Management system for managing password for accessing plurality of service devices and method for controlling management system

The password management system addresses security and convenience issues by using a shared password algorithm with variable and fixed keys, enabling secure, collective password updates across multiple devices without direct key transmission.

WO2026071556A1PCT designated stage Publication Date: 2026-04-02LS ELECTRIC CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing password management systems face challenges in securely managing multiple service devices, including the inconvenience of manual password changes and security vulnerabilities during transmission, especially when collective password management is employed.

Method used

A password management system and method that uses a server to generate and distribute a shared password algorithm to both worker terminals and service devices, allowing secure, collective password changes based on variable and fixed keys, with hint information for key updates, reducing direct transmission of changed keys.

Benefits of technology

Enhances security by preventing direct transmission of changed keys, ensuring secure and efficient password updates across multiple devices while maintaining synchronization and reducing manual input efforts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025013791_02042026_PF_FP_ABST
    Figure KR2025013791_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a password management system for managing a password for accessing a plurality of service devices. The password management system comprises: a password algorithm defining a rule for generating a password on the basis of a plurality of keys; a server for providing the plurality of keys to the plurality of service devices and a worker terminal, and changing at least one key according to whether a password change condition is satisfied; the worker terminal for generating a first password according to the password algorithm on the basis of the at least one key provided from the server, and inputting the first password to any one of the plurality of service devices; and the plurality of service devices for generating a second password according to the password algorithm on the basis of the at least one key provided from the server, and when the first password input from the worker terminal matches the second password, allowing access of the worker terminal and providing a service according to a request of the worker terminal.
Need to check novelty before this filing date? Find Prior Art

Description

A management system for managing passwords for accessing multiple service devices and a control method for the management system

[0001] The present invention relates to a password management system for managing passwords for an operator to access a plurality of service devices.

[0002] A password refers to a unique string of characters entered by an operator to a service device so that the device can identify them as an operator with legitimate authority. It is widely used as a basic security procedure to authenticate authorized operators. However, since using a single password for an extended period poses a risk of exposure and misuse, changing the password after a certain period is required to maintain security.

[0003] However, changing the password involves the inconvenience of requiring the operator to manually enter a new password into the service device and proceed with the password change procedure. Furthermore, while an operator can change passwords individually when there is only one or a couple of service devices, there is a problem in that the operator cannot change passwords individually when the number of service devices ranges from several to dozens or hundreds.

[0004] Meanwhile, a method was considered to provide a server to collectively manage passwords for multiple service devices and to change passwords collectively using said server. However, this method presents a problem in that the operator must know the passwords changed by the server; furthermore, if the operator receives the passwords from the server via their own terminal, there is a risk of security vulnerabilities arising during the password transmission process. In other words, if the passwords provided from the server to the operator's terminal are stolen, there is a problem that they could be used for malicious access to the aforementioned multiple service devices.

[0005] Accordingly, various methods are currently being researched to collectively manage passwords for the aforementioned multiple service devices while strengthening the security of passwords provided to worker terminals.

[0006] The present invention aims to solve the aforementioned problems and other problems, and aims to provide a password management system and a control method for the management system that can not only manage passwords for a plurality of service devices collectively but also maintain high security for passwords set on each service device.

[0007] Furthermore, the present invention aims to provide a password management system capable of restricting access to and operation of a service device when an operator attempts to access the service device during an operation time when operation is not permitted, and a method for controlling the management system.

[0008] According to one aspect of the present invention for achieving the above or other purposes, a password management system according to an embodiment of the present invention comprises: a password algorithm defining rules for generating a password based on at least one key; a server that provides the at least one key to a plurality of service devices and a worker terminal and changes the at least one key according to whether a preset password change condition is satisfied; a worker terminal that stores the password algorithm provided by the server, generates a first password according to the password algorithm based on at least one key provided by the server, and inputs the generated first password to any one of the plurality of service devices; and the plurality of service devices that store the password algorithm provided by the server, generate a second password according to the password algorithm based on at least one key provided by the server, allow the connection of the worker terminal when the first password input by the worker terminal matches the second password, and provide a service according to the request of the worker terminal.

[0009] In one embodiment, the at least one key is characterized as being information at a point in time immediately prior to when the at least one key was changed.

[0010] In one embodiment, the password is generated according to a rule defined in the password algorithm based on at least one fixed key having a predetermined fixed value and at least one variable key having a value that can be varied by the server, and the server changes the value of the variable key depending on whether the password change condition is satisfied and transmits it to the worker terminal and the plurality of service devices.

[0011] In one embodiment, each of the plurality of service devices determines at least one of its own unique information and its own connection address information as the at least one fixed key, and generates the second password based on the determined fixed key and at least one variable key provided by the server.

[0012] In one embodiment, the worker terminal is characterized by, before entering the first password, establishing a communication connection to a service device to request a service, identifying the service device, detecting at least one of the unique information and connection address information of the identified service device as at least one fixed key, and generating the first password based on the detected fixed key and at least one variable key provided by the server.

[0013] In one embodiment, the worker terminal requests information of service devices for which work is permitted from the server to the worker, who is the owner of the worker terminal, and stores unique information and connection address information of at least one of the provided service devices in response to the request.

[0014] In one embodiment, the server stores situation information related to the changed at least one key whenever the at least one key is changed for password change, and changes the at least one key according to the previously stored situation information, and when the at least one key is changed, transmits hint information referring to the at least one situation information related to the changed at least one key to the worker terminal, and the worker terminal detects at least one situation information corresponding to the hint information among the previously stored situation information, generates the changed at least one changed key according to the detected at least one situation information, and generates the first password according to the generated at least one key.

[0015] In one embodiment, the server provides a password algorithm table configured such that a plurality of different password algorithms are each matched to a different mapping number to the plurality of service devices and the worker terminal, provides a mapping number corresponding to any one password algorithm included in the password algorithm table to the plurality of service devices and the worker terminal, and when a preset change condition is satisfied, provides a different mapping number corresponding to the other password algorithm to the plurality of service devices, thereby changing the password algorithm used by the plurality of service devices for password generation.

[0016] In one embodiment, the preset change condition is characterized by being satisfied when a preset time elapses or a preset event occurs.

[0017] In one embodiment, the preset event is characterized by including a case where a new service device is included in the plurality of service devices or at least one service device is removed from the plurality of service devices.

[0018] In one embodiment, the server is characterized by, when information regarding a password algorithm is requested from the worker terminal, requesting authentication information of the worker who is the owner of the worker terminal, and when the worker is authenticated based on the authentication information received through the worker terminal, providing the worker terminal with a specific mapping number corresponding to the password algorithm currently used by the plurality of service devices for password generation.

[0019] In one embodiment, the server is characterized by issuing a temporary password with a limited number of uses or usage time to the worker terminal when the worker is authenticated, and providing the specific mapping number to the worker terminal when a temporary password not restricted by the restriction condition for usage is received from the worker terminal.

[0020] In one embodiment, the server is characterized by providing information on the work time during which work is allowed to the authenticated worker, along with the specific mapping number, to the worker terminal when the worker is authenticated.

[0021] In one embodiment, the worker terminal inputs information of the work time along with the first password into a service device, and the service device that receives the first password determines whether to allow the worker terminal to connect based on information of the time at which the first password was entered and information of the work time when the first password and the second password match.

[0022] In addition, according to one aspect of the present invention, a control method for a password management system that manages a password capable of accessing the plurality of service devices, comprising a server, a plurality of service devices, and a worker terminal according to an embodiment of the present invention, is characterized in that the server comprises: a password algorithm that defines a rule for generating a password based on at least one key, and the step of transmitting the at least one key to the worker terminal and the plurality of service devices; the step of the worker terminal generating a first password according to the password algorithm provided by the server based on at least one key provided by the server; the step of each of the plurality of service devices generating a second password according to the password algorithm provided by the server based on at least one key provided by the server; the step of the worker terminal inputting the first password into any one of the plurality of service devices; and the step of the service device allowing the worker terminal to access and providing a service requested by the worker terminal when the first password input by the worker terminal matches the second password.

[0023] In one embodiment, the method further comprises the steps of: the server changing the at least one key according to whether a preset password change condition is satisfied; the server transmitting the changed at least one key to the worker terminal and the plurality of service devices; and the worker terminal and the plurality of service devices generating a first password and a second password changed according to the changed at least one key.

[0024] In one embodiment, each of the plurality of service devices determines at least one of its own unique information and its own connection address information as the at least one fixed key, and generates the second password based on the determined fixed key and at least one variable key provided by the server, and the worker terminal, before inputting the first password, establishes a communication connection to any one of the service devices to request a service to identify the service device, detects at least one of the unique information and connection address information of the identified service device as the at least one fixed key, and generates the first password based on the detected fixed key and at least one variable key provided by the server.

[0025] In one embodiment, the step of the server transmitting the password algorithm and the at least one key to the worker terminal and the plurality of service devices further comprises the step of the server transmitting to the plurality of service devices a password algorithm table configured such that a plurality of different password algorithms are each matched to a different mapping number and a specific algorithm mapping number corresponding to one of the password algorithms, and the step of the plurality of service devices detecting a password algorithm according to the specific algorithm mapping number; and the step of the server changing the at least one key further comprises the step of the server transmitting to the plurality of service devices another algorithm mapping number corresponding to a password algorithm different from one of the password algorithms, and the step of the plurality of service devices detecting the other password algorithm according to the other algorithm mapping number.

[0026] In one embodiment, the step of the worker terminal generating the first password comprises: the server providing the specific algorithm mapping number to the worker terminal in response to a request from the worker terminal; the worker terminal detecting any one password algorithm corresponding to the specific algorithm mapping number from the password algorithm table; and the worker terminal generating the first password according to the detected password algorithm based on at least one key provided by the server.

