Management system for managing password for accessing plurality of service devices, and service device access method for management system
The password management system uses a password mapping table to securely manage multiple devices by transmitting mapping numbers instead of passwords, simplifying changes and ensuring access restrictions, thus enhancing security and reducing operator burden.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-05
- Publication Date
- 2026-04-02
AI Technical Summary
Existing password management systems face challenges in securely managing multiple service devices, including the inconvenience of manual password changes and security vulnerabilities during transmission, especially when dealing with dozens or hundreds of devices.
A password management system using a password mapping table where multiple passwords are pre-set, allowing only password mapping numbers to be transmitted, and a method to restrict access based on mapping numbers and additional information like working time and device permissions.
Enhances security by preventing direct password transmission, simplifies password changes across multiple devices, and reduces operator load while ensuring access is restricted to permitted devices and times.
Smart Images

Figure KR2025013789_02042026_PF_FP_ABST
Abstract
Description
A management system for managing passwords for accessing multiple service devices and a method for accessing service devices of the management system
[0001] The present invention relates to a password management system for managing passwords for an operator to access a plurality of service devices.
[0002] A password refers to a unique string of characters entered by an operator to a service device so that the device can identify them as an operator with legitimate authority. It is widely used as a basic security procedure to authenticate authorized operators. However, since using a single password for an extended period poses a risk of exposure and misuse, changing the password after a certain period is required to maintain security.
[0003] However, changing the password involves the inconvenience of requiring the operator to manually enter a new password into the service device and proceed with the password change procedure. Furthermore, while an operator can change passwords individually when there is only one or a couple of service devices, there is a problem in that the operator cannot change passwords individually when the number of service devices ranges from several to dozens or hundreds.
[0004] Meanwhile, a method was considered to provide a server to collectively manage passwords for multiple service devices and to change passwords collectively using said server. However, this method presents a problem in that the operator must know the passwords changed by the server; furthermore, if the operator receives the passwords from the server via their own terminal, there is a risk of security vulnerabilities arising during the password transmission process. In other words, if the passwords provided from the server to the operator's terminal are stolen, there is a problem that they could be used for malicious access to the aforementioned multiple service devices.
[0005] Accordingly, various methods are currently being researched to collectively manage passwords for the aforementioned multiple service devices while strengthening the security of passwords provided to worker terminals.
[0006] The present invention aims to solve the aforementioned problems and other problems, and aims to provide a password management system capable of maintaining high security for the changed passwords by using a password table in which multiple passwords are pre-set to collectively change the passwords for the multiple service devices, and by transmitting only the information of the password mapping number of the password table mapped to the changed password to the worker terminal instead of the changed password, thereby preventing the transmission of the password, and a connection method for accessing the service devices from the management system.
[0007] Furthermore, the present invention aims to provide a password management system capable of restricting access to and operation of a service device when an operator attempts to access a service device for which operation is not permitted, and a method for accessing the service device from the management system.
[0008] Furthermore, the present invention aims to provide a password management system capable of restricting access to and operation of a service device when an operator attempts to access the service device during an operation time when operation is not permitted, and a method for accessing the service device from the management system.
[0009] According to one aspect of the present invention for achieving the above or other purposes, a password management system according to an embodiment of the present invention comprises: a server that provides a password mapping table configured such that a plurality of different passwords are each matched to a different mapping number to a plurality of service devices and at least one pre-registered worker terminal, and provides a specific mapping number corresponding to any one password included in the password mapping table to the plurality of service devices; a worker terminal that requests information regarding any one password from the server, and when the specific mapping number is received as a response to the request, detects a password corresponding to the specific mapping number from a previously stored password mapping table and inputs a user input according to the detected password to any one of the plurality of service devices; and a plurality of service devices that set any one password as a password that allows access based on the password mapping table provided by the server and the specific mapping number, and provide a service corresponding to any one password to the worker terminal when the user input input from the worker terminal is the password that allows access.
[0010] In one embodiment, the server provides a different mapping number that matches one of the passwords and another password to the plurality of service devices depending on whether a preset password change condition is satisfied, and the password change condition is satisfied when a preset time elapses or a preset event occurs.
[0011] In one embodiment, the preset event is characterized by including a case where a new service device is included in the plurality of service devices or at least one service device is removed from the plurality of service devices.
[0012] In one embodiment, the server is characterized by, when information regarding any one of the passwords is requested from the worker terminal, requesting authentication information of the worker who is the owner of the worker terminal, and providing the specific mapping number to the worker terminal when the worker is authenticated based on the authentication information received through the worker terminal.
[0013] In one embodiment, the server is characterized by issuing a temporary password with a limited number of uses or usage time to the worker terminal when the worker is authenticated, and providing the specific mapping number to the worker terminal when a temporary password not restricted by the restriction condition for usage is received from the worker terminal.
[0014] In one embodiment, when the worker is authenticated, the server provides at least one of the following as additional information to the worker terminal along with the specific mapping number: information on the work allowance time for which work is permitted to the authenticated worker and information on at least one service device for which work is permitted; the worker terminal further inputs the additional information to the service device when the user input corresponding to the password corresponding to the specific mapping number is input to the service device; and the service device determines whether to allow the worker terminal to connect based on the additional information when the user input from the worker terminal is the password for which access is permitted.
[0015] In one embodiment, the server is characterized by, when the worker is authenticated, encrypting at least one of information regarding the working time for which work is permitted to the authenticated worker and information regarding at least one service device for which work is permitted, and providing the encrypted additional information to the worker terminal along with the specific mapping number.
[0016] In one embodiment, the server encrypts information regarding at least one service device to which work is permitted for the authenticated worker into information regarding the work time to which work is permitted for the authenticated worker, and the service device detects the current time, decrypts the additional encrypted information into information regarding the work time corresponding to the detected current time, and determines whether to allow the worker terminal to connect based on the decrypted information regarding the at least one service device.
[0017] In one embodiment, the server encrypts the additional information based on the specific mapping number, and the service device decrypts the additional information based on the mapping number of the password corresponding to the user input entered from the worker terminal.
[0018] In one embodiment, the worker terminal is provided with a display unit capable of outputting visual information, and outputs a password corresponding to a specific mapping number detected from a previously stored password mapping table as visual information through the display unit, and the plurality of service devices include a light sensor capable of acquiring visual information, and recognizes visual information output through the display unit of the worker terminal through the light sensor, and scans the recognized visual information to detect user input included in the visual information.
[0019] In one embodiment, the time information is characterized as being information in which a password corresponding to the specific mapping number is visualized as a QR (Quick Response) code or a barcode image.
[0020] In one embodiment, the server encrypts and transmits the specific mapping number based on the unique information of the authenticated worker's pre-registered worker terminal, and the worker terminal obtains the specific mapping number by decrypting the encrypted specific mapping number received from the server based on the unique information of the worker terminal.
[0021] In one embodiment, the server images a bit sequence obtained by binaryizing the encrypted specific mapping number and transmits it as an encrypted image according to a preset image compression format, and the worker terminal decompresses the received encrypted image into a bit sequence according to the preset image compression format and decodes the decompressed bit sequence into the specific mapping number.
[0022] In one embodiment, the server images the second bit sequence in which the unique information of the authenticated worker's registered worker terminal is binary-coded and inserted at a preset location of the first bit sequence in which the encrypted specific mapping number is binary-coded; and the worker terminal decompresses the received encrypted image into a bit sequence according to the preset image compression format, and obtains the specific mapping number by encoding the bit sequence in which the second bit sequence is removed from a preset location of the decompressed bit sequence.
[0023] According to one aspect of the present invention for achieving the above or other purposes, a method for connecting a service device in a password management system according to an embodiment of the present invention comprises: a step in which the server transmits a password mapping table, configured such that a plurality of different passwords are each matched to a different mapping number, to the plurality of service devices and at least one worker terminal registered with the server; a step in which the server transmits a specific mapping number corresponding to any one of the passwords in the password mapping table to the plurality of service devices according to whether a pre-configured password change condition is satisfied; a step in which the plurality of service devices set a password corresponding to the specific mapping number as a password that allows access to the plurality of service devices; a step in which the worker terminal requests connection information from the server that allows access to at least one of the plurality of service devices; a step in which the server transmits the specific mapping number as the connection information to the worker terminal as a response to the received request; a step in which the worker terminal detects a password matching the specific mapping number from the password mapping table previously received from the server; and a step in which the worker terminal receives a user input corresponding to the detected password and the received user input is the plurality The method is characterized by comprising the steps of transmitting to one of the service devices, the service device determining whether the received user input matches a password that allows the connection, and the service device allowing the connection of the worker terminal that transmitted the user input according to the determination result.
[0024] In one embodiment, the step of the server transmitting the specific mapping number to the worker terminal comprises: the server requesting authentication information of the worker from the worker terminal; the server authenticating the worker through the authentication information provided by the worker terminal in accordance with the request; the server transmitting a temporary password with a limited number of uses or usage time to the worker terminal when the authentication of the worker is successful; the worker terminal transmitting the worker's input corresponding to the temporary password to the server; the server allowing the connection of the worker terminal based on whether the worker's input matches the temporary password and whether the temporary password satisfies a restriction condition; and the server transmitting the specific mapping number to the worker terminal when the connection of the worker terminal is allowed.
[0025] In one embodiment, the authentication information is characterized by including at least one of the following: the worker's work location information, the unique information of the worker terminal possessed by the worker, biometric information for biometric recognition of the worker, and authentication information provided by an accredited certification authority that provides authentication services.
[0026] In one embodiment, the step of the server transmitting the specific mapping number to the worker terminal further comprises the step of the server detecting information on the working time for which work is permitted to the worker or information on at least one service device for which work is permitted to the worker, and the step of the server transmitting the detected information on the working time or information on the at least one service device to the worker terminal together with the specific mapping number as additional information.
[0027] In one embodiment, the step of the worker terminal transmitting the user input to any one of the plurality of service devices further includes the step of the worker terminal transmitting additional information together with the user input to any one of the service devices, and the step of the service device allowing the connection of the worker terminal that transmitted the user input further includes the step of the service device detecting the current time or its own unique information when the received user input matches the password for which the connection is allowed, the step of the service device checking whether information corresponding to the detected current time or its own unique information is included in the additional information, and the step of the service device determining whether to allow the connection of the worker terminal that transmitted the user input according to the result of the check.
