured so that a plurality of different passwords are matched to different mapping numbers. And when the mapping number is received, the password corresponding to the received mapping number is detected from the password mapping table, and the detected password can be changed to a password of a specific account level.

[0102] Alternatively, the control unit (100) may receive at least one password generation key from the server (20) for generating a password using a pre-configured password generation algorithm. When the password generation key is received, a new password may be generated based on the received password generation key and the pre-configured password generation algorithm. The generated new password may then be changed to a password of a specific account level.

[0103] In the above description, the configuration of the system (1) according to an embodiment of the present invention and the configuration of the server (20), worker terminal (30), and service device (10) constituting the system (1) have been described in detail.

[0104] In the following description, we will examine in detail the operation process of providing different services depending on the method of inputting account information and the subject inputting said account information in a system according to an embodiment of the present invention, with reference to multiple flowcharts.

[0105] FIG. 3 is a flowchart illustrating the operation process in which a service device (10) limits the range of accounts allowed to be accessed according to the method of inputting account information and the subject of inputting account information in a system (1) according to an embodiment of the present invention. For convenience of explanation, the following description assumes that the account levels of accessible accounts are divided into three stages: low level, middle level, and high level. However, it goes without saying that the present invention is not limited thereto.

[0106] Referring to FIG. 3, a service device (10) according to an embodiment of the present invention may receive a connection request to input account information and a password (PW) to the service device (10) (S300).

[0107] Here, the connection request may be a communication connection request from a server (20) or a worker terminal (30) according to a wireless communication method. Alternatively, if a worker requests the service device (10) to open or activate an input unit (120) in order to directly input the account information and password (PW), the service device (10) may determine the connection request as a direct request from the worker. Alternatively, if the worker terminal (30) is connected to the service device (10) via a pre-configured wired communication connection method to input the account information and password (PW), the wired connection may be detected as a connection request for inputting the account information and password.

[0108] When such a connection request is detected, the service device (10) can determine the account level to which a connection to the service device (10) is allowed according to the method in which the connection was requested (S301).

[0109] For example, if the connection request detected at step S300 is a direct connection request, the service device (10) can determine that accounts of all account levels are accessible. That is, as in the example described above, if the account levels are divided into three stages of low, middle, and high levels, when the direct connection request is detected, the service device (10) can determine that accounts of all account levels, including the high level, are accessible.

[0110] On the other hand, if the connection request detected in the above S300 step is a connection request via a wireless communication connection, the service device (10) may restrict access to accounts according to some account levels. Therefore, as in the example described above, if the account levels are divided into three stages—low level, middle level, and high level—the service device (10) may restrict access to high-level accounts. Accordingly, when a connection request via the communication connection is detected, the service device (10) may allow access only to middle-level and low-level accounts. That is, the service device (10) may restrict access to the service device (10) to account levels where a specific service is provided, based on the currently detected connection request method, i.e., when account information and password are entered via a wireless communication connection. The operation process of the above S301 step, in which the account level to which access is allowed is determined according to the detected connection request method, will be examined in more detail below with reference to Fig. 4 below.

[0111] Meanwhile, in the above step S301, if the account levels for which access is allowed are determined according to the method in which the access is requested, that is, the method in which account information and password are entered, the service device (10) can determine whether the access request was made through a communication connection (S302). If, as a result of the check in the above step S302, the method in which the account information and password are entered is a direct connection method using the input unit (120) of the service device (10), the service device (10) can proceed to step S306, which checks whether account information and password have been entered from the access request device that requested the access.

[0112] Meanwhile, if the above connection request is made through a communication connection, the entity requesting the connection, i.e., the type of the connection request device, can be identified (S303). And depending on the type of the identified connection request device, the range of account levels allowed to connect to the service device (10) can be further restricted (S304).

[0113] For example, in step S302 above, a server (20) or a worker terminal (30) may establish a communication connection with a service device (10) to input account information and a password. Then, in step S304 above, the service device (10) can identify the device to which the communication is connected. In this case, since the devices that can connect to the service device (10) may be a server (20) or a worker terminal (30), the service device (10) can identify the entity of the connection request device that inputs the account information and password in step S304 as the server (20) or the worker terminal (30).

[0114] And the service device (10) can determine the range of account levels for which access is allowed differently depending on whether the identified access request device is a server (20) or a worker terminal (30). For example, if the identified access request device is a worker terminal (30), the service device (10) can limit the range of account levels for which access is allowed to a low level. Then, when the worker terminal (30) connects to the service device (10) via wireless communication, it may be able to connect only with low-level account information.

[0115] That is, even if a worker inputs middle-level or high-level account information and a password matching that account information through the worker terminal (30), the account level accessible to the service device (10) may be limited to a low level depending on the input method and the input subject of the account information and password input. In this case, since the service available to the service device (10) is determined according to the account level of the connected account, the service available to the service device (10) may be determined according to the input method and the input subject of the account information and password input.