[0027] According to at least one embodiment of the present invention, the present invention allows a password generation algorithm (hereinafter referred to as the password algorithm) capable of generating a password to be shared between a worker terminal and a plurality of service devices, thereby enabling the worker terminal and the service devices to each generate the same password, so that each worker terminal can connect to each service device without direct transmission of the password. Accordingly, the present invention has the effect of significantly enhancing the security of the password.

[0028] In addition, the present invention has the effect of changing the passwords of a plurality of service devices collectively by changing at least one of the keys used for password generation and distributing it to a plurality of service devices when a pre-set password change condition is satisfied. Furthermore, by transmitting other information capable of detecting the changed key value, rather than the changed key value, to the worker terminal, thereby enabling the worker terminal to generate a changed password according to the changed key, the security of the password can be further enhanced.

[0029] FIG. 1 is a block diagram illustrating the configuration of a management system for managing passwords for accessing a plurality of service devices according to an embodiment of the present invention.

[0030] FIGS. 2a and 2b are block diagrams illustrating the configuration of a worker terminal and a service device constituting a management system according to an embodiment of the present invention.

[0031] FIG. 3 is a flowchart illustrating the operation process of collectively changing passwords for a plurality of service devices in a management system according to an embodiment of the present invention.

[0032] FIG. 4 is a flowchart illustrating the operation process of a worker terminal connecting to a service device in a management system according to an embodiment of the present invention.

[0033] FIG. 5 is a flowchart illustrating the operation process of a management system according to an embodiment of the present invention, which collectively changes the password algorithms used by a worker terminal and a plurality of service devices for password generation using a password algorithm table.

[0034] FIG. 6 is a flowchart illustrating the operation process of a worker terminal connecting to a service device in a management system according to an embodiment of the present invention.

[0035] FIG. 7 is a flowchart illustrating the operation process in which a server provides information on the working time allowed to a worker, along with information on a password algorithm, in a management system according to the present invention.

[0036] FIG. 8 is a flowchart illustrating the operation process in which a service device determines whether to connect a worker terminal based on part-time information entered along with a password and the current time in a management system according to an embodiment of the present invention.

[0037] FIG. 9 is a flowchart illustrating the operation process in which a worker terminal images and displays a password generated according to a password algorithm in a management system according to an embodiment of the present invention.

[0038] FIG. 10 is an example diagram illustrating an example of a password image shown in FIG. 9.

[0039] FIG. 11 is a flowchart illustrating the operation process of determining whether a worker terminal is connected based on the result of a service device recognizing a password image in a management system according to an embodiment of the present invention.

[0040] It should be noted that technical terms used in this specification are used merely to describe specific embodiments and are not intended to limit the invention. Additionally, singular expressions used in this specification include plural expressions unless the context clearly indicates otherwise. The suffixes "module" and "part" for components used in the following description are assigned or used interchangeably solely for the ease of drafting the specification and do not inherently possess distinct meanings or roles.

[0041] In this specification, terms such as "composed of" or "comprising" should not be interpreted as necessarily including all of the various components or steps described in the specification, and should be interpreted as potentially excluding some of the components or steps, or including additional components or steps.

[0042] In addition, when describing the technology disclosed in this specification, if it is determined that a detailed description of related prior art could obscure the essence of the technology disclosed in this specification, such detailed description is omitted.

[0043] In addition, the attached drawings are intended only to facilitate understanding of the embodiments disclosed in this specification, and the technical concept disclosed in this specification is not limited by the attached drawings; it should be understood that they include all modifications, equivalents, and substitutions that fall within the concept and technical scope of the present invention. Furthermore, not only each of the embodiments described below, but also combinations of embodiments may fall within the concept and technical scope of the present invention as modifications, equivalents, and substitutions that fall within the concept and technical scope of the present invention.

[0044] Hereinafter, embodiments disclosed in this specification will be described in detail with reference to the attached drawings.

[0045] FIG. 1 is a block diagram illustrating the configuration of a management system for managing passwords for accessing a plurality of service devices according to an embodiment of the present invention.

[0046] Referring to FIG. 1, a management system (1) according to an embodiment of the present invention may be configured to include a plurality of service devices (10-1, 10-2, ... 10-n), a server (20) that communicates with the plurality of service devices, and a worker terminal (30) that can communicate with the plurality of service devices and the server.

[0047] Here, the service device may be a device that allows access only when a designated password is entered. For example, the service device may be a device capable of providing communication services and may include a monitoring device, such as a CCTV, which allows only authorized operators to view recorded or captured video, or a protection device, such as a protection relay, which performs monitoring, measurement, and protection functions for power facilities. Additionally, the service device may include an Intelligent Electric Device (IED) capable of controlling at least one function of a power facility, as well as performing monitoring, measurement, and protection functions for at least one power facility.

[0048] Such a service device may be equipped with at least one of a display unit, such as a display capable of outputting visual information capable of displaying information, or an audio output unit capable of outputting audio information. Additionally, it may be equipped with a light sensor capable of acquiring visual information, such as a camera. In this case, the service device may be equipped with a function capable of scanning and recognizing visual information, i.e., an image, acquired through the light sensor.

[0049] Additionally, the service device may have a pre-assigned password for access, and may be configured to allow access only through the pre-assigned password. In this case, the service device may be connected via wired or wireless communication to a device that wishes to access the service device, such as a worker terminal (30), and when a communication connection is established, the service device may be required to input the pre-assigned password.

[0050] And if the password entered through the worker terminal (30) matches the aforementioned pre-specified password, the service device may allow the connection of the worker terminal (30). And if the connection is allowed, the service device may provide a pre-specified service in response to the request of the worker terminal (30).

[0051] For example, the service device may provide the worker terminal (30) with monitoring data collected by the service device, i.e., recorded or captured video data, or monitoring data collected over a certain period regarding the status of specific power facilities or equipment, in response to a request from the worker terminal (30) to which the connection is permitted. Alternatively, the service device may provide information on a setting value currently set in the service device, for example, a reference value for performing a specific function, or provide a function to change the setting value, in response to a request from the worker terminal (30) to which the connection is permitted.

[0052] In order to manage passwords that allow each worker to access one of the service devices (10) through a worker terminal, the management system (1) according to an embodiment of the present invention may have a server (20) that can be wirelessly or wiredly connected to the plurality of service devices.

[0053] The above server (20) may be provided with a password generation algorithm (hereinafter referred to as the password algorithm) capable of generating a password using at least one key. The password algorithm may be an algorithm capable of generating a string of a certain length, i.e., a password, containing at least one number according to at least one input value, i.e., at least one key. In this case, the password algorithm may refer to a series of ordered procedures, methods, or rules capable of generating a password according to the at least one key. The password algorithm may generate different output values, i.e., different passwords, when the input value changes, i.e., when at least one key changes.

[0054] The server (20) can transmit the password algorithm to each of the plurality of service devices. It can also transmit the password algorithm to a pre-registered worker terminal (30). Accordingly, the password algorithm can be shared with both the plurality of service devices and the pre-registered worker terminal.

[0055] Meanwhile, in the case of a worker terminal that is not registered with the server (20), the password algorithm may not be provided by the server (20) before being registered with the server (20). Therefore, in order for a worker to replace the worker terminal with another device, a process of registering a new worker terminal with the server (20) may be required. In this case, deletion of the worker's previously registered worker terminal (30) may be required from the server (20), and during the deletion process, deletion confirmation information transmitted from the previously registered worker terminal (30) to the server (20) may be required.

[0056] That is, in order to register a new worker terminal to the server (20), the deletion confirmation information provided by the previous worker terminal (30) must be received by the server (20) so that the previously registered previous worker terminal (30) can be deleted from the server (20), and the server registration for the new worker terminal can be performed only after the previous worker terminal (30) is deleted from the server (20).

[0057] Meanwhile, when a new worker terminal is registered, the newly registered worker terminal (30) may request the password algorithm from the server (20). In this case, the server (20) may request authentication information for authenticating the worker from the worker terminal (30), and may provide the information of the password algorithm to the worker terminal (30) only when the worker is authenticated.

[0058] For example, the server (20) may request pre-configured authentication information of the worker for authentication of the worker. The authentication information may include a password pre-configured by the worker or biometric information for biometric authentication, such as a fingerprint, iris, or facial image. Additionally, the authentication information may include authentication information provided by an accredited certification authority that provides authentication services, such as a telecommunications company that provides authentication services.

[0059] Meanwhile, the worker terminal (30) can generate a password for accessing the service device based on a password algorithm provided by the server (20) and at least one designated key value. Here, various devices may be used as the worker terminal (30). For example, the worker terminal (30) may include a smartphone, a laptop computer, a PDA (personal digital assistant), a slate PC, a tablet PC, an ultrabook, or a wearable device, such as a smartwatch, equipped with at least one display unit such as a display.

[0060] Meanwhile, separate from the password generated by the above-mentioned worker terminal (30), each service device can generate a password based on a password algorithm shared through the server (20) and a designated key value. And when a password is entered from a worker terminal (30) connected via wired or wireless communication, the password entered from the worker terminal (30) can be compared with the password generated by itself.

[0061] In this case, the worker terminal (30) and the service device share a password algorithm as described above, and at least one key for generating a password using the password algorithm may also be predetermined. Therefore, the password entered from the worker terminal (30) and the password generated by the service device may be identical. When the passwords match, the service device allows the worker terminal to connect and can provide the services requested by the worker terminal (30).

[0062] That is, the server (20) can transmit at least one key capable of generating a password through the password algorithm to the worker terminal (30) and a plurality of service devices, respectively. Accordingly, the worker terminal (30) and each of the plurality of devices can generate a password based on the password algorithm provided by the server (20) and at least one key provided by the server (20).

[0063] In this case, the worker terminal (30) can input the generated password into a service device that wishes to receive the service. The service device can then compare the password input from the worker terminal (30) with the password it has generated to check whether they match. If the passwords match, the service device can allow the worker terminal (30) to connect.