[0028] According to at least one embodiment of the present invention, the present invention allows a server to collectively change passwords for a plurality of service devices using a password table in which a plurality of passwords are pre-set. When a worker terminal of an authenticated worker is connected, only the password mapping number information of the password table mapped to the changed password can be transmitted to the connected worker terminal. Then, the worker terminal can access the service device and perform operations by inputting the password corresponding to the password mapping number from the stored password table into each service device. Accordingly, the present invention has the effect of maintaining high security for the changed passwords by not directly transmitting the passwords changed by the server to the worker terminal. In addition, since the passwords of the plurality of service devices are periodically and automatically changed by the server, the load on the worker for changing passwords for the plurality of service devices can be reduced.
[0029] Furthermore, according to at least one embodiment of the present invention, the present invention may provide information regarding a password mapping number to a worker terminal, and simultaneously provide at least one of information regarding service devices to which work is permitted for the authenticated worker and information regarding the work time to which work is permitted for the authenticated worker. The provided information is provided together with the password entered when the worker terminal transmits the password, and by comparing it with the information of the service device or the current time, the permission to access the service device and to perform work can be determined. Accordingly, the present invention has the effect of restricting access to a service device to which work is not permitted or access to a service device at a time when work is not permitted.
[0030] FIG. 1 is a block diagram illustrating the configuration of a management system for managing passwords for accessing a plurality of service devices according to an embodiment of the present invention.
[0031] FIG. 2 is a flowchart illustrating the operation process of managing passwords for a plurality of service devices using a password matching table in a management system according to an embodiment of the present invention.
[0032] FIG. 3 is a flowchart illustrating the process of a worker accessing a service device through a password management number provided by a server in a management system according to an embodiment of the present invention.
[0033] FIG. 4a is a flowchart illustrating an operation process in which information on the working time allowed to the worker is further provided along with password mapping number information in a management system according to an embodiment of the present invention.
[0034] FIG. 4b is a flowchart illustrating the operation process in which a service device determines whether to allow access and operation of a worker terminal based on random number information input along with a password in a management system according to an embodiment of the present invention.
[0035] FIG. 5a is a flowchart illustrating the operation process in which information about a service device allowed to a worker is further provided along with password mapping number information in a management system according to an embodiment of the present invention.
[0036] FIG. 5b is a flowchart illustrating the operation process in which a service device determines whether to allow a worker's work based on information of the service device that is entered along with a password in a management system according to an embodiment of the present invention.
[0037] FIG. 6 is a flowchart illustrating the operation process of randomizing (encrypting) information provided to a worker terminal using information regarding the working time allowed to the worker as a random number key in a management system according to an embodiment of the present invention.
[0038] FIG. 7 is a flowchart illustrating the operation process in which a service device decrypts information provided from a worker terminal using information of the current time as a random number key in a management system according to an embodiment of the present invention.
[0039] FIG. 8 is a flowchart illustrating the operation process in which a worker terminal accesses a service device using a password image corresponding to a password mapping number provided from a server in a management system according to an embodiment of the present invention.
[0040] FIG. 9 is an example diagram illustrating an example of a password image used in FIG. 8.
[0041] FIG. 10 is a flowchart illustrating the operation process in which password mapping number information is encrypted and decrypted according to the unique information of the worker terminal during the operation process of FIG. 8.
[0042] FIG. 11 is a flowchart illustrating the operation process of image-transmitting information including a password mapping number as an example of the encryption / decryption process of FIG. 10.
[0043] FIG. 12 is a flowchart illustrating the operation process of encrypting and transmitting imaged password mapping number information as an example of the encryption and decryption process of FIG. 10.
[0044] It should be noted that technical terms used in this specification are used merely to describe specific embodiments and are not intended to limit the invention. Additionally, singular expressions used in this specification include plural expressions unless the context clearly indicates otherwise. The suffixes "module" and "part" for components used in the following description are assigned or used interchangeably solely for the ease of drafting the specification and do not inherently possess distinct meanings or roles.
[0045] In this specification, terms such as "composed of" or "comprising" should not be interpreted as necessarily including all of the various components or steps described in the specification, and should be interpreted as potentially excluding some of the components or steps, or including additional components or steps.
[0046] In addition, when describing the technology disclosed in this specification, if it is determined that a detailed description of related prior art could obscure the essence of the technology disclosed in this specification, such detailed description is omitted.
[0047] In addition, the attached drawings are intended only to facilitate understanding of the embodiments disclosed in this specification, and the technical concept disclosed in this specification is not limited by the attached drawings; it should be understood that they include all modifications, equivalents, and substitutions that fall within the concept and technical scope of the present invention. Furthermore, not only each of the embodiments described below, but also combinations of embodiments may fall within the concept and technical scope of the present invention as modifications, equivalents, and substitutions that fall within the concept and technical scope of the present invention.
[0048] Hereinafter, embodiments disclosed in this specification will be described in detail with reference to the attached drawings.
[0049] FIG. 1 is a block diagram illustrating the configuration of a management system for managing passwords for accessing a plurality of service devices according to an embodiment of the present invention.
[0050] Referring to FIG. 1, a management system (1) according to an embodiment of the present invention may be configured to include a plurality of service devices (10-1, 10-2, ... 10-n), a server (20) that communicates with the plurality of service devices, and a worker terminal (30) that can communicate with the plurality of service devices and the server.
[0051] Here, the service device may be a device that allows access only when a designated password is entered. For example, the service device may be a device capable of providing communication services and may include a monitoring device, such as a CCTV, which allows only authorized operators to view recorded or captured video, or a protection device, such as a protection relay, which performs monitoring, measurement, and protection functions for power facilities. Additionally, the service device may include an Intelligent Electric Device (IED) capable of controlling at least one function of a power facility, as well as performing monitoring, measurement, and protection functions for at least one power facility.
[0052] Such a service device may be equipped with at least one of a display unit, such as a display capable of outputting visual information capable of displaying information, or an audio output unit capable of outputting audio information. Additionally, it may be equipped with a light sensor capable of acquiring visual information, such as a camera. In this case, the service device may be equipped with a function capable of scanning and recognizing visual information, i.e., an image, acquired through the light sensor.
[0053] Additionally, the service device may have a pre-assigned password for access, and may be configured to allow access only through the pre-assigned password. In this case, the service device may be connected via wired or wireless communication to a device that wishes to access the service device, such as a worker terminal (30), and when a communication connection is established, the service device may be required to input the pre-assigned password.
[0054] And if the password entered through the worker terminal (30) matches the aforementioned pre-specified password, the service device may allow the connection of the worker terminal (30). And if the connection is allowed, the service device may provide a pre-specified service in response to the request of the worker terminal (30).
[0055] For example, the service device may provide the worker terminal (30) with monitoring data collected by the service device, i.e., recorded or captured video data, or monitoring data collected over a certain period regarding the status of specific power facilities or equipment, in response to a request from the worker terminal (30) to which the connection is permitted. Alternatively, the service device may provide information on a setting value currently set in the service device, for example, a reference value for performing a specific function, or provide a function to change the setting value, in response to a request from the worker terminal (30) to which the connection is permitted.
[0056] Here, the service device may provide different services depending on the password entered from the worker terminal (30). For example, there may be multiple passwords that allow access from the worker terminal (30) to each service device. In this case, the different passwords may correspond to different services provided by the service device. And when the provided services are different, the range of information or functions that the service device can provide to the worker terminal that is allowed access may differ.
[0057] For example, if the password entered from the worker terminal (30) matches a pre-set first password, the service device may provide the worker terminal (30) with a service (first service) that allows only verification of the measured value measured by the service device. On the other hand, if the password entered from the worker terminal (30) matches a pre-set second password, the service device may provide the worker terminal (30) with a service (second service) that allows verification of not only the measured value measured by the service device but also a reference value (set value) set to perform a specific function by the service device. Furthermore, if the password entered from the worker terminal (30) matches a pre-set third password, the service device may provide the worker terminal (30) with a service (third service) that allows verification of the measured value measured by the service device and the reference value for performing a specific function, as well as the change of the set value (third service).
[0058] Such passwords may be assigned to the worker terminal (30) based on the authentication result of the worker who is the owner of the worker terminal (30). That is, if the services allowed to the worker are up to the first service, information related to the first password may be provided to the worker terminal (30). On the other hand, if the services allowed to the worker are the second service or the third service, information related to the second password or the third password may be provided to the worker terminal (30).
[0059] In order to manage the authority for each worker and the passwords to be provided to each worker's terminal accordingly, the management system (1) according to an embodiment of the present invention may include a server (20) that can be wirelessly or wiredly connected to the plurality of service devices.
[0060] The server (20) above may store multiple passwords that are different for the services that can be provided as described above. It may also include information about a worker capable of performing work for each service device (10-1, 10-2, ..., 10-n). In this case, the information about the worker may include authentication information capable of authenticating each worker, and for each worker, may include information about the service devices to which work is allowed for each worker, and information about the working time of each worker.
[0061] Here, the authentication information of the worker may include the worker's work location information, information of the terminal possessed by the worker, i.e., the worker terminal (30) (e.g., unique information such as a serial number), and biometric information for biometric recognition of the worker, such as a password, fingerprint, iris, or facial image. Additionally, the authentication information may include authentication information provided by an accredited certification authority that provides authentication services, such as a telecommunications company that provides authentication services.
[0062] In addition, the information regarding the service devices subject to the work may include unique information of the service devices to which the worker is permitted to work, or information of unique codes such as the location code of the service device. Furthermore, the information regarding the worker's working time may include part-time information regarding which the worker is permitted to work according to the worker's work schedule.
[0063] Meanwhile, the server (20) can manage the passwords set for each service device. For example, the server (20) can collectively change the passwords that allow the worker terminal (30) to access each service device at a predetermined time interval.
[0064] Here, the server (20) may use a password mapping table containing multiple different passwords to manage the passwords set for each service device. In this case, the password mapping table may be a table configured such that multiple different passwords are matched to different password mapping numbers, as shown in Table 1 below. The server (20) may change the password set for each service device by randomly selecting a password included in the password mapping table at a predetermined time interval.