[0116] Meanwhile, if the identified connection request device is a server (20), the service device (10) may limit the range of account levels for which connection is allowed to middle level and low level. Therefore, when connecting to the service device (10) by entering account information and password through the user input unit (21) provided in the server (20), it may be possible to connect with account information of the middle level or low level. Therefore, when connecting to the service device (10) through the user input unit (21) provided in the server (20), it may be possible to connect with account information according to any one of the account levels excluding some account levels (e.g., high level).

[0117] Meanwhile, if the range of account levels for which access is allowed is limited according to the type of access request device identified in step S304, the service device (10) can check whether account information and password have been entered from the access request device that requested the access (S306). And if account information and password are entered from the access request device in step S306, the service device can check whether the entered account information is an account of an account level for which access is allowed (S308).

[0118] The service device (10) can check, in step S308, whether the account information entered from the connection request device corresponds to an account according to the account level for which connection is allowed determined in steps S301 and S305.

[0119] That is, if the account level for which access is allowed is limited to a low level depending on the method of inputting the account information and the type of the connection request device, the service device (10) can check whether the account information input from the connection request device is for any one of the accounts stored in the low-level account information storage unit (161).

[0120] Or, if the account level for which access is allowed is limited to a middle level and a low level depending on the method of inputting the account information and the type of the connection request device, the service device (10) can check whether the account information input from the connection request device is for one of the accounts stored in the low-level account information storage unit (161) and the low-middle account information storage unit (162).

[0121] In addition, if the account level for which access is allowed includes a high-level account depending on the method of inputting the account information and the type of the access request device, the service device (10) can check whether the account information input from the access request device is for any one of the accounts stored in the low-level account information storage unit (161) and the low-middle account information storage unit (162) as well as the high-level account information storage unit (163).

[0122] If, as a result of the above check, the entered account information does not correspond to any of the accounts included within the range of account levels for which access is permitted according to the input method and the input subject (access request device) in which the account information and password were entered, the service device (10) may reject the access request of the access request device. In this case, the service device (10) may notify account error alarm information indicating that the account is not accessible as a response to the account information and password entered from the access request device (S309).

[0123] On the other hand, if, as a result of the check in step S308 above, the entered account information corresponds to one of the accounts included within the range of account levels for which access is permitted according to the input method and the input subject (access request device) in which the account information and password were entered, the service device (10) can check whether the entered password is a password that matches the password of the account corresponding to the entered account information (S310). And if the passwords match, the access request device can be allowed to access, and a service according to the account level of the accessed account can be provided (S312). However, if the passwords do not match, the service device (10) can notify the access request device of password mismatch notification information indicating that the passwords do not match, and refuse the access request device.

[0124] Meanwhile, FIG. 4 is a flowchart illustrating in more detail the operation process in which a service device (10) according to an embodiment of the present invention determines an account level that is allowed to connect according to the connection method of a connection request device.

[0125] Referring to FIG. 4, the service device (10) according to an embodiment of the present invention can check whether the connection request detected in step S300 of FIG. 3 is a communication connection (1. communication connection) received from a server (20) or a worker terminal (30) to input account information and password, or a direct input request (2. direct input request) requested by a worker to directly input the account information and password to the service device (10) (S402).

[0126] If, as a result of checking step S402 above, the connection request is a direct input request, the service device (10) may open or activate the input unit (120) of the service device (10) so that the worker can directly input account information and password according to the worker's request (S405). Then, the worker can directly input account information and password through the input unit (120). In this case, the service device (10) may determine a range of account levels that include not only low level and middle level but also high level as account levels accessible for the worker's direct input. Therefore, when the worker directly inputs account information, access to high level accounts as well as low level and middle level accounts may be allowed.

[0127] On the other hand, if the connection request is the communication connection (1. communication connection) as a result of the check in step S402 above, the service device (10) may allow the communication connection of the connection request device (S404). Then, in step S404, the service device (10) may establish a communication connection with the connection request device using a wireless communication method or a wired communication method.

[0128] In this case, the above 'communication connected state' can be distinguished from the 'connected state'. The above 'communication connected state' may be a state in which information or data can be transmitted and received with the connection request device connected to the communication, but a state in which no service is provided. On the other hand, the above 'connected state' may mean a state in which communication is not only established with the connected device, but the service device (10) also provides a service in response to the request of the connected connection request device.

[0129] If a communication connection is established with the connection request device in step S404 using a wired communication method or a wireless communication method, the service device (10) can check whether the communication connection established with the connection request device is established using a pre-set wired communication method (S406).

[0130] And if the result of the check in step S406 above indicates that the communication connection is established via wireless communication, the range of account levels allowed to access the service device (10) can be limited to restrict access to high-level accounts. Thus, middle level and low level can be determined as account levels allowed to access (S408). Therefore, if the account information input from the connection request device corresponds to account information for a high-level account, the connection request from the connection request device based on the account information of the high-level account can be rejected.