[0064] Meanwhile, the server (20) may change the at least one key depending on whether the pre-set password change condition is satisfied. In this case, if the input key is changed, the password generated through the password algorithm may also change. That is, by changing the at least one key provided to the worker terminal (30) and each service device, the server (20) can collectively change the passwords that allow the worker terminal (30) to access each service device.

[0065] Meanwhile, at least one of the keys for generating the password may be a variable part that can be varied. In this case, the keys for generating the password may be divided into a fixed part and a variable part, where the fixed part is a value that is fixed in advance and the variable part is a value that can be varied by the server (20). And when the value of the variable part changes, a different output value, i.e., a different password, may be generated through the password algorithm even if the password algorithm is the same.

[0066] Using this, the server (20) can change the password by changing the at least one key when a pre-set password change condition is satisfied, such as a request from any one service device or a pre-set period expiration. For example, any one service device may determine that the password change condition is satisfied when the time elapsed since the last password change reaches a pre-set time. Then, it may request the server (20) to change the password. And when a password change request is received from any one service device, the password can be changed.

[0067] In this case, the server (20) can change and transmit the key value, that is, the variable part's key value, to each service device. Here, the key values ​​corresponding to the fixed part among the keys for generating a password may be information stored in the service device in advance. Therefore, only some information for generating a password may be transmitted to each service device, and the entire set of keys for generating a password may not be transmitted. Thus, the security of the password can be further improved.

[0068] Furthermore, the server (20) may directly transmit to each service device some of the keys for generating a password, that is, some of the changed key values ​​corresponding to the variable part, while transmitting only other information related to the changed key values, such as hint information, to the worker terminal (30). In this case, the hint information may be included in the information for notifying the password change according to the changed key and transmitted to the worker terminal (30).

[0069] Then, the worker terminal (30) can detect the changed key value based on the hint information received from the server (20). Then, the detected key value and the key values ​​of the fixed part, which have been fixed in advance, are input into a password algorithm to generate a password for accessing the service device. Accordingly, in the present invention, the changed password, i.e., the changed key value, may not be directly transmitted to the worker terminal, and other information (hint information) may be transmitted to the worker terminal (30). Therefore, the leakage of the changed key value can be prevented, and the security of the password can be further improved.

[0070] In order to enable the worker terminal (30) to detect the changed key value using hint information in this way, the server (20) can change the key value corresponding to the variable part to one of the information previously acquired by the worker terminal (30).

[0071] For example, when the password is changed because the key value of the variable part is changed, the server (20) may provide information to the worker terminal (30) regarding information from a point in time prior to when the password change occurred, that is, information from a point in time when the key value of the variable part for generating the currently used password was provided by the server (20), or information regarding the subject that caused the password change, for example, information about the subject requesting the password change. Then, if the key value of the variable part is changed again in the future, the server may transmit a code corresponding to the time of change (e.g., 1) or a code corresponding to the subject of the change (e.g., 2) as hint information to the worker terminal (30). Then, depending on whether the hint information is 1 or 2, the worker terminal may detect one of the information collected during the previous password change. And the detected information may be used as information for the changed key.

[0072] For example, as one of the keys of the variable part for generating a password, the server (20) may select information of the previous change time. Then, information of the time when the password was changed immediately before (hereinafter referred to as the previous password change time) may be selected as a key for generating a new password. Here, a change of password means a change of the keys that generate the password, and the previous password change time may be a time when at least one of the keys that generate the previous password was changed. Therefore, when the previous password change time is selected as a key of the variable part for generating a new password, information of the recent time when at least one of the keys that generate the previous password was changed is selected as a key for generating the new password and may be transmitted to each service device (10) as a new variable part key.

[0073] And the server (20) can transmit hint information corresponding to the key of the new variable part to the worker terminal (30). In this case, as described above, if the hint information is 1, it indicates the time of the previous change, and if the hint information is 2, it indicates the subject of the previous change, then the server (20) can transmit the hint information '1' to the worker terminal (30).

[0074] Then, the worker terminal (30) can detect the information regarding the time of the change of the previous password based on the received hint information '1' among the previously collected information related to the change of the previous password, for example, information regarding the time of the change of the previous password and information regarding the subject that caused the change of the previous password, as the key of the variable part changed for the generation of a new password. Then, by inputting the detected key and the pre-specified fixed part keys into the password algorithm, a new password according to the key of the changed variable part can be obtained. Then, by inputting the new password into the service device, access to the service device where the password was generated according to the key of the changed variable part can be established.

[0075] Meanwhile, among the keys for generating a password, the fixed part may be composed of fixed keys that are not changed even when the password is changed, as described above. In this case, the keys of the fixed part may be information provided in advance from the server (20) or information that the service device has in advance.

[0076] For example, the keys of the fixed part described above may include unique information of each service device or connection address information of each service device (e.g., IP address information). In this case, since the unique information and connection address information differ for each service device, different passwords may be generated for each service device even when the same password algorithm is used.

[0077] In this case, the worker terminal (30) may use the unique information of the service device or the connection address information of each service device as keys for a fixed part for password generation in order to connect to a specific service device. To this end, the worker terminal (30) may store information of the service devices to be connected in advance.

[0078] And when the worker terminal (30) establishes communication with any one of the service devices, it can identify the service device currently connected to the communication as a specific service device connected for the worker's work. Then, from memory, it can detect unique information or connection address information of the identified specific service device as information for fixed keys for password generation. Then, by inputting the information of at least one variable key detected from the hint information together with the information of the detected fixed keys into a pre-stored password algorithm, a password for accessing the specific service device can be generated.

[0079] In this case, the memory of the specific service device may store its own unique information and connection address information. Accordingly, when at least one new variable key is received from the server (20), the received variable key and fixed keys corresponding to its own unique information and connection address information can be input into a password algorithm to generate a new password that allows access. And when a password matching the generated password is entered from the worker terminal (30), the access of that worker terminal (30) can be allowed.

[0080] Meanwhile, the unique information and information of service devices stored in the memory of the worker terminal (30) may be information of service devices to which work is permitted to the owner of the worker terminal (30), i.e., the worker. In this case, the information of the service devices to which work is permitted may be provided from the server (20) upon the request of the worker terminal (30). In this case, the server (20) may provide the information of the service devices to which work is permitted to the worker terminal (30) only if the worker of the worker terminal (30) who requested the information of the service devices to which work is permitted is a pre-authenticated worker.

[0081] FIGS. 2a and 2b are block diagrams illustrating the configuration of a worker terminal (30) and a service device (10) that constitute a management system according to an embodiment of the present invention.

[0082] First, referring to FIG. 2a which illustrates the configuration of a worker terminal (30), the worker terminal (30) according to an embodiment of the present invention may be configured to include a communication unit (310), a password (PW) generation unit (320), a memory (330), a control unit (300), and a display unit (340). Since the components illustrated in FIG. 2a are not essential for implementing the worker terminal (30), the worker terminal (30) described in this specification may have more or fewer components than those listed above. For example, the worker terminal (30) may further include at least one user input unit (not illustrated) capable of receiving user input from a user, i.e., a worker.

[0083] More specifically, the communication unit (310) among the above components may include one or more modules that enable wireless or wired communication connections between the worker terminal (30) and the server (20), and between the worker terminal (30) and at least one service device.

[0084] Additionally, the password generation unit (320) can perform calculations on at least one key input according to a stored password algorithm under the control of the control unit (300) and output the calculation result as a password. Here, the at least one key may include keys of a variable unit and a fixed unit.

[0085] And the memory (330) can store data that supports functions that the worker terminal (30) can perform. The memory (330) can store commands or data for the execution of a program or application that can execute functions provided by the worker terminal (30). It can also temporarily store data that is input / output for the execution of a program or application.

[0086] As data supporting functions that a worker terminal (30) can perform, the memory (330) can store situational information collected from the server (20) in relation to password changes. For example, the situational information may include information at the time when the password is changed, such as when the value of a variable part among the keys for password generation is changed by the server (20) and the password is changed. It may also include information about the entity that caused the password change, such as a specific service device that requested the password change or generated an event requiring the password change. For example, when a new service device is registered or an existing service device is removed, the information of the newly registered service device or the information of the removed existing service device, as well as the information of the entity that caused the password change (e.g., unique information), may be collected from the server (20) as situational information. The collected situational information may be stored in a specific area on the terminal memory (330). Hereinafter, one area on the memory (330) where situation information related to the above password change is stored will be referred to as the password situation information storage unit (331).

[0087] Additionally, the memory (330) may store information about service devices that are allowed to be operated by the worker who is the owner of the worker terminal (30). In this case, the information about the service devices that are allowed to be operated, i.e., the target devices, provided by the server (20), may include unique information about the target device and connection address information about the target device. In this case, the connection address information of the target device may be used for a communication connection to the target device and may also be used to identify the target device through whether a communication connection is established. Hereinafter, a portion of the terminal memory (330) where the information about the target devices is stored will be referred to as the target device information storage unit (332).

[0088] Meanwhile, when the worker terminal (30) requests information about the target devices, the server (20) can check the information about the target devices stored in the target device information storage unit (332). And if there are target devices that are allowed to the worker of the worker terminal (30) but for which necessary information is not stored in the target device information storage unit (332), the server can transmit the information about the target devices, i.e., information including unique information and connection address information, to the worker terminal (30). However, if the information about target devices that are not allowed to the worker of the worker terminal (30) is stored in the target device information storage unit (332), the information about the target devices that are not allowed to the worker may be deleted from the memory (330) in response to the request for information about the target devices.

[0089] Additionally, the memory (330) may store data for the operation of a password algorithm provided by the server (20) (hereinafter referred to as password algorithm data). The password algorithm data may include instructions for executing the password algorithm and may be stored in the password algorithm storage unit (333) of the memory (330). Additionally, the password algorithm storage unit (333) may store data for at least one password algorithm provided by the server (20).

