Method and apparatus for registering a device for use
Claim Score by NHIP
Abstract
A server and method for supporting device registration by the server are provided. The present disclosure relates to a sensor network, Machine Type Communication (MTC), Machine-to-Machine (M2M) communication, and technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the above technologies, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services.

Term
10.2 yearsto projected expiry
Projected expiry 5 December 2036, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
88 claims: 12 independent, 76 dependent
- 1A method for supporting device registration by a server, the method comprising:receiving an authentication information generation request from a user terminal;determining a control allowance area of the user terminal in response to the authentication information generation request;generating authentication information based on a predetermined authentication method for the determined control allowance area;andrequesting a control device to register the generated authentication information,wherein the authentication method includes information on an object to be authenticated for the determined control allowance area.
- 1A method for supporting device registration by a server, the method comprising:receiving an authentication information generation request from a user terminal;determining a control allowance area of the user terminal in response to the authentication information generation request;generating authentication information based on a predetermined authentication method for the determined control allowance area;andrequesting a control device to register the generated authentication information,wherein the authentication method includes information on an object to be authenticated for the determined control allowance area.
- 6A method for registering a device for use of a control device by a gateway, the method comprising:receiving, from a user terminal, a control request for a control device;determining whether authentication information corresponding to the gateway is registered in the control device;if the authentication information corresponding to the gateway is registered in the control device, determining an authentication method of an area controlled by the gateway;andif the authentication method is an equipment authentication, granting a control authority to the control device based on the determined authentication method and an authentication identification message received from an equipment in the area controlled by the gateway,wherein the authentication method includes information on an object to be authenticated for a control allowance area of the user terminal.
- 6A method for registering a device for use of a control device by a gateway, the method comprising:receiving, from a user terminal, a control request for a control device;determining whether authentication information corresponding to the gateway is registered in the control device;if the authentication information corresponding to the gateway is registered in the control device, determining an authentication method of an area controlled by the gateway;andif the authentication method is an equipment authentication, granting a control authority to the control device based on the determined authentication method and an authentication identification message received from an equipment in the area controlled by the gateway,wherein the authentication method includes information on an object to be authenticated for a control allowance area of the user terminal.
- 15Broadest claimClaim Score 74, broad(NHIP)A method for supporting device registration by a control device, the method comprising:receiving a connection initiation request from a gateway of a registration area;registering authentication information in response to the connection initiation request;determining an authentication method of an area to be controlled based on the authentication information;if the authentication method is an equipment authentication, transmitting the authentication information to an equipment of the area to be controlled;andreceiving a control authority corresponding to the authentication information from a gateway of the area to be controlled.
- 15Broadest claimClaim Score 74, broad(NHIP)A method for supporting device registration by a control device, the method comprising:receiving a connection initiation request from a gateway of a registration area;registering authentication information in response to the connection initiation request;determining an authentication method of an area to be controlled based on the authentication information;if the authentication method is an equipment authentication, transmitting the authentication information to an equipment of the area to be controlled;andreceiving a control authority corresponding to the authentication information from a gateway of the area to be controlled.
- 23A server that supports a device registration, the server comprising:a communication unit that communicates information with at least one of a gateway or a user terminal;anda controller that determines a control allowance area of the user terminal in response to an authentication information generation request received from the user terminal, generates authentication information based on a pre-determined authentication method for the determined control allowance area, and requests a control device to register the generated authentication information.
- 23A server that supports a device registration, the server comprising:a communication unit that communicates information with at least one of a gateway or a user terminal;anda controller that determines a control allowance area of the user terminal in response to an authentication information generation request received from the user terminal, generates authentication information based on a pre-determined authentication method for the determined control allowance area, and requests a control device to register the generated authentication information.
- 28A gateway that registers a device for use of a control device, the gateway comprising:a communication unit that communicates information with a server, a user terminal, and a control device;anda controller that receives, from the user terminal, a control request of the control device, determines whether authentication information corresponding to the gateway is registered in the control device, determines an authentication method of an area controlled by the gateway if the authentication information is registered in the control device, and grants, if the authentication method is an equipment authentication, a control authority to the control device based on the determined authentication method and an authentication identification message received from an equipment in the area controlled by the gateway,wherein the authentication method includes information on an object to be authenticated for a control allowance area of the user terminal.
- 28A gateway that registers a device for use of a control device, the gateway comprising:a communication unit that communicates information with a server, a user terminal, and a control device;anda controller that receives, from the user terminal, a control request of the control device, determines whether authentication information corresponding to the gateway is registered in the control device, determines an authentication method of an area controlled by the gateway if the authentication information is registered in the control device, and grants, if the authentication method is an equipment authentication, a control authority to the control device based on the determined authentication method and an authentication identification message received from an equipment in the area controlled by the gateway,wherein the authentication method includes information on an object to be authenticated for a control allowance area of the user terminal.
- 37A control device that supports device registration, the control device comprising:a communication unit that communicates information with a server, a gateway, a user terminal, and a control device;anda controller that receives a connection initiation request from a gateway of a registration area, registers authentication information in response to the connection initiation request, determines an authentication method of an area to be controlled based on the authentication information, if the authentication method is an equipment authentication, transmits the authentication information to an equipment in the area to be controlled, and receives a control authority for the area corresponding to the authentication information from the gateway of the area to be controlled.
- 37A control device that supports device registration, the control device comprising:a communication unit that communicates information with a server, a gateway, a user terminal, and a control device;anda controller that receives a connection initiation request from a gateway of a registration area, registers authentication information in response to the connection initiation request, determines an authentication method of an area to be controlled based on the authentication information, if the authentication method is an equipment authentication, transmits the authentication information to an equipment in the area to be controlled, and receives a control authority for the area corresponding to the authentication information from the gateway of the area to be controlled.
Independent claims12
500 paragraphs in 10 sections, as filed
PRIORITY
PRIORITY
This application claims priority under 35 U.S.C. §119(a) to Korean Patent Application No. 10-2014-0159086, which was filed in the Korean Intellectual Property Office on Nov. 14, 2014, the entire content of which is incorporated herein by reference.
This application claims priority under 35 U.S.C. §119(a) to Korean Patent Application No. 10-2014-0159086, which was filed in the Korean Intellectual Property Office on Nov. 14, 2014, the entire content of which is incorporated herein by reference.
BACKGROUND OF THE INVENTION
BACKGROUND OF THE INVENTION
1. Field of the Invention
1. Field of the Invention
The present invention relates generally to the registration of a device to a gateway, and more particularly, to a method and apparatus for granting a control authority to a control device, after the control device passes an authentication procedure in a control area.
The present invention relates generally to the registration of a device to a gateway, and more particularly, to a method and apparatus for granting a control authority to a control device, after the control device passes an authentication procedure in a control area.
2. Description of the Prior Art
2. Description of the Prior Art
The Internet is now evolving to the Internet of Things (IoT), where distributed entities, such as things, e.g., powered objects, exchange and process information without human intervention. The Internet of Everything (IoE), which is a combination of the IoT technology and Big Data processing technology through connection with a cloud server, has emerged. As technology elements, such as “sensing technology”, “wired/wireless communication and network infrastructure”, “service interface technology”, and “security technology” have been demanded for IoT implementation, a sensor network, a Machine-to-Machine (M2M) communication, Machine Type Communication (MTC), etc., are currently being researched.
The Internet is now evolving to the Internet of Things (IoT), where distributed entities, such as things, e.g., powered objects, exchange and process information without human intervention. The Internet of Everything (IoE), which is a combination of the IoT technology and Big Data processing technology through connection with a cloud server, has emerged. As technology elements, such as “sensing technology”, “wired/wireless communication and network infrastructure”, “service interface technology”, and “security technology” have been demanded for IoT implementation, a sensor network, a Machine-to-Machine (M2M) communication, Machine Type Communication (MTC), etc., are currently being researched.
An IoT environment may provide intelligent Internet technology services that create a new value to human life by collecting and analyzing data generated among connected things.
An IoT environment may provide intelligent Internet technology services that create a new value to human life by collecting and analyzing data generated among connected things.
IoT may be applied to a variety of fields including smart home, smart building, smart city, smart car or connected cars, smart grid, health care, smart appliances and advanced medical services through convergence and combination between existing Information Technology (IT) and various industrial applications.
IoT may be applied to a variety of fields including smart home, smart building, smart city, smart car or connected cars, smart grid, health care, smart appliances and advanced medical services through convergence and combination between existing Information Technology (IT) and various industrial applications.
However, as IoT technology and the Internet evolve as described above, in the equipment controlled by a user using the mobile device, technologies such as information security, registration procedures, and authentication procedures for control devices are desired in order to prevent control and/or hacking by an unauthorized user.
However, as IoT technology and the Internet evolve as described above, in the equipment controlled by a user using the mobile device, technologies such as information security, registration procedures, and authentication procedures for control devices are desired in order to prevent control and/or hacking by an unauthorized user.
SUMMARY OF THE INVENTION
SUMMARY OF THE INVENTION
The present invention has been made to address the above-mentioned technical problems.
The present invention has been made to address the above-mentioned technical problems.
An aspect of the present invention is to provide a method and apparatus for registering a control device for controlling equipment in a system.
An aspect of the present invention is to provide a method and apparatus for registering a control device for controlling equipment in a system.
Another aspect of the present invention is to provide a device and method for generating an authentication key to register to a control device based on user information and a control area of the user, and granting a control authority for the control area if an authentication procedure is completed using the authentication key.
Another aspect of the present invention is to provide a device and method for generating an authentication key to register to a control device based on user information and a control area of the user, and granting a control authority for the control area if an authentication procedure is completed using the authentication key.
In accordance with an aspect of the present invention, a method is provided for supporting, by a server, a registration of a device for use. The method includes receiving an authentication information generation request from a user terminal; determining a control allowance area of the user terminal in response to the authentication information generation request; generating authentication information based on a predetermined authentication method for the determined control allowance area; and requesting a control device to register the generated authentication information. The authentication method includes information on an object to be authenticated for the determined control allowance area.
In accordance with an aspect of the present invention, a method is provided for supporting, by a server, a registration of a device for use. The method includes receiving an authentication information generation request from a user terminal; determining a control allowance area of the user terminal in response to the authentication information generation request; generating authentication information based on a predetermined authentication method for the determined control allowance area; and requesting a control device to register the generated authentication information. The authentication method includes information on an object to be authenticated for the determined control allowance area.
In accordance with another aspect of the present invention, a method is provided for registering a device for use of a control device by a gateway. The method includes receiving, from a user terminal, a control request for a control device; determining whether authentication information corresponding to the gateway is registered in the control device; if the authentication information corresponding to the gateway is registered in the control device, determining an authentication method of an area controlled by the gateway; and if the authentication method is an equipment authentication, granting a control authority to the control device based on the determined authentication method and an authentication identification message received from an equipment in the area controlled by the gateway. The authentication method includes information on an object to be authenticated for a control allowance area of the user terminal.
In accordance with another aspect of the present invention, a method is provided for registering a device for use of a control device by a gateway. The method includes receiving, from a user terminal, a control request for a control device; determining whether authentication information corresponding to the gateway is registered in the control device; if the authentication information corresponding to the gateway is registered in the control device, determining an authentication method of an area controlled by the gateway; and if the authentication method is an equipment authentication, granting a control authority to the control device based on the determined authentication method and an authentication identification message received from an equipment in the area controlled by the gateway. The authentication method includes information on an object to be authenticated for a control allowance area of the user terminal.
In accordance with another aspect of the present invention, a method is provided for supporting, by a control device, a registration of a device for use. The method includes receiving a connection initiation request from a gateway of a registration area; registering authentication information in response to the connection initiation request; determining an authentication method of an area to be controlled based on the authentication information; if the authentication method is an equipment authentication, transmitting the authentication information to an equipment of the area to be controlled; and receiving a control authority corresponding to the authentication information from a gateway of the area to be controlled.
In accordance with another aspect of the present invention, a method is provided for supporting, by a control device, a registration of a device for use. The method includes receiving a connection initiation request from a gateway of a registration area; registering authentication information in response to the connection initiation request; determining an authentication method of an area to be controlled based on the authentication information; if the authentication method is an equipment authentication, transmitting the authentication information to an equipment of the area to be controlled; and receiving a control authority corresponding to the authentication information from a gateway of the area to be controlled.
In accordance with another aspect of the present invention, a server is provided, which supports registration of a device for use. The server includes a communication unit that communicates information with at least one of a gateway or a user terminal; and a controller that determines a control allowance area of the user terminal in response to an authentication information generation request received from the user terminal, generates authentication information based on a pre-determined authentication method for the determined control allowance area, and requests a control device to register the generated authentication information.
In accordance with another aspect of the present invention, a server is provided, which supports registration of a device for use. The server includes a communication unit that communicates information with at least one of a gateway or a user terminal; and a controller that determines a control allowance area of the user terminal in response to an authentication information generation request received from the user terminal, generates authentication information based on a pre-determined authentication method for the determined control allowance area, and requests a control device to register the generated authentication information.
In accordance with another aspect of the present invention, a gateway is provided, which registers a device for use of a control device. The gateway includes a communication unit that communicates information with a server, a user terminal, and a control device; and a controller that determines whether authentication information corresponding to the gateway is registered in the control device when receiving, from the user terminal, a control request of the control device, determines an authentication method of an area controlled by the gateway when the authentication information is registered in the control device, and grants, when the authentication method is an equipment authentication, a control authority to the control device based on the determined authentication method and an authentication identification message received from an equipment in the area controlled by the gateway. The authentication method includes information on an object to be authenticated for a control allowance area of the user terminal.
In accordance with another aspect of the present invention, a gateway is provided, which registers a device for use of a control device. The gateway includes a communication unit that communicates information with a server, a user terminal, and a control device; and a controller that determines whether authentication information corresponding to the gateway is registered in the control device when receiving, from the user terminal, a control request of the control device, determines an authentication method of an area controlled by the gateway when the authentication information is registered in the control device, and grants, when the authentication method is an equipment authentication, a control authority to the control device based on the determined authentication method and an authentication identification message received from an equipment in the area controlled by the gateway. The authentication method includes information on an object to be authenticated for a control allowance area of the user terminal.
In accordance with another aspect of the present invention, a control device is provided, which supports registration of a device for use. The control device includes a communication unit that communicates information with a server, a gateway, a user terminal, and a control device; and a controller that receives a connection initiation request from a gateway of a registration area, registers authentication information in response to the connection initiation request, determines an authentication method of an area to be controlled based on the authentication information, when the authentication method is an equipment authentication, transmits the authentication information to an equipment in the area to be controlled, and receives a control authority for the area corresponding to the authentication information from the gateway of the area to be controlled.
In accordance with another aspect of the present invention, a control device is provided, which supports registration of a device for use. The control device includes a communication unit that communicates information with a server, a gateway, a user terminal, and a control device; and a controller that receives a connection initiation request from a gateway of a registration area, registers authentication information in response to the connection initiation request, determines an authentication method of an area to be controlled based on the authentication information, when the authentication method is an equipment authentication, transmits the authentication information to an equipment in the area to be controlled, and receives a control authority for the area corresponding to the authentication information from the gateway of the area to be controlled.