[0131] On the other hand, if the above communication connection is established using a pre-configured wired communication method, the service device (10) may consider the input of connection information according to the wired communication method as a direct input by the worker. Accordingly, the service device (10) may proceed to step S410 to determine the range of account levels allowed for connection, including high-level accounts. Accordingly, when a worker establishes a wired communication connection to the service device (10) using a communication cable of a pre-configured method with their worker terminal (30), the service device (10) may consider the connection request from the worker terminal (30) made through the wired communication connection as a direct request by the worker, thereby allowing connection not only to middle-level accounts and low-level accounts but also to high-level accounts.

[0132] Meanwhile, as described above, it has been mentioned that the system (1) according to the embodiment of the present invention can receive a service (a service corresponding to a low level) from the service device (10) by connecting to the service device (10) via a wireless communication method of the worker terminal (30). In this case, the system (1) according to the embodiment of the present invention may be configured to allow connection to the service device (10) only for the worker terminal (30) of an authenticated worker.

[0133] FIG. 5 is a flowchart illustrating the operation process in which a server (20) of a system (1) according to an embodiment of the present invention grants a low-level account to a worker terminal (30) in response to a request from a worker terminal (30).

[0134] Referring to FIG. 5, first, the worker terminal (30) can establish a communication connection with the server (20). Then, the worker terminal (30) can request connection information from the communication-connected server (20) to access the service device (10) for the purpose of performing work on the service device (10) (S511). In this case, simultaneously with the request for the connection information, the worker can transmit authentication information to the server (20) to authenticate themselves. Then, the server (20) can perform authentication of the worker based on the authentication information received from the worker terminal (30) (S512).

[0135] Here, the authentication information may include a password pre-set by the operator or biometric information for biometric authentication, such as a fingerprint, iris, or facial image. Additionally, the authentication information may include authentication information provided by an accredited certification authority that provides authentication services, such as a telecommunications carrier that provides authentication services.

[0136] Additionally, the server (20) may require additional authentication information from the worker. In this case, the additional authentication information may further include at least one of the worker's work location information, information of the terminal the worker possesses, i.e., the worker terminal (30) (e.g., unique information such as a serial number), and information on the working time allowed to the worker.

[0137] Therefore, even if a worker is authenticated through the above authentication information, for example, biometric information, additional authentication of the worker may fail if the worker's work location differs from the current location of the worker terminal (30) requesting the above connection information, or if the time at which the connection information was requested is outside the working time allowed to the worker. Additionally, additional authentication of the worker may fail if the worker terminal requesting the above password information is not the worker terminal of a previously registered worker. And if the above additional authentication fails, the server (20) may determine that the worker's authentication failed in step S512.

[0138] Meanwhile, in step S512 above, if the authentication of the worker according to the authentication information provided from the worker terminal (30) is successful, the server (20) can transmit low-level account information and a low-level password that can access the service device with a low-level account to the authenticated worker's worker terminal (30) (S513).

[0139] And the server (20) can transmit the information of the low-level account information and low-level password provided to the worker terminal (30) to at least one service device (10) (S514). In this case, the server (20) can transmit the information of the low-level account information and low-level password only to at least one service device where work is permitted to the worker of the worker terminal (30). Therefore, when the worker terminal (30) inputs the low-level account information and low-level password, access may be permitted only to at least one service device where work is permitted to the worker of the worker terminal (30). And when access is permitted, a service corresponding to the low level may be provided.

[0140] In this way, connection information (account information and password) that enables access to a low-level account of at least one service device is transmitted to the worker terminal (30), and by transmitting the connection information that enables access to the low-level account of at least one service device to the worker terminal (30), a low-level account that enables access to the at least one service device can be assigned to the worker terminal (30) (S510).

[0141] In this case, the connection information transmitted from the server (20) to the at least one service device may include restriction conditions of the low-level password, for example, information on the validity period. Accordingly, the low-level account information and low-level password provided to the worker terminal (30) may be passwords that can only be used for a limited time. Therefore, if the preset validity period expires, connection to the service device (20) may no longer be allowed.

[0142] Meanwhile, when a low-level account is assigned to the worker terminal (30) in step S510, the worker terminal (30) can input the low-level account information, namely the ID and low-level password, received from the server (20) into one of the service devices (10) (S520). Then, the service device (10) can determine whether the password corresponding to the input low-level account information matches the password of the connection information provided by the server (20) (S530).

[0143] And if the password of the above low-level account does not match or if the restriction conditions set on the above low-level account are satisfied, that is, if the usage period has expired, the service device (10) may not allow the connection of the worker terminal (30). Then, the service device (10) may provide notification information to the worker terminal (30) indicating that the entered password does not match (S560).

[0144] Meanwhile, the service device (10) may allow the connection of the worker terminal (30) if the account information and password of the low-level account entered from the worker terminal (30) match the connection information of the low-level account provided by the server (20), and the restriction conditions set on the low-level account are not satisfied, that is, if the usage period has not expired (S540). And when the connection of the worker terminal (30) to the server (20) is allowed, the service device (10) may provide the worker terminal (30) with a service according to the request of the worker terminal (30), that is, a service according to the low-level account (S550).