[0090] Meanwhile, the control unit (300) typically controls the overall operation of the worker terminal (30). The control unit (300) can provide various functions according to the worker's request by processing signals, data, and information that are input or output through the components described above, or by running an application program stored in the memory (330).

[0091] For example, the control unit (300) may receive and store password algorithm data from a communication-connected server (20). Additionally, when password change notification information is received from the server (20), the control unit (300) may detect the variable key value among the keys for generating the changed password based on the hint information included in the received password change notification information. For example, the hint information may be information indicating the time when the previous password was changed. Accordingly, the control unit (300) may determine the information detected based on the hint information among the information stored in the password (PW) status information storage unit (331) of the memory (330) as the variable key value among the keys for generating the changed password.

[0092] Meanwhile, the control unit (300) can establish a communication connection with a specific service device in accordance with the request of the operator. In this case, the control unit (300) can establish a communication connection with the specific service device by using connection address information corresponding to the specific service device in accordance with the operator's request, among the target device information stored in the memory (330). When a communication connection is established, the service device currently connected to the communication can be identified as the specific service device. This is because the connection address information is one of the unique information of the specific service device.

[0093] When a communication connection with the specific service device is established, and the communication-connected service device is identified as the specific service device, the control unit (300) can detect the key value of the detected variable unit and the information of the specific service device among the target device information stored in the memory (330). Then, the detected information of the specific service device can be input into the password generation unit (320) as the key value of the fixed unit for password generation. Here, the information of the specific service device used as the key value of the fixed unit may include at least one of unique information such as the serial number of the specific service device and the connection address information of the specific service device.

[0094] Meanwhile, when the key value of the fixed part and the key value of the variable part are input into the password generation unit (320), the control unit (300) can control the password generation unit (320) to generate a password. In this case, the generated password is a password generated with the key value of the variable part changed according to the hint information received from the server (20), and a password different from the previously generated password can be generated. That is, the password can be changed.

[0095] Then, the control unit (300) can input the generated password, i.e., the changed password, into a specific service device currently connected via communication. In this case, the control unit (300) can display the changed password through the display unit (340), and allow the user to input the displayed password directly through the user input unit (not shown), thereby allowing the changed password to be input into the specific service device. Alternatively, the control unit (300) can image the changed password and display the imaged password, i.e., the password image, on the display unit (340). Then, the specific service device can identify and recognize the password image using a light sensor, etc., and the changed password may be input into the specific service device according to the recognition result of the specific service device.

[0096] Meanwhile, the specific service device (10) may allow the connection of the worker terminal (30) if the password generated by itself matches the password entered from the control unit (300). Then, the control unit (300) of the worker terminal (30) may request the specific service device to provide services that the service device can provide, such as verifying measurement values. The specific service device may provide services in accordance with the request received from the worker terminal (30) to which the connection has been allowed. Then, the control unit (300) may visualize the data provided as a response to the requested service and display it on the display unit (340).

[0097] Meanwhile, FIG. 2b is a block diagram illustrating the configuration of a service device (10) in a management system (1) according to an embodiment of the present invention.

[0098] Referring to FIG. 2b, the service device (10) may be configured to include a communication unit (110), a password (PW) generation unit (120), a memory (130), a control unit (100), and a light sensor (140). Since the components illustrated in FIG. 2b are not essential for implementing the service device (10), the service device (10) described herein may have more or fewer components than those listed above. For example, although not illustrated, the service device (10) may further include components for performing services that it can provide.

[0099] For example, if the service device (10) is a surveillance device such as a CCTV, it may further include components such as a camera for performing the surveillance function; and if the service device (10) is a protection relay, it may further include at least one component such as a current sensor or a voltage sensor for performing surveillance, measurement, and protection functions for power equipment. Additionally, if the service device is an intelligent electronic device (IED), it may further include at least one component capable of controlling at least one function of the power equipment according to the measurement results of the power equipment.

[0100] More specifically, the communication unit (110) among the above components may include one or more modules that enable wireless or wired communication connections between the service device (10) and the server (20), and between the service device (10) and at least one worker terminal (30).

[0101] Additionally, the password generation unit (120) can perform calculations on at least one key input according to a stored password algorithm under the control of the control unit (100) and output the calculation result as a password. Here, the at least one key may include keys of a variable unit and a fixed unit.

[0102] And the memory (130) can store data that supports functions that the service device (10) can perform. The memory (130) can store instructions or data for the execution of a program or application that can execute functions provided by the service device (10). It can also temporarily store data that is input / output for the execution of a program or application.

[0103] As data supporting functions that the service device (10) can perform, the memory (130) can store variable keys provided by the server (20) in relation to password changes. For example, the variable keys may be information at a specific point in time provided by the server (20) (e.g., information at the time of the immediate previous password change) or information of the subject of the immediate previous password change (e.g., information of the service device that requested the immediate previous password change).

[0104] To this end, when the server (20) receives a password change request from any one of the service devices (10), it may change at least one of the keys of the variable unit for generating a password according to the received change request and store information at the time of change. In addition, it may store the unique information of the service device that transmitted the password change request as information of the password change subject. Furthermore, the stored information at the time of password change or information of the password change subject may be used as one of the keys of the variable unit during the next password change.

[0105] Hereinafter, a portion of the memory (130) in which at least one variable key value received from the server (20) to generate a new password is stored is referred to as a password key information storage portion (131).

[0106] Additionally, the memory (130) may store information of the service device. In this case, the information of the service device (10) may include unique information of the service device (10) and connection address information for communication connection of the service device (10). Hereinafter, a region on the memory (130) where the information of the service device (10) is stored will be referred to as the unique information storage unit (132).

[0107] Additionally, the memory (130) may store data for the operation of a password algorithm provided by the server (20) (hereinafter referred to as password algorithm data). The password algorithm data may include instructions for executing the password algorithm and may be stored in the password algorithm storage unit (133) of the memory (130). Additionally, the password algorithm storage unit (133) may store data for at least one password algorithm provided by the server (20).

[0108] Meanwhile, the control unit (100) typically controls the overall operation of the service device (10). The control unit (100) can perform functions that the service device (10) can provide, such as monitoring functions or measurement functions, by processing signals, data, and information that are input or output through the components described above, or by running an application program stored in the memory (130), and can provide the results of the performance of the above functions to the worker terminal (30) as a service provided according to the worker's request.

[0109] To this end, when the control unit (100) receives a changed key value, i.e., a new variable key value, from the server (20), it can input at least one of the received new variable key value and the information of the service device (10) stored in the unique information storage unit (132) into the password generation unit (120) as the fixed key value. Then, by controlling the password generation unit (120), the password generated from the password generation unit (120) according to the new variable key value and the fixed key value can be stored as a password that allows access.

[0110] And when communication is established with the worker terminal (30), the control unit (100) can compare the password entered from the connected worker terminal (30) with the password generated according to the key value of the new variable unit and the key value of the fixed unit. And, only when the passwords match, access to the worker terminal (30) can be allowed. And when the worker terminal (30) that has been allowed access requests the provision of results according to the functions provided by the service device, such as verification of measurement values, the results collected according to the functions provided by the service device, such as monitoring data or measurement data, can be provided to the worker terminal (30) in response to the request.

[0111] In the above description, the configuration of a management system (1) according to an embodiment of the present invention and the configuration of a server (20), a worker terminal (30), and a service device (10) constituting the management system (1) have been described in detail.

[0112] In the following description, we will examine in detail the operation process in which passwords capable of accessing multiple service devices are managed in a management system according to an embodiment of the present invention, with reference to multiple flowcharts.

[0113] First, FIG. 3 is a flowchart illustrating the operation process of changing passwords for a plurality of service devices in a management system (1) according to an embodiment of the present invention.

[0114] Referring to FIG. 3, the server (20) can first distribute a pre-configured password algorithm to a pre-registered worker terminal (30) and a plurality of service devices (10-1, 10-2, ... 10-n). Accordingly, in the management system (1) according to an embodiment of the present invention, the worker terminal (30) and the plurality of service devices (10-1, 10-2, ... 10-n) can all share the same password algorithm. Here, the password algorithm refers to a series of ordered procedures, methods, or rules capable of generating a password according to at least one key, and the same password can be generated when the input keys are the same. On the other hand, if at least one of the input keys is different, a different password can be generated.

[0115] And the server (20) can check whether a pre-configured password change condition is satisfied. Here, the password change condition may be when a password change request is received from one of the service devices (10) among the plurality of service devices (10-1, 10-2, ... 10-n) (S330).

[0116] For example, any one of the above service devices (10) can check whether the time elapsed since the point in time when the password was previously changed (hereinafter referred to as the previous password change point) has exceeded a preset time. Here, the point in time when the password was changed may be the point in time when at least one of the key values ​​for generating a password according to a password algorithm is changed. In this case, the key values ​​for generating the password may include a fixed part whose value does not change and a variable part whose value can be varied. Here, since the key values ​​of the fixed part are not changed, the point in time when the key value is changed may be the point in time when the key value of the variable part is changed.

[0117] Meanwhile, the key value of the variable part may be provided by the server (20). That is, any one of the service devices (10) can determine the time when a new key value of the variable part is received from the server (20) as the time for changing the password, and determine whether the password change condition is satisfied based on whether a preset time has elapsed since the time when the new key value of the variable part is received (340). Then, if the password change requirement is satisfied as a result of the determination in step S340, that is, if a preset time has elapsed, a password change request can be transmitted to the server (20) (S342).

[0118] Then, when a password change requirement is satisfied from any one of the service devices (10), the server (20) can change the key value of the variable part among the key values ​​for password generation (S310). Here, as described above, the server (20) can determine the information at the time of the previous password change or the information about the subject of the previous password change as the key value of the variable part.