BRIEF DESCRIPTION OF THE DRAWINGS
BRIEF DESCRIPTION OF THE DRAWINGS
The above and other aspects, features, and advantages of certain embodiments of the present invention will be more apparent from the following detailed description when taken in conjunction with the accompanying drawings, in which:
The above and other aspects, features, and advantages of certain embodiments of the present invention will be more apparent from the following detailed description when taken in conjunction with the accompanying drawings, in which:
<figref idrefs="DRAWINGS">FIG. 1</figref> illustrates a system for registering a device to a gateway according to an embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 1</figref> illustrates a system for registering a device to a gateway according to an embodiment of the present invention;
<figref idrefs="DRAWINGS">FIG. 2</figref> is a signal flow diagram illustrating a method for registering a security key in a registration area according to an embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 2</figref> is a signal flow diagram illustrating a method for registering a security key in a registration area according to an embodiment of the present invention;
<figref idrefs="DRAWINGS">FIG. 3</figref> is a signal flow diagram illustrating a process for issuing a security key to a user terminal by a gateway of a control area according to an embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 3</figref> is a signal flow diagram illustrating a process for issuing a security key to a user terminal by a gateway of a control area according to an embodiment of the present invention;
<figref idrefs="DRAWINGS">FIG. 4</figref> is a signal flow diagram illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 4</figref> is a signal flow diagram illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention;
<figref idrefs="DRAWINGS">FIG. 5</figref> is a signal flow diagram illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 5</figref> is a signal flow diagram illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention;
<figref idrefs="DRAWINGS">FIG. 6</figref> is a signal flow diagram illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 6</figref> is a signal flow diagram illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention;
<figref idrefs="DRAWINGS">FIG. 7</figref> is a flowchart illustrating a method for supporting, by a server, a connection between a control device and a gateway according to an embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 7</figref> is a flowchart illustrating a method for supporting, by a server, a connection between a control device and a gateway according to an embodiment of the present invention;
<figref idrefs="DRAWINGS">FIG. 8</figref> is a flowchart illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 8</figref> is a flowchart illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention;
<figref idrefs="DRAWINGS">FIG. 9</figref> illustrates a server according to an embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 9</figref> illustrates a server according to an embodiment of the present invention;
<figref idrefs="DRAWINGS">FIG. 10</figref> illustrates a gateway according to an embodiment of the present invention; and
<figref idref="DRAWINGS">FIG. 10</figref> illustrates a gateway according to an embodiment of the present invention; and
<figref idrefs="DRAWINGS">FIG. 11</figref> illustrates a control device according to an embodiment of the present invention.
<figref idref="DRAWINGS">FIG. 11</figref> illustrates a control device according to an embodiment of the present invention.
DETAILED DESCRIPTION OF EMBODIMENTS OF THE INVENTION
DETAILED DESCRIPTION OF EMBODIMENTS OF THE INVENTION
Various embodiments of the present invention will now be described in detail with reference to the accompanying drawings. In the following description, specific details such as detailed configuration and components are merely provided to assist the overall understanding of these embodiments of the present invention. Therefore, it should be apparent to those skilled in the art that various changes and modifications of the embodiments described herein can be made without departing from the scope and spirit of the present invention. In addition, descriptions of well-known functions and constructions are omitted for clarity and conciseness.
Various embodiments of the present invention will now be described in detail with reference to the accompanying drawings. In the following description, specific details such as detailed configuration and components are merely provided to assist the overall understanding of these embodiments of the present invention. Therefore, it should be apparent to those skilled in the art that various changes and modifications of the embodiments described herein can be made without departing from the scope and spirit of the present invention. In addition, descriptions of well-known functions and constructions are omitted for clarity and conciseness.
For similar reasoning, in the accompanying drawings, some elements may be exaggerated, omitted, or schematically illustrated. Further, the size of each element does not necessarily reflect the actual size.
For similar reasoning, in the accompanying drawings, some elements may be exaggerated, omitted, or schematically illustrated. Further, the size of each element does not necessarily reflect the actual size.
Herein, it will be understood that each block of the flowchart illustrations, and combinations of blocks in the flowchart illustrations, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart block or blocks. These computer program instructions may also be stored in a computer usable or computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer usable or computer-readable memory produce an article of manufacture including instruction means that implement the function specified in the flowchart block or blocks. The computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions that execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.
Herein, it will be understood that each block of the flowchart illustrations, and combinations of blocks in the flowchart illustrations, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart block or blocks. These computer program instructions may also be stored in a computer usable or computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer usable or computer-readable memory produce an article of manufacture including instruction means that implement the function specified in the flowchart block or blocks. The computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions that execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.
Further, each block of the flowchart illustrations may represent a module, segment, or portion of code, which includes one or more executable instructions for implementing the specified logical function(s).
Further, each block of the flowchart illustrations may represent a module, segment, or portion of code, which includes one or more executable instructions for implementing the specified logical function(s).
In some alternative implementations, the functions noted in the blocks may occur out of the illustrated order. For example, two blocks shown in succession may in fact be executed substantially at the same time or in the reverse order, depending upon the functionality involved.
In some alternative implementations, the functions noted in the blocks may occur out of the illustrated order. For example, two blocks shown in succession may in fact be executed substantially at the same time or in the reverse order, depending upon the functionality involved.
Herein, the term “unit” or “module” refers to a software element or a hardware element, such as a Field Programmable Gate Array (FPGA) or an Application Specific Integrated Circuit (ASIC), which performs a predetermined function. However, the term “unit” or “module” are not limited to meaning software or hardware. A unit or module may be constructed either to be stored in an addressable storage medium or to execute one or more processors. Therefore, the term “unit” or “module” includes, for example, software elements, object-oriented software elements, class elements or task elements, processes, functions, properties, procedures, sub-routines, segments of a program code, drivers, firmware, micro-codes, circuits, data, database, data structures, tables, arrays, and parameters.
Herein, the term “unit” or “module” refers to a software element or a hardware element, such as a Field Programmable Gate Array (FPGA) or an Application Specific Integrated Circuit (ASIC), which performs a predetermined function. However, the term “unit” or “module” are not limited to meaning software or hardware. A unit or module may be constructed either to be stored in an addressable storage medium or to execute one or more processors. Therefore, the term “unit” or “module” includes, for example, software elements, object-oriented software elements, class elements or task elements, processes, functions, properties, procedures, sub-routines, segments of a program code, drivers, firmware, micro-codes, circuits, data, database, data structures, tables, arrays, and parameters.
Herein, the elements and functions provided by a unit or module may be either divided into a larger number of elements, units, or modules, or combined into a smaller number of elements, units, or modules. Further, the elements, units, or modules may be implemented to reproduce one or more Central Processing Units (CPUs) within a device or a security multimedia card.
Herein, the elements and functions provided by a unit or module may be either divided into a larger number of elements, units, or modules, or combined into a smaller number of elements, units, or modules. Further, the elements, units, or modules may be implemented to reproduce one or more Central Processing Units (CPUs) within a device or a security multimedia card.
<figref idrefs="DRAWINGS">FIG. 1</figref> illustrates a system for registering a device to a gateway according to an embodiment of the present invention.
<figref idref="DRAWINGS">FIG. 1</figref> illustrates a system for registering a device to a gateway according to an embodiment of the present invention.
Referring to <figref idrefs="DRAWINGS">FIG. 1</figref>, the system includes a user terminal <b>100</b>, a control device <b>105</b>, e.g., a smartwatch, a gateway <b>110</b> of a registration area (e.g., a hotel lobby), a gateway <b>120</b> of a control area (e.g., a guestroom), a gateway <b>140</b> of another control area (e.g., a shop), a plurality of equipment <b>115</b>, <b>125</b>, and <b>145</b> of the respective gateways <b>110</b>, <b>120</b>, and <b>140</b>, and a server <b>130</b>.
Referring to <figref idref="DRAWINGS">FIG. 1</figref>, the system includes a user terminal <b>100</b>, a control device <b>105</b>, e.g., a smartwatch, a gateway <b>110</b> of a registration area (e.g., a hotel lobby), a gateway <b>120</b> of a control area (e.g., a guestroom), a gateway <b>140</b> of another control area (e.g., a shop), a plurality of equipment <b>115</b>, <b>125</b>, and <b>145</b> of the respective gateways <b>110</b>, <b>120</b>, and <b>140</b>, and a server <b>130</b>.
The user terminal <b>100</b> may connect a user and the system. The user may perform various operations for registering the control device <b>105</b> to one of the gateways through the user terminal <b>100</b>. The user terminal <b>100</b> may receive an Identification (ID) and password configuration from the user at the time of an initial connection by the user to the system. The user terminal <b>100</b> may generate a user account in the system based on the received configuration.
The user terminal <b>100</b> may connect a user and the system. The user may perform various operations for registering the control device <b>105</b> to one of the gateways through the user terminal <b>100</b>. The user terminal <b>100</b> may receive an Identification (ID) and password configuration from the user at the time of an initial connection by the user to the system. The user terminal <b>100</b> may generate a user account in the system based on the received configuration.
For example, the user terminal <b>100</b> may include a smartphone, and/or a storage medium that stores algorithms or the like. The user terminal <b>100</b> may connect to the server <b>130</b> of the system based on the received configuration in an environment such as a wireless Local Area Network (LAN). For example, the user terminal <b>100</b> may include a communication module for connecting to the server <b>130</b>. The user terminal <b>100</b> may request registration of a user thereof using a user account.
For example, the user terminal <b>100</b> may include a smartphone, and/or a storage medium that stores algorithms or the like. The user terminal <b>100</b> may connect to the server <b>130</b> of the system based on the received configuration in an environment such as a wireless Local Area Network (LAN). For example, the user terminal <b>100</b> may include a communication module for connecting to the server <b>130</b>. The user terminal <b>100</b> may request registration of a user thereof using a user account.
The user terminal <b>100</b> may include a display unit, an input unit, a storage unit, and a control device, and may display, on the display unit, settings for receiving the ID and Password configuration from the user. In addition, the display unit may include a touchpad that allows the user to input information using a finger or a touch pen.
The user terminal <b>100</b> may include a display unit, an input unit, a storage unit, and a control device, and may display, on the display unit, settings for receiving the ID and Password configuration from the user. In addition, the display unit may include a touchpad that allows the user to input information using a finger or a touch pen.
The display unit may display an indication as to whether the user account is registered in the server, and when the user account is not registered in the server, the settings for repetitively receiving the ID and Password configuration. When the user account is registered in the server <b>130</b>, the display unit may display a registration completion message.
The display unit may display an indication as to whether the user account is registered in the server, and when the user account is not registered in the server, the settings for repetitively receiving the ID and Password configuration. When the user account is registered in the server <b>130</b>, the display unit may display a registration completion message.
The user terminal <b>100</b> may be a mobile device or a wearable electronic device, as well as the smartphone. Examples of the wearable device include a mounting-on glasses type device, a bracelet type device, an arm band type device, and a pendant type device.
The user terminal <b>100</b> may be a mobile device or a wearable electronic device, as well as the smartphone. Examples of the wearable device include a mounting-on glasses type device, a bracelet type device, an arm band type device, and a pendant type device.
The user terminal <b>100</b> may store “user information” in the storage unit. The user information may include information on a user's name, address, occupation, etc. The user information may be used as a reference to distinguish the plurality of users stored in the server. In addition, the user information may include grade information at the time of the registration by the user on the server <b>130</b>. The grade information may include information on an area in which the control is permitted to the user registered through the user terminal <b>100</b>. The grade information may be differentially determined for each user, for example, based on a fee paid by the user for registering to the system. The control allowance area information generated by the server <b>130</b> may be based on the user information.
The user terminal <b>100</b> may store “user information” in the storage unit. The user information may include information on a user's name, address, occupation, etc. The user information may be used as a reference to distinguish the plurality of users stored in the server. In addition, the user information may include grade information at the time of the registration by the user on the server <b>130</b>. The grade information may include information on an area in which the control is permitted to the user registered through the user terminal <b>100</b>. The grade information may be differentially determined for each user, for example, based on a fee paid by the user for registering to the system. The control allowance area information generated by the server <b>130</b> may be based on the user information.
The user terminal <b>100</b> may be connected to a gateway of a control area using a wireless communication in the control area. For example, the wireless communication may include Bluetooth, WIFI, WIFI-Direct, Zigbee, Z-wave, or Near Field Communication (NFC).
The user terminal <b>100</b> may be connected to a gateway of a control area using a wireless communication in the control area. For example, the wireless communication may include Bluetooth, WIFI, WIFI-Direct, Zigbee, Z-wave, or Near Field Communication (NFC).
The user terminal <b>100</b> may request a gateway of a control area to control the control area utilizing wireless communication. Thereafter, the user terminal <b>100</b> may receive, from the gateway of the control area, a result of the control request.
The user terminal <b>100</b> may request a gateway of a control area to control the control area utilizing wireless communication. Thereafter, the user terminal <b>100</b> may receive, from the gateway of the control area, a result of the control request.
When the gateway of the control area to which the control request has been made corresponds to a gateway of the control area of which a control by the user terminal <b>100</b> has been allowed, the user terminal <b>100</b> may receive a security key from the gateway. The “security key” indicates that the user terminal <b>100</b> has a control authority in the control area to which the control request has been made according to the user information or user-included grade information.
When the gateway of the control area to which the control request has been made corresponds to a gateway of the control area of which a control by the user terminal <b>100</b> has been allowed, the user terminal <b>100</b> may receive a security key from the gateway. The “security key” indicates that the user terminal <b>100</b> has a control authority in the control area to which the control request has been made according to the user information or user-included grade information.
The user terminal <b>100</b> may perform a control command along with the security key, after receiving the issued security key. In addition, the user terminal <b>100</b> may proceed with an authentication process of the control device <b>105</b> in the control area using the control command and the security key.
The user terminal <b>100</b> may perform a control command along with the security key, after receiving the issued security key. In addition, the user terminal <b>100</b> may proceed with an authentication process of the control device <b>105</b> in the control area using the control command and the security key.
In addition, the user terminal <b>100</b> may display a message indicating the result of the above-described process. That is, when the user terminal <b>100</b> receives the security key from a gateway of a control allowance area, the user terminal <b>100</b> may display an identification message for the control allowance area. However, when the user terminal <b>100</b> makes a control request for an area to which the control is not allowed, the user terminal <b>100</b> will not receive the security key from a gateway of the control area. For example, after making a control request to a gateway of a control area, when no response is received within a certain time, the user terminal <b>100</b> may determine that the control is not allowed for the control requested area. When the control is not allowed for the control requested area, the user terminal <b>100</b> may display a message indicating that the control for the area is not allowed.
In addition, the user terminal <b>100</b> may display a message indicating the result of the above-described process. That is, when the user terminal <b>100</b> receives the security key from a gateway of a control allowance area, the user terminal <b>100</b> may display an identification message for the control allowance area. However, when the user terminal <b>100</b> makes a control request for an area to which the control is not allowed, the user terminal <b>100</b> will not receive the security key from a gateway of the control area. For example, after making a control request to a gateway of a control area, when no response is received within a certain time, the user terminal <b>100</b> may determine that the control is not allowed for the control requested area. When the control is not allowed for the control requested area, the user terminal <b>100</b> may display a message indicating that the control for the area is not allowed.
The control device <b>105</b> may be used by a user to control the equipment <b>115</b>, <b>125</b>, and <b>145</b> in each area. For example, the control device <b>105</b> may be a smart phone, a mobile device, or a wearable device.