[0145] Meanwhile, according to the above description, it has been mentioned that the system (1) according to an embodiment of the present invention can collectively change passwords of a specific account level. For example, the system (1) can pre-designate a password that can access middle-level accounts or a password that can access high-level accounts, and collectively change the passwords according to pre-set password change conditions.

[0146] In this case, the server (20) of the system (1) may use a password mapping table in which multiple different passwords are matched to different mapping numbers to collectively change the passwords of the specific account level, or may use a method of sharing a password generation algorithm that generates a password based on at least one input key and changing the at least one key.

[0147] FIG. 6 is a flowchart illustrating the operation process in which a server of a system (1) according to an embodiment of the present invention collectively changes a specific account level password assigned to a worker terminal (30) using a password mapping table shared among service devices.

[0148] Referring to FIG. 6, first, the server (20) of the system (1) of the present invention may receive a password mapping table in which a plurality of different passwords are matched to different mapping numbers from the administrator of the server (20) or a higher-level system (S600). Then, the received password mapping table may be transmitted to each service device (10-1, 10-2, ... 10-n) that is connected to the server (20) (S610-1, S610-2, ... , S610-n). Then, each service device (10-1, 10-2, ... 10-n) may store the received password mapping table.

[0149] And the server (20) can arbitrarily determine a password mapping number that matches any one of the passwords included in the password mapping table (S620). Then, the determined password mapping number can be transmitted to each service device (10-1, 10-2, ... 10-n) (S620-1, S620-2, ... S620-n). Then, each service device (10-1, 10-2, ... 10-n) can search for a password that matches the password mapping number received from the server (20) from the previously stored password mapping table, and set the searched password as a password of a specific account level that allows access to the service device (S621-1, S621-2, ... S621-n)). Thus, a password that allows access to a specific account level account at each service device can be collectively determined as a password corresponding to a specific mapping number of the password mapping table.

[0150] Meanwhile, when a password mapping number corresponding to a specific password is transmitted to each service device (10-1, 10-2, ... 10-n), the server (20) can check whether a pre-set password change condition is satisfied (S630). Here, the pre-set password change condition can be determined based on whether a pre-set time has elapsed since the time when the password mapping number was determined, for example, the time when the password mapping number was changed (the time of the previous change).

[0151] Alternatively, if a pre-configured event occurs, for example, when a new service device is connected or an existing connected service device is removed from the system (1), the server (20) may determine that the pre-configured password change condition is satisfied. Then, the server (20) may proceed again to step S620 to restart the process of determining the password mapping number, and accordingly, a password mapping number corresponding to the new password may be determined.

[0152] Meanwhile, when a new password mapping number is determined, the server (20) can repeat steps S610-1 through S610-n to transmit the new password mapping number to each service device (10-1, 10-2, ... 10-n). Then, each service device (10-1, 10-2, ... 10-n) can repeat steps S620-1 through S620-n and steps S621-1 through S621-n to determine the password corresponding to the new password mapping number received from the server (20) as the password that allows access to an account of a specific account level at each service device. That is, the password that allows access to an account of a specific account level at each service device can be changed collectively.

[0153] Meanwhile, FIG. 7 is a flowchart illustrating the connection process in which a worker terminal (30) of the system (1) illustrated in FIG. 6 connects to a service device (10).

[0154] Referring to FIG. 7, first, the worker terminal (30) can establish a communication connection with the server (20). Then, the worker terminal (30) can transmit authentication information capable of authenticating the worker to the server (20) simultaneously with a request for connection information to access the service device (10) (700). Then, the server (20) can perform authentication of the worker based on the authentication information received from the worker terminal (30) (S702).

[0155] Here, the authentication information may include a password pre-set by the operator or biometric information for biometric authentication, such as a fingerprint, iris, or facial image. Additionally, the authentication information may include authentication information provided by an accredited certification authority that provides authentication services, such as a telecommunications carrier that provides authentication services.

[0156] Here, the server (20) may request additional authentication information from the worker. In this case, the additional authentication information may include at least one of the worker's work location information, information about the terminal the worker possesses, i.e., the worker terminal (30) (e.g., unique information such as a serial number), and information about the working time allowed to the worker. In this case, even if the worker is authenticated through the authentication information, for example, biometric information, the additional authentication of the worker may fail if the worker's work location differs from the current location of the worker terminal (30) requesting the password information, or if the time at which the password information was requested is outside the working time allowed to the worker. Additionally, the additional authentication of the worker may fail if the worker terminal requesting the password information is not the worker terminal of a previously registered worker. And if the additional authentication fails, the server (20) may determine that the worker's authentication has failed in step S702.

[0157] Meanwhile, in step S702 above, if the authentication of the worker according to the authentication information provided by the worker terminal (30) is successful, the server (20) may transmit a temporary password that allows access to the server (20) to the authenticated worker's worker terminal (30) (S704). The temporary password may be a password that can be used for a limited time or a limited number of times (e.g., one-time use), and may mean a password that no longer allows access to the server (20) once the pre-set usage period has expired or the number of uses has been exhausted.