[0119] And the server (20) can distribute the key value of the new variable to a plurality of service devices (10-1, 10-2, ... 10-n) (S320-1, ... S320-n). Then the plurality of service devices (10-1, 10-2, ... 10-n) generate a new password according to the received key value of the new variable, and accordingly, the password generated in each of the plurality of service devices (10-1, 10-2, ... 10-n) can all be changed.

[0120] Here, the server (20) may also transmit the key value of the new variable part to the worker terminal (30). Alternatively, the server (20) may provide the worker terminal (30) with hint information that allows the worker terminal to infer the key value of the new variable part instead of the key value of the new variable part. In this case, the key value of the new variable part or the hint information may be transmitted through password change notification information that informs the worker terminal (30) that the password has been changed (320).

[0121] Meanwhile, the server (20) may store the time when the current password was changed, that is, the time when the new variable key value was determined and distributed, as situational information related to the password change, in order to use it as the key value of the variable when the next password change occurs. It may also store the unique information of the entity that requested the current password change, for example, the service device (10) mentioned above. Then, the information at the time when the new variable key value was determined and distributed, or the unique information of the service device (10) mentioned above, can be used as the key value of the new variable for the next password change. Furthermore, the situational information regarding the current password change stored by the server (20) may be provided to the worker terminal (30) upon the request of the worker terminal (30).

[0122] Meanwhile, the generation of a new password based on the key value of the new variable part, i.e., the change of the password, may be carried out on the premise that the service device is operating normally. For example, if the service device is equipped with a fault diagnosis function that diagnoses whether it is faulty on its own, the password change may be restricted according to the fault diagnosis result.

[0123] For example, if, as a result of the self-diagnosis of a service device, the service device is in a mild fault state where the execution of its preset functions is possible—for instance, a state where a fault alarm is generated but monitoring or measurement functions are still executable—the service device may generate a new password based on a new variable key value received from the server. In other words, the password change may not be restricted when the preset functions are executable.

[0124] However, if, as a result of the self-diagnosis of a service device, it is in a critical failure state where the execution of the service device's preset functions is impossible—for example, if the monitoring function or the measurement function is impossible and it is switched to a standby state—the password change function of the service device may be restricted. In this case, even if a new variable key value is received from the server by the service device (10), a new password may not be generated.

[0125] The generation of a new password based on the key value of the new variable unit, i.e., the change of the password, may be restricted depending on the result of executing a designated function of the service device. For example, if the service device is a protective meter or an IED, the change of the password based on the key value of the new variable unit may be performed only if the current or voltage measurement result of the service device for a specific power facility is within the normal range. That is, if the current or voltage measured by the service device exceeds a preset normal range, the change of the password based on the key value of the new variable unit may be restricted.

[0126] Meanwhile, as shown in FIG. 3 above, a request to change a password may be made from any one of the plurality of service devices (10-1, 10-2, ... 10-n). Meanwhile, since the satisfaction of the password change condition can be determined at each of the plurality of service devices, a request to change a password may be made simultaneously at the plurality of service devices. In this case, if a preset time for determining whether the password change condition is satisfied is predetermined, information about the time of the previous password change can be inferred by calculating backward from the time of the password change request made simultaneously at the plurality of service devices.

[0127] Accordingly, the plurality of service devices may arbitrarily determine the time at which the password change request is transmitted to the server (20) when the password change condition is satisfied, within a preset time range. That is, when the password change condition is satisfied, the time at which the password change request is transmitted may be delayed within an arbitrary time. Accordingly, even if the plurality of service devices simultaneously determine that the password change condition is satisfied, the time at which each service device transmits the password change request to the server (20) may differ from one another.

[0128] Meanwhile, since the timing of the transmission of the password change request by each service device differs as described above, while one service device is delaying the transmission of the password change request, another service device may request a password change from the server (20). Then, the server (20) may transmit a variable key value for generating a new password in accordance with the received password change request. Then, the service device may change the password according to the newly received variable key value.

[0129] In this way, when a new variable key value for generating a new password is received from the server (20), a preset time for determining whether the password change condition is satisfied can be reset. Accordingly, any one of the service devices can cancel the transmission of the delayed password change request if the key value for generating a new password is transmitted from the server (20) within the delay time during which the transmission of the password change request is delayed.

[0130] Meanwhile, FIG. 4 is a flowchart illustrating the operation process in which a worker terminal (30) accesses a service device (10) through a changed password in a management system (1) according to an embodiment of the present invention.

[0131] Referring to FIG. 4, first, the server (20) can determine one of the stored situation information related to the password changed immediately prior, that is, immediately before, as a variable key for generating a new password, as described in step S310 of FIG. 3 (S400). Then, as in steps S320-1 to S320-n of FIG. 3, the determined variable key can be transmitted to the service device (10) (S410). Then, the service device (10), having received the new variable key through step S410, can generate a new password based on the pre-designated fixed key and the newly received variable key (S412).

[0132] Here, the key of the fixed part may include at least one of the unique information and connection address information of the service device (10). Additionally, the new variable part key provided by the server (20) may be information at the time of the previous password change or information of the person who changed the previous password. That is, the new password generated in step S412 may be a password generated by receiving at least one of the unique information and connection address information of the service device (10) and information at the time of the previous password change or information of the person who changed the previous password as input keys.

[0133] Meanwhile, in step S400, the server (20) may transmit information regarding the type of situation information determined as a variable key for generating a new password to the worker terminal (30) as hint information (S420). For example, if the situation information consists of two pieces of information, such as information at the time of the previous password change or information of the person who changed the previous password, the hint information may be information intended to refer to either the information at the time of the previous password change or the information of the person who changed the previous password.

[0134] For example, hint information '1' may refer to information regarding the time of the previous password change among the above situation information. And hint information '2' may refer to information regarding the subject of the previous password change among the above situation information. Accordingly, the worker terminal (30) may determine one of the situation information stored in the password situation information storage unit (331) of the terminal memory (330) as the key value of the variable unit for generating the newly changed password, depending on whether the hint information included in the password change information notifying the server (20) that the password has been changed is 1 or 2 (S422).

[0135] And the worker terminal (30) can collect situation information related to the currently changed password from the server (20) (S424). In this case, the step S424 may include the process of the worker terminal (30) requesting situation information related to the currently changed password from the server (20), and the process of the server (20) providing situation information related to the currently changed password stored in the server (20) in response to the request of the worker terminal (30). In this case, the server (20) may require authentication of the worker from the worker terminal (30), and may provide situation information related to the currently changed password only when the worker is authenticated.

[0136] Meanwhile, when the collection of situation information related to the currently changed password from the server (20) is completed in step S424, the worker terminal (30) can establish a communication connection with any one of the multiple service devices (service device (10)) (S426). For this communication connection, the worker terminal (30) can use the connection address information of the service device (10) stored in the target device information storage unit (332) of the memory (330). That is, the worker terminal (30) can establish a communication connection with any one of the service devices according to the information of at least one service device for which work has been pre-allowed to the worker.

[0137] Accordingly, the worker terminal (30) can identify whether the service device (10) is a device that is allowed to be operated by the worker based on whether a communication connection with the service device (10) is possible. And when the service device (10) is identified through the communication connection, the information of the identified service device (10) stored in the target device information storage unit (332) can be detected (S428). Then, based on the detected information of the service device (10), a fixed key value for password generation is determined, and among the situation information stored in the password situation information storage unit (331), one situation information corresponding to the hint information received from the server (20) can be determined as the variable key value. Then, the password generation unit (320) can be controlled to generate a new password based on the determined fixed key value and the variable key value (S430).

[0138] When a password is generated in step S430, the worker terminal (30) can input the generated password into the service device (10) (S432). For example, the worker terminal (30) can input the generated password into the service device as a value entered through a user input unit, or transmit it to the communication-connected service device (10) as wireless data or wired data. Then, the service device (10) can check whether the password generated in step S412 matches the password input from the worker terminal (30) in step S432 (S434).

[0139] And if the password does not match as a result of the check in step S434 above, the service device (10) transmits password mismatch information to the worker terminal (30) and may not allow the connection of the worker terminal (30) (S438). Then, the password mismatch information may be displayed on the display unit (340) of the worker terminal (30).

[0140] On the other hand, if, as a result of the check in step S434, the password entered from the worker terminal (30) matches the password generated in step S412, the service device (10) may allow the connection of the currently connected worker terminal (30) and allow the work of the worker terminal (30) (S436). In this case, the service device (10) may provide a service to the worker terminal (30) in accordance with the request of the worker terminal (30).

[0141] Meanwhile, in the above description, an example was described in which a single password generation algorithm, that is, a password algorithm, is shared by a server (20), a plurality of service devices (10-1, 10-2, ... 10-n), and a worker terminal (30), but it is obvious that there may be multiple password algorithms. In this case, the server (20) can select one of the multiple password algorithms according to a pre-set condition and transmit the information of the selected password algorithm to the plurality of service devices (10-1, 10-2, ... 10-n) and the worker terminal (30) for sharing.

[0142] First, the server (20) can generate a password algorithm table including the plurality of password algorithms. In this case, each of the plurality of password algorithms can be mapped to a serial number of the password algorithm table.

[0143] In this case, the password algorithm table may be a table configured such that multiple different password algorithms are each matched to a different algorithm mapping number, as shown in Table 1 below. And when a pre-configured password algorithm change condition is satisfied, the server (20) may arbitrarily select a specific password algorithm included in the password algorithm table and transmit information related to the selected password algorithm, namely the algorithm mapping number, to the worker terminal and each service device. Accordingly, the password algorithms used by the worker terminal (30) and each service device to generate passwords can be changed collectively.

[0144] Table 1 below is an example of such a password algorithm table, illustrating an example where 20 different password algorithms are each matched to a different serial number.