The control device <b>105</b> may be used by a user to control the equipment <b>115</b>, <b>125</b>, and <b>145</b> in each area. For example, the control device <b>105</b> may be a smart phone, a mobile device, or a wearable device.
Alternatively, the system may include a plurality of control devices <b>105</b>, which can be connected to a gateway of a registered area utilizing wireless communication, e.g., Bluetooth, WIFI, WIFI-Direct, Zigbee, Z-wave, or NFC.
Alternatively, the system may include a plurality of control devices <b>105</b>, which can be connected to a gateway of a registered area utilizing wireless communication, e.g., Bluetooth, WIFI, WIFI-Direct, Zigbee, Z-wave, or NFC.
Further, each of the gateways <b>110</b> and <b>120</b> and the controller <b>105</b> may include a communication module or the like for performing wireless communication.
Further, each of the gateways <b>110</b> and <b>120</b> and the controller <b>105</b> may include a communication module or the like for performing wireless communication.
The control device <b>105</b> may register an authentication key generated by the server <b>130</b> through the gateway <b>110</b> of the registration area. The authentication key may be used to authenticate the user in the area to be controlled by the control device <b>105</b>. In addition, the authentication key may include authentication information. Accordingly, in the following description, “authentication key” may be used interchangeably with “authentication information”.
The control device <b>105</b> may register an authentication key generated by the server <b>130</b> through the gateway <b>110</b> of the registration area. The authentication key may be used to authenticate the user in the area to be controlled by the control device <b>105</b>. In addition, the authentication key may include authentication information. Accordingly, in the following description, “authentication key” may be used interchangeably with “authentication information”.
The authentication key may perform the authentication procedure with a gateway of an area to be controlled. In addition, the authentication key may perform the authentication procedure with equipment of the area to be controlled.
The authentication key may perform the authentication procedure with a gateway of an area to be controlled. In addition, the authentication key may perform the authentication procedure with equipment of the area to be controlled.
The authentication key may be generated in the server <b>130</b>, based on the authentication method in the control area to be performed the authentication.
The authentication key may be generated in the server <b>130</b>, based on the authentication method in the control area to be performed the authentication.
The control device <b>105</b> may display information for registering in the server <b>130</b>. For example, when receiving a connection initiation request from the gateway <b>110</b> of the registration area through the wireless communication, the control device <b>105</b> may display a message indicating the receipt of the request.
The control device <b>105</b> may display information for registering in the server <b>130</b>. For example, when receiving a connection initiation request from the gateway <b>110</b> of the registration area through the wireless communication, the control device <b>105</b> may display a message indicating the receipt of the request.
The connection initiation request received from the gateway <b>110</b> of the registration area may include a registration request for the authentication key generated by the server <b>130</b>.
The connection initiation request received from the gateway <b>110</b> of the registration area may include a registration request for the authentication key generated by the server <b>130</b>.
In addition, the control device <b>105</b> may display, upon receiving the request, a message requesting the user to connect with the gateway <b>110</b> of the registration area and registration approval for the authentication key generated by the server <b>130</b>. For example, the message requesting the registration approval displayed on the control device <b>105</b> may be in the form of a pop-up window in which the user may press a button to approve the connection to the gateway <b>110</b> and the registration of the authentication key.
In addition, the control device <b>105</b> may display, upon receiving the request, a message requesting the user to connect with the gateway <b>110</b> of the registration area and registration approval for the authentication key generated by the server <b>130</b>. For example, the message requesting the registration approval displayed on the control device <b>105</b> may be in the form of a pop-up window in which the user may press a button to approve the connection to the gateway <b>110</b> and the registration of the authentication key.
The control device <b>105</b> may perform an authentication procedure in order to control the equipment <b>115</b> in the control area. The control device <b>105</b> may perform an authentication procedure using the registered authentication key. The control device <b>105</b> may determine the authentication method of the area to be controlled based on the registered authentication key.
The control device <b>105</b> may perform an authentication procedure in order to control the equipment <b>115</b> in the control area. The control device <b>105</b> may perform an authentication procedure using the registered authentication key. The control device <b>105</b> may determine the authentication method of the area to be controlled based on the registered authentication key.
For example, the authentication method may include information on an object which is to be authenticated for each of the control areas and at least one among the server authentication, the gateway authentication, and the equipment authentication in the control area.
For example, the authentication method may include information on an object which is to be authenticated for each of the control areas and at least one among the server authentication, the gateway authentication, and the equipment authentication in the control area.
In addition, the authentication method may be determined based on the characteristics of the control area. For example, based on the characteristics of the control area, by differentially applying the authentication method by each area, it is possible to proceed with an authentication process that meets the security criterion required for each area.
In addition, the authentication method may be determined based on the characteristics of the control area. For example, based on the characteristics of the control area, by differentially applying the authentication method by each area, it is possible to proceed with an authentication process that meets the security criterion required for each area.
For example, when the determined authentication method is server authentication, because the authentication in the registration area has already been made from the server <b>130</b> using the user accounts and user information, the control device <b>105</b> receives the control authority of the control area without an additional authentication, e.g., in public areas not requiring high security.
For example, when the determined authentication method is server authentication, because the authentication in the registration area has already been made from the server <b>130</b> using the user accounts and user information, the control device <b>105</b> receives the control authority of the control area without an additional authentication, e.g., in public areas not requiring high security.
In addition, when the determined authentication method is a gateway authentication, the control device <b>105</b> may perform an authentication procedure by transmitting an authentication key corresponding to a gateway of the control area.
In addition, when the determined authentication method is a gateway authentication, the control device <b>105</b> may perform an authentication procedure by transmitting an authentication key corresponding to a gateway of the control area.
In addition, when the determined authentication method is an equipment authentication, the control device <b>105</b> determines the number of the equipment to be authenticated in/by the control area. The control device <b>105</b> then transmits the authentication key to the equipment in the control area corresponding to the determined number of the equipment. For example, the control device <b>105</b> may select equipment to perform the authentication procedure in the control area. The control device <b>105</b> and the equipment in the control area can be connected using wireless communication, e.g., Bluetooth, WIFI, WIFI-Direct, Zigbee, Z-wave, or NFC.
In addition, when the determined authentication method is an equipment authentication, the control device <b>105</b> determines the number of the equipment to be authenticated in/by the control area. The control device <b>105</b> then transmits the authentication key to the equipment in the control area corresponding to the determined number of the equipment. For example, the control device <b>105</b> may select equipment to perform the authentication procedure in the control area. The control device <b>105</b> and the equipment in the control area can be connected using wireless communication, e.g., Bluetooth, WIFI, WIFI-Direct, Zigbee, Z-wave, or NFC.
In addition, the control device <b>105</b> may separately receive an authentication key for the equipment authentication. For example, instead of receiving a registration request of the authentication key from the gateway <b>110</b> of the registration area, as described above, the control device <b>105</b> may transmit an authentication initiation request to a gateway of a control area, and in response to the authentication initiation request, may receive an authentication key for equipment authentication from the gateway of the control area. In this process, the control device <b>105</b> may receive additional authentication from the server <b>130</b> through the gateway of the control area, e.g., GW <b>140</b> of the shop.
In addition, the control device <b>105</b> may separately receive an authentication key for the equipment authentication. For example, instead of receiving a registration request of the authentication key from the gateway <b>110</b> of the registration area, as described above, the control device <b>105</b> may transmit an authentication initiation request to a gateway of a control area, and in response to the authentication initiation request, may receive an authentication key for equipment authentication from the gateway of the control area. In this process, the control device <b>105</b> may receive additional authentication from the server <b>130</b> through the gateway of the control area, e.g., GW <b>140</b> of the shop.
When the authentication process has been completed, the control device <b>105</b> may receive, from the gateway of the control area, an authority for the equipment control.
When the authentication process has been completed, the control device <b>105</b> may receive, from the gateway of the control area, an authority for the equipment control.
As described above, because the authentication is made by connecting the control device <b>105</b> and equipment in a control area without a gateway, through an authentication procedure that uses a method for transmitting an authentication key to the equipment, the risk of exposure of the authentication key corresponding to the gateway can be reduced.
As described above, because the authentication is made by connecting the control device <b>105</b> and equipment in a control area without a gateway, through an authentication procedure that uses a method for transmitting an authentication key to the equipment, the risk of exposure of the authentication key corresponding to the gateway can be reduced.
In accordance with another embodiment of the present invention, the control device <b>105</b> may receive an authentication initiation request from a gateway of a control area, in order to start the authentication process. Further, the control device <b>105</b> may transmit an authentication complete message to the gateway of the control area.
In accordance with another embodiment of the present invention, the control device <b>105</b> may receive an authentication initiation request from a gateway of a control area, in order to start the authentication process. Further, the control device <b>105</b> may transmit an authentication complete message to the gateway of the control area.
The control device <b>105</b> may display information for the user to control the device. The control device <b>105</b> may be connected to a gateway of a control area through wireless communication. Further, the gateways <b>110</b>, <b>120</b>, and <b>140</b> and the controller <b>105</b> may include a communication module or the like for performing the wireless communication as described above.
The control device <b>105</b> may display information for the user to control the device. The control device <b>105</b> may be connected to a gateway of a control area through wireless communication. Further, the gateways <b>110</b>, <b>120</b>, and <b>140</b> and the controller <b>105</b> may include a communication module or the like for performing the wireless communication as described above.
The control device <b>105</b> may display, when receiving authority for controlling equipment from a gateway of a control area, a message indicating that there is a control authority. The control device <b>105</b> may display, when the control authority is granted from the control area, information on one or more equipment that can be controlled in the control area. That is, the control device <b>105</b> may display the information on the list of the controllable equipment and the control method thereof.
The control device <b>105</b> may display, when receiving authority for controlling equipment from a gateway of a control area, a message indicating that there is a control authority. The control device <b>105</b> may display, when the control authority is granted from the control area, information on one or more equipment that can be controlled in the control area. That is, the control device <b>105</b> may display the information on the list of the controllable equipment and the control method thereof.
The control device <b>105</b> may also be used for identifying the user, as a procedure for authenticating in order to grant control authority in the control area. That is, when the control device <b>105</b> is a wearable device, the control device <b>105</b> may utilize measured unique biological information, e.g., a finger print, as an additional authentication factor.
The control device <b>105</b> may also be used for identifying the user, as a procedure for authenticating in order to grant control authority in the control area. That is, when the control device <b>105</b> is a wearable device, the control device <b>105</b> may utilize measured unique biological information, e.g., a finger print, as an additional authentication factor.
The unique biological information of the user generally refers to biological information that can identify a user and may include information on physical and behavioral characteristics. Examples of physical characteristics may include a fingerprint, an iris, a facial feature, a vein, etc., and examples of behavioral characteristics may include voice, signatures, etc.
The unique biological information of the user generally refers to biological information that can identify a user and may include information on physical and behavioral characteristics. Examples of physical characteristics may include a fingerprint, an iris, a facial feature, a vein, etc., and examples of behavioral characteristics may include voice, signatures, etc.
Accordingly, when a user has stolen the control device <b>105</b>, the unique biological information as an additional authentication factor can prevent the unauthorized user from being identified as an operator that has a legitimate right to operate the control device <b>105</b>.
Accordingly, when a user has stolen the control device <b>105</b>, the unique biological information as an additional authentication factor can prevent the unauthorized user from being identified as an operator that has a legitimate right to operate the control device <b>105</b>.
Further, in the authentication method for each area, when an area requires a high security level, the gateway control area may further request the control device <b>105</b> to collect the user's biological information. In order to compare the user's biological information collected through the control device <b>105</b>, the server <b>130</b> may receive the collected user's biological information from an external server, or may collect the user's biological information at the time of receiving the authentication key by the control device <b>105</b> from the server <b>130</b>.
Further, in the authentication method for each area, when an area requires a high security level, the gateway control area may further request the control device <b>105</b> to collect the user's biological information. In order to compare the user's biological information collected through the control device <b>105</b>, the server <b>130</b> may receive the collected user's biological information from an external server, or may collect the user's biological information at the time of receiving the authentication key by the control device <b>105</b> from the server <b>130</b>.
In addition, the control device <b>105</b> may be utilized for executing an automatic control of the control device <b>105</b> in a predetermined area by using the unique biological information measured by the device <b>105</b>. For example, the gateway <b>120</b> of the control area may collect a change of the user's unique biological information and an operation pattern of the equipment <b>125</b> detected through the control device <b>105</b>, which is authenticated through the process. In this case, the user's current biometric-specific information may be detected through the control device <b>105</b> and current user's unique biological information can be transmitted to the gateway <b>120</b> of the control area. The gateway <b>120</b> of the control area may perform automatic control of the equipment <b>125</b> according to the stored operation pattern of the equipment <b>125</b> by receiving the information.
In addition, the control device <b>105</b> may be utilized for executing an automatic control of the control device <b>105</b> in a predetermined area by using the unique biological information measured by the device <b>105</b>. For example, the gateway <b>120</b> of the control area may collect a change of the user's unique biological information and an operation pattern of the equipment <b>125</b> detected through the control device <b>105</b>, which is authenticated through the process. In this case, the user's current biometric-specific information may be detected through the control device <b>105</b> and current user's unique biological information can be transmitted to the gateway <b>120</b> of the control area. The gateway <b>120</b> of the control area may perform automatic control of the equipment <b>125</b> according to the stored operation pattern of the equipment <b>125</b> by receiving the information.
In addition, it is possible to determine the user's location in the control area by using the control device <b>105</b>, e.g., based on the movement of the control device <b>105</b> detected by a control sensor attached to the equipment of the control area. For example, the gateway <b>120</b> of the control area may control the equipment <b>125</b> in the control area, and when the equipment <b>125</b> corresponds to fixed equipment, the location information of the equipment can be stored. Therefore, when the control device <b>105</b> is in close proximity to the equipment <b>125</b>, and the gateway <b>120</b> of the control area may collect signals received from the equipment <b>125</b> and determine the position of the control device <b>105</b>.
In addition, it is possible to determine the user's location in the control area by using the control device <b>105</b>, e.g., based on the movement of the control device <b>105</b> detected by a control sensor attached to the equipment of the control area. For example, the gateway <b>120</b> of the control area may control the equipment <b>125</b> in the control area, and when the equipment <b>125</b> corresponds to fixed equipment, the location information of the equipment can be stored. Therefore, when the control device <b>105</b> is in close proximity to the equipment <b>125</b>, and the gateway <b>120</b> of the control area may collect signals received from the equipment <b>125</b> and determine the position of the control device <b>105</b>.
Alternatively, the control device <b>105</b> may be the same device as the user terminal <b>100</b>. That is, the user terminal <b>100</b> may be used to register a user account on the server <b>130</b>, and may be used as the control device <b>105</b> for controlling the equipment in the control area.
Alternatively, the control device <b>105</b> may be the same device as the user terminal <b>100</b>. That is, the user terminal <b>100</b> may be used to register a user account on the server <b>130</b>, and may be used as the control device <b>105</b> for controlling the equipment in the control area.
Further, a plurality of control devices <b>105</b> may be present for the same user. That is, the user may perform the operations described above using a plurality of control devices <b>105</b>.
Further, a plurality of control devices <b>105</b> may be present for the same user. That is, the user may perform the operations described above using a plurality of control devices <b>105</b>.