[0065] Table 1 below is an example of the password mapping table above, illustrating an example where 20 different passwords are each matched to different password mapping numbers.
[0066] PW Mapping Number Password115098525134663657247......1992378020102347
[0067] Meanwhile, the above password mapping table may be stored in both the server (20) and each service device. To this end, the above password mapping table may be distributed to each service device by the server (20). For example, the above password mapping table may be transmitted from the server (20) and stored during the initial connection operation when the service device first communicates with the server (20).
[0068] In this way, since the same password mapping table stored in the server (20) is stored in each service device, the server (20) can transmit only the information of the password mapping number corresponding to a specific password from the password mapping table to each service device. Then, each service device that receives the password mapping number information can change the password set in each service device collectively by changing the password to a password that matches the received password mapping number. Therefore, password changes for each of the multiple service devices can be achieved simply by changing the password mapping number that matches a specific password. Furthermore, when changing the password, only the password mapping number information is transmitted and the password information is not directly transmitted, so the security of the password information between the server (20) and each service device can be further strengthened.
[0069] In this way, the operation process of collectively changing the passwords that a worker terminal (30) can access in each service device (10-1, 10-2, ..., 10-n) through the password mapping table above will be examined in more detail with reference to Fig. 2 below.
[0070] Meanwhile, the above password mapping table may also be transmitted to a pre-configured worker terminal (30) of a worker whose authentication has been completed. For example, when a worker first registers their terminal (worker terminal (30)), the server (20) may store information about the worker terminal (30) and, at the same time, transmit information about the password mapping table shared with each service device to the worker terminal (30). That is, the information about the password mapping table may be provided from the server (20) only to the pre-configured terminal of the worker registered with the server (20).
[0071] Here, various devices may be used as the worker terminal (30). For example, the worker terminal (30) may include a smartphone, a laptop computer, a PDA (personal digital assistant), a slate PC, a tablet PC, an ultrabook, or a wearable device, such as a smartwatch, equipped with at least one display such as a display.
[0072] Meanwhile, in the case of a worker terminal not registered with the server (20), the password mapping table may not be provided by the server (20) before being registered with the server (20). Therefore, in order for a worker to replace a worker terminal with another device, a process of registering a new worker terminal with the server (20) may be required. In this case, deletion of the worker's previously registered worker terminal (30) may be required from the server (20), and deletion confirmation information transmitted from the previously registered worker terminal (30) to the server (20) during the deletion process may be required. That is, in order to register a new worker terminal with the server (20), the deletion confirmation information provided by the previous worker terminal (30) must be received by the server (20) so that the previously registered worker terminal (30) can be deleted from the server (20), and server registration for the new worker terminal can be achieved only after the previous worker terminal (30) is deleted from the server (20).
[0073] Meanwhile, a previously registered worker terminal (30) may request information on a password that can access the service device from the server (20). In this case, the server (20) may request authentication information for authenticating the worker from the worker terminal (30), and may provide the information on the password to the worker terminal (30) only when the worker is authenticated.
[0074] For example, the server (20) may request pre-configured authentication information of the worker for authentication of the worker. The authentication information may include a password pre-configured by the worker or biometric information for biometric authentication, such as a fingerprint, iris, or facial image. Additionally, the authentication information may include authentication information provided by an accredited certification authority that provides authentication services, such as a telecommunications company that provides authentication services.
[0075] Additionally, the server (20) may perform additional authentication using additional authentication information of the worker. In this case, as authentication information for the additional authentication, at least one of the following may be used: information on the worker's work location, information on the terminal possessed by the worker, i.e., the worker terminal (30) (e.g., unique information such as a serial number), and information on the working time allowed to the worker. That is, even if the worker is authenticated through the authentication information, the additional authentication of the worker may fail if the worker's work location differs from the current location of the worker terminal (30) requesting the password information, or if the time at which the password information was requested from the worker terminal (30) is outside the working time allowed to the worker. Additionally, if the worker terminal requesting the password information is not the worker terminal of a previously registered worker (e.g., comparison of the unique information of the authenticated worker's previously registered worker terminal), the additional authentication of the worker may fail. And if the additional authentication fails, the server (20) may not provide the password information to the worker terminal (30).
[0076] Meanwhile, if the above authentication or both the above authentication and additional authentication are completed, the server (20) may provide password mapping number information currently provided to each service device in response to a password information request from the authenticated worker terminal (30). In this case, if the worker terminal (30) is already registered with the server (20), the password mapping table may be stored in the worker terminal (30). Accordingly, the worker terminal (30) can search for a password matching the password mapping number information provided by the server (20) from the stored password mapping table.
[0077] Here, when the authentication of the worker is completed, the server (20) may issue a temporary password to the worker terminal (30) requesting the password information, which may be used for a limited time or only a limited number of times (e.g., once). And if the temporary password granted within the limited time or only once is transmitted from the worker terminal (30), the server may allow connection with the server (20). And if connection with the server (20) is allowed, the server may provide the password mapping number information currently provided to each service device to the worker terminal (30).
[0078] In this case, the temporary password has a limited time or number of uses as described above, and may be deleted and become unusable once the available time has elapsed or the limited number of uses has been exhausted. That is, if the available time has elapsed or the allowed number of uses has been exhausted, even an authenticated worker cannot connect to the server (20) using the issued temporary password, and accordingly, an authentication procedure may be required again.
[0079] Meanwhile, when the worker terminal (30) receives password mapping number information from the server (20), it can establish a communication connection with the service device. For example, the worker terminal (30) can establish a communication connection with the service device through a wired connection or a wireless connection. When the service device and the worker terminal (30) are established in communication, the password corresponding to the password mapping number received from the server (20), which is retrieved from a previously stored password mapping table, can be entered into the service device connected in communication.
[0080] In this case, the retrieved password may be displayed on the display unit of the worker terminal (30), and the password may be entered into a service device connected to the worker terminal (30) by the worker directly entering the displayed password into the user input unit of the worker terminal (30). Alternatively, the worker terminal (30) may enter the retrieved password into a service device connected to the worker terminal directly upon the worker's request.
[0081] Then, the service device can check whether the password entered from the communication-connected worker terminal (30) matches the currently set password, that is, the password corresponding to the password mapping number set by the server (20). And only if the password matches, the connection of the communication-connected worker terminal (30) can be allowed.
[0082] Here, the service device can check whether the password received from the communication-connected worker terminal (30) matches any one of the passwords corresponding to the password mapping numbers set by the server (20). In this case, the different passwords corresponding to the mapping numbers may be passwords for which the service device can provide different services. Accordingly, the service device can provide a service corresponding to the password that matches the password received from the communication-connected worker terminal (30) in accordance with the request of the communication-connected worker terminal (30).
[0083] As described above, in the management system (1) according to an embodiment of the present invention, when there is a password request from a worker terminal (30), the server (20) can provide password mapping number information instead of password information. Therefore, since password information that allows access to a service device is not directly transmitted to the worker terminal (30), the security of the password information between the server (20) and the worker terminal (30) can be further enhanced.
[0084] FIG. 2 is a flowchart illustrating the operation process of managing passwords for a plurality of service devices using a password matching table in a management system (1) according to an embodiment of the present invention.
[0085] Referring to FIG. 2, first, the server (20) of the management system (1) of the present invention may receive a password mapping table as shown in Table 1 from the administrator of the server (20) or a higher-level system (S200). Then, the received password mapping table may be transmitted to each service device (10-1, 10-2, ... 10-n) that is connected to the server (20) (S200-1, S200-2, ... , S200-n). Then, each service device (10-1, 10-2, ... 10-n) may store the received password mapping table.
[0086] Then, the server (20) can arbitrarily determine a password mapping number that matches any one of the passwords included in the password mapping table (S210). Then, the determined password mapping number can be transmitted to each service device (10-1, 10-2, ... 10-n). Then, each service device (10-1, 10-2, ... 10-n) can search for a password that matches the password mapping number received from the server (20) from the previously stored password mapping table. Then, the searched password can be set as a password that allows access to the service device (S220-1, S220-2, ... S220-n).
[0087] In the above step S201, the server (20) can determine a plurality of password mapping numbers corresponding to a plurality of different passwords for each service that can be provided by each service device (10-1, 10-2, ... 10-n). And in steps S220-1 to S220-n, the plurality of password mapping numbers determined by the server (20) can be transmitted to each service device (10-1, 10-2, ... 10-n).
[0088] In this case, the server (20) can transmit information about the service corresponding to each password mapping number while transmitting each password mapping number. Accordingly, one or more password mapping numbers corresponding to each of the one or more services that can be provided by the service device can be transmitted to each service device (10-1, 10-2, ... 10-n), and a password corresponding to a different password mapping number can be set for each service device (10-1, 10-2, ... 10-n) for each different service that can be provided.
[0089] Meanwhile, when a password mapping number is transmitted to each service device (10-1, 10-2, ... 10-n), the server (20) can check whether a pre-set password change condition is satisfied (S230). Here, the pre-set password change condition can be determined based on whether a pre-set time has elapsed since the time when the password mapping number was determined, for example, the time when the password mapping number was changed (the time of the previous change).
[0090] Alternatively, if a pre-configured event occurs, for example, when a new service device is connected or an existing connected service device is removed from the management system (1), the server (20) may determine that the pre-configured password change condition is satisfied. Then, the server (20) may proceed again to step S210 to restart the process of determining the password mapping number, and accordingly, a password mapping number corresponding to the new password may be determined.
[0091] Meanwhile, the above-mentioned password change condition may include a password change delay condition. For example, if a failure occurs in at least one service device, the server (20) may hold the elapsed time of the above-mentioned time while the service device that failed is being repaired. In this case, if the elapsed time is held, the point at which the password change condition is satisfied may be delayed by the held time. For example, if it takes 10 hours for a service device to fail and be repaired, the server (20) may hold the elapsed time of the above-mentioned time for a period corresponding to the above 10 hours. Accordingly, the point at which the password change condition is satisfied may be delayed by 10 hours depending on the elapsed time of the above-mentioned time.
[0092] Meanwhile, when a new password mapping number is determined, the server (20) can repeat steps S210-1 through S210-n to transmit the new password mapping number to each service device (10-1, 10-2, ... 10-n). Then, each service device (10-1, 10-2, ... 10-n) can repeat steps S220-1 through S220-n to set a password corresponding to the new password mapping number received from the server (20).