[0158] When the above temporary password is provided to the worker terminal (30), the worker terminal (30) can input the temporary password provided from the server (20) into the server (20) (S706).

[0159] Then, the server (20) can check whether the temporary password entered from the worker terminal (30) is a password that allows access to the server (20) (S708). In this case, the server (20) can check not only whether the temporary password matches, but also whether the restriction conditions set on the temporary password are not satisfied.

[0160] And if the above temporary password does not match or if the restriction conditions set on the above temporary password are satisfied, that is, if the usage period has expired or the number of uses has been exhausted, the server (20) may not allow the connection of the worker terminal (30) according to the above temporary password. Then the server (20) may send notification information indicating that the temporary password does not match to the worker terminal (30) currently connected to the communication (S709).

[0161] Meanwhile, if the temporary password entered from the worker terminal (30) matches and the restriction condition set on the temporary password is not satisfied, the server (20) may allow the connection of the worker terminal (30) (S710). And if the connection of the worker terminal (30) is allowed, the server (20) may transmit password mapping number information corresponding to the password currently set on each service device to the connected worker terminal (30) (S711).

[0162] Then, the worker terminal (30) can detect a password corresponding to a password mapping number provided by the server (20) from a previously stored password mapping table (S712). Here, the password mapping table may be provided by the server (20) when the worker terminal (30) is first registered with the server (20). That is, the password mapping table may be provided by the server (20) only to the worker terminal (30) registered with the server (20).

[0163] Meanwhile, the worker terminal (30) can establish a communication connection with the service device (10) to which the worker intends to perform work. In this case, the communication connection with the service device (10) can be established through a wired connection via a wired cable connecting the worker terminal (30) and the service device (10).

[0164] When a wired communication connection is established with the service device (10), the worker terminal (30) can input the password detected through the password mapping number provided by the server (20) into the service device (10) (S714). For example, the worker terminal (30) can display the detected password on the display unit of the worker terminal (30), and the worker can input the password into the service device (10) by inputting the displayed password through the user input unit of the worker terminal (30).

[0165] Then, the service device (10) can check whether the password entered from the worker terminal (30) is a password that matches the password mapping number provided by the server (20), which is a password that is currently allowed to connect (S716). And if the password does not match as a result of the check in step S716, the service device (10) can transmit password mismatch information to the worker terminal (30) and not allow the connection of the worker terminal (30) (S719). Then, the password mismatch information can be displayed on the display unit of the worker terminal (30).

[0166] On the other hand, if, as a result of the check in step S716, the password entered from the worker terminal (30) matches the password that matches the password mapping number provided by the server (20), the service device (10) may allow the connection of the currently connected worker terminal (30) and allow the work of the worker terminal (30) (S718). In this case, the service device (10) may allow access to an account of a specific account level according to the entered password. And, the service according to the specific account level may be provided at the request of the worker terminal (30).

[0167] Meanwhile, Figure 7 above assumes a case where the worker terminal (30) is connected to the service device (10) via a wired communication connection. Alternatively, the worker may directly input the password detected according to the specific account level account information and the mapping number provided by the server through the input unit (120) of the service device (10).

[0168] Then, the service device (10) can detect an account level corresponding to the account information input through the input unit (120) and detect a specific password corresponding to the account level of the account input through the input unit (120). Here, the specific password may be a password detected from a password mapping table according to a specific mapping number provided by the server (20). The service device (10) can determine whether the specific password matches the password input through the input unit (120). And, based on the determination result, it can allow access according to the specific account level and provide a service according to the specific account level.

[0169] Meanwhile, according to the above description, when a worker terminal (30) connects to a service device (10) via wireless communication, it was explained that the account level allowing access by the worker terminal (30) can be restricted to a low level depending on the input method (wireless communication method) and the input subject (worker terminal (30)) for entering account information and password. However, the account level restriction based on the input method and input subject for entering account information and password can be temporarily relaxed by one level in accordance with the request of the server (20) or an authenticated worker, or only for worker terminals (30) that satisfy pre-set authentication conditions. Therefore, as described above, when a worker terminal (30) connects to a service device (10) via wireless communication, access can be allowed up to a middle level account depending on the relaxation of the account level.

[0170] However, when the account level restriction is relaxed in this way, the account level restriction according to the pre-set input method and input subject is relaxed, the service server (20) can determine whether the connection of the worker terminal (30) to which the service according to the relaxed account level restriction is provided has been terminated.

[0171] For example, the service device (10) may determine that the connection of the worker terminal (30) has been terminated when the communication connection with the worker terminal (30) is disconnected. And when the connection with the worker terminal (30) is terminated, the service device (10) may transmit connection termination notification information to the server (20) indicating the termination of the account connection at a specific account level. Then the server (20) may receive the connection termination notification information.

[0172] Here, the connection termination notification information may correspond to the password change condition described in FIG. 6. Accordingly, the server (20) can change the mapping number determining the password corresponding to the specific account level to a mapping number corresponding to any other password in the password mapping table. In this case, the server (20) can change the password corresponding to the account level of the account connected by the worker terminal (30), i.e., the middle level, in accordance with the relaxation of the account level restriction.