In particular, the plurality of control devices <b>105</b> may be used to apply differentiated authentication methods for each operation of the user in the control area. More specifically, when the security level is determined for each operation of the user, the differentiated authentication methods can be applied based on the number and types of the plurality of control devices <b>105</b> to reach the security level.
In particular, the plurality of control devices <b>105</b> may be used to apply differentiated authentication methods for each operation of the user in the control area. More specifically, when the security level is determined for each operation of the user, the differentiated authentication methods can be applied based on the number and types of the plurality of control devices <b>105</b> to reach the security level.
In addition, in order to reach the security level, the differentiated authentication methods can be applied, which are considered based on the number and types of the unique identification information of the user acquired from a plurality of control devices <b>105</b>. The unique identification information can identify whether the operator of the control devices <b>105</b> is an authorized user of the control devices <b>105</b>.
In addition, in order to reach the security level, the differentiated authentication methods can be applied, which are considered based on the number and types of the unique identification information of the user acquired from a plurality of control devices <b>105</b>. The unique identification information can identify whether the operator of the control devices <b>105</b> is an authorized user of the control devices <b>105</b>.
For example, the unique identification information may include a password input into the user terminal <b>100</b> when creating a user account in order to request authentication key generation from the server <b>130</b>. Further, the unique identification information may include a user authentication issued by an official authentication authority.
For example, the unique identification information may include a password input into the user terminal <b>100</b> when creating a user account in order to request authentication key generation from the server <b>130</b>. Further, the unique identification information may include a user authentication issued by an official authentication authority.
However, when the control device <b>105</b> is a wearable device, the unique identification information may include the measured user-specific biological information as described above.
However, when the control device <b>105</b> is a wearable device, the unique identification information may include the measured user-specific biological information as described above.
In addition, in order to apply the differential authentication methods according to the security level, all the number of and types of the plurality of control devices <b>105</b>, and the number of and types of the unique identification information can be combined and utilized. Further, it is possible to perform an authentication procedure using a plurality of control devices <b>105</b> of the users in a certain group unit. For example, if a group is formed of two users using one room, the control authority can be granted to the two users only when the authentication procedure on the control device <b>105</b> by the two users has completed for any operation.
In addition, in order to apply the differential authentication methods according to the security level, all the number of and types of the plurality of control devices <b>105</b>, and the number of and types of the unique identification information can be combined and utilized. Further, it is possible to perform an authentication procedure using a plurality of control devices <b>105</b> of the users in a certain group unit. For example, if a group is formed of two users using one room, the control authority can be granted to the two users only when the authentication procedure on the control device <b>105</b> by the two users has completed for any operation.
The gateways <b>110</b>, <b>120</b>, and <b>140</b> of the registration area and the control areas connect the control device <b>105</b> and the equipment <b>115</b>, <b>125</b>, and <b>145</b>.
The gateways <b>110</b>, <b>120</b>, and <b>140</b> of the registration area and the control areas connect the control device <b>105</b> and the equipment <b>115</b>, <b>125</b>, and <b>145</b>.
In addition, a separate gateway device may be used as the gateways <b>110</b>, <b>120</b>, and <b>140</b> for respective areas, and one of the equipment <b>115</b>, <b>125</b>, and <b>145</b> within the area may perform the role of the gateway. The gateways <b>110</b>, <b>120</b>, and <b>140</b> may register the control device <b>105</b> for controlling the equipment <b>115</b>, <b>125</b>, and <b>145</b>.
In addition, a separate gateway device may be used as the gateways <b>110</b>, <b>120</b>, and <b>140</b> for respective areas, and one of the equipment <b>115</b>, <b>125</b>, and <b>145</b> within the area may perform the role of the gateway. The gateways <b>110</b>, <b>120</b>, and <b>140</b> may register the control device <b>105</b> for controlling the equipment <b>115</b>, <b>125</b>, and <b>145</b>.
Further, the gateways <b>110</b>, <b>120</b>, and <b>140</b> may register and control one or more equipment <b>115</b>, <b>125</b>, and <b>145</b> in the control areas.
Further, the gateways <b>110</b>, <b>120</b>, and <b>140</b> may register and control one or more equipment <b>115</b>, <b>125</b>, and <b>145</b> in the control areas.
The gateways <b>110</b>, <b>120</b>, and <b>140</b> may transmit and receive information for control, to and from the control device <b>105</b>, using wireless communication. Further, the gateways <b>110</b>, <b>120</b>, and <b>140</b> may transmit and receive information for control, to and from the equipment <b>115</b>, <b>125</b>, and <b>145</b>, using wireless communication.
The gateways <b>110</b>, <b>120</b>, and <b>140</b> may transmit and receive information for control, to and from the control device <b>105</b>, using wireless communication. Further, the gateways <b>110</b>, <b>120</b>, and <b>140</b> may transmit and receive information for control, to and from the equipment <b>115</b>, <b>125</b>, and <b>145</b>, using wireless communication.
As described above, each of the gateways <b>110</b>, <b>120</b>, and <b>140</b> may include a wireless communication module for wireless communication.
As described above, each of the gateways <b>110</b>, <b>120</b>, and <b>140</b> may include a wireless communication module for wireless communication.
Additionally, the gateway <b>110</b> of the registration area may include all the functions of the gateways <b>120</b> and <b>140</b> of the control areas.
Additionally, the gateway <b>110</b> of the registration area may include all the functions of the gateways <b>120</b> and <b>140</b> of the control areas.
The gateway <b>110</b> of the registration area may receive, from the server <b>130</b>, a registration request of the authentication key for the control device <b>105</b>. The gateway <b>110</b> of the registration area may transmit a connection initiation request to the control device <b>105</b> in response to the registration request for authentication key. The gateway <b>110</b> of the registration area may transmit the registration request for the authentication key by including the registration request in the connection initiation request. The gateway <b>110</b> of the registration area may transmit the connection information to the server <b>130</b>, when receiving a connection complete message from the control device <b>105</b>. The gateway <b>110</b> of the registration area may inform the gateways <b>120</b> and <b>140</b> of the control areas that a control is permitted to the control device <b>105</b> in the control areas by registering the authentication key to the control device <b>105</b>.
The gateway <b>110</b> of the registration area may receive, from the server <b>130</b>, a registration request of the authentication key for the control device <b>105</b>. The gateway <b>110</b> of the registration area may transmit a connection initiation request to the control device <b>105</b> in response to the registration request for authentication key. The gateway <b>110</b> of the registration area may transmit the registration request for the authentication key by including the registration request in the connection initiation request. The gateway <b>110</b> of the registration area may transmit the connection information to the server <b>130</b>, when receiving a connection complete message from the control device <b>105</b>. The gateway <b>110</b> of the registration area may inform the gateways <b>120</b> and <b>140</b> of the control areas that a control is permitted to the control device <b>105</b> in the control areas by registering the authentication key to the control device <b>105</b>.
The gateway <b>120</b> of the control area may issue, when receiving the control request from the user terminal <b>100</b>, a security key to the user terminal <b>100</b> using the control device <b>105</b>. The gateway <b>120</b> of the control area may issue the security key when the authentication key registered in the control device <b>105</b> corresponds to the gateway itself. The authentication key is generated based on the control allowance area that is determined based on the user information to be controlled. When the authentication key is registered to the control device <b>105</b>, control is permitted to the user of the control device <b>105</b> in the control area.
The gateway <b>120</b> of the control area may issue, when receiving the control request from the user terminal <b>100</b>, a security key to the user terminal <b>100</b> using the control device <b>105</b>. The gateway <b>120</b> of the control area may issue the security key when the authentication key registered in the control device <b>105</b> corresponds to the gateway itself. The authentication key is generated based on the control allowance area that is determined based on the user information to be controlled. When the authentication key is registered to the control device <b>105</b>, control is permitted to the user of the control device <b>105</b> in the control area.
As described above, in accordance with an embodiment of the present invention, differentiated services may be provided to the user for each area by the gateways <b>120</b> and <b>140</b> of the control areas. In addition, it is possible to improve a security level of user control by granting control to only control devices registered the authentication key generated by the server <b>130</b>.
As described above, in accordance with an embodiment of the present invention, differentiated services may be provided to the user for each area by the gateways <b>120</b> and <b>140</b> of the control areas. In addition, it is possible to improve a security level of user control by granting control to only control devices registered the authentication key generated by the server <b>130</b>.
In addition, when receiving a control command and a security key from the user terminal <b>100</b> having been issued the security key, the gateways <b>120</b> and <b>140</b> of the control areas may perform a further authentication procedure with respect to the control device <b>105</b>. That is, the gateways <b>120</b> and <b>140</b> of the control areas may determine the authentication method in the control area and perform an authentication procedure with respect to the control device <b>105</b>.
In addition, when receiving a control command and a security key from the user terminal <b>100</b> having been issued the security key, the gateways <b>120</b> and <b>140</b> of the control areas may perform a further authentication procedure with respect to the control device <b>105</b>. That is, the gateways <b>120</b> and <b>140</b> of the control areas may determine the authentication method in the control area and perform an authentication procedure with respect to the control device <b>105</b>.
The gateways <b>120</b> and <b>140</b> of the control areas may utilize, for the authentication procedure, the equipment <b>125</b> and <b>145</b> in the control areas controlled by the gateways <b>120</b> and <b>140</b> of the control areas, depending on the authentication method.
The gateways <b>120</b> and <b>140</b> of the control areas may utilize, for the authentication procedure, the equipment <b>125</b> and <b>145</b> in the control areas controlled by the gateways <b>120</b> and <b>140</b> of the control areas, depending on the authentication method.
By performing the additional authentication procedures as described above, because the connection with one or more equipment is required, as well as the connection of the gateway <b>120</b>, it is possible to prevent theft and unauthorized use of a distributed authentication key.
By performing the additional authentication procedures as described above, because the connection with one or more equipment is required, as well as the connection of the gateway <b>120</b>, it is possible to prevent theft and unauthorized use of a distributed authentication key.
The equipment <b>115</b>, <b>125</b>, and <b>145</b> may include equipment that can be controlled by the user in the respective areas. For example, the equipment <b>125</b> may be controlled by the control device <b>105</b> being registered in the gateway <b>120</b> within the control area.
The equipment <b>115</b>, <b>125</b>, and <b>145</b> may include equipment that can be controlled by the user in the respective areas. For example, the equipment <b>125</b> may be controlled by the control device <b>105</b> being registered in the gateway <b>120</b> within the control area.
The equipment <b>125</b> and <b>145</b> may perform an authentication for granting a control authority to the control device <b>105</b> in the control areas using the authentication information For example, the equipment <b>125</b> and <b>145</b> may receive the authentication key from the control device <b>105</b> using the wireless communication. When the authentication key corresponds to the authentication key previously received by the equipment, the equipment may transmit an authentication identification message to the gateway <b>120</b> of the control area.
The equipment <b>125</b> and <b>145</b> may perform an authentication for granting a control authority to the control device <b>105</b> in the control areas using the authentication information For example, the equipment <b>125</b> and <b>145</b> may receive the authentication key from the control device <b>105</b> using the wireless communication. When the authentication key corresponds to the authentication key previously received by the equipment, the equipment may transmit an authentication identification message to the gateway <b>120</b> of the control area.
The authentication key may include a Media Access Control (MAC) address of the control device <b>105</b>. For example, the MAC address, i.e., a quasi-unique identifier attached to network adapters, may be configured with 48 bits, which operate as a name of a particular network adapter, and includes an identification code of a manufacturer company or the like.
The authentication key may include a Media Access Control (MAC) address of the control device <b>105</b>. For example, the MAC address, i.e., a quasi-unique identifier attached to network adapters, may be configured with 48 bits, which operate as a name of a particular network adapter, and includes an identification code of a manufacturer company or the like.
In addition, the authentication information may correspond to any information that the server <b>130</b> has generated. In this case, the equipment <b>125</b> and <b>145</b> in the control areas may receive, from the gateways <b>120</b> and <b>140</b> of the control areas, the MAC address information on the control device <b>105</b> to be pre-authenticated and then store the MAC address information. When receiving the MAC address from the control device <b>105</b>, the equipment <b>125</b> and <b>145</b> in the control areas may compare the MAC address received from the control device <b>105</b> to the MAC address received from the gateways <b>120</b> and <b>140</b> of the control areas and stored in advance, and then may determine whether to authenticate the control device <b>105</b> based on the comparison. The equipment <b>125</b> and <b>145</b> in the control areas may transmit, when completing the authentication on the control device <b>105</b>, an authentication identification message to the gateways <b>120</b> and <b>140</b> of the control areas.
In addition, the authentication information may correspond to any information that the server <b>130</b> has generated. In this case, the equipment <b>125</b> and <b>145</b> in the control areas may receive, from the gateways <b>120</b> and <b>140</b> of the control areas, the MAC address information on the control device <b>105</b> to be pre-authenticated and then store the MAC address information. When receiving the MAC address from the control device <b>105</b>, the equipment <b>125</b> and <b>145</b> in the control areas may compare the MAC address received from the control device <b>105</b> to the MAC address received from the gateways <b>120</b> and <b>140</b> of the control areas and stored in advance, and then may determine whether to authenticate the control device <b>105</b> based on the comparison. The equipment <b>125</b> and <b>145</b> in the control areas may transmit, when completing the authentication on the control device <b>105</b>, an authentication identification message to the gateways <b>120</b> and <b>140</b> of the control areas.
The server <b>130</b> may receive and store, from each device, information for the system to operate, and then transmit the information to each device. That is, the server <b>130</b> may be connected to the gateways <b>110</b> and <b>120</b> for each area and the user terminal <b>100</b>, and may transmit and receive the information to and from the gateway and the user terminal, e.g., using wireless communication.
The server <b>130</b> may receive and store, from each device, information for the system to operate, and then transmit the information to each device. That is, the server <b>130</b> may be connected to the gateways <b>110</b> and <b>120</b> for each area and the user terminal <b>100</b>, and may transmit and receive the information to and from the gateway and the user terminal, e.g., using wireless communication.
The server <b>130</b> may differentially determine the information for allowing a user to control in an area. That is, the server <b>130</b> may receive the user information from the user terminal <b>100</b> and determine a control allowance area for the user based on the user information. In addition, the server <b>130</b> may determine the authentication method of the control device <b>105</b> in the control allowance area. The authentication method may be determined in advance based on the information according to the characteristics of the control allowance area. The authentication method may include information on the object to be authenticated for each of the control areas. As described above, the authentication method may include server authentication, gateway authentication, and/or equipment authentication in the control area.
The server <b>130</b> may differentially determine the information for allowing a user to control in an area. That is, the server <b>130</b> may receive the user information from the user terminal <b>100</b> and determine a control allowance area for the user based on the user information. In addition, the server <b>130</b> may determine the authentication method of the control device <b>105</b> in the control allowance area. The authentication method may be determined in advance based on the information according to the characteristics of the control allowance area. The authentication method may include information on the object to be authenticated for each of the control areas. As described above, the authentication method may include server authentication, gateway authentication, and/or equipment authentication in the control area.
The server <b>130</b> may generate an authentication key to be registered in the control device <b>105</b> based on the determined authentication method. That is, the server <b>130</b> may generate an authentication key corresponding to the authentication object that is determined by the authentication method.
The server <b>130</b> may generate an authentication key to be registered in the control device <b>105</b> based on the determined authentication method. That is, the server <b>130</b> may generate an authentication key corresponding to the authentication object that is determined by the authentication method.