[0093] Accordingly, the management system (1) according to an embodiment of the present invention can collectively change the passwords that allow access to the plurality of service devices (10-1, 10-2, ... 10-n) without transmitting the actual passwords, simply by transmitting password mapping number information corresponding to a specific password from the server (20) to each service device (10-1, 10-2, ... 10-n). In addition, the server (20) can automatically change the passwords that allow access to each service device when a preset time has elapsed or a preset event occurs, by automatically transmitting new password mapping number information to each service device (10-1, 10-2, ... 10-n) depending on whether a preset password change condition is satisfied.
[0094] Meanwhile, FIG. 3 is a flowchart illustrating the process of a worker accessing a service device (10) using a worker terminal (30) through a password management number provided by a server in a management system (1) according to an embodiment of the present invention. In the following description, the service device (10) may refer to any one of the plurality of service devices (10-1, 10-2, ... 10-n) that is connected to the worker terminal (30) through communication.
[0095] Referring to FIG. 3, first, the worker terminal (30) can establish a communication connection with the server (20) (S300). Then, the worker terminal (30) can request connection information from the communication-connected server (20) to access the service device (10) for the purpose of performing work on the service device (10) (S301). In this case, simultaneously with the request for the connection information, the worker can transmit authentication information to the server (20) to authenticate themselves. Then, the server (20) can perform authentication of the worker based on the authentication information received from the worker terminal (30) (S302).
[0096] Here, the authentication information may include a password pre-set by the operator or biometric information for biometric authentication, such as a fingerprint, iris, or facial image. Additionally, the authentication information may include authentication information provided by an accredited certification authority that provides authentication services, such as a telecommunications carrier that provides authentication services.
[0097] Here, the server (20) may request additional authentication information from the worker. In this case, the additional authentication information may include at least one of the worker's work location information, information about the terminal the worker possesses, i.e., the worker terminal (30) (e.g., unique information such as a serial number), and information about the working time allowed to the worker. In this case, even if the worker is authenticated through the authentication information, for example, biometric information, the additional authentication of the worker may fail if the worker's work location differs from the current location of the worker terminal (30) requesting the password information, or if the time at which the password information was requested is outside the working time allowed to the worker. Additionally, the additional authentication of the worker may fail if the worker terminal requesting the password information is not the worker terminal of a previously registered worker. And if the additional authentication fails, the server (20) may determine that the worker's authentication has failed in step S302.
[0098] Meanwhile, in step S302 above, if the authentication of the worker according to the authentication information provided by the worker terminal (30) is successful, the server (20) may transmit a temporary password that allows access to the server (20) to the authenticated worker's worker terminal (30) (S304). The temporary password may be a password that can be used for a limited time or a limited number of times (e.g., one-time use), and may mean a password that no longer allows access to the server (20) once the pre-set usage period has expired or the number of uses has been exhausted.
[0099] When the above temporary password is provided to the worker terminal (30), the worker terminal (30) can input the temporary password provided from the server (20) into the server (20) (S306). For example, the above temporary password may be displayed on the display unit of the worker terminal (30), and the worker may input the above temporary password into the server (20) connected to the worker terminal (30) by directly inputting the displayed temporary password into the user input unit of the worker terminal (30). Alternatively, the worker terminal (30) may input the above displayed temporary password into the server (20) connected to the worker terminal (30) directly upon the worker's request.
[0100] Then, the server (20) can check whether the temporary password entered from the worker terminal (30) is a password that allows access to the server (20) (S308). That is, the server (20) can check not only whether the temporary password matches, but also whether the restriction conditions set on the temporary password are not satisfied.
[0101] And if the above temporary password does not match or if the restriction conditions set on the above temporary password are satisfied, that is, if the usage period has expired or the number of uses has been exhausted, the connection of the worker terminal (30) to the server (20) according to the above temporary password may not be allowed. Then the server (20) may send notification information indicating that the temporary password does not match to the worker terminal (30) currently connected to the communication (S309).
[0102] Meanwhile, the server (20) may allow the worker terminal (30) to connect to the server (20) if the temporary password entered from the worker terminal (30) matches and the restriction conditions set on the temporary password are not satisfied, that is, if the usage period has not expired or there are remaining usage attempts (S310). And when the worker terminal (30) is allowed to connect to the server (20), the server (20) may transmit password mapping number information corresponding to the password currently set on each service device to the connected worker terminal (30) (S311).
[0103] Meanwhile, there may be multiple passwords allowed to access each service device, depending on the available services. Accordingly, in step S311, the server (20) may transmit to the worker terminal (30) only the password mapping number mapped to a password corresponding to a specific service allowed to be provided to the authenticated worker, among the multiple password mapping numbers corresponding to each of the multiple passwords allowed to access each service device.
[0104] Then, the worker terminal (30) can detect a password corresponding to a password mapping number provided by the server (20) from a previously stored password mapping table (S312). Here, the password mapping table may be provided by the server (20) when the worker terminal (30) is first registered with the server (20). That is, the password mapping table may be provided by the server (20) only to the worker terminal (30) registered with the server (20).
[0105] And the worker terminal (30) can establish a communication connection with the service device (10) to which the worker intends to perform work. The communication connection with the service device (10) can be established through a wired connection via a wired cable connecting the worker terminal (30) and the service device (10). Alternatively, it can be established through short-range wireless communication formed between the worker terminal (30) and the service device (10).
[0106] When a communication connection is established with the service device (10), the worker terminal (30) can input the password detected through the password mapping number provided by the server (20) into the service device (10) (S314). For example, the worker terminal (30) can display the detected password on the display unit of the worker terminal (30), and the worker can input the password into the service device (10) connected to the worker terminal (30) by directly inputting the displayed password through the user input unit of the worker terminal (30). Alternatively, the worker terminal (30) may input the displayed password into the service device (10) connected to the worker terminal (30) directly upon the worker's request.
[0107] Then, the service device (10) can check whether the password entered from the worker terminal (30) is a password that matches the password mapping number provided by the server (20), which is a password currently allowed for connection (S316). And if the password does not match as a result of the check in step S316, the service device (10) can transmit password mismatch information to the worker terminal (30) and not allow the connection of the worker terminal (30) (S319). Then, the password mismatch information can be displayed on the display unit of the worker terminal (30).
[0108] On the other hand, if, as a result of the check in step S316, the password entered from the worker terminal (30) matches the password that matches the password mapping number provided by the server (20), the service device (10) may allow the connection of the currently connected worker terminal (30) and allow the work of the worker terminal (30) (S318). In this case, the service device (10) may provide the worker terminal (30) with a service that is allowed according to the password entered from the worker terminal (30) in accordance with the request of the worker terminal (30).
[0109] Meanwhile, the server (20) according to an embodiment of the present invention checks information on the work location and work time allowed to the authenticated worker through the additional authentication, and can cause the authentication to fail if the worker terminal (30) requests connection information to the service device (10) at a work time or work location not allowed to the worker. Accordingly, it is possible to prevent the worker terminal (30) from connecting to the service device (10) at a time or work location not allowed to the worker.
[0110] However, as described above, the management system (1) of the present invention is configured such that a worker terminal (30) obtains connection information, i.e., password mapping number information, of a service device (10) through a server (20), and the worker terminal (30) accesses the service device (10) through the obtained password mapping number information. The time or place where the worker terminal (30) obtains the connection information from the server (20) may differ from the time or place where the worker terminal (30) accesses the service device (10). Accordingly, when the connection information is obtained from the server (20) at a time or place where additional authentication is possible, it may be difficult to restrict the worker terminal that obtained the connection information through the authentication from accessing the service device at a different time or place, for example, at an unauthorized time or place.
[0111] Accordingly, the management system (1) of the present invention can restrict access to the service device (10) by the worker terminal (30) not only through additional authentication but also depending on whether the worker of the worker terminal (30) is allowed to perform work on the service device (10) when the actual worker terminal (30) accesses the service device (10).
[0112] FIGS. 4a and 4b are flowcharts illustrating the operation processes of a server (20) and a service device (10) as an embodiment of a management system (1) according to an embodiment of the present invention, wherein information on the working time allowed to a worker is further provided to a worker terminal (30) along with password mapping number information, which is connection information to a service device (10), and the service device (10) further checks the information on the working time allowed to the worker, thereby enabling only authorized workers to perform work on the service device (10).
[0113] First, FIG. 4a is a flowchart illustrating the operation process of a server (20) that further provides information on the working time allowed to the worker, along with the password mapping number information, to the worker terminal (30).
[0114] Referring to FIG. 4a, the server (20) of the management system (1) according to an embodiment of the present invention can first detect a password mapping number corresponding to the password currently set on each service device when the temporary password information received from the worker terminal (30) of the authenticated worker matches and the restriction condition is not satisfied (S400).
[0115] And the server (20) can detect the worker of the worker terminal (30) that has been assigned the temporary password (S402). Then, it can detect previously stored work information corresponding to the detected worker, and detect information on the work time allowed for the detected worker (part time information) from the detected work information (S404).
[0116] Here, the above work information may be information including information on the work time allowed to the worker and information on the service devices to which the worker is allowed to work. That is, the above work information is information that includes each worker's own work time and information on the service devices that the worker must work on, and may be part of work schedule information that encompasses the entire work schedule of all workers over a certain period. In this case, the above work schedule information may be stored in the server (20), and when the server (20) detects a worker of the worker terminal (30) that has been assigned the temporary password in step S402, the server (20) may extract work content corresponding to the detected worker from the above work schedule information and detect information on the work time allowed to the detected worker from the extracted work content.
[0117] Here, if the above worker is a rotating worker in which multiple workers take turns working for a certain period of time, the information on the work time may be part-time information regarding the work time allowed to the detected worker.
[0118] For example, if the 24 hours of a day are divided into 3-hour intervals, the part-time information corresponding to each work hour may be as shown in Table 2 below.
[0119] Work Time Part Time 09:00:01 ~ 12:00:00 5 12:00:01 ~ 15:00:00 6 15:00:01 ~ 18:00:00 7 18:00:01 ~ 21:00:00 8 21:00:01 ~ 00:00:00 1 00:00:01 ~ 03:00:00 2 03:00:01 ~ 06:00:00 3 06:00:01 ~ 09:00:00 4
[0120] If the part-time information for each work time is as shown in Table 2 above, the part-time information for a worker granted work time from 9:00 AM to 12:00 PM may be 5. In this case, the server (20) can detect the part-time information 5 in step S404 above.