[0173] To this end, the server (20) can change the mapping number determining the password corresponding to the middle level to a mapping number corresponding to any other password in the password mapping table. Then, according to the process below step S620 described in FIG. 6, the mapping number corresponding to the any other password is transmitted to each service device, and accordingly, the password corresponding to the middle level can be changed collectively in each service device. Thus, the security risk associated with temporarily relaxing account level restrictions based on the pre-set input method and input subject can be minimized.

[0174] Meanwhile, the above description explains that the account level can be relaxed for the worker terminal (30). Similarly, restrictions on access to a service device through the server (20) based on the method of inputting account information and password and the input subject can also be temporarily relaxed. For example, if emergency measures are required for an emergency situation, the account level restriction on access to a service device through the server (20) can be temporarily relaxed by inputting pre-configured account information into the server (20) through the user input unit (21).

[0175] In this way, when the account level restriction is temporarily relaxed for access to the service device through the server (20), the server (20) can access the service device (10) at the level of a maximum high-level account by relaxing the account level restriction by one step. Then, the service device (10) can allow access to the maximum high-level account in response to the request of the server (20) and provide the service accordingly.

[0176] Then, the server (20) can check whether the connection with the service device (10) has been terminated. And when the connection with the service device (10) is terminated, the server (20) determines that the password change condition is satisfied and, in accordance with the relaxation of the account level restriction, can change the password corresponding to the account level that the server (20) is currently connected to through the service device (10), i.e., the high level.

[0177] To this end, the server (20) can change the mapping number that determines the password corresponding to the high level to a mapping number corresponding to any other password in the password mapping table. Then, according to the process below step S620 described in FIG. 6, the mapping number corresponding to the any other password is transmitted to each service device, and accordingly, the password corresponding to the high level can be changed collectively in each service device.

[0178] Meanwhile, FIG. 8 is a flowchart illustrating the operation process in which a server (20) of a system (1) according to an embodiment of the present invention collectively changes a specific account level password assigned to a worker terminal (30) using a password generation algorithm shared among service devices.

[0179] Referring to FIG. 8, the server (20) can first distribute a pre-configured password generation algorithm to a pre-registered worker terminal (30) and a plurality of service devices (10-1, 10-2, ... 10-n). Accordingly, in the system (1) according to an embodiment of the present invention, the worker terminal (30) and the plurality of service devices (10-1, 10-2, ... 10-n) can all share the same password generation algorithm.

[0180] Here, a password generation algorithm refers to a series of ordered procedures, methods, or rules capable of generating a password based on at least one key, and can generate the same password if the input keys are identical. On the other hand, if at least one of the input keys is different, a different password can be generated.

[0181] And the server (20) can transmit at least one key to each service device for generating a password that can access each service device at a specific account level (S801-1, S801-2, ... S801-n). Then each service device can receive the same at least one key from the server (20), and accordingly, can generate the same password that can access the specific account level through the previously stored password generation algorithm.

[0182] Then the server (20) can check whether the pre-set password change conditions are satisfied (S820).

[0183] Here, the above-mentioned pre-set password change condition may be satisfied depending on whether a pre-set time has elapsed since the point in time when the password was previously changed, or depending on whether a pre-set specific event occurs. For example, the server (20) may determine that the above-mentioned password change condition is satisfied when a new service device is connected, or when an existing connected service device is removed from the system (1).

[0184] Meanwhile, as described above, at least one key for generating a password through a pre-configured password generation algorithm, i.e., a password generation key, may be provided by the server (20). In this case, if the at least one key provided by the server (20) is changed, each service device may generate a new password according to the changed key. Therefore, the password corresponding to the specific account level may be changed collectively by each service device. That is, the time when the new password generation key is transmitted from the server (20) may be the time when the password is changed.

[0185] And the server (20) can change the password generation key when the password change requirement is met (S810). And the server (20) can distribute the changed password generation key to a plurality of service devices (10-1, 10-2, ... 10-n) (S811-1, ... S811-n). Then the plurality of service devices (10-1, 10-2, ... 10-n) generate a new password according to the received new password generation key, and accordingly, the passwords that allow access to the account according to the specific account level generated in each of the plurality of service devices (10-1, 10-2, ... 10-n) can be changed collectively.

[0186] Meanwhile, the worker terminal (30) may receive from the server (20) a password generation algorithm identical to the password generation algorithm distributed to service devices, as shown in step S800 above. However, at least one key capable of generating a password through the password generation algorithm may be provided by the server (20) upon request from the worker terminal (30).

[0187] For example, the worker terminal (30) may transmit a connection request and authentication information to the server (20) for access to the service device (10), similar to what is described in FIG. 7 above. The server (20) may provide a temporary password to the worker terminal (30) only when the worker is authenticated through the authentication information, and when the worker terminal (30) accesses the server (20) through the temporary password, the server may provide the password generation key currently distributed to each service device to the worker terminal (30). Then, the worker terminal (30) may generate a password based on the password generation key provided by the server (20) and display the generated password on the display unit, thereby enabling the worker to access the service device (10) at the specific account level.