The server <b>130</b> may request the gateway <b>110</b> of the registration area to register the generated authentication key to the control device <b>105</b> to be used by the user. The server <b>130</b> may receive connection information from the gateway <b>110</b> of the registration area. The connection information may include a registration completion message for the authentication key.
The server <b>130</b> may request the gateway <b>110</b> of the registration area to register the generated authentication key to the control device <b>105</b> to be used by the user. The server <b>130</b> may receive connection information from the gateway <b>110</b> of the registration area. The connection information may include a registration completion message for the authentication key.
The server <b>130</b> may apply a security standard by differentiating the authentication procedure according to the characteristics of the control area for authentication, by generating the authentication key differentially applied with an authentication method according to the control allowance area, as described above, and registering the authentication key to the control device <b>105</b>.
The server <b>130</b> may apply a security standard by differentiating the authentication procedure according to the characteristics of the control area for authentication, by generating the authentication key differentially applied with an authentication method according to the control allowance area, as described above, and registering the authentication key to the control device <b>105</b>.
In addition, if the authentication method in the control area is an equipment authentication, the server <b>130</b> may generate the authentication key by separating the authentication key for the gateway and the authentication key for the equipment in the control area. That is, to register the authentication key to the control device <b>105</b> through the gateway <b>110</b> of the registration area as described above, it is possible to generate an authentication key corresponding to the gateway <b>120</b> of the control area and then request the registration of the authentication key. Thereafter, when receiving the server authentication request from the gateway <b>120</b> of the control area, it is possible to progress an additional authentication process and generate an authentication key for the equipment <b>125</b> of the control area. Through the additional authentication process, it is possible to adjust an authentication level for the control area requiring more intensive security.
In addition, if the authentication method in the control area is an equipment authentication, the server <b>130</b> may generate the authentication key by separating the authentication key for the gateway and the authentication key for the equipment in the control area. That is, to register the authentication key to the control device <b>105</b> through the gateway <b>110</b> of the registration area as described above, it is possible to generate an authentication key corresponding to the gateway <b>120</b> of the control area and then request the registration of the authentication key. Thereafter, when receiving the server authentication request from the gateway <b>120</b> of the control area, it is possible to progress an additional authentication process and generate an authentication key for the equipment <b>125</b> of the control area. Through the additional authentication process, it is possible to adjust an authentication level for the control area requiring more intensive security.
In addition, the server <b>130</b> may receive a user behavior pattern through the control device <b>105</b> and receive, from the gateways <b>120</b> and <b>140</b> of the control areas, history information for the operations of the equipment <b>125</b> and <b>145</b> corresponding to the change of the biological-specific information. The server <b>130</b> may store the history information based on the user information of the user. The server <b>130</b> may then transmit the history information to the gateway <b>120</b> of the control area, such that the history information can be used for automatic control of the equipment <b>125</b> and <b>145</b> in accordance with the behavior pattern of the user in the gateways <b>120</b> and <b>140</b> of the control areas.
In addition, the server <b>130</b> may receive a user behavior pattern through the control device <b>105</b> and receive, from the gateways <b>120</b> and <b>140</b> of the control areas, history information for the operations of the equipment <b>125</b> and <b>145</b> corresponding to the change of the biological-specific information. The server <b>130</b> may store the history information based on the user information of the user. The server <b>130</b> may then transmit the history information to the gateway <b>120</b> of the control area, such that the history information can be used for automatic control of the equipment <b>125</b> and <b>145</b> in accordance with the behavior pattern of the user in the gateways <b>120</b> and <b>140</b> of the control areas.
As described above, the system illustrated in <figref idrefs="DRAWINGS">FIG. 1</figref> is characterized in that it can be used to provide a differentiated service for each area. For example, the system may be applied to buildings, hospitals, offices, hotels, etc. In the following, for the understanding of the present invention, descriptions will be given mainly to an example of a hotel, but the scope of the present invention is not limited thereto.
As described above, the system illustrated in <figref idref="DRAWINGS">FIG. 1</figref> is characterized in that it can be used to provide a differentiated service for each area. For example, the system may be applied to buildings, hospitals, offices, hotels, etc. In the following, for the understanding of the present invention, descriptions will be given mainly to an example of a hotel, but the scope of the present invention is not limited thereto.
<figref idrefs="DRAWINGS">FIG. 2</figref> is a signal flow diagram illustrating a method for registering a security key in a registration area according to an embodiment of the present invention.
<figref idref="DRAWINGS">FIG. 2</figref> is a signal flow diagram illustrating a method for registering a security key in a registration area according to an embodiment of the present invention.
Referring to <figref idrefs="DRAWINGS">FIG. 2</figref>, in step S<b>230</b>, a user terminal <b>220</b> receives Identification (ID) information and password information from a user and generates a user account. The user terminal <b>220</b> may display a screen for receiving the ID information and password information through the display unit of the user terminal. In addition, the user terminal <b>220</b> may include a touch pad, provided on the display unit, for receiving the information from the user. The information can be received by using a touch pen or a user's finger on the touch pad.
Referring to <figref idref="DRAWINGS">FIG. 2</figref>, in step S<b>230</b>, a user terminal <b>220</b> receives Identification (ID) information and password information from a user and generates a user account. The user terminal <b>220</b> may display a screen for receiving the ID information and password information through the display unit of the user terminal. In addition, the user terminal <b>220</b> may include a touch pad, provided on the display unit, for receiving the information from the user. The information can be received by using a touch pen or a user's finger on the touch pad.
In step S<b>235</b>, the user terminal <b>220</b> sends, to the server <b>215</b>, an authentication key generation request including the generated user account information. The authentication key generation request may also include user information of the user terminal.
In step S<b>235</b>, the user terminal <b>220</b> sends, to the server <b>215</b>, an authentication key generation request including the generated user account information. The authentication key generation request may also include user information of the user terminal.
As described above, the user information indicates information on a specific user of the terminal <b>220</b>. For example, the user information may be obtained from subscription information of a carrier to which the user terminal <b>220</b> subscribes, and may include information on a user's name, address, occupation, etc. The user information may be used as a reference to distinguish the plurality of users stored in the server <b>215</b>. In addition, the user information may be used for generating user behavior pattern stored in the server <b>215</b> and the history information for operations of equipment corresponding to a change of biological-specific information.
As described above, the user information indicates information on a specific user of the terminal <b>220</b>. For example, the user information may be obtained from subscription information of a carrier to which the user terminal <b>220</b> subscribes, and may include information on a user's name, address, occupation, etc. The user information may be used as a reference to distinguish the plurality of users stored in the server <b>215</b>. In addition, the user information may be used for generating user behavior pattern stored in the server <b>215</b> and the history information for operations of equipment corresponding to a change of biological-specific information.
In addition, the user information may include grade information at the time of the registration by the user on the server <b>215</b>. The grade information may indicate the information on the degree of control authority which can be obtained in the system by the user who is registered through the user terminal <b>220</b>. The grade information may include, for example, information on the control allowance area. For example, when the user uses the user terminal <b>220</b> to send the authentication key generation request to the server <b>215</b>, the grade information may be determined based on user reservation information, payment information, etc.
In addition, the user information may include grade information at the time of the registration by the user on the server <b>215</b>. The grade information may indicate the information on the degree of control authority which can be obtained in the system by the user who is registered through the user terminal <b>220</b>. The grade information may include, for example, information on the control allowance area. For example, when the user uses the user terminal <b>220</b> to send the authentication key generation request to the server <b>215</b>, the grade information may be determined based on user reservation information, payment information, etc.
In step S<b>240</b>, the server <b>215</b> generates a server authentication key, in response to the request. For example, the server <b>215</b> may determine a control allowance area based on the grade information included in the user information. The control allowance area indicates a control area in which a user who is registered in the server <b>215</b> using the user terminal <b>220</b> may control equipment using a control device <b>200</b>.
In step S<b>240</b>, the server <b>215</b> generates a server authentication key, in response to the request. For example, the server <b>215</b> may determine a control allowance area based on the grade information included in the user information. The control allowance area indicates a control area in which a user who is registered in the server <b>215</b> using the user terminal <b>220</b> may control equipment using a control device <b>200</b>.
For example, when the grade information corresponds to grade five, control allowance area information on the user can be determined as having only the control authority for the user's room. However, if the grade information corresponds to grade three, control allowance area information on the user can be determined as having the control authority for a restaurant and a sauna, in addition to the user's room.
For example, when the grade information corresponds to grade five, control allowance area information on the user can be determined as having only the control authority for the user's room. However, if the grade information corresponds to grade three, control allowance area information on the user can be determined as having the control authority for a restaurant and a sauna, in addition to the user's room.
The server <b>215</b> may generate an authentication key corresponding to a gateway of a control area that corresponds to the control allowance area.
The server <b>215</b> may generate an authentication key corresponding to a gateway of a control area that corresponds to the control allowance area.
The server <b>215</b> may determine an authentication method of a control area that corresponds to the control allowance area. The server <b>215</b> may determine the authentication method of the control allowance area based on information that is determined beforehand by the server <b>215</b>. The authentication method may include information on an object to be authenticated for each control area. As described above, the authentication method may include server authentication, gateway authentication, and/or equipment authentication in the control area. In addition, the authentication method may be determined based on characteristics of a control area.
The server <b>215</b> may determine an authentication method of a control area that corresponds to the control allowance area. The server <b>215</b> may determine the authentication method of the control allowance area based on information that is determined beforehand by the server <b>215</b>. The authentication method may include information on an object to be authenticated for each control area. As described above, the authentication method may include server authentication, gateway authentication, and/or equipment authentication in the control area. In addition, the authentication method may be determined based on characteristics of a control area.
When the determined authentication method of the control allowance area is a server Authentication, the server <b>215</b> determines whether the user has a registration authority based on the received user information. For example, for a hotel, by comparing reservation information stored in advance and the user information, if it is determined that the user has the registration authority based on the comparison, another authentication key is not generated.
When the determined authentication method of the control allowance area is a server Authentication, the server <b>215</b> determines whether the user has a registration authority based on the received user information. For example, for a hotel, by comparing reservation information stored in advance and the user information, if it is determined that the user has the registration authority based on the comparison, another authentication key is not generated.
When the determined authentication method of the control allowance area is a gateway authentication, the server <b>215</b> generates an authentication key corresponding to a gateway <b>225</b> of the control allowance area, i.e., a control gateway.
When the determined authentication method of the control allowance area is a gateway authentication, the server <b>215</b> generates an authentication key corresponding to a gateway <b>225</b> of the control allowance area, i.e., a control gateway.
In addition, when the determined authentication method of the control allowance area is an equipment Authentication, the server <b>215</b> determines a number of equipment to be authenticated among equipment in the control allowance area. Thereafter, the server <b>215</b> may generate an authentication key corresponding to the determined number of equipment.
In addition, when the determined authentication method of the control allowance area is an equipment Authentication, the server <b>215</b> determines a number of equipment to be authenticated among equipment in the control allowance area. Thereafter, the server <b>215</b> may generate an authentication key corresponding to the determined number of equipment.
In step S<b>245</b>, the server <b>215</b> transmits an authentication key registration request for the control device <b>200</b> to a gateway <b>205</b> of a registration area, i.e., a registration gateway.
In step S<b>245</b>, the server <b>215</b> transmits an authentication key registration request for the control device <b>200</b> to a gateway <b>205</b> of a registration area, i.e., a registration gateway.
In step S<b>250</b>, the registration gateway <b>205</b> transmits a connection initiation request to the control device <b>200</b>. The connection initiation request may include a registration request for authentication keys of the control device <b>200</b>.
In step S<b>250</b>, the registration gateway <b>205</b> transmits a connection initiation request to the control device <b>200</b>. The connection initiation request may include a registration request for authentication keys of the control device <b>200</b>.
In step S<b>252</b>, the control device <b>200</b> registers the authentication key, in response to the registration request for authentication keys included in the connection initiation request. The control device <b>200</b> may display, on the display unit, when receiving the registration request of the authentication key, a message requesting approval of the registration of the authentication key. The message requesting approval of the registration may be displayed in the form of a pop-up, on the display unit of the control device <b>200</b>, and include a button. The user may input the approval signal of the authentication key registration to the control device <b>200</b>, e.g., by touching the message of the control device <b>200</b> using a touch pen or a finger and input an authentication key registration approval signal.
In step S<b>252</b>, the control device <b>200</b> registers the authentication key, in response to the registration request for authentication keys included in the connection initiation request. The control device <b>200</b> may display, on the display unit, when receiving the registration request of the authentication key, a message requesting approval of the registration of the authentication key. The message requesting approval of the registration may be displayed in the form of a pop-up, on the display unit of the control device <b>200</b>, and include a button. The user may input the approval signal of the authentication key registration to the control device <b>200</b>, e.g., by touching the message of the control device <b>200</b> using a touch pen or a finger and input an authentication key registration approval signal.
In step S<b>254</b>, after receiving the approval signal of the authentication key registration, the control device <b>200</b> transmits the device-specific information to the registration gateway <b>205</b>. The device-specific information may include information on the type of the control device <b>200</b>, the manufacturer of the control device <b>200</b>, and/or information for identifying the control device <b>200</b>. The device-specific information may also include a MAC address of the control device <b>200</b>.
In step S<b>254</b>, after receiving the approval signal of the authentication key registration, the control device <b>200</b> transmits the device-specific information to the registration gateway <b>205</b>. The device-specific information may include information on the type of the control device <b>200</b>, the manufacturer of the control device <b>200</b>, and/or information for identifying the control device <b>200</b>. The device-specific information may also include a MAC address of the control device <b>200</b>.
The control device <b>200</b> may transmit a message indicating that the registration of the authentication key is completed with the device-specific information.
The control device <b>200</b> may transmit a message indicating that the registration of the authentication key is completed with the device-specific information.
In step S<b>256</b>, the registration gateway <b>205</b> transmits a connection request, upon receiving the device-specific information and the authentication key registration completion message.
In step S<b>256</b>, the registration gateway <b>205</b> transmits a connection request, upon receiving the device-specific information and the authentication key registration completion message.
In step S<b>258</b>, the control device <b>200</b> transmits a connection completion message to the registration gateway <b>205</b>, when completing the connection with the registration gateway <b>205</b>.
In step S<b>258</b>, the control device <b>200</b> transmits a connection completion message to the registration gateway <b>205</b>, when completing the connection with the registration gateway <b>205</b>.
In step S<b>260</b>, the registration gateway <b>205</b> transmits the connection information to the server <b>215</b>. The connection information may include the received device-specific information.
In step S<b>260</b>, the registration gateway <b>205</b> transmits the connection information to the server <b>215</b>. The connection information may include the received device-specific information.
In step S<b>270</b>, the server <b>215</b> transmits the received connection information of the control area to the control gateway <b>225</b>.
In step S<b>270</b>, the server <b>215</b> transmits the received connection information of the control area to the control gateway <b>225</b>.
Through the process illustrated on <figref idrefs="DRAWINGS">FIG. 2</figref>, an authentication key differentiated for each area can be registered to the control device <b>200</b> and a differentiated authentication procedure can be executed in the control area using the authentication key.
Through the process illustrated on <figref idref="DRAWINGS">FIG. 2</figref>, an authentication key differentiated for each area can be registered to the control device <b>200</b> and a differentiated authentication procedure can be executed in the control area using the authentication key.