[0121] Meanwhile, when part-time information, which is information about the working time allowed to the worker, is detected, the server (20) can generate random information by randomizing the detected working time information, i.e., the part-time information, according to a pre-set random number key (S406). Here, the random number key is a key for encrypting the working time information and may be a key pre-set between the worker terminal (30) and the server (20).
[0122] Alternatively, the server (20) may use a password mapping number corresponding to the password currently set for each service device as the random number key. For example, if the password mapping number corresponding to the password currently set for each service device is 16, the server (20) may use the password mapping number '16' to randomize the part-time information '5', which is the information of the detected worker's working time, into a random number to generate random number information. For example, the server (20) may generate a random number '80' as the random number information by multiplying the password mapping number '16' by the part-time information '5'.
[0123] And when random number information is generated, the server (20) can transmit the generated random number information, along with the password mapping number information detected in step S400, to a worker terminal (30) that is allowed to connect to the server (20) (S408).
[0124] In this case, the above random number information may be hidden data that is not displayed on the worker terminal (30). That is, the above random number information may be information that is not displayed on the worker terminal (30). Therefore, if the worker inputs a password into the service device (10) by directly inputting a password corresponding to a password mapping number provided by the server (20) through the user input section of the worker terminal (30), the above random number information may not only not be displayed as a password that the worker must input, but may also be data that the worker does not need to input.
[0125] However, when the above-mentioned worker terminal (30) inputs a password corresponding to a password mapping number provided by the server (20) into the service device (10), it may transmit the random number information received along with the password mapping number along with the input password. For example, when the worker terminal (30) is connected to the service device (10) and the worker inputs a password and selects the 'transmit' key, the worker terminal (30) may transmit the random number information along with the password entered by the worker to the service device (10) connected to the communication. Alternatively, in the case where the worker terminal (30) automatically inputs a password searched according to the password mapping number provided by the server (20) into the service device (10), if the worker selects 'password transmission', the random number information along with the searched password may be transmitted to the service device (10) connected to the communication.
[0126] Then, the service device (10) that receives random number information along with the password can determine whether to allow the connection and operation of the worker terminal (30) based on the password and the random number information.
[0127] FIG. 4b is a flowchart illustrating the operation process in which, in a management system (1) according to an embodiment of the present invention, a service device (10) determines whether to allow access and operation of a worker terminal (30) based on random number information input along with a password.
[0128] First, the service device (10) can check whether the password entered from the communication-connected worker terminal (30), as shown in step S316 of FIG. 3, matches the password corresponding to the password mapping number set by the current server (20), that is, the password that allows access. And if the password entered from the worker terminal (30) matches the password that allows access, it can further check whether the worker of the worker terminal (30) is in a state where work is allowed based on the random number information.
[0129] Referring to FIG. 4b, if the password entered from the worker terminal (30) matches the password allowed for connection as a result of the password check in step S316 of FIG. 3, the service device (10) can decrypt the random number information entered along with the password from the worker terminal (30) using a pre-set random number key (S450). In this case, if the random number key is a password mapping number corresponding to the password allowed for connection currently set in the service device (10), the service device (10) can decrypt the random number information using the password mapping number.
[0130] For example, as described above, if the random number information is generated by multiplying a pre-set random number key and the worker's part-time information, and the pre-set random number key is a password mapping number, the service device (10) can decrypt the random number information based on the password mapping number that matches the password currently entered from the worker terminal (30). In this case, if the password mapping number that matches the password entered from the worker terminal (30) is '16', the service device (10) can decrypt the random number information by dividing it by the password mapping number '16' and decrypt the result into the part-time information. Therefore, as in the example described above, if the random number information is '80', the service device (10) can calculate the worker's part-time information '5' based on the password mapping number '16'.
[0131] And the service device (10) can detect the current time and detect part-time information corresponding to the detected current time (S452). Then, the part-time information corresponding to the detected current time can be compared with the decoded part-time information of the worker to check whether they match (S454).
[0132] For example, if the current time is 09:35, the service device (10) can determine the part-time information corresponding to the current time as '5' based on the above Table 2. Then, the part-time information '5' corresponding to the current time can be compared with the decrypted part-time information of the worker. In this case, since the part-time information matches each other, the service device (10) can determine that the current time is the time when work is allowed for the worker of the worker terminal (30). Accordingly, the connection of the worker terminal (30) can be allowed, and a service can be provided according to the request of the worker terminal (30) that has been allowed to connect (S456).
[0133] On the other hand, if the current time is 14:15, the service device (10) can determine the part-time information corresponding to the current time as '6' based on Table 2 above. Then, the part-time information '6' corresponding to the current time can be compared with the decrypted part-time information of the worker. In this case, if the decrypted part-time information is '5', the part-time information is inconsistent with each other, so the service device (10) can determine that the current time is a time when work is not permitted for the worker of the worker terminal (30). Therefore, the service device (10) determines that the connection request at a time when work is not permitted is an unauthorized operation and can refuse the connection of the worker terminal (30). In this case, information indicating that it is an unauthorized operation may be transmitted to and displayed on the worker terminal (30), or notification information indicating that it is an unauthorized operation may be output on the display unit of the service device (10) (S458).
[0134] Meanwhile, FIGS. 4a and 4b described above illustrate an example of rejecting a connection of a worker terminal (30) by determining whether the work is unauthorized based on whether the work time is granted to the worker; however, it is obvious that similarly, information about the service device granted to the worker can be randomized using the random number information and provided together with a password. FIGS. 5a and 5b are examples of such cases.
[0135] First, FIG. 5a is a flowchart illustrating the operation process in which information of a service device allowed to an operator, along with password mapping number information, is further provided as random number information in a management system (1) according to an embodiment of the present invention.
[0136] Referring to FIG. 5a, the server (20) of the management system (1) according to an embodiment of the present invention can detect a password mapping number corresponding to the password currently set on each service device when the temporary password information received from the worker terminal (30) of the authenticated worker matches and the restriction condition is not satisfied (S500).
[0137] And the server (20) can detect a worker of the worker terminal (30) that has been assigned the temporary password (S502). Then, it can detect previously stored work information corresponding to the detected worker, and from the detected work information, detect information related to at least one service device to which the detected worker is allowed to work (S504).
[0138] Here, the information related to the service device may be unique information of at least one service device to which the worker is allowed to work. For example, the unique information may be information such as a unique code number or serial number assigned to each service device. In this case, the unique information of at least one service device to which the worker is allowed to work may be part of work schedule information that encompasses the entire work schedule of all workers over a certain period, serving as work information for the worker. The work schedule information may be stored in the server (20), and when the server (20) detects a worker of the worker terminal (30) that has been assigned the temporary password in step S502, it may extract work content corresponding to the detected worker from the work schedule information and detect unique information of at least one service device to which the detected worker is allowed to work from the extracted work content (S506).
[0139] Meanwhile, when unique information of service devices allowed to work for the worker is detected, the server (20) can generate random information by randomizing the unique information of the detected service devices according to a pre-set random number key (S508). Here, the random number key is a key for encrypting the unique information of service devices allowed to work for the worker, and may be a key pre-set between the worker terminal (30) and the server (20).
[0140] Alternatively, the server (20) may use a password mapping number corresponding to the password currently set for each service device as the random number key. For example, if the password mapping number corresponding to the password currently set for each service device is 16, the server (20) may use the password mapping number '16' to randomize the unique information of at least one detected service device into a random number to generate random number information.
[0141] And when random number information is generated, the server (20) can transmit the generated random number information, along with the password mapping number information detected in step S500, to a worker terminal (30) that is allowed to connect to the server (20) (S510).
[0142] In this case, the above random number information may be hidden data that is not displayed on the worker terminal (30). That is, the above random number information may be information that is not displayed on the worker terminal (30). Therefore, if the worker inputs a password into the service device (10) by directly inputting a password corresponding to a password mapping number provided by the server (20) through the user input section of the worker terminal (30), the above random number information may not only not be displayed as a password that the worker must input, but may also be data that the worker does not need to input.
[0143] However, when the above-mentioned worker terminal (30) inputs a password corresponding to a password mapping number provided by the server (20) into the service device (10), it can transmit random number information received from the server (20) along with the password mapping number, along with the input password.
[0144] Then, the service device (10) that receives random number information along with the password can determine whether to allow the connection and operation of the worker terminal (30) based on the password and the random number information.
[0145] Meanwhile, FIG. 5b is a flowchart illustrating the operation process in which a service device (10) determines whether to allow a worker's work based on information of the service device that is entered along with a password in a management system (1) according to an embodiment of the present invention.
[0146] First, the service device (10) can check whether the password entered from the communication-connected worker terminal (30), as shown in step S316 of FIG. 3, matches the password corresponding to the password mapping number set by the current server (20), that is, the password that allows access. And if the password entered from the worker terminal (30) matches the password that allows access, it can further check whether the worker of the worker terminal (30) is in a state where work is allowed based on the random number information.
[0147] Referring to FIG. 5b, if the password entered from the worker terminal (30) matches the password allowed for connection as a result of the password check in step S316 of FIG. 3, the service device (10) can decrypt the random number information entered along with the password from the worker terminal (30) using a pre-set random number key (S550). In this case, if the random number key is a password mapping number corresponding to the password allowed for connection currently set in the service device (10), the service device (10) can decrypt the random number information using the password mapping number.
[0148] And the service device (10) can check whether its own unique information is included in the decrypted random number information (S552). And if its own unique information is included in the decrypted random number information, the service device (10) can determine that the worker of the currently connected worker terminal (30) is a worker who is allowed to perform work on itself. Accordingly, the service device (10) can allow the connection of the worker terminal (30) and provide a service according to the request of the worker terminal (30) that is allowed to connect (S554).
[0149] On the other hand, if, as a result of the check in step S552 above, the decrypted random number information does not contain one's own unique information, the service device (10) can determine that the worker of the currently connected worker terminal (30) is a worker for whom work is not permitted. Therefore, the service device (10) can refuse the connection of the worker terminal (30). In this case, information indicating that it is an unauthorized operation may be transmitted to and displayed on the worker terminal (30), or notification information indicating that it is an unauthorized operation may be output on the display unit of the service device (10) (S556).