[0188] Meanwhile, although the description in FIGS. 6 to 8 above assumes only the case where the worker terminal (30) connects to the service device (10), it is obvious that even when connecting to the service device (10) through the server (20), the connection to the service device (10) may be made in a similar manner to the description in FIGS. 6 to 8.

[0189] However, in the case of FIGS. 6 to 8, it is assumed that the worker directly accesses the service device (10) through the input unit (120) or that the worker terminal (30) is connected to the service device (10) via a wired connection. The password that is changed collectively according to the description in FIGS. 6 to 8 may be a password that can access the service device as a high-level account.

[0190] However, in the case of the server (20), according to the description in FIGS. 3 to 4 above, the service device (10) restricts the account level to which access is allowed based on the method of inputting account information and password and the input subject, so that when accessing the service device (10) through the server (20) to the user input unit (21), it may be possible to access the service device (10) with a maximum middle-level account. Therefore, in this case, the password that is changed collectively according to the description in FIGS. 6 to 8 above may be a password that allows access to the service device with a middle-level account.

[0191] Additionally, as described above, after the server (20) or worker terminal (30) connects to the service device (10) with a high-level account or a middle-level account, respectively, due to the temporary relaxation of account level restrictions, the operation process of FIG. 8 may be performed to collectively change the passwords of the accounts connected to the service device (10) by the server (20) or worker terminal (30).

[0192] The present invention described above can be implemented as computer-readable code on a medium on which a program is recorded. A computer-readable medium includes all types of recording devices in which data that can be read by a computer system is stored. Examples of computer-readable media include HDD (Hard Disk Drive), SSD (Solid State Disk), SSD (Silicon Disk Drive), ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage device, etc., and also include implementation in the form of a carrier wave (e.g., transmission over the Internet).

[0193] Accordingly, the above detailed description should not be interpreted restrictively in all respects but should be considered exemplary. The scope of the invention should be determined by a reasonable interpretation of the appended claims, and all modifications within the equivalent scope of the invention are included within the scope of the invention.

Claims

1. A service device that provides, in response to the input of connection information including account information and password, the result of executing at least one function that is executable or is being executed as a service according to the input of said connection information, A communication unit including a wired communication module and a wireless communication module for performing communication connections with a pre-configured server and worker terminal; An input unit including an input means for receiving user input; A driving unit comprising at least one component for executing the function of the above-mentioned service device; A memory storing multiple account information classified by different account levels corresponding to different services, and passwords matching each of the multiple account information; and, A service device characterized by including a control unit that determines an input method in which the above connection information is input, determines a range of accessible account levels including at least one account level for which access is allowed with the input connection information according to the determination result, allows access based on whether the account information included in the input connection information is an account of an account level included within the range of accessible account levels, and provides a service corresponding to the account level included in the input connection information as a response to the input of the connection information.

2. In paragraph 1, the control unit is, Depending on whether the above connection information is input through a communication connection or input through the above input unit, the input method is determined as either input through a communication connection or direct input, and the range of the above connectable account level is determined differently according to the determined input method. The range of accessible accounts determined when the above input method is the above direct input is, A service device characterized by including more account levels than those included in the range of connectable account levels determined when the above input method is the above communication connection.

3. In paragraph 2, the control unit is, If the above input method is a communication connection, further determine whether it is a wireless communication connection using the wireless communication module or a wired communication connection using the wired communication module, and A service device characterized by considering the input method of the connection information as the direct input when the above communication connection is a wired communication connection.

4. In Paragraph 3, The above account level is, It includes a low level capable of providing a service that allows only verification of stored data upon operation of the service device, a middle level capable of providing a service that allows not only verification of stored data upon operation of the service device but also setting a value for a conditional function that enables the service device to execute a specific function, and a high level capable of providing a service that can directly control whether the specific function is executed and the state of execution beyond the execution conditions under which the specific function that the service device can perform is executed. A service device characterized in that, when the above input method is a communication connection, at least one of the above account levels is excluded from the above accessible account level range.

5. In paragraph 4, the control unit is, A service device characterized by further determining an input subject who inputs the above connection information, and limiting the range of accessible account levels that can access the service device through the connection information according to the input method of the determined connection information and the input subject of the determined connection information.

6. In Paragraph 5, The inputter of the above connection information is, Any one of the above-mentioned configured server, the above-mentioned worker terminal, and the worker, The above control unit is, If the input method of the above connection information is a wireless communication connection, the above-mentioned range of connectable account levels is limited to the above-mentioned middle level and the above-mentioned low level, and A service device characterized by further restricting the range of possible account levels to a low level when the input method of the above connection information is a wireless communication connection and the input subject of the above connection information is the worker terminal.

7. In paragraph 1, the service device is, A service device characterized by comprising, as a device capable of providing communication services, a monitoring device capable of viewing recorded or captured video only by authorized workers, a protection relay that performs monitoring, measurement, and protection functions for power equipment, and an intelligent electric device (IED) capable of controlling at least one function of power equipment as well as monitoring, measurement, and protection functions for at least one power equipment.