<figref idrefs="DRAWINGS">FIG. 3</figref> is a signal flow diagram illustrating a process for issuing a security key to a user terminal by a gateway of a control area according to an embodiment of the present invention.
<figref idref="DRAWINGS">FIG. 3</figref> is a signal flow diagram illustrating a process for issuing a security key to a user terminal by a gateway of a control area according to an embodiment of the present invention.
Referring to <figref idrefs="DRAWINGS">FIG. 3</figref>, in step S<b>320</b>, a user terminal <b>310</b> sends a control request to a gateway <b>305</b> of the control area, i.e., a control gateway, for control allowance in the control area thereof.
Referring to <figref idref="DRAWINGS">FIG. 3</figref>, in step S<b>320</b>, a user terminal <b>310</b> sends a control request to a gateway <b>305</b> of the control area, i.e., a control gateway, for control allowance in the control area thereof.
In step S<b>330</b>, the control gateway <b>305</b> sends a device information request to a control device <b>300</b>, in order to determine whether the control of the user terminal <b>310</b> is allowed in the control area.
In step S<b>330</b>, the control gateway <b>305</b> sends a device information request to a control device <b>300</b>, in order to determine whether the control of the user terminal <b>310</b> is allowed in the control area.
In step S<b>335</b>, the control device <b>300</b> transmits device-specific information to the control gateway <b>305</b>, in response to the device information request. The device-specific information may be the same as that transmitted to the registration gateway <b>205</b> in step S<b>254</b> of <figref idrefs="DRAWINGS">FIG. 2</figref>.
In step S<b>335</b>, the control device <b>300</b> transmits device-specific information to the control gateway <b>305</b>, in response to the device information request. The device-specific information may be the same as that transmitted to the registration gateway <b>205</b> in step S<b>254</b> of <figref idref="DRAWINGS">FIG. 2</figref>.
In step S<b>340</b>, the control gateway <b>305</b> determines whether to allow the control to the user terminal <b>310</b> in the control area. Depending on the authentication method of the control area, the operation of the control gateway <b>305</b> can be different. For example, as described above, when the authentication method of the control area is a server authentication, because the control gateway <b>305</b> has a server authentication in registration area, the control of the control area with respect to the user terminal <b>310</b> can be allowed without passing through the step S<b>340</b>. However, when the authentication method of the control area is a gateway authentication or an equipment authentication, then the control gateway <b>305</b> may determine whether to allow the control in the control area by the user terminal <b>310</b>, in step S<b>340</b>. In <figref idrefs="DRAWINGS">FIG. 3</figref>, it is assumed that the authentication method of the control area is a gateway authentication or an equipment authentication.
In step S<b>340</b>, the control gateway <b>305</b> determines whether to allow the control to the user terminal <b>310</b> in the control area. Depending on the authentication method of the control area, the operation of the control gateway <b>305</b> can be different. For example, as described above, when the authentication method of the control area is a server authentication, because the control gateway <b>305</b> has a server authentication in registration area, the control of the control area with respect to the user terminal <b>310</b> can be allowed without passing through the step S<b>340</b>. However, when the authentication method of the control area is a gateway authentication or an equipment authentication, then the control gateway <b>305</b> may determine whether to allow the control in the control area by the user terminal <b>310</b>, in step S<b>340</b>. In <figref idref="DRAWINGS">FIG. 3</figref>, it is assumed that the authentication method of the control area is a gateway authentication or an equipment authentication.
The control gateway <b>305</b> may determine whether to allow the control, depending on whether device-specific information is included in the control device connection information that has been received, e.g., in step S<b>270</b> in <figref idrefs="DRAWINGS">FIG. 2</figref>. However, when the control device <b>300</b> transmits the authentication key registered in the control device <b>300</b> with the device-specific information in step S<b>335</b>, it is possible for the control gateway <b>305</b> to determine whether to allow the control depending on whether the authentication key corresponds to the control gateway <b>305</b>.
The control gateway <b>305</b> may determine whether to allow the control, depending on whether device-specific information is included in the control device connection information that has been received, e.g., in step S<b>270</b> in <figref idref="DRAWINGS">FIG. 2</figref>. However, when the control device <b>300</b> transmits the authentication key registered in the control device <b>300</b> with the device-specific information in step S<b>335</b>, it is possible for the control gateway <b>305</b> to determine whether to allow the control depending on whether the authentication key corresponds to the control gateway <b>305</b>.
When it is determined that the control by the user terminal is allowed in the control area, the control gateway <b>305</b> transmits a security key to the user terminal <b>310</b> in step S<b>345</b>.
When it is determined that the control by the user terminal is allowed in the control area, the control gateway <b>305</b> transmits a security key to the user terminal <b>310</b> in step S<b>345</b>.
In step S<b>350</b>, in response to the security key, the user terminal <b>310</b> transmits a control command and the received security key to the control gateway <b>305</b>.
In step S<b>350</b>, in response to the security key, the user terminal <b>310</b> transmits a control command and the received security key to the control gateway <b>305</b>.
In determining whether the user terminal <b>310</b> has the control authority and issuing a security key, the control gateway <b>305</b> may prevent equipment control by an unauthorized user terminal. In addition, a user terminal to which a security key for the control area has already been issued does not need the security key to be re-issued when making a control request to the control area. Therefore, the control gateway <b>305</b> does not need to repeatedly determine whether to allow the control for the control area.
In determining whether the user terminal <b>310</b> has the control authority and issuing a security key, the control gateway <b>305</b> may prevent equipment control by an unauthorized user terminal. In addition, a user terminal to which a security key for the control area has already been issued does not need the security key to be re-issued when making a control request to the control area. Therefore, the control gateway <b>305</b> does not need to repeatedly determine whether to allow the control for the control area.
When the user terminal <b>310</b> transmits the control command with the security key to the control gateway <b>305</b>, the control gateway <b>305</b> determines whether the control device <b>300</b> in the control area requires additional authentication.
When the user terminal <b>310</b> transmits the control command with the security key to the control gateway <b>305</b>, the control gateway <b>305</b> determines whether the control device <b>300</b> in the control area requires additional authentication.
When the authentication method of the control area is a gateway Authentication, the control gateway <b>305</b> may determine that the authentication is completed by checking the device-specific information of the control device <b>300</b> or the authentication key, in step S<b>340</b>. Thus, in this case, when the user terminal <b>310</b> executes the control command with the security key, it is possible to grant the control authority to the control device <b>300</b>, in step S<b>350</b>.
When the authentication method of the control area is a gateway Authentication, the control gateway <b>305</b> may determine that the authentication is completed by checking the device-specific information of the control device <b>300</b> or the authentication key, in step S<b>340</b>. Thus, in this case, when the user terminal <b>310</b> executes the control command with the security key, it is possible to grant the control authority to the control device <b>300</b>, in step S<b>350</b>.
However, when the authentication method of the control area is an equipment Authentication, an additional authentication procedure using equipment of the control area is to be performed, as will be described in more detail below with reference to <figref idrefs="DRAWINGS">FIGS. 4, 5, and 6</figref>.
However, when the authentication method of the control area is an equipment Authentication, an additional authentication procedure using equipment of the control area is to be performed, as will be described in more detail below with reference to <figref idref="DRAWINGS">FIGS. 4, 5, and 6</figref>.
<figref idrefs="DRAWINGS">FIG. 4</figref> is a signal flow diagram illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention. Specifically, <figref idrefs="DRAWINGS">FIG. 4</figref> illustrates an equipment authentication method performed by a control device of a control area.
<figref idref="DRAWINGS">FIG. 4</figref> is a signal flow diagram illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention. Specifically, <figref idref="DRAWINGS">FIG. 4</figref> illustrates an equipment authentication method performed by a control device of a control area.
Referring to <figref idrefs="DRAWINGS">FIG. 4</figref>, in step S<b>425</b>, a control device <b>400</b>, when detecting an access to the control area, determines a number of equipment to be authenticated based on an authentication key registered in the control device <b>400</b>. To detect that the control device <b>400</b> accesses the control area, it is possible to use wireless communication with a control gateway <b>420</b>.
Referring to <figref idref="DRAWINGS">FIG. 4</figref>, in step S<b>425</b>, a control device <b>400</b>, when detecting an access to the control area, determines a number of equipment to be authenticated based on an authentication key registered in the control device <b>400</b>. To detect that the control device <b>400</b> accesses the control area, it is possible to use wireless communication with a control gateway <b>420</b>.
The control device <b>400</b> may determine, depending on the number of authentication keys corresponding to the equipment included in the registered authentication key, the number of equipment that should receive the authentication key.
The control device <b>400</b> may determine, depending on the number of authentication keys corresponding to the equipment included in the registered authentication key, the number of equipment that should receive the authentication key.
In steps S<b>430</b> and S<b>440</b>, the control device <b>400</b> transmits, based on the determined number of the equipment to be authenticated, the authentication key for the equipment to equipment <b>410</b> and <b>415</b> in the control area. For example, the control device <b>400</b> may randomly select equipment among the equipment in the control area and transmit an authentication key corresponding to the selected equipment. The authentication key may be one that has been generated by a server and registered at the control device <b>400</b> in a registration area.
In steps S<b>430</b> and S<b>440</b>, the control device <b>400</b> transmits, based on the determined number of the equipment to be authenticated, the authentication key for the equipment to equipment <b>410</b> and <b>415</b> in the control area. For example, the control device <b>400</b> may randomly select equipment among the equipment in the control area and transmit an authentication key corresponding to the selected equipment. The authentication key may be one that has been generated by a server and registered at the control device <b>400</b> in a registration area.
In addition, the authentication key may include a MAC address of the control device <b>400</b>. If the authentication key corresponds to the MAC address of the control device <b>400</b>, a control gateway <b>420</b> may receive the MAC address from the server in the registration area, and the equipment <b>410</b> and <b>415</b> in the control area may receive and store the MAC address.
In addition, the authentication key may include a MAC address of the control device <b>400</b>. If the authentication key corresponds to the MAC address of the control device <b>400</b>, a control gateway <b>420</b> may receive the MAC address from the server in the registration area, and the equipment <b>410</b> and <b>415</b> in the control area may receive and store the MAC address.
If the authentication key received in steps S<b>430</b> and S<b>440</b> corresponds to the equipment <b>410</b> and <b>415</b>, the equipment <b>410</b> and <b>415</b> transmit a new key corresponding to the authentication key in steps S<b>435</b> and S<b>445</b>.
If the authentication key received in steps S<b>430</b> and S<b>440</b> corresponds to the equipment <b>410</b> and <b>415</b>, the equipment <b>410</b> and <b>415</b> transmit a new key corresponding to the authentication key in steps S<b>435</b> and S<b>445</b>.
The new key is transmitted to inform the control device <b>400</b> that the authentication has been identified by using a key exchange scheme.
The new key is transmitted to inform the control device <b>400</b> that the authentication has been identified by using a key exchange scheme.
In steps S<b>437</b> and S<b>447</b>, the equipment <b>410</b> and <b>415</b> transmit an authentication identification message to the control gateway <b>420</b>.
In steps S<b>437</b> and S<b>447</b>, the equipment <b>410</b> and <b>415</b> transmit an authentication identification message to the control gateway <b>420</b>.
In step S<b>450</b>, the control gateway <b>420</b> grants a control authority for the control device <b>400</b>, based on the received authentication identification message. That is, if the authentication method of the control area is an equipment authentication, the control gateway <b>420</b> may determine the number of equipment to be authenticated in the control area.
In step S<b>450</b>, the control gateway <b>420</b> grants a control authority for the control device <b>400</b>, based on the received authentication identification message. That is, if the authentication method of the control area is an equipment authentication, the control gateway <b>420</b> may determine the number of equipment to be authenticated in the control area.
Similarly to the steps S<b>437</b> and S<b>447</b>, when receiving the authentication identification message from the equipment <b>410</b> and <b>415</b>, it is possible to determine whether the number of the received messages equals the number of the equipment to be authenticated. When the number of the received authentication identification messages equals the determined number of equipment to be authenticated, the control gateway <b>420</b> may grant equipment control authority to the control device <b>400</b> in step S<b>450</b>.
Similarly to the steps S<b>437</b> and S<b>447</b>, when receiving the authentication identification message from the equipment <b>410</b> and <b>415</b>, it is possible to determine whether the number of the received messages equals the number of the equipment to be authenticated. When the number of the received authentication identification messages equals the determined number of equipment to be authenticated, the control gateway <b>420</b> may grant equipment control authority to the control device <b>400</b> in step S<b>450</b>.
When the control device <b>400</b> has the equipment control authority granted from the control gateway <b>420</b>, a description will be given where the connection with the control gateway <b>420</b> is broken and the control device <b>400</b> attempts to re-access the control area. In this case, because the control authority has already been granted to the control device <b>400</b>, it is possible to start the control for the equipment in the control area, by performing an authentication key exchange between the equipment <b>410</b> and <b>415</b>, which have already performed the authentication.
When the control device <b>400</b> has the equipment control authority granted from the control gateway <b>420</b>, a description will be given where the connection with the control gateway <b>420</b> is broken and the control device <b>400</b> attempts to re-access the control area. In this case, because the control authority has already been granted to the control device <b>400</b>, it is possible to start the control for the equipment in the control area, by performing an authentication key exchange between the equipment <b>410</b> and <b>415</b>, which have already performed the authentication.
When performing the authentication procedure for the exchange of authentication keys between the control device <b>400</b> and the equipment <b>410</b> and <b>415</b> in the control area, as illustrated in <figref idrefs="DRAWINGS">FIG. 4</figref>, authentication key theft can be prevented by the exchange of distributed authentication keys. In addition, in the authentication process, the authentication procedure can be performed without gateway intervention, and the exposure risk of the authentication key corresponding to the gateway can be reduced.
When performing the authentication procedure for the exchange of authentication keys between the control device <b>400</b> and the equipment <b>410</b> and <b>415</b> in the control area, as illustrated in <figref idref="DRAWINGS">FIG. 4</figref>, authentication key theft can be prevented by the exchange of distributed authentication keys. In addition, in the authentication process, the authentication procedure can be performed without gateway intervention, and the exposure risk of the authentication key corresponding to the gateway can be reduced.
<figref idrefs="DRAWINGS">FIG. 5</figref> is a signal flow diagram illustrating a procedure for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention. Specifically, <figref idrefs="DRAWINGS">FIG. 5</figref>, similar to <figref idrefs="DRAWINGS">FIG. 4</figref>, describes an embodiment in which an equipment authentication method is to be performed by a control device of the control area.
<figref idref="DRAWINGS">FIG. 5</figref> is a signal flow diagram illustrating a procedure for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention. Specifically, <figref idref="DRAWINGS">FIG. 5</figref>, similar to <figref idref="DRAWINGS">FIG. 4</figref>, describes an embodiment in which an equipment authentication method is to be performed by a control device of the control area.
Referring to <figref idrefs="DRAWINGS">FIG. 5</figref>, in step S<b>521</b>, a control device <b>500</b> receives an equipment authentication initiation request from a control gateway <b>520</b>. That is, when a user terminal executes a control command with a security key in the control area, the control gateway <b>520</b> transmits an equipment authentication initiation request to the control device <b>500</b> detected in the control area. The following steps S<b>525</b> to S<b>550</b> are the same as steps S<b>425</b> to S<b>450</b> of <figref idrefs="DRAWINGS">FIG. 4</figref>. Accordingly, a repetitive description of steps S<b>525</b> to S<b>550</b> is omitted herein.