[0145] Serial Number Password Algorithm 1 1st Password Algorithm 2 2nd Password Algorithm 3 3rd Password Algorithm......19 19th Password Algorithm 20 20th Password Algorithm

[0146] Here, the password algorithms corresponding to different serial numbers may each be different password algorithms. Hereinafter, the serial number of the password algorithm table mapped to each of the plurality of password algorithms will be referred to as the algorithm mapping number. Furthermore, the password algorithm may mean a series of ordered procedures, methods, or rules capable of generating a password according to at least one key. Accordingly, different password algorithms may be different series of ordered procedures, methods, or rules capable of generating a password according to at least one key. Therefore, when the password algorithms are different, different passwords may be generated even if the input key is the same.

[0147] And the server (20) can transmit the password algorithm table to a plurality of service devices (10-1, 10-2, ... 10-n). For example, the password algorithm table may be transmitted from the server (20) and stored during the initial connection operation in which a service device communicates with the server (20) to register with the server (20).

[0148] Therefore, the same password algorithm table may be stored in each service device. The server (20) may transmit only the algorithm mapping number corresponding to one of the password algorithms to be used for password generation among the password algorithms included in the password algorithm table to each service device. Then, each service device that receives the algorithm mapping number changes the password algorithm to the password algorithm matching the received algorithm mapping number, thereby allowing the method of generating a password according to the key input by each service device, that is, the password algorithm, to be changed collectively.

[0149] Meanwhile, the above password algorithm table may also be transmitted to the pre-configured worker terminal (30) of the authenticated worker. For example, when a worker first registers their terminal (worker terminal (30)), the server (20) may store information about the worker terminal (30) and, at the same time, transmit information about the password algorithm table transmitted to each of the service devices to the worker terminal (30). That is, the password algorithm table may be provided from the server (20) only to the pre-configured terminal of the worker registered with the server (20).

[0150] In this way, since the password algorithm table is transmitted to each service device (10-1, 10-2, ..., 10-n) and worker terminal (30), the server (20) can collectively change the method of generating passwords (password algorithms) according to the input key by transmitting only the algorithm mapping number corresponding to a specific password algorithm.

[0151] FIG. 5 is a flowchart illustrating the operation process in which a management system (1) according to an embodiment of the present invention collectively changes the password algorithms used by a worker terminal (30) and a plurality of service devices (10-1, 10-2, ... 10-n) for password generation using a password algorithm table.

[0152] Referring to FIG. 5, first, the server (20) of the management system (1) of the present invention may receive and store a password algorithm table as shown in Table 1 from the administrator of the server (20) or a higher-level system (S500). Then, the server (20) may transmit the input password algorithm table to each service device (10-1, 10-2, ... 10-n) that is connected to the server (20) (S510-1, S510-2, ... , S510-n). Then, each service device (10-1, 10-2, ... 10-n) may store the received password algorithm table.

[0153] And the server (20) can arbitrarily determine an algorithm mapping number that matches any one of the password algorithms included in the password algorithm table (S520). Then, the determined algorithm mapping number can be transmitted to each service device (10-1, 10-2, ... 10-n) (S530-1, S530-2, ... S530-n). Then, each service device (10-1, 10-2, ... 10-n) can detect a password algorithm that matches the algorithm mapping number received from the server (20) from the previously stored password algorithm table, and determine the detected password algorithm as the password algorithm currently designated by the server (20) (S531-1, S531-2, ... S531-n).

[0154] Meanwhile, when an algorithm mapping number corresponding to a specific password algorithm is transmitted to each service device (10-1, 10-2, ... 10-n), the server (20) can check whether a pre-set password algorithm change condition is satisfied (S540). Here, whether the pre-set password algorithm change condition is satisfied can be determined based on whether a pre-set time has elapsed since the time when the algorithm mapping number was determined, for example, the time when the algorithm mapping number was changed immediately prior (immediately prior) (immediately prior change time).

[0155] Alternatively, the above password algorithm change condition may be satisfied when a pre-set event occurs, for example, when a new service device is connected or when an existing connected service device is removed from the management system (1).

[0156] Then the server (20) can proceed again to step S520 to start the process of determining the algorithm mapping number anew, and accordingly, the algorithm mapping number corresponding to the new password algorithm can be determined.

[0157] Meanwhile, when a new algorithm mapping number is determined, the server (20) can repeat steps S530-1 through S530-n to transmit the new algorithm mapping number to each service device (10-1, 10-2, ... 10-n). Then, each service device (10-1, 10-2, ... 10-n) can repeat steps S531-1 through S531-n to change the algorithm for password generation to a password algorithm corresponding to the new algorithm mapping number received from the server (20).

[0158] FIG. 6 is a flowchart illustrating the operation process of a worker terminal connecting to a service device in a management system according to an embodiment of the present invention. In the following description, the service device (10) may refer to any one of the plurality of service devices (10-1, 10-2, ... 10-n) that is connected to the worker terminal (30) through communication.

[0159] Referring to FIG. 6, first, the worker terminal (30) can establish a communication connection with the server (20). Then, the worker terminal (30) can request connection information from the communication-connected server (20) to access the service device (10) for the purpose of performing work on the service device (10) (S600). In this case, simultaneously with the request for the connection information, the worker can transmit authentication information to the server (20) to authenticate themselves. Then, the server (20) can perform authentication of the worker based on the authentication information received from the worker terminal (30) (S602).

[0160] Here, the authentication information may include a password pre-set by the operator or biometric information for biometric authentication, such as a fingerprint, iris, or facial image. Additionally, the authentication information may include authentication information provided by an accredited certification authority that provides authentication services, such as a telecommunications carrier that provides authentication services.

[0161] Additionally, the server (20) may require additional authentication information from the worker. In this case, the additional authentication information may further include at least one of the worker's work location information, information of the terminal the worker possesses, i.e., the worker terminal (30) (e.g., unique information such as a serial number), and information on the working time allowed to the worker.

[0162] Therefore, even if a worker is authenticated through the above authentication information, for example, biometric information, additional authentication of the worker may fail if the worker's work location differs from the current location of the worker terminal (30) requesting the above connection information, or if the time at which the connection information was requested is outside the working time allowed to the worker. Additionally, additional authentication of the worker may fail if the worker terminal requesting the above password information is not the worker terminal of a previously registered worker. And if the above additional authentication fails, the server (20) may determine that the worker's authentication failed in step S602.

[0163] Meanwhile, in step S602 above, if the authentication of the worker according to the authentication information provided by the worker terminal (30) is successful, the server (20) may transmit a temporary password that allows access to the server (20) to the authenticated worker's worker terminal (30) (S604). The temporary password may be a password that can be used for a limited time or a limited number of times (e.g., one-time use), and may mean a password that no longer allows access to the server (20) once the pre-set usage period has expired or the number of uses has been exhausted.

[0164] When the above temporary password is provided to the worker terminal (30), the worker terminal (30) can input the temporary password provided from the server (20) into the server (20) (S606). For example, the above temporary password may be displayed on the display unit (340) of the worker terminal (30), and may be input into the server (20) connected to the worker terminal (30) by the worker directly inputting the displayed temporary password into the user input unit of the worker terminal (30). Alternatively, the worker terminal (30) may input the displayed temporary password into the server (20) connected to the worker terminal (30) directly upon the worker's request.

[0165] Then, the server (20) can check whether the temporary password entered from the worker terminal (30) is a password that allows access to the server (20) (S608). That is, the server (20) can check not only whether the temporary password matches, but also whether the restriction conditions set on the temporary password are not satisfied.

[0166] And if the above temporary password does not match or if the restriction conditions set on the above temporary password are satisfied, that is, if the usage period has expired or the number of uses has been exhausted, the connection of the worker terminal (30) to the server (20) according to the above temporary password may not be allowed. Then the server (20) may send notification information indicating that the temporary password does not match to the worker terminal (30) currently connected to the communication (S609).

[0167] Meanwhile, the server (20) may allow the worker terminal (30) to connect to the server (20) if the temporary password entered from the worker terminal (30) matches and the restriction conditions set on the temporary password are not satisfied, that is, if the usage period has not expired or there are remaining usage attempts (S610). And when the worker terminal (30) is allowed to connect to the server (20), the server (20) may transmit algorithm mapping number information corresponding to the password algorithm currently set on each service device to the connected worker terminal (30) (S610).

[0168] Then, the worker terminal (30) can detect a password algorithm corresponding to an algorithm mapping number provided by the server (20) from a previously stored password algorithm table (S612). Then, the worker terminal (30) can generate a password that can access the service device (10) by inputting a fixed key value corresponding to at least one of the unique information and connection address information of the service device (10) and a variable key value corresponding to the hint information received from the server (20) into any one of the password algorithms that match the algorithm mapping number provided by the server (20) (S614). Here, the service device (10) can be identified through a communication connection with the worker terminal (30), and at least one of the unique information and connection address information of the service device (10) can be detected according to the identification result of the service device (10). In addition, the password generation process in step S614 may be as described in steps S400 to S430 of FIG. 4.

[0169] Then, the worker terminal (30) can input the password generated in step S614 into the communication-connected service device (10) (S616). Then, the service device (10) can compare the password input from the worker terminal (30) with the password it generated to check whether they match (S618).

[0170] Here, the password generated by the service device (10) may be a password generated by inputting a fixed key value, which includes at least one of a variable key value received from the server (20), its own unique information, and a connection address information, into a password algorithm corresponding to an algorithm mapping number received from the server (20).

[0171] If, as a result of the check in step S618 above, the password matches, the service device (10) may allow the connection of the currently connected worker terminal (30) and allow the work of the worker terminal (30) (S620). In this case, the service device (10) may provide a service to the worker terminal (30) in accordance with the request of the worker terminal (30).

[0172] On the other hand, if the password does not match as a result of the check in step S618 above, the service device (10) transmits password mismatch information to the worker terminal (30) and may not allow the connection of the worker terminal (30) (S622). Then, the password mismatch information may be displayed on the display unit (340) of the worker terminal (30).