[0150] Meanwhile, the server (20) of the management system (1) according to an embodiment of the present invention may randomize information of unique information of service devices that are allowed to work for an authenticated worker, and information of the work time that is allowed to work for the worker, using a random number key, and transmit the randomized information to the worker terminal (30). In this case, since the random number key that can decrypt the random information is different from the password mapping number transmitted to the authenticated worker, higher security can be maintained.
[0151] FIG. 6 is a flowchart illustrating the operation process of randomizing (encrypting) information provided to a worker terminal using information of the working time allowed to the worker as a random number key in a management system (1) according to an embodiment of the present invention in such cases.
[0152] Referring to FIG. 6, when the server (20) detects unique information of service devices to which work is allowed for the authenticated worker in step S506 of FIG. 5a, it can detect information of the work time to which work is allowed for the authenticated worker (S600). Here, the information of the work time can be detected from work schedule information that encompasses the entire work schedule of all workers for a certain period, just like the unique information of service devices to which work is allowed for the authenticated worker.
[0153] Here, if the above worker is a rotating worker in which multiple workers take turns working for a set period of time, the information on the work time may be part-time information regarding the work time allowed to the detected worker, as distinguished as shown in Table 2 above. Then, the server (20) can generate a random key using a combination of the information on the detected work time, i.e., part-time information, and the password mapping number transmitted to the authenticated worker (S602).
[0154] For example, if the password mapping number to be transmitted to the worker is '16' and the part-time information corresponding to the currently detected worker's work time is '5', the server (20) can generate a random key with 165 or 516, which is a combination of the part-time information and the password mapping number, or '80', which is the number obtained by multiplying the part-time information and the password mapping number.
[0155] Then, the server (20) can generate random number information by randomizing the unique information of the service devices that are allowed to work for the detected authenticated worker according to the generated random number key (S604). In this case, the random number information generated in step S604 may be the random number information generated in step S508 of FIG. 5a. Accordingly, the server (20) proceeds to step S510 of FIG. 5a and can transmit to the worker terminal (30) connected to the server (20) via a temporary password a password mapping number matching the password currently allowed to access each service device and the random number information generated in step S604 as a response to the input of the temporary password. Here, the random number information may be hidden information that is not displayed to the worker.
[0156] Meanwhile, as seen in FIG. 6, a service device (10) that receives random number information that has been randomized with a random number key reflecting information on the working time allowed to the worker can decode the random number information based on the information of the time at which the random number information was input from the worker terminal (30), that is, the current time.
[0157] FIG. 7 is a flowchart illustrating the operation process in which a service device (10) decrypts information provided from a worker terminal (30) using information of the current time as a random number key in a management system (1) according to an embodiment of the present invention.
[0158] Referring to FIG. 7, if the password input from the worker terminal (30) matches the password that is allowed for access as a result of the password check in step S316 of FIG. 3, the service device (10) may enter step S550, which decrypts the random number information input along with the password from the worker terminal (30) using a pre-set random number key. In this case, the service device (10) may first detect the current time and detect part-time information corresponding to the detected current time (S700). Then, the service device (10) may detect a password mapping number that matches the password input from the worker terminal (30) from a pre-stored password mapping table (S702).
[0159] And the service device (10) can generate a random number key by combining part-time information corresponding to the detected current time and a password mapping number that matches the password input from the worker terminal (30) (S704). In this case, the method of combining the part-time information and the password mapping number detected in steps S700 and S702, or the method of generating a random number key according to the part-time information and the password mapping number, may be a method agreed upon in advance with the server (20).
[0160] When a random number key is generated in step S704 above, the service device (10) can decrypt the random number information entered along with the password from the worker terminal (30) based on the generated random number key (S706). In this case, the decrypted information may include unique information of the service devices to which the worker is allowed to work. Accordingly, the service device (10) can proceed to the process below step S552 of FIG. 5b to determine whether the worker terminal (30) is connected based on whether its unique information is included in the decrypted random number information.
[0161] Accordingly, if a request for connection to a service device (10) is made during a working time that is not permitted to the worker, the worker's connection request may be rejected as the random number information is not decrypted. Even if a request for connection to a service device that is not permitted to the worker is made during a working time that is permitted, the worker's connection request may be rejected based on the unique information of the service devices included in the decrypted random number information. That is, even if the password entered from the worker terminal (30) is a password that matches a pre-configured password mapping number that is permitted to connect, if it is not during a working time permitted to the worker or if it is not a service device that is permitted to the worker, the connection of the worker terminal (30) to the service device (10) may be rejected.
[0162] Meanwhile, the above description describes a configuration in which a worker terminal (30) obtains password mapping number information obtained from a server (20), detects a password corresponding to the obtained password mapping number, and inputs the detected password into a communication-connected service device (10).
[0163] However, in this case, there is a problem that the worker must directly input the password corresponding to the password mapping number obtained from the server (20) into the worker terminal (30) that is connected to the service device (10). In addition, if the worker terminal (30) automatically transmits the password corresponding to the password mapping number to the service device (10), there is a problem that communication between the service device (10) and the worker terminal (30) is established before the worker terminal (30) inputs the password into the service device (10), and thus communication between the service device (10) and the worker terminal (30) is established before it is determined whether the worker terminal (30) is a terminal that is allowed to connect.
[0164] In order to solve the problem of communication being established between the service device (10) and the worker terminal (30) before the worker terminal (30) is determined to be a terminal that is allowed to connect, such as when the worker terminal (30) must directly enter a password or before it is determined whether the worker terminal (30) is a terminal that is allowed to connect, the management system (1) according to an embodiment of the present invention may allow the worker terminal (30) to image a password corresponding to password mapping number information obtained from the server (20), and the service device (10) to recognize the imaged password and extract the password through an image recognition unit provided in the service device (10), such as a camera, to determine whether the worker terminal (30) is a terminal that is allowed to connect.
[0165] FIG. 8 is a flowchart illustrating the operation process in which a worker terminal (30) connects to a service device (10) using a password image corresponding to a password mapping number provided by a server (20) in a management system (1) according to an embodiment of the present invention. FIG. 9 is an example diagram illustrating an example of a password image used in FIG. 8.
[0166] Referring to FIG. 8, in a management system (1) according to an embodiment of the present invention, a worker terminal (30) may establish a communication connection with a server (20) to obtain information on a password mapping number corresponding to a password currently set on a service device (10), in the same manner as step S300 of FIG. 3. Then, as described in steps S302 to S310 of FIG. 3, authentication information for authenticating a worker may be transmitted to the server (20) along with a request for connection information, i.e., password mapping number information, and the server (20) may perform authentication of the worker through the received authentication information. When the worker is authenticated, the server (20) may issue a temporary password with a limited number of uses or usage period to the worker terminal (30), and may allow access to the worker terminal (30) based on whether a temporary password identical to the issued temporary password is entered from the worker terminal (30).
[0167] When a connection to the above worker terminal (30) is allowed, the server (20) can transmit password mapping number information corresponding to the password currently set for each service device to the worker terminal (30) in response to a connection information request from the worker terminal (30) that is allowed to connect (S800). Then, the worker terminal (30) can detect the password corresponding to the password mapping number received from the server (20) from a previously stored password mapping table (S802).
[0168] Then, the worker terminal (30) can image the detected password according to a preset image method (S804). In this case, the worker terminal (30) can convert the detected password into binary numbers and generate a password image based on the converted binary sequence, i.e., the bit sequence. For example, the password image may be in the form of a QR (Quick Response) code (900) corresponding to the detected password, as shown in FIG. 9, or a barcode.
[0169] And in step S804 above, when an imaged password, i.e., a password image, is generated, the worker terminal (30) can display the generated password image on the display unit at the request of the worker. In this case, at the request of the worker, the worker terminal (30) can display the password image at a location where it can be scanned by the optical sensor of the service device (10) that the worker intends to work on. Then, the service device (10) scans the password image displayed on the display unit of the worker terminal (30) through the optical sensor, for example, a camera, and can recognize and identify the scanned password image (S808).
[0170] When a password image is recognized and identified in step S808 above, the service device (10) can extract a password included in the recognized and identified password image from the password image (S810). When a password is extracted from the password image, the service device (10) can check whether the extracted password is a password that allows access to the service device (10), as described below in step S316 of FIG. 3. If at least one password that allows access matches the password extracted from the password image, the service device can allow a communication connection with the worker terminal (30) where the password image is displayed on the display unit and allow access to the worker terminal (30). Then, in response to a request from the worker terminal (30), the service that is allowed according to the password extracted from the recognized and identified password image can be provided to the worker terminal (30).
[0171] However, if the password extracted from the password image does not match any of the at least one password that is allowed to connect, the service device (10) can output information indicating that the password does not match on the display unit of the service device (10).
[0172] Meanwhile, the above description explains that when an authenticated worker enters a suitable temporary password, the server (20) transmits password mapping number information as a response. However, the security of the password mapping number may be further enhanced by encrypting and transmitting the password mapping number information transmitted from the server (20) to the worker terminal (30).
[0173] In this case, the step S800 in which password mapping number information is provided from the server (20) to the worker terminal (30) in FIG. 8 may further include the step of the server (20) encrypting the password mapping number and the worker terminal (30) decrypting it.
[0174] FIG. 10 illustrates the operation process in which password mapping number information is encrypted and transmitted as described above, and illustrates the operation process in which the password mapping number is encrypted and transmitted according to the unique information pre-set by the worker terminal (30).
[0175] Referring to FIG. 10, the server (20) of the management system (1) according to an embodiment of the present invention can detect the pre-set unique information of the worker terminal (30) when an authenticated worker enters a suitable temporary password through the worker terminal (30) (S1000).
[0176] In this case, the server (20) can detect the unique information of a pre-registered worker terminal corresponding to the authenticated worker as the pre-set unique information. Then, the server (20) can use the pre-set unique information of the worker terminal (30) as an encryption key to encrypt a password mapping number corresponding to the password currently allowed to access each service device (S1002).