Referring to <figref idref="DRAWINGS">FIG. 5</figref>, in step S<b>521</b>, a control device <b>500</b> receives an equipment authentication initiation request from a control gateway <b>520</b>. That is, when a user terminal executes a control command with a security key in the control area, the control gateway <b>520</b> transmits an equipment authentication initiation request to the control device <b>500</b> detected in the control area. The following steps S<b>525</b> to S<b>550</b> are the same as steps S<b>425</b> to S<b>450</b> of <figref idref="DRAWINGS">FIG. 4</figref>. Accordingly, a repetitive description of steps S<b>525</b> to S<b>550</b> is omitted herein.
<figref idrefs="DRAWINGS">FIG. 6</figref> is a signal flow diagram illustrating a procedure for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention. Specifically, <figref idrefs="DRAWINGS">FIG. 6</figref> illustrates a method for an equipment authentication in which a server is additionally involved.
<figref idref="DRAWINGS">FIG. 6</figref> is a signal flow diagram illustrating a procedure for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention. Specifically, <figref idref="DRAWINGS">FIG. 6</figref> illustrates a method for an equipment authentication in which a server is additionally involved.
Referring to <figref idrefs="DRAWINGS">FIG. 6</figref>, a control device <b>600</b> transmits an authentication request to a control gateway <b>620</b> in step S<b>630</b>. That is, the control device <b>600</b> may detect that it has an access to the control area using wireless communication with the control gateway <b>620</b>.
Referring to <figref idref="DRAWINGS">FIG. 6</figref>, a control device <b>600</b> transmits an authentication request to a control gateway <b>620</b> in step S<b>630</b>. That is, the control device <b>600</b> may detect that it has an access to the control area using wireless communication with the control gateway <b>620</b>.
In step S<b>640</b>, the control gateway <b>620</b> transmits a server authentication request to a server <b>625</b>.
In step S<b>640</b>, the control gateway <b>620</b> transmits a server authentication request to a server <b>625</b>.
Upon receiving the server authentication request in step S<b>640</b>, the server <b>625</b> may perform a server authentication with respect to the control device <b>600</b>. In addition, the control device <b>600</b> may transmit, in the server authentication request, the authentication key registered in the registration area.
Upon receiving the server authentication request in step S<b>640</b>, the server <b>625</b> may perform a server authentication with respect to the control device <b>600</b>. In addition, the control device <b>600</b> may transmit, in the server authentication request, the authentication key registered in the registration area.
The server <b>625</b> may determine whether the authentication key registered in the control device <b>600</b> is an authentication key generated by the server <b>625</b>. In addition, the server <b>625</b> may determine whether the control device <b>600</b> has a control authority for the control area based on the registered authentication key.
The server <b>625</b> may determine whether the authentication key registered in the control device <b>600</b> is an authentication key generated by the server <b>625</b>. In addition, the server <b>625</b> may determine whether the control device <b>600</b> has a control authority for the control area based on the registered authentication key.
In step S<b>645</b>, when it is determined that the control device <b>600</b> has a control authority in the control area, the server <b>625</b> transmits an authentication identification message to the control gateway <b>620</b>.
In step S<b>645</b>, when it is determined that the control device <b>600</b> has a control authority in the control area, the server <b>625</b> transmits an authentication identification message to the control gateway <b>620</b>.
The server <b>625</b> may also transmit, in the authentication identification message, an authentication key, which corresponds to equipment to be additionally authenticated by the control device <b>600</b> in the control area. That is, if the authentication method of the area the user intends to control is an equipment authentication, the server <b>625</b> may generate an authentication key that corresponds to the equipment and request a registration to the control device in the registration area, and may request a registration to the control device, after performing the additional authentication process in the control area.
The server <b>625</b> may also transmit, in the authentication identification message, an authentication key, which corresponds to equipment to be additionally authenticated by the control device <b>600</b> in the control area. That is, if the authentication method of the area the user intends to control is an equipment authentication, the server <b>625</b> may generate an authentication key that corresponds to the equipment and request a registration to the control device in the registration area, and may request a registration to the control device, after performing the additional authentication process in the control area.
In step S<b>650</b>, the control gateway <b>620</b> transmits, to the control device <b>600</b>, a list of equipment to be specifically authenticated. That is, differently from the embodiments illustrated in <figref idrefs="DRAWINGS">FIG. 4</figref> and <figref idrefs="DRAWINGS">FIG. 5</figref>, wherein the number of the equipment to be authenticated is determined and the control device may select the equipment to be randomly authenticated and perform the authentication procedure, an authentication procedure for the equipment included in the received authentication equipment list has to be performed. Further, the control gateway <b>620</b> may transmit the authentication key generated, after executing the server authentication, at the time of transmitting the list of equipment. The control device <b>600</b> receiving the authentication key and the authentication equipment list may initiate the authentication procedure based on the authentication equipment list.
In step S<b>650</b>, the control gateway <b>620</b> transmits, to the control device <b>600</b>, a list of equipment to be specifically authenticated. That is, differently from the embodiments illustrated in <figref idref="DRAWINGS">FIG. 4</figref> and <figref idref="DRAWINGS">FIG. 5</figref>, wherein the number of the equipment to be authenticated is determined and the control device may select the equipment to be randomly authenticated and perform the authentication procedure, an authentication procedure for the equipment included in the received authentication equipment list has to be performed. Further, the control gateway <b>620</b> may transmit the authentication key generated, after executing the server authentication, at the time of transmitting the list of equipment. The control device <b>600</b> receiving the authentication key and the authentication equipment list may initiate the authentication procedure based on the authentication equipment list.
Assuming that the equipment <b>610</b> and <b>615</b> are included in the authentication equipment list, in step S<b>660</b> and step S<b>670</b>, the control device <b>600</b> transmits the authentication request to the equipment <b>610</b> and <b>615</b>. The control device <b>600</b> may transmit the authentication request with the authentication key generated by the server <b>625</b>. The equipment <b>610</b> and <b>615</b>, which have received the authentication request, may determine whether the authentication key corresponds thereto.
Assuming that the equipment <b>610</b> and <b>615</b> are included in the authentication equipment list, in step S<b>660</b> and step S<b>670</b>, the control device <b>600</b> transmits the authentication request to the equipment <b>610</b> and <b>615</b>. The control device <b>600</b> may transmit the authentication request with the authentication key generated by the server <b>625</b>. The equipment <b>610</b> and <b>615</b>, which have received the authentication request, may determine whether the authentication key corresponds thereto.
When it is determined that the authentication key corresponds to the equipment <b>610</b> and <b>615</b>, in step S<b>665</b> and step S<b>675</b>, the equipment <b>610</b> and <b>615</b> transmit the authentication identification message to the control device <b>600</b>.
When it is determined that the authentication key corresponds to the equipment <b>610</b> and <b>615</b>, in step S<b>665</b> and step S<b>675</b>, the equipment <b>610</b> and <b>615</b> transmit the authentication identification message to the control device <b>600</b>.
In step S<b>680</b>, the control device <b>600</b> transmits, when receiving the authentication identification message with respect to all the equipment that transmit the authentication request, the authentication complete message to the control gateway <b>620</b>.
In step S<b>680</b>, the control device <b>600</b> transmits, when receiving the authentication identification message with respect to all the equipment that transmit the authentication request, the authentication complete message to the control gateway <b>620</b>.
In step S<b>690</b>, the control gateway <b>620</b> grants equipment control authority to the control device <b>600</b>.
In step S<b>690</b>, the control gateway <b>620</b> grants equipment control authority to the control device <b>600</b>.
As described above, without registering the authentication key to the equipment to be authenticated in the registration area, after performing the additional server authentication in the control area, and then registering the authentication key corresponding to the equipment, the degree of security for a particular area can be enhanced.
As described above, without registering the authentication key to the equipment to be authenticated in the registration area, after performing the additional server authentication in the control area, and then registering the authentication key corresponding to the equipment, the degree of security for a particular area can be enhanced.
<figref idrefs="DRAWINGS">FIG. 7</figref> is a flowchart illustrating a method for supporting, by a server, a connection between a control device and a gateway according to an embodiment of the present invention. Specifically, <figref idrefs="DRAWINGS">FIG. 7</figref> is a flowchart illustrating a process of generating, by a server, an authentication key to be registered in a control device in order to connect the control device to the gateway.
<figref idref="DRAWINGS">FIG. 7</figref> is a flowchart illustrating a method for supporting, by a server, a connection between a control device and a gateway according to an embodiment of the present invention. Specifically, <figref idref="DRAWINGS">FIG. 7</figref> is a flowchart illustrating a process of generating, by a server, an authentication key to be registered in a control device in order to connect the control device to the gateway.
Referring to <figref idrefs="DRAWINGS">FIG. 7</figref>, in step S<b>700</b>, the server receives an authentication key generation request from a user terminal. The authentication key generation request may include a user account and user information generated by the user terminal. As described above, the user information indicates information on a specific user who uses the user terminal.
Referring to <figref idref="DRAWINGS">FIG. 7</figref>, in step S<b>700</b>, the server receives an authentication key generation request from a user terminal. The authentication key generation request may include a user account and user information generated by the user terminal. As described above, the user information indicates information on a specific user who uses the user terminal.
In step <b>710</b>, the server determines a control allowance area based on the user information.
In step <b>710</b>, the server determines a control allowance area based on the user information.
In step S<b>720</b>, the server determines area-specific authentication method for the control allowance area. The server may determine the authentication method of the control allowance area based on information that is determined beforehand in the server, as described above.
In step S<b>720</b>, the server determines area-specific authentication method for the control allowance area. The server may determine the authentication method of the control allowance area based on information that is determined beforehand in the server, as described above.
In step S<b>730</b>, the server generates an authentication key based on the area-specific authentication method.
In step S<b>730</b>, the server generates an authentication key based on the area-specific authentication method.
When the determined authentication method of the control allowance area is a server authentication, the server determines whether the user has a registration authority based on the received user information.
When the determined authentication method of the control allowance area is a server authentication, the server determines whether the user has a registration authority based on the received user information.
When the determined authentication method of the control allowance area is a gateway authentication, the server generates an authentication key corresponding to the gateway of the control allowance area.
When the determined authentication method of the control allowance area is a gateway authentication, the server generates an authentication key corresponding to the gateway of the control allowance area.
When the determined authentication method of the control allowance area corresponds to an equipment authentication, the server determines the number of equipment to be authenticated among the equipment in the control allowance area. The server may generate an authentication key corresponding to the determined number of the equipment.
When the determined authentication method of the control allowance area corresponds to an equipment authentication, the server determines the number of equipment to be authenticated among the equipment in the control allowance area. The server may generate an authentication key corresponding to the determined number of the equipment.
In step S<b>740</b>, the server requests, from a registration gateway, registration of the authentication key with respect to the control device.
In step S<b>740</b>, the server requests, from a registration gateway, registration of the authentication key with respect to the control device.
In step S<b>750</b>, the server receives, from the registration area gateway, the connection information of the control device. That is, when the gateway of the registration area initiates a connection in order to request the control device for the authentication key registration, the control device approves the registration of the authentication key, and the connection is completed, the gateway of the registration area may transmit the connection information with the control device to the server. The server may store the connection information of the control device that has been received.
In step S<b>750</b>, the server receives, from the registration area gateway, the connection information of the control device. That is, when the gateway of the registration area initiates a connection in order to request the control device for the authentication key registration, the control device approves the registration of the authentication key, and the connection is completed, the gateway of the registration area may transmit the connection information with the control device to the server. The server may store the connection information of the control device that has been received.
In step S<b>760</b>, the server transmits the connection information of the control device to the control gateway. The connection information of the control device is transmitted to the control gateway and can be used for authentication procedures for granting a control device registration and control authority in the control area.
In step S<b>760</b>, the server transmits the connection information of the control device to the control gateway. The connection information of the control device is transmitted to the control gateway and can be used for authentication procedures for granting a control device registration and control authority in the control area.
<figref idrefs="DRAWINGS">FIG. 8</figref> is a flowchart illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention. Specifically, <figref idrefs="DRAWINGS">FIG. 8</figref> is a flowchart illustrating a process of issuing a security key to the user terminal by a control gateway and performing an authentication procedure for the control device.
<figref idref="DRAWINGS">FIG. 8</figref> is a flowchart illustrating a process for granting equipment control authority to a control device by a gateway of a control area according to an embodiment of the present invention. Specifically, <figref idref="DRAWINGS">FIG. 8</figref> is a flowchart illustrating a process of issuing a security key to the user terminal by a control gateway and performing an authentication procedure for the control device.
Referring to <figref idrefs="DRAWINGS">FIG. 8</figref>, the control gateway receives a control request from a user terminal in step S<b>800</b>. The control gateway may determine whether the authentication method of the control area corresponds to a server authentication in step S<b>805</b>.
Referring to <figref idref="DRAWINGS">FIG. 8</figref>, the control gateway receives a control request from a user terminal in step S<b>800</b>. The control gateway may determine whether the authentication method of the control area corresponds to a server authentication in step S<b>805</b>.
If the determined authentication method is not server authentication in step S<b>805</b>, the control gateway determines whether the area controlled by the control gateway is an area in which the control by the user terminal <b>100</b> has been allowed in step S<b>810</b>.
If the determined authentication method is not server authentication in step S<b>805</b>, the control gateway determines whether the area controlled by the control gateway is an area in which the control by the user terminal <b>100</b> has been allowed in step S<b>810</b>.
However, if the determined authentication method is server authentication in step S<b>805</b>, or if the area controlled by the control gateway is an area in which the control by the user terminal <b>100</b> has been allowed in step S<b>810</b>, a security key is issued to the user terminal in step S<b>820</b>. That is, for the server authentication, because the server performs the authentication procedure by the user accounts and user information included in the authentication key generation request received from the user terminal, it is possible to grant a control authority to the control device, without an additional authentication procedure.
However, if the determined authentication method is server authentication in step S<b>805</b>, or if the area controlled by the control gateway is an area in which the control by the user terminal <b>100</b> has been allowed in step S<b>810</b>, a security key is issued to the user terminal in step S<b>820</b>. That is, for the server authentication, because the server performs the authentication procedure by the user accounts and user information included in the authentication key generation request received from the user terminal, it is possible to grant a control authority to the control device, without an additional authentication procedure.
The control gateway <b>120</b> may determine whether the control area is an area where a control is permitted to the user terminal, when the authentication key registered in the control device <b>105</b> corresponds to the control gateway itself. The control gateway <b>120</b> may also request the device-specific information from the control device, in order to determine whether the control area is an area where a control is permitted to the user terminal.
The control gateway <b>120</b> may determine whether the control area is an area where a control is permitted to the user terminal, when the authentication key registered in the control device <b>105</b> corresponds to the control gateway itself. The control gateway <b>120</b> may also request the device-specific information from the control device, in order to determine whether the control area is an area where a control is permitted to the user terminal.
When receiving the device-specific information from the control device, it is possible to determine that the control area is an area where a control is permitted to the user terminal, based on the device connection information received from the server. The authentication key is generated in the server based on the control allowance area that is determined based on the user information to be controlled, and the registration of the authentication key to the control device <b>105</b> means that a control is permitted to the user in the control area.