[0173] Meanwhile, the server (20) according to an embodiment of the present invention can check the information on the work location and work time allowed to the authenticated worker through the additional authentication, thereby causing the authentication to fail if the worker terminal (30) requests connection information to the service device (10) at a work time or work location not allowed to the worker. Thus, it has been mentioned that it is possible to prevent the worker terminal (30) from connecting to the service device (10) at a time or work location not allowed to the worker.

[0174] Accordingly, the management system (1) of the present invention can restrict access to the service device (10) by the worker terminal (30) not only through additional authentication but also depending on whether the worker of the worker terminal (30) is allowed to perform work on the service device (10) when the actual worker terminal (30) accesses the service device (10).

[0175] To this end, the server (20) transmits an algorithm mapping number to an authenticated worker, and further transmits information regarding the work time allowed to the worker, and may also transmit information regarding the work time allowed to the worker further to the service device when the service device is connected.

[0176] FIG. 7 is a flowchart illustrating the operation process in which a server (20) provides information on the working time allowed to a worker along with information on a password algorithm in a management system (1) according to the present invention.

[0177] Referring to FIG. 7, the server (20) of the management system (1) according to an embodiment of the present invention can detect the worker of the worker terminal (30) that was granted the temporary password when the temporary password information received from the worker terminal (30) of the worker who has successfully authenticated matches and the restriction conditions are not satisfied (S700). Then, it can detect previously stored work information corresponding to the detected worker and detect information on the work time (part-time information) for which work is allowed to the detected worker from the detected work information (S702).

[0178] Here, the above work information may be information including information on the work time allowed to the worker and information on the service devices to which the worker is allowed to work. That is, the above work information is information that includes each worker's own work time and information on the service devices to which the worker must work, and may be part of work schedule information that encompasses the entire work schedule of all workers over a certain period.

[0179] In this case, the above work schedule information may be stored in the server (20), and when the server (20) detects a worker of the worker terminal (30) who has been assigned the temporary password in step S700, it may extract work content corresponding to the detected worker from the work schedule information and detect information on the work time allowed to the detected worker from the extracted work content.

[0180] Here, if the above worker is a rotating worker in which multiple workers take turns working for a certain period of time, the information on the work time may be part-time information regarding the work time allowed to the detected worker.

[0181] For example, if the 24 hours of a day are divided into 3-hour intervals, the part-time information corresponding to each work hour may be as shown in Table 2 below.

[0182] Work Time Part Time 09:00:01 ~ 12:00:00 5 12:00:01 ~ 15:00:00 6 15:00:01 ~ 18:00:00 7 18:00:01 ~ 21:00:00 8 21:00:01 ~ 00:00:00 1 00:00:01 ~ 03:00:00 2 03:00:01 ~ 06:00:00 3 06:00:01 ~ 09:00:00 4

[0183] If the part-time information for each work time is as shown in Table 2 above, the part-time information of a worker granted work time from 9:00 AM to 12:00 PM may be 5. In this case, the server (20) can detect the part-time information 5 in step S404 above. Meanwhile, when the part-time information, which is the information of the work time allowed to the worker, is detected, the server (20) can generate random information by randomizing the detected work time information, i.e., the part-time information, according to a pre-set random number key (S704). Here, the pre-set random number key may be a key pre-set between the worker terminal (30) and the server (20). For example, if the pre-set random number key is 16, the server (20) can generate random information by using the random number key '16' to randomize the part-time information '5', which is the information of the detected worker's work time, into an arbitrary number. For example, the server (20) can generate a random number '80' as the random number information by multiplying the password mapping number '16' by the part-time information '5'.

[0184] And when random number information is generated, the server (20) can transmit it to the worker terminal (30) that is allowed to connect to the server (20), along with information on the algorithm mapping number corresponding to the password algorithm currently set on each service device (S706).

[0185] In this case, the above random number information may be hidden data that is not displayed on the worker terminal (30). That is, the above random number information may be information that is not displayed on the worker terminal (30). Therefore, if a worker inputs a password to the service device (10) by directly inputting a password generated on the worker terminal (30) through a password algorithm via the user input section of the worker terminal (30), the above random number information may be data that is not displayed as the password that the worker must input.

[0186] However, when a password is entered into the service device (10) from the worker terminal (30), the worker terminal (30) can transmit random number information obtained by randomizing the part-time information along with the password. For example, when the worker terminal (30) is connected to the service device (10) and the worker enters a password and selects the 'transmit' key, the worker terminal (30) can transmit the random number information along with the password entered by the worker to the service device (10) connected to the communication. Alternatively, if the worker selects 'password transmission', the worker terminal (30) can transmit the random number information along with the password generated by the worker terminal (30) to the service device (10) connected to the communication.

[0187] Then, the service device (10) that receives random number information along with the password can determine whether to allow the connection and operation of the worker terminal (30) based on the password and the random number information.

[0188] FIG. 8 is a flowchart illustrating the operation process in which a service device determines whether to connect a worker terminal based on part-time information entered along with a password and the current time in a management system according to an embodiment of the present invention.

[0189] First, the service device (10) can check whether the password entered from the communication-connected worker terminal (30) matches the password generated based on the variable key value received from the server (20) and the fixed key value according to its own unique information, according to the password algorithm corresponding to the algorithm mapping number set from the current server (20). And if the passwords match each other, it can further check whether the worker of the worker terminal (30) is in a state where work is allowed based on the random number information entered along with the password entered from the worker terminal (30).

[0190] Referring to FIG. 8, if the password input from the worker terminal (30) matches the password generated by the service device (10), the service device (10) can decrypt the random number information input along with the password from the worker terminal (30) using a pre-set random number key (S800). In this case, the random number key may be a key pre-set by the server (20). For example, the server (20) may specify a random number key and transmit the specified random number key to the worker terminal (30) and each service device, thereby enabling the server (20), the worker terminal (30), and a plurality of service devices to have a pre-set random number key.

[0191] For example, as described above, if the random number information is generated by multiplying the pre-set random number key and the worker's part-time information, the random number information can be decrypted into part-time information in the reverse order of generating the random number information. Therefore, if the pre-set random number key is '16', the service device (10) can decrypt the part-time information by dividing the random number information input from the worker terminal (30) along with the password. Thus, as in the example described above, if the random number information is '80', the service device (10) can calculate the worker's part-time information '5' based on the pre-set random number key '16'.

[0192] And the service device (10) can detect the current time and detect part-time information corresponding to the detected current time (S802). Then, it can compare the part-time information corresponding to the detected current time with the decoded part-time information of the worker to check whether they match (S804).

[0193] For example, if the current time is 09:35, the service device (10) can determine the part-time information corresponding to the current time as '5' based on the above Table 2. Then, the part-time information '5' corresponding to the current time can be compared with the decrypted part-time information of the worker. In this case, since the part-time information matches each other, the service device (10) can determine that the current time is the time when work is allowed for the worker of the worker terminal (30). Accordingly, the connection of the worker terminal (30) can be allowed, and a service can be provided according to the request of the worker terminal (30) that has been allowed to connect (S806).

[0194] On the other hand, if the current time is 14:15, the service device (10) can determine the part-time information corresponding to the current time as '6' based on Table 2 above. Then, the part-time information '6' corresponding to the current time can be compared with the decrypted part-time information of the worker. In this case, if the decrypted part-time information is '5', the part-time information is inconsistent with each other, so the service device (10) can determine that the current time is a time when work is not permitted for the worker of the worker terminal (30). Therefore, the service device (10) determines that the connection request at a time when work is not permitted is an unauthorized operation and can refuse the connection of the worker terminal (30). In this case, information indicating that it is an unauthorized operation may be transmitted to and displayed on the worker terminal (30), or notification information indicating that it is an unauthorized operation may be output on the display unit of the service device (10) (S808).

[0195] Meanwhile, as described above, the service device (10) may be equipped with a light sensor (140) capable of recognizing visual information. In this case, by using the light sensor (140), the worker terminal (30) can more easily connect to the service device (10) using an imaged password without the need to directly input a password.

[0196] FIGS. 9 to 11 relate to the operation process of a worker terminal (30) when such an imaged password is provided, and the operation process of a service device (10) that determines whether the worker terminal (30) is connected through a password recognized from the imaged password, and may be an operation process corresponding to each operation process of the worker terminal (30) and the service device (10) in step S1100 of FIG. 6.

[0197] FIG. 9 is a flowchart illustrating the operation process in which a worker terminal images and displays a password generated according to a password algorithm in a management system according to an embodiment of the present invention. FIG. 10 illustrates an example of the imaged password.

[0198] First, referring to FIG. 9, in step S614 of FIG. 6, when a password that can access the service device (10) is generated by inputting a fixed key value corresponding to at least one of the unique information and connection address information of the service device (10) and a variable key value corresponding to the hint information received from the server (20) into a password algorithm that matches the algorithm mapping number provided from the server (20), the worker terminal (30) can convert (encode) the generated password into binary. Then, a password image can be generated according to the converted binary sequence, that is, the bit sequence (S902). For example, the password image may be in the form of a QR (Quick Response) code (900) corresponding to the detected password as shown in FIG. 10, or a barcode.

[0199] And when the above-mentioned imaged password, i.e., the password image, is generated, the worker terminal (30) can display the generated password image on the display unit (340) at the worker's request (S904). In this case, at the worker's request, the worker terminal (30) can display the password image at a designated location that can be scanned by the optical sensor (140) of the service device (10) that the worker intends to work on. Then, the service device (10) scans the password image displayed on the display unit of the worker terminal (30) through the optical sensor (140), for example, a camera, and can recognize and identify the scanned password image.

[0200] Here, the process of the worker terminal (30) displaying a password image and the service device (10) scanning and recognizing the password image displayed on the worker terminal (30) may be part of the process of inputting a password from the worker terminal (30) to the service device (10).