[0177] Here, the server (20) can encrypt only the password mapping number mapped to one of the passwords corresponding to one of the services allowed to be provided to the authenticated worker, among the plurality of password mapping numbers corresponding to one of the plurality of passwords allowed to be accessed to each of the service devices, using the pre-set unique information.
[0178] And the server (20) can provide the encrypted password mapping number in response to the input of the appropriate temporary password of the authenticated worker (S1004). Then the worker terminal (30) receives the encrypted password mapping number and can decrypt the received password mapping number based on pre-set unique information, for example, the unique information of the worker terminal (30) (S1006). Then, proceeding to step S802 of FIG. 8, the password corresponding to the decrypted password mapping number can be detected from the password mapping table stored in the worker terminal (30).
[0179] Meanwhile, although the above description uses the unique information of the worker terminal (30) that has been pre-set as an example to be used as an encryption key and a decryption key, this is merely an example of the present invention and is not limited thereto. That is, it is obvious that any other information set by the worker may be used as the encryption key and the decryption key. In this case, the worker may pre-set the encryption / decryption key when registering the worker terminal (30) with the server (20), and when encrypted password mapping number information is received from the server (20) in step S1004, the worker may decrypt the password mapping number information by inputting the encryption / decryption key set by the worker in step S1006.
[0180] Meanwhile, according to the above description, the present invention has mentioned that when the server (20) transmits password mapping number information to the worker terminal (30), it may additionally transmit not only the password mapping number but also unique information of service devices to which the worker is allowed to work and information on the working time to which the worker is allowed to work (e.g., part-time information) by converting them into random number information. In this case, to enhance the security of the password mapping number and the random number information, the server (20) may image the password mapping number information and the random number information, convert the imaged password mapping number information and the random number information into a preset format, for example, an image compression format, and transmit them as image data.
[0181] FIG. 11 is a flowchart illustrating an operation process in which information including password mapping numbers is converted into an image and transmitted as information in an image format, as an example of the encryption and decryption process of such password mapping number information.
[0182] Referring to FIG. 11, the server (20) of the management system (1) according to an embodiment of the present invention can detect a password mapping number corresponding to one of the passwords currently allowed to access the service device that corresponds to the service allowed to be provided to the authenticated worker when the authenticated worker enters a suitable temporary password through the worker terminal (30). Then, the server can detect the work information of the authenticated worker from work schedule information that encompasses the entire work schedule of all workers for a certain period, and detect the unique information of the service devices allowed to work for the authenticated worker and the information on the work time allowed to work for the authenticated worker (e.g., part-time information). Then, at least one of the detected unique information of the service devices or the information on the work time can be randomized as described in FIG. 4a or FIG. 5a to generate random number information (S1100).
[0183] Then, the server (20) can convert the detected password mapping number and the generated random number information into binary and encode them into a bit sequence (S1101). Then, the bit sequence corresponding to the password mapping number and the random number information can be converted into an image (S1102). For example, the bit sequence corresponding to the password mapping number and the random number information can be converted into an image such as a QR code or a barcode, as seen in FIG. 9. Then, the server (20) can compress the bit sequence, that is, the image corresponding to the password mapping number and the random number information, using a preset image compression format to generate image data according to the image compression format. Here, the image compression format may be a widely known image compression format such as PNG, GIF, JPEG, BMP, TIFF, HEIC, etc.
[0184] Then, the server (20) can transmit an image of the password mapping number and random number information, compressed in the pre-set image compression format, in response to the input of a suitable temporary password by the authenticated worker (S1104). Then, the worker terminal (30) receives the image of the pre-set compression format transmitted from the server (20), and can decompress the received image according to the pre-set compression format and re-encode it into a bit sequence (S1106). Then, the encoded bit sequence can be decoded into the password mapping number and random number information (S1108).
[0185] A worker terminal (30) that has obtained a password mapping number and random number information from a server (20) through step S1108 above can detect a password mapped to the password mapping number and input the detected password into a service device (10) to be accessed. As the password is input and the random number information is transmitted to the service device (10) together, as described in FIGS. 4b and 5b, it can be determined whether the worker of the worker terminal (30) has accessed the service device (10) during the permitted working time or has attempted to access the service device where the working is permitted. Depending on the determination result, it can be determined whether to access the service device (10) even if the passwords match.
[0186] Meanwhile, the worker terminal (30) that has obtained the password mapping number and random number information from the server (20) may image the password and random number information mapped to the password mapping number as described in FIGS. 8 and 9 and display them on the display unit. In this case, the password image may include the random number information. Therefore, when the service device (10) recognizes and identifies the password image, the random number information along with the password may be input into the service device (10).
[0187] Meanwhile, in the case of the image in FIG. 11 that visualizes the password mapping number and random number information, the image itself may represent the password mapping number and random number information (e.g., QR code image). Therefore, there may be a problem in that the password mapping number may be exposed if the image is exposed. Accordingly, the image in which the password mapping number and random number information are visualized may be encrypted and transmitted, thereby transmitting the password mapping number and random number information to the worker terminal (30) in the form of an encrypted image.
[0188] FIG. 12 is a flowchart illustrating the operation process of encrypting and transmitting image-based password mapping number information.
[0189] Referring to FIG. 12, the server (20) of the management system (1) according to an embodiment of the present invention can detect a password mapping number corresponding to one of the services that are allowed to be provided to the authenticated worker among the passwords that are currently allowed to access the service device when an authenticated worker enters a suitable temporary password through the worker terminal (30).
[0190] In addition, work information of the authenticated worker can be detected from work schedule information that encompasses the entire work schedules of all workers over a certain period, thereby detecting unique information of service devices to which work is permitted for the authenticated worker and information on the work time to which work is permitted for the authenticated worker (e.g., part-time information). Then, at least one of the detected unique information of service devices or the information on the work time can be randomized as described in FIG. 4a or FIG. 5a to generate random number information (S1200).
[0191] And the server (20) can binarize the detected password mapping number and the random number information to encode them into a first bit sequence (S1201). And the server (20) can binarize the unique information of the authenticated worker's terminal registered in the server (20) to encode it into a second bit sequence (S1202). And the second bit sequence can be inserted into a pre-set position of the first bit sequence to generate an encrypted bit sequence (S1204).
[0192] To do this, the server (20) can shift the part corresponding to the position after the first bit sequence by the number of digits of the second bit sequence. For example, if the number of digits of the second bit sequence is 64 (64 bits) and the position is 35, the server (20) can shift the remaining bit sequence after the 35th bit of the first bit sequence by the number of digits of the second bit sequence, which is 64 bits. Then, the second bit sequence can be inserted into the shifted position to generate the encrypted bit sequence.
[0193] Then, the server (20) can convert the encrypted bit sequence into an image (S1206). For example, the server (20) can convert the encrypted bit sequence into an image such as a QR code or a barcode, as seen in FIG. 9. Then, the server (20) can compress the image corresponding to the encrypted bit sequence using a preset image compression format to generate image data according to the preset image compression format. Here, the image compression format may be a widely known image compression format such as PNG, GIF, JPEG, BMP, TIFF, HEIC, etc.
[0194] Then, the server (20) can transmit an image of the encrypted bit sequence compressed in a preset image compression format in response to the input of a suitable temporary password by the authenticated worker (S1208). Then, the worker terminal (30) receives the image of the preset compression format transmitted from the server (20), and can decompress the received image according to the preset compression format and re-encode it into a bit sequence (S1210).
[0195] And the worker terminal (30) can generate a bit sequence by binarizing its own unique information. Then, through the decompression of the image in step S1210, a bit sequence corresponding to the number of digits of the bit sequence corresponding to its own unique information can be extracted from a pre-set location of the encoded bit sequence, that is, a pre-set location agreed upon in advance with the server (20) (S1212). Then, the extracted bit sequence and the bit sequence corresponding to its own unique information can be compared to check whether the bit sequences match (S1214).
[0196] And, depending on the comparison result, if the bit sequence corresponding to one's own unique information and the bit sequence extracted from a pre-set position of the bit sequence corresponding to the image match, the bits after the extracted bit sequence in the bit sequence corresponding to the image can be reverse-shifted by the number of digits of the bit sequence corresponding to one's own unique information (S1216).
[0197] For example, as in the example described above, if the pre-set position is 35 and the bit sequence corresponding to the unique information of the worker terminal (30) is 64 bits, the worker terminal (30) can reverse shift the 99th bit (35 + 64) of the encoded bit sequence by 64 bits through the decompression of the image received from the server (20). Thus, in the encrypted bit sequence, a bit sequence identical to the first bit sequence before the second bit sequence is inserted can be generated through the reverse shift of the bit sequence.
[0198] Then, the worker terminal (30) can decode the reverse-shifted bit sequence, i.e., the first bit sequence, to obtain password mapping number and random number information (S1218).
[0199] A worker terminal (30) that has obtained a password mapping number and random number information from a server (20) through step S1208 can detect a password mapped to the password mapping number and input the detected password into a service device (10) to be accessed. As the password is input and the random number information is transmitted to the service device (10) together, as described in FIGS. 4b and 5b, it can be determined whether the worker of the worker terminal (30) has accessed the service device (10) during the permitted working time or has attempted to access the service device where the working is permitted. Depending on the determination result, it can be determined whether to access the service device (10) even if the passwords match.
[0200] Meanwhile, the worker terminal (30) that has obtained the password mapping number and random number information from the server (20) may display the password and random number information mapped to the password mapping number as an image (e.g., QR code or barcode) on the display unit as described in FIGS. 8 and 9. In this case, the password image may include the random number information. Therefore, when the service device (10) recognizes and identifies the password image, the random number information may be input to the service device (10) along with the password.
[0201] Meanwhile, although specific embodiments have been described in the above description of the present invention, various modifications may be implemented without departing from the scope of the present invention. In particular, in the embodiments of the present invention, cases where transmission errors occur during the transmission of information were not considered; however, in the case of transmission errors, it is understood that the error may be detected through a CRC check or checksum method and displayed on the worker terminal (30), etc. In this case, if a transmission error occurs, the worker may obtain information including a password mapping number again from the server (20).
[0202] Meanwhile, in the description above, it was mentioned that the server (20) may provide a temporary password to the authenticated worker's worker terminal (30) to access the server (20). In this case, the temporary password to access the server (20) is issued only to the authenticated worker, and it goes without saying that the temporary password may also be used as a password for accessing the service device (10).