8. In Paragraph 4, The aforementioned configured server is, Provides temporary access information including a temporary account and a temporary password that can access the service device at the low level upon a request by an authenticated worker, transmits the temporary access information to at least one service device where the authenticated worker's work is allowed, and grants the low-level account to the authenticated worker's worker terminal. The above temporary account and temporary password are, A service device characterized by an account and password with a limited usage period.

9. A control method for a service device that provides, in response to the input of connection information including account information and password, the result of execution of at least one function that is executable or is being executed as a service according to the input of said connection information, A step of determining the input method in which the above connection information is input; A step of determining a range of accessible account levels including at least one account level that is allowed to be accessed with the input connection information, according to the input method of the determined connection information; A step of detecting an account level corresponding to the account information included in the input connection information from a plurality of account information classified by different account levels corresponding to each different service stored previously; A step of checking whether the detected account level is included within the determined range of accessible account levels; and, A method for controlling a service device characterized by including the step of checking whether the password included in the input connection information matches a previously stored password according to the above check result, and providing a service corresponding to the detected account level as the input of the connection information according to whether the password matches.

10. In Paragraph 9, The step of determining the input method in which the above connection information is input is: A control method for a service device characterized by a step of determining the input method as either input via a communication connection or direct input, depending on whether the above connection information is input via a communication connection or input via an input unit provided in the service device.

11. In Paragraph 10, The step of determining the input method in which the above connection information is input is: If the above input method is a communication connection, a step of determining whether it is a wireless communication connection using a wireless communication module or a wired communication connection using a wired communication module; and, A control method for a service device characterized by further including the step of considering the input method of the connection information as the direct input when the communication connection is a wired communication connection.

12. In Paragraph 9, The step of determining the input method in which the above connection information is input is: It further includes a step of determining the input subject inputting the above connection information, and The step of determining the above accessible account level range is, A control method for a service device characterized by further including a step of further restricting the range of account levels for which access is allowed with the input connection information according to the input subject of the determined connection information, within the range of account levels for which access is possible determined according to the input method of the determined connection information.

13. A plurality of service devices that provide, in response to the input of connection information including account information and password, the result of execution of at least one function that is executable or is being executed as a service according to the input of said connection information; and, It includes a server configured to provide multiple account information classified by different account levels for each different service and a password matching each of the multiple account information to the multiple service devices, and to transmit connection information entered through a user input unit to the service devices via a pre-configured communication connection method. The above service device is, A system characterized by determining an input method in which the above connection information is input, determining a range of accessible account levels including at least one account level for which access is allowed with the input connection information according to the determination result, allowing access based on whether the account information included in the input connection information is an account of an account level included within the range of accessible account levels, and providing a service corresponding to the account level included in the input connection information as a response to the input of the connection information.

14. In Paragraph 13, the above account level is, A system characterized by including: a low level capable of providing a service that allows only verification of stored data according to the operation of the service device; a middle level capable of providing a service that allows not only verification of stored data according to the operation of the service device but also setting a value for a conditional function that allows the service device to execute a specific function; and a high level capable of providing a service that allows direct control of whether the specific function is executed and the state of execution beyond the execution conditions in which the specific function that the service device can perform is executed.

15. In Paragraph 14, the above service device is, When the connection information is input via the aforementioned pre-configured communication connection method, the range of the possible account levels for connection is determined differently depending on the input subject inputting the connection information, and If the above input entity is the above server, it determines the range of accessible account levels including the above middle-level accounts and the above low-level accounts, and A system characterized by determining a range of accessible account levels including the low-level accounts when the input subject is a worker's terminal.

16. In Paragraph 13, the above server, A password mapping table configured such that a plurality of different passwords are each matched to a different mapping number is transmitted to the plurality of service devices, and a specific mapping number corresponding to any one password included in the password mapping table is provided to the plurality of service devices to determine a password that matches a specific account level. A system characterized by providing a mapping number that matches any other password according to a pre-configured password change condition of the specific account level to the plurality of service devices to collectively change the passwords that match the specific account level.

17. In Paragraph 13, the above server is, A password generation algorithm defining rules for generating a password based on at least one password generation key is transmitted to the plurality of service devices, and the at least one password generation key is provided to the plurality of service devices so that the plurality of service devices generate the same password that matches a specific account level. A system characterized by changing at least one password generation key according to a pre-configured password change condition of the specific account level, and providing the changed at least one password generation key to the plurality of service devices to collectively change passwords matching the specific account level.

Citation Information

Patent Citations

  • Information processing system, information processing device, information processing method, and program

    JP7158692B2

  • Apparatus and methods for storing electronic access clients

    KR1020140107168A

  • Smart Industrial Safety Integrated Management System

    KR102677042B1

  • Coggingless Coreless BLDC Motor

    KR102697517B1

  • Determining authentication assurance from user-level and account-level indicators

    US10911425B1