[0201] Meanwhile, FIG. 11 is a flowchart illustrating the operation process of determining whether a worker terminal (30) is connected based on the result of a service device (10) recognizing a password image in a management system (1) according to an embodiment of the present invention.

[0202] Referring to FIG. 11, the service device (10) can first scan and recognize a password image through a light sensor (140) (S1102). Then, the recognized password image can be encoded into a bit sequence (S1104). Then, the encoded bit sequence can be decoded back into a string to generate a password corresponding to the scanned and recognized password image.

[0203] And when a password is generated from a password image, the service device (10) can check whether the generated password matches the password it has generated (S1108). Here, the password generated by the service device (10) may be a password generated based on a variable key value received from the server (20) and a fixed key value according to its own unique information, according to a password algorithm corresponding to an algorithm mapping number set from the current server (20).

[0204] And, as a result of the check in step S1108 above, if the passwords match, a communication connection with the worker terminal (30) can be allowed, and access to the worker terminal (30) can be allowed. And, in response to a request from the worker terminal (30), a service allowed according to the password extracted from the recognized and identified password image can be provided to the worker terminal (30) (S1110).

[0205] However, if the passwords do not match as a result of the check in step S1108 above, the service device (10) may output information indicating that the passwords do not match on the display unit of the service device (10) (S1112). In this case, the connection of the worker terminal (30) to the service device (10) may be refused.

[0206] Meanwhile, the above description explained a configuration in which a worker terminal establishes a communication connection with a service device using connection address information and identifies the service device based on whether a communication connection is established. However, if the worker terminal connects directly to the service device via a wired connection, the connection address information may not be used.

[0207] In this manner, when a worker terminal is connected to a service device via a wired connection, the worker terminal can receive identification information of the currently connected service device through wired communication. Based on the received identification information, the worker can determine whether the service device is authorized for operation. If the wired service device is indeed authorized for operation, a password can be generated based on the unique information of the identified service device stored in the target device information storage unit and the status information of the most recently changed password according to the hint information provided by the server. The generated password can also be entered through the wired service device.

[0208] The present invention described above can be implemented as computer-readable code on a medium on which a program is recorded. A computer-readable medium includes all types of recording devices in which data that can be read by a computer system is stored. Examples of computer-readable media include HDD (Hard Disk Drive), SSD (Solid State Disk), SSD (Silicon Disk Drive), ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage device, etc., and also include implementation in the form of a carrier wave (e.g., transmission over the Internet).

[0209] Accordingly, the above detailed description should not be interpreted restrictively in all respects but should be considered exemplary. The scope of the invention should be determined by a reasonable interpretation of the appended claims, and all modifications within the equivalent scope of the invention are included within the scope of the invention.

Claims

1. A password algorithm that defines rules for generating a password based on at least one key, and a server that provides the at least one key to a plurality of service devices and a worker terminal, and changes the at least one key depending on whether a preset password change condition is satisfied; A worker terminal that stores a password algorithm provided by the server, generates a first password according to the password algorithm based on at least one key provided by the server, and inputs the generated first password into any one of the plurality of service devices; and A password management system characterized by including a plurality of service devices that store a password algorithm provided by the server, generate a second password according to the password algorithm based on at least one key provided by the server, allow access to the worker terminal when a first password entered by the worker terminal matches the second password, and provide a service according to the request of the worker terminal.

2. In paragraph 1, the above at least one key is, A password management system characterized by being information from the point immediately prior to when at least one key was changed.

3. In Paragraph 1, The above password is, It is generated according to rules defined in the password algorithm based on at least one fixed key having a predetermined fixed value and at least one variable key having a value that can be varied by the server, and The above server is, A password management system characterized by changing the value of the variable key and transmitting it to the worker terminal and the plurality of service devices depending on whether the above password change condition is satisfied.

4. In paragraph 3, each of the plurality of service devices is, At least one of its own unique information and its own connection address information is determined as the at least one fixed key, and A password management system characterized by generating the second password based on the fixed key determined above and at least one variable key provided by the server.

5. In paragraph 4, the above worker terminal is, A password management system characterized by, before entering the first password, establishing a communication connection to a service device to request a service to identify the service device, detecting at least one of the unique information and connection address information of the identified service device as at least one fixed key, and generating the first password based on the detected fixed key and at least one variable key provided by the server.

6. In paragraph 5, the above worker terminal is, A password management system characterized by requesting information of service devices for which work is permitted from the server to the worker, who is the owner of the worker terminal, and storing unique information and connection address information of at least one service device provided in response to the request.

7. In Paragraph 1, The above server is, Whenever the at least one key is changed for password change, context information related to the at least one key that has been changed is stored, and the at least one key is changed according to the at least one context information that was previously stored. When the above at least one key is changed, hint information referring to the at least one situation information related to the changed at least one key is transmitted to the worker terminal, and The above worker terminal is, A password management system characterized by detecting at least one situation information corresponding to the hint information among the previously stored situation information, generating at least one modified key according to the detected at least one situation information, and generating the first password according to the generated at least one key.

8. In paragraph 1, the above server is, A password algorithm table configured such that a plurality of different password algorithms are each matched to a different mapping number is provided to the plurality of service devices and the worker terminal, and a mapping number corresponding to any one of the password algorithms included in the password algorithm table is provided to the plurality of service devices and the worker terminal. A password management system characterized by providing a different mapping number corresponding to the other password algorithm to the plurality of service devices when a pre-set change condition is satisfied, thereby changing the password algorithm used by the plurality of service devices for password generation.

9. In Paragraph 8, the previously established change conditions are, A password management system characterized by being satisfied when a preset time elapses or a preset event occurs.

10. In Paragraph 9, the previously established event is, A password management system characterized by including a case in which a new service device is included in the plurality of service devices or at least one service device is removed from the plurality of service devices.

11. In paragraph 8, the above server is, A password management system characterized by, when information regarding a password algorithm is requested from the above-mentioned worker terminal, requesting authentication information of the worker who is the owner of the above-mentioned worker terminal, and when the worker is authenticated based on the authentication information received through the above-mentioned worker terminal, providing the above-mentioned plurality of service devices to the above-mentioned worker terminal a specific mapping number corresponding to the password algorithm currently used for password generation.

12. In Paragraph 11, the above server is, A password management system characterized by issuing a temporary password with a limited number of uses or usage time to the worker terminal when the worker is authenticated, and providing the specific mapping number to the worker terminal when a temporary password not restricted by the restriction condition for usage restriction is received from the worker terminal.

13. In Paragraph 12, the above server is, A password management system characterized by providing information on the working hours during which work is permitted to the authenticated worker, along with the specific mapping number, to the worker terminal when the above-mentioned worker is authenticated.

14. In Paragraph 13, The above worker terminal is, Input the information of the work time along with the first password into one of the service devices, and The service device that receives the above-mentioned first password is, A password management system characterized by determining whether to allow access to the worker terminal based on information about the time at which the first password was entered and information about the working time when the first password and the second password match.

15. A control method for a password management system comprising a server, a plurality of service devices and a worker terminal, and managing a password capable of accessing the plurality of service devices, wherein The above server defines a password algorithm that defines a rule for generating a password based on at least one key, and transmits the at least one key to the worker terminal and the plurality of service devices; The above worker terminal generates a first password according to a password algorithm provided by the server based on at least one key provided by the server; Each of the plurality of service devices generates a second password according to a password algorithm provided by the server based on at least one key provided by the server; The above worker terminal inputs the first password into any one of the plurality of service devices; and, A method for controlling a password management system, characterized in that any one of the above service devices includes the step of allowing access to the worker terminal and providing a service requested by the worker terminal when the first password entered from the worker terminal matches the second password.

16. In Paragraph 15, The above server changes the at least one key depending on whether a pre-set password change condition is satisfied; The server transmits the modified at least one key to the worker terminal and the plurality of service devices; and, A control method for a password management system characterized by further including the step of generating a first password and a second password changed according to at least one changed key, wherein the above worker terminal and the above plurality of service devices.

17. In Paragraph 15, Each of the above plurality of service devices is, At least one of one's own unique information and one's own connection address information is determined as the at least one fixed key, and the second password is generated based on the determined fixed key and at least one variable key provided by the server. The above worker terminal is, A control method for a password management system characterized by, before entering the first password, establishing a communication connection to any one of the service devices to request a service to identify the service device, detecting at least one of the unique information and connection address information of the identified service device as at least one fixed key, and generating the first password based on the detected fixed key and at least one variable key provided by the server.

18. In Paragraph 16, The step of the server transmitting the password algorithm and the at least one key to the worker terminal and the plurality of service devices is: The server transmits to the plurality of service devices a password algorithm table configured such that a plurality of different password algorithms are each matched to a different mapping number, and a specific algorithm mapping number corresponding to one of the password algorithms; and The plurality of service devices further include the step of detecting a password algorithm according to the specific algorithm mapping number, The step of the server changing the at least one key is The server transmits another algorithm mapping number corresponding to a different password algorithm from any one of the password algorithms to the plurality of service devices; and, A control method for a password management system characterized by further including the step of the plurality of service devices detecting the other password algorithm according to the other algorithm mapping number.

19. In Paragraph 18, The step of the above worker terminal generating the first password is The step of the server providing the specific algorithm mapping number to the worker terminal in response to a request from the worker terminal; The above worker terminal detects one password algorithm corresponding to the specific algorithm mapping number from the password algorithm table; and, A method for controlling a password management system, characterized in that the above-described worker terminal includes the step of generating a first password according to any one of the detected password algorithms based on at least one key provided from the server.

Citation Information

Patent Citations

  • Information processing system, information processing device, information processing method, and program

    JP7158692B2

  • Apparatus and method for managing password

    KR101627078B1

  • Password management system and method for changing password using password management system

    KR101689848B1

  • User centric authentication mehtod and system

    KR102035312B1

  • Password management system

    US20170070494A1