[0203] For example, if the server (20) successfully authenticates a worker who requested connection information, it may provide a temporary password with a limited usage time or number of uses to the authenticated worker's pre-registered worker terminal (30). The temporary password may also be distributed to a plurality of service devices that are connected to the server (20). Accordingly, the worker terminal (30) may be able to connect to the plurality of service devices using the temporary password.
[0204] Meanwhile, as mentioned in the description above, multiple passwords allowing access may be set for each service device. It was also mentioned that the services provided by each of the aforementioned passwords may differ. In this case, access to the service device using the aforementioned temporary password may only provide basic functions; for example, if the service device is a measuring device or an IED, it may only provide a service that allows verification of the measured values measured by the service device. Through this, it is possible to receive the limited services provided by the service device even if a password corresponding to a suitable password mapping number is not entered.
[0205] In addition, the provision of restricted services using a temporary password in this manner can be carried out regardless of the time limits for work allowed to the operator or whether the operator is permitted to work on the relevant service device. That is, an authenticated operator can receive basic services provided by each service device by accessing it via the temporary password, even if it is a time when work is not permitted or a service device for which work is not scheduled. By doing so, the authenticated operator can check the status of multiple service devices regardless of whether work is permitted when necessary, thereby enabling flexible response to urgent situations.
[0206] The present invention described above can be implemented as computer-readable code on a medium on which a program is recorded. A computer-readable medium includes all types of recording devices in which data that can be read by a computer system is stored. Examples of computer-readable media include HDD (Hard Disk Drive), SSD (Solid State Disk), SSD (Silicon Disk Drive), ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage device, etc., and also include implementation in the form of a carrier wave (e.g., transmission over the Internet).
[0207] Accordingly, the above detailed description should not be interpreted restrictively in all respects but should be considered exemplary. The scope of the invention should be determined by a reasonable interpretation of the appended claims, and all modifications within the equivalent scope of the invention are included within the scope of the invention.
Claims
1. A server that provides a password mapping table configured such that multiple different passwords are each matched to a different mapping number to multiple service devices and at least one pre-registered worker terminal, and provides a specific mapping number corresponding to any one password included in the password mapping table to the multiple service devices; A worker terminal that requests information regarding any one of the above passwords from the server, and when a specific mapping number is received in response to the request, detects a password corresponding to the specific mapping number from a previously stored password mapping table and inputs a user input according to the detected password to any one of the plurality of service devices; and A password management system characterized by including a plurality of service devices that set one of the passwords as an allowed password based on the password mapping table provided by the server and the specific mapping number, and provide a service corresponding to one of the passwords to the worker terminal when the user input entered from the worker terminal is the allowed password.
2. In Paragraph 1, The above server is, Depending on whether the pre-set password change conditions are satisfied, another mapping number matching one of the above passwords and another password is provided to the plurality of service devices, and The above password change conditions are, A password management system characterized by being satisfied when a preset time elapses or a preset event occurs.
3. In paragraph 2, the previously set event is, A password management system characterized by including a case in which a new service device is included in the plurality of service devices or at least one service device is removed from the plurality of service devices.
4. In paragraph 1, the server is, A password management system characterized by, when information regarding any one of the above passwords is requested from the above worker terminal, requesting authentication information of the worker who is the owner of the above worker terminal, and providing the above specific mapping number to the above worker terminal when the worker is authenticated based on the authentication information received through the above worker terminal.
5. In paragraph 4, the above server is, A password management system characterized by issuing a temporary password with a limited number of uses or usage time to the worker terminal when the worker is authenticated, and providing the specific mapping number to the worker terminal when a temporary password not restricted by the restriction condition for usage restriction is received from the worker terminal.
6. In Paragraph 4, The above server is, When the above worker is authenticated, at least one of the information on the work allowance time during which work is permitted for the authenticated worker and the information on at least one service device to which work is permitted is provided to the worker terminal along with the specific mapping number as additional information, and The above worker terminal is, When the user input corresponding to the password corresponding to the specific mapping number is input to any one of the service devices, the additional information is further input to any one of the service devices, and Any one of the above service devices is, A password management system characterized by determining whether to allow access to the worker terminal based on additional information when the user input entered from the worker terminal is a password that allows access.
7. In Paragraph 6, The above server is, A password management system characterized by, when the above-mentioned worker is authenticated, encrypting at least one of information regarding the working time for which work is permitted to the authenticated worker and information regarding at least one service device for which work is permitted, and providing the encrypted additional information together with the specific mapping number to the worker terminal.
8. In Paragraph 7, The above server is, Information regarding at least one service device for which work is permitted to the above-mentioned authenticated worker is encrypted into information regarding the work time for which work is permitted to the above-mentioned authenticated worker, and Any one of the above service devices is, A password management system characterized by detecting a current time, decrypting additional encrypted information using information on a work time corresponding to the detected current time, and determining whether to allow access to the worker terminal based on the decrypted information regarding at least one service device.
9. In Paragraph 7, The above server is, Encrypt the additional information based on the specific mapping number above, and Any one of the above service devices is, A password management system characterized by decrypting the additional information based on a mapping number of a password corresponding to a user input entered from the above-mentioned worker terminal.
10. In Paragraph 1, The above worker terminal is, A display unit capable of outputting time information is provided, and a password corresponding to the specific mapping number detected from a previously stored password mapping table is output as time information through the display unit. The above plurality of service devices are, A password management system characterized by including a light sensor capable of acquiring visual information, recognizing visual information output through a display unit of a worker terminal via the light sensor, and scanning the recognized visual information to detect user input included in the visual information.
11. In Paragraph 10, the above-mentioned time information is, A password management system characterized by the information in which a password corresponding to the above-mentioned specific mapping number is visualized as a QR (Quick Response) code or barcode image.
12. In Paragraph 4, The above server is, Based on the unique information of the previously registered worker terminal of the above-mentioned authenticated worker, the above-mentioned specific mapping number is encrypted and transmitted, and The above worker terminal is, A password management system characterized by obtaining a specific mapping number by decrypting the specific mapping number received from the server based on the unique information of the worker terminal.
13. In Paragraph 12, The above server is, The bit sequence obtained by binaryizing the above-mentioned encrypted specific mapping number is converted into an image and transmitted as an encrypted image according to a pre-set image compression format, and The above worker terminal is, A password management system characterized by decompressing the received password image into a bit sequence according to the preset image compression format and decoding the decompressed bit sequence into the specific mapping number.
14. In Paragraph 13, The above server is, The second bit sequence, in which the unique information of the authenticated worker's previously registered worker terminal is binary-coded and inserted into a pre-set position of the first bit sequence, which is binary-coded from the aforementioned encrypted specific mapping number, is imaged, and The above worker terminal is, A password management system characterized by decompressing the received password image into a bit sequence according to the preset image compression format, and encoding the bit sequence obtained by removing the second bit sequence from a preset position of the decompressed bit sequence to obtain the specific mapping number.
15. A method for connecting to a service device in a password management system comprising a server, a plurality of service devices and a worker terminal, and managing a password capable of connecting to the plurality of service devices, wherein The server transmits a password mapping table, configured such that a plurality of different passwords are each matched to a different mapping number, to the plurality of service devices and at least one worker terminal registered with the server; The server transmits a specific mapping number corresponding to one of the passwords in the password mapping table to the plurality of service devices depending on whether a pre-set password change condition is satisfied; The step of the plurality of service devices setting a password corresponding to the specific mapping number as a password that allows access to the plurality of service devices; The step of the above worker terminal requesting connection information from the server that enables it to connect to at least one of the plurality of service devices; The server transmits the specific mapping number as the connection information to the worker terminal as a response to the received request; The above worker terminal detects a password matching the specific mapping number from the password mapping table previously received from the server; The above worker terminal receives user input corresponding to the detected password and transmits the received user input to any one of the plurality of service devices; One of the above service devices determines whether the received user input matches the password that allows the connection; and, A method for connecting a service device of a password management system, characterized in that any one of the above service devices includes the step of allowing the connection of a worker terminal that transmitted the user input according to the determination result.
16. In Paragraph 15, The step of the server transmitting the specific mapping number to the worker terminal is: The above server requests the worker's authentication information from the worker terminal; The step of the server authenticating the worker through authentication information provided from the worker terminal in accordance with the request; The server transmits a temporary password with a limited number of uses or usage time to the worker terminal when the authentication of the worker is successful; The above worker terminal transmits the worker's input corresponding to the above temporary password to the server; The server allows access to the worker terminal based on whether the worker's input matches the temporary password and whether the temporary password satisfies restriction conditions; and, A method for connecting a service device of a password management system, characterized by including the step of transmitting a specific mapping number to the worker terminal when the server allows the worker terminal to connect.
17. In Paragraph 16, the above certification information is, A method for accessing a service device of a password management system, characterized by including at least one of the following: work location information of the worker, unique information of a worker terminal possessed by the worker, biometric information for biometric recognition of the worker, and authentication information provided by an accredited certification authority providing authentication services.
18. In Paragraph 15, The step of the server transmitting the specific mapping number to the worker terminal is: The server detects information of the working time for which work is permitted to the worker or information of at least one service device for which work is permitted to the worker; and, A method for accessing a service device of a password management system, characterized by further including the step of the server transmitting information of the detected work time or information of the at least one service device to the worker terminal along with the specific mapping number as additional information.
19. In Paragraph 18, The step of the above worker terminal transmitting the above user input to any one of the plurality of service devices is The above worker terminal further includes the step of transmitting the additional information together with the user input to any one of the service devices, and The step in which any one of the above service devices allows the connection of the worker terminal that transmitted the user input is: A step in which any one of the above service devices detects the current time or its own unique information when the received user input matches the password that allows the connection; A step in which any one of the above service devices checks whether information corresponding to the detected current time or its own unique information is included in the additional information; and, A method for connecting a service device of a password management system, characterized in that any one of the above service devices further includes a step of determining whether to allow the connection of a worker terminal that transmitted the user input according to the check result.
Citation Information
Patent Citations
Password management device, password management method and password management system
JP2012190056A
Information processing system, information processing device, information processing method, and program
JP7158692B2
Apparatus and method for managing password
KR101627078B1
Method and server for improving security of password authentication
KR101749304B1
Password management system
US20170070494A1