When receiving the device-specific information from the control device, it is possible to determine that the control area is an area where a control is permitted to the user terminal, based on the device connection information received from the server. The authentication key is generated in the server based on the control allowance area that is determined based on the user information to be controlled, and the registration of the authentication key to the control device <b>105</b> means that a control is permitted to the user in the control area.
When the control area is not an area where a control is permitted to the user terminal in step <b>810</b>, the control gateway ends the procedure.
When the control area is not an area where a control is permitted to the user terminal in step <b>810</b>, the control gateway ends the procedure.
In step S<b>830</b>, the gateway of the control area receives a control command with a security key from the user terminal.
In step S<b>830</b>, the gateway of the control area receives a control command with a security key from the user terminal.
In step S<b>840</b>, the gateway of the control area determines whether the authentication method of the control area is an equipment authentication. For example, the authentication method may include information on the object which has to be authenticated for each of the control areas.
In step S<b>840</b>, the gateway of the control area determines whether the authentication method of the control area is an equipment authentication. For example, the authentication method may include information on the object which has to be authenticated for each of the control areas.
In step S<b>850</b>, the control gateway grants an access authority to the control device, when the authentication method is not the equipment authentication, e.g., is a gateway authentication. That is, the control gateway may determine whether the control area is an area where a control is permitted to the user terminal, when transmitting the security key to the user terminal. Because the control gateway has identified the authentication key that corresponds to the control gateway and has been transmitted by the control device, it can be seen that the authentication on the control gateway has been completed.
In step S<b>850</b>, the control gateway grants an access authority to the control device, when the authentication method is not the equipment authentication, e.g., is a gateway authentication. That is, the control gateway may determine whether the control area is an area where a control is permitted to the user terminal, when transmitting the security key to the user terminal. Because the control gateway has identified the authentication key that corresponds to the control gateway and has been transmitted by the control device, it can be seen that the authentication on the control gateway has been completed.
However, when the authentication method is the equipment authentication, the control gateway determines a number of equipment to be authenticated in step S<b>860</b>. The number of the equipment to be authenticated may be determined in advance according to the characteristics of the control area controlled by the control gateway.
However, when the authentication method is the equipment authentication, the control gateway determines a number of equipment to be authenticated in step S<b>860</b>. The number of the equipment to be authenticated may be determined in advance according to the characteristics of the control area controlled by the control gateway.
In step S<b>870</b>, the control gateway determines whether the same number of authentication identification messages have been received from the equipment in the control area, as the determined number of equipment. When the same number of authentication identification messages has been received from the equipment in the control area as the determined number of equipment, the control gateway grants an access authority to the control device in step S<b>850</b>.
In step S<b>870</b>, the control gateway determines whether the same number of authentication identification messages have been received from the equipment in the control area, as the determined number of equipment. When the same number of authentication identification messages has been received from the equipment in the control area as the determined number of equipment, the control gateway grants an access authority to the control device in step S<b>850</b>.
When the same number of authentication identification messages have not been received from the equipment in the control area as the determined number of equipment, after a predetermined time, the control gateway ends the procedure.
When the same number of authentication identification messages have not been received from the equipment in the control area as the determined number of equipment, after a predetermined time, the control gateway ends the procedure.
In accordance with another embodiment of the present invention, a description will be given of a control method including automatic control for equipment using a control device, when the user has completed authentication in the control allowance area.
In accordance with another embodiment of the present invention, a description will be given of a control method including automatic control for equipment using a control device, when the user has completed authentication in the control allowance area.
First, the gateway of the control area may automatically control the equipment in the control area based on the user behavior history information in the control area. That is, the gateway of the control area may collect the change of the user's unique biological information and the operation pattern of the equipment detected through the control device, e.g., when the control device is a wearable device. The gateway may collect the change of the user's unique biological information for each user using the authentication key included in the control device. The gateway may transmit the collected information to the server.
First, the gateway of the control area may automatically control the equipment in the control area based on the user behavior history information in the control area. That is, the gateway of the control area may collect the change of the user's unique biological information and the operation pattern of the equipment detected through the control device, e.g., when the control device is a wearable device. The gateway may collect the change of the user's unique biological information for each user using the authentication key included in the control device. The gateway may transmit the collected information to the server.
The server generates history information based on the operation pattern information of the equipment that corresponds to the change of the user-specific unique biological information. The history information may include the operation pattern information of the equipment that corresponds to the change of the user group-specific unique biological information.
The server generates history information based on the operation pattern information of the equipment that corresponds to the change of the user-specific unique biological information. The history information may include the operation pattern information of the equipment that corresponds to the change of the user group-specific unique biological information.
For example, assuming the system is applied to a hotel, the user is an adult male in his 20s, a control allowance area is a room, and the adult man is detected as being in the room, it is determined that the man is sleeping when the heart rate and body temperature are at a constant numerical value or less, and it is possible to control the operation of lighting in the room and an air conditioning device.
For example, assuming the system is applied to a hotel, the user is an adult male in his 20s, a control allowance area is a room, and the adult man is detected as being in the room, it is determined that the man is sleeping when the heart rate and body temperature are at a constant numerical value or less, and it is possible to control the operation of lighting in the room and an air conditioning device.
In addition, the gateway of the control area may determine the position of a user using the control device, and may automatically control the equipment of the control area based on the determined user position. For example, when the user is allowed to control certain areas of the accommodation and the control device of the user has completed the authentication procedure, the lighting in the control area can be automatically controlled according to the movement of the user. Regardless of having a conventional control authority, different from a sensor of the lighting which detects every movement of the user and then turns the lighting on/off accordingly, the embodiment enables the user, to whom a control in the control area is permitted, to have a differentiated control of the equipment.
In addition, the gateway of the control area may determine the position of a user using the control device, and may automatically control the equipment of the control area based on the determined user position. For example, when the user is allowed to control certain areas of the accommodation and the control device of the user has completed the authentication procedure, the lighting in the control area can be automatically controlled according to the movement of the user. Regardless of having a conventional control authority, different from a sensor of the lighting which detects every movement of the user and then turns the lighting on/off accordingly, the embodiment enables the user, to whom a control in the control area is permitted, to have a differentiated control of the equipment.
In addition, when the user is permitted to control a certain control area and the control device of the user has completed the authentication procedure, a door may be automatically opened or closed by detecting that the user has come close to the door of the control area. More specifically, when the control device is not detected in the control area, but a door lock of a control area door detects a signal transmitted from the control device above a certain threshold value, the detection information is transmitted to the gateway, and the gateway controls to open the door lock of the door. In addition, when the user is detected to be within the control area but the signal detected by the door lock of the door is less than a predetermined threshold value, the gateway may maintain the locked state of the door lock.
In addition, when the user is permitted to control a certain control area and the control device of the user has completed the authentication procedure, a door may be automatically opened or closed by detecting that the user has come close to the door of the control area. More specifically, when the control device is not detected in the control area, but a door lock of a control area door detects a signal transmitted from the control device above a certain threshold value, the detection information is transmitted to the gateway, and the gateway controls to open the door lock of the door. In addition, when the user is detected to be within the control area but the signal detected by the door lock of the door is less than a predetermined threshold value, the gateway may maintain the locked state of the door lock.
In addition, the gateway of the control area may transmit the information on the control area to the control device, using the location information of the control device. For example, when the user is allowed to control a shop, and the user wearing the control device has come close to the shop, the gateway of the shop may transmit product information or discount information to the control device of the user.
In addition, the gateway of the control area may transmit the information on the control area to the control device, using the location information of the control device. For example, when the user is allowed to control a shop, and the user wearing the control device has come close to the shop, the gateway of the shop may transmit product information or discount information to the control device of the user.
In addition, various embodiments of the present invention include a differentiated authentication method for providing a control authority for the equipment for each area and also a differentiated authentication method for granting a control authority for each operation. As the operation-specific differentiated authentication method, a description will be given on using at least one of a plurality of control devices and user-specific identification information or a combination thereof.
In addition, various embodiments of the present invention include a differentiated authentication method for providing a control authority for the equipment for each area and also a differentiated authentication method for granting a control authority for each operation. As the operation-specific differentiated authentication method, a description will be given on using at least one of a plurality of control devices and user-specific identification information or a combination thereof.
In accordance with an embodiment of the present invention, it is assumed that the operation, which the user performs in a room or in a space, has a predetermined score to acquire the control authority. In this case, it is assumed that the scores corresponding to the type of user-specific identification information and scores corresponding to the type of the plurality of control devices are also determined in advance. Accordingly, the user may acquire the control authority when the scores, which are obtained by adding the scores of the plurality of control devices and the user-specific identification information which are utilized in the authentication procedure, reach a predetermined score for the specific operation.
In accordance with an embodiment of the present invention, it is assumed that the operation, which the user performs in a room or in a space, has a predetermined score to acquire the control authority. In this case, it is assumed that the scores corresponding to the type of user-specific identification information and scores corresponding to the type of the plurality of control devices are also determined in advance. Accordingly, the user may acquire the control authority when the scores, which are obtained by adding the scores of the plurality of control devices and the user-specific identification information which are utilized in the authentication procedure, reach a predetermined score for the specific operation.
For example, for an operation of turning on a TV in the room, a predetermined score is assumed to be 30 points, and for an operation of payment in the store, a predetermined score is assumed to be 100 points. Further, when the user's terminal is used as the control device, and the authentication with the gateway is completed, it is assumed to be 10 points, and when a user wearable device is used as the control device, and the authentication with the gateway is completed, it is assumed to be 20 points. In addition, when an authentication is done by a password set by the user in advance, it is assumed to be 20 points, and when an authentication using a fingerprint which is user-specific biological information, it is assumed to be 40 points. The user may satisfy 30 points by authenticating the terminal and the wearable device with the gateway in the room, in order to acquire the control authority for the operation to turn on the TV in the room.
For example, for an operation of turning on a TV in the room, a predetermined score is assumed to be 30 points, and for an operation of payment in the store, a predetermined score is assumed to be 100 points. Further, when the user's terminal is used as the control device, and the authentication with the gateway is completed, it is assumed to be 10 points, and when a user wearable device is used as the control device, and the authentication with the gateway is completed, it is assumed to be 20 points. In addition, when an authentication is done by a password set by the user in advance, it is assumed to be 20 points, and when an authentication using a fingerprint which is user-specific biological information, it is assumed to be 40 points. The user may satisfy 30 points by authenticating the terminal and the wearable device with the gateway in the room, in order to acquire the control authority for the operation to turn on the TV in the room.
In another method, the user may also acquire the control authority of turning on the TV, when the authentication is done by using terminal authentication and a fingerprint which is unique biological information. However, for the operation of the payment in the store, for recognition using the terminal and a fingerprint, in order to satisfy the score, it is possible to acquire a control authority when the authentication is done using a password and a fingerprint as well as authentication of the terminal and the wearable device.
In another method, the user may also acquire the control authority of turning on the TV, when the authentication is done by using terminal authentication and a fingerprint which is unique biological information. However, for the operation of the payment in the store, for recognition using the terminal and a fingerprint, in order to satisfy the score, it is possible to acquire a control authority when the authentication is done using a password and a fingerprint as well as authentication of the terminal and the wearable device.
In addition, in accordance with an embodiment of the present invention, it is assumed that the operation, which the user performs in the room or in the space, has a predetermined security level to acquire the control authority. That is, as described above, in order to acquire a control authority for the operation, it is possible to pre-determine a section that varies discontinuously, rather than having a continuous score. In this case, step 1, step 2, and step 3 can be determined by dividing the level of the operation, and a plurality of control devices and the user-specific identification information needed to obtain the control authority for the operation of each stage can be determined in advance. For example, different from the use of the score to grant a control authority for the operation, when a predetermined security level of the operation for the payment is determined as step 5, it is possible to determine that the control authority may be obtained only when one of the unique biological information is included in order to satisfy the security level.
In addition, in accordance with an embodiment of the present invention, it is assumed that the operation, which the user performs in the room or in the space, has a predetermined security level to acquire the control authority. That is, as described above, in order to acquire a control authority for the operation, it is possible to pre-determine a section that varies discontinuously, rather than having a continuous score. In this case, step 1, step 2, and step 3 can be determined by dividing the level of the operation, and a plurality of control devices and the user-specific identification information needed to obtain the control authority for the operation of each stage can be determined in advance. For example, different from the use of the score to grant a control authority for the operation, when a predetermined security level of the operation for the payment is determined as step 5, it is possible to determine that the control authority may be obtained only when one of the unique biological information is included in order to satisfy the security level.
Further, it is possible to perform an authentication procedure using a plurality of control devices of the users in a certain group unit. For example, if two users use one room and forms a group, in order to use room service billed to the room, it is possible to grant control authority to the two users after completing the authentication of the two users. In addition, it is possible to apply a method of utilizing at least one or a combination of the plurality of control devices and unique identification information of the user as described above with respect to the authentication procedure of the plurality of users.
Further, it is possible to perform an authentication procedure using a plurality of control devices of the users in a certain group unit. For example, if two users use one room and forms a group, in order to use room service billed to the room, it is possible to grant control authority to the two users after completing the authentication of the two users. In addition, it is possible to apply a method of utilizing at least one or a combination of the plurality of control devices and unique identification information of the user as described above with respect to the authentication procedure of the plurality of users.
That is, the gateway may request additional authentication from the control device, when an additional authentication method for receiving a control authority for each operation is required for the control device that has received a control authority for an area. The gateway may determine, when receiving, from the terminal, the message requesting a grant of the control authority for certain operations, the authentication method for the operations. The authentication method of the operations may be determined by a method such as pre-determined score or security levels for the authentication of the operation described above. The gateway may determine the authentication method of the operation based on the method of receiving in advance from the server.
That is, the gateway may request additional authentication from the control device, when an additional authentication method for receiving a control authority for each operation is required for the control device that has received a control authority for an area. The gateway may determine, when receiving, from the terminal, the message requesting a grant of the control authority for certain operations, the authentication method for the operations. The authentication method of the operations may be determined by a method such as pre-determined score or security levels for the authentication of the operation described above. The gateway may determine the authentication method of the operation based on the method of receiving in advance from the server.
The gateway that has determined the authentication method may request the control device for the authentication based on the determined authentication method. For example, when the authentication method is determined as a security level determined in advance and user's unique biological information is required due to the predetermined security level, it is possible to transmit the message requesting the collection of the user's unique biological information to the control device. Although the aforementioned method corresponds to an embodiment of the differentiated authentication method to grant the control authority for each operation, the present invention is not limited thereto.
The gateway that has determined the authentication method may request the control device for the authentication based on the determined authentication method. For example, when the authentication method is determined as a security level determined in advance and user's unique biological information is required due to the predetermined security level, it is possible to transmit the message requesting the collection of the user's unique biological information to the control device. Although the aforementioned method corresponds to an embodiment of the differentiated authentication method to grant the control authority for each operation, the present invention is not limited thereto.
In addition, various embodiments of the present invention may be applied to payment services. That is, when applying the system to an area which provides services to the user, the user may make a collective payment after using the service by completing an authentication procedure of the control device in at least one control allowance area. The user may use the control device, which is authenticated in the control allowance area, as a simplified payment device, thereby increasing user convenience. In addition, a control is not permitted to an unauthorized user and theft and unauthorized use can be prevented.
In addition, various embodiments of the present invention may be applied to payment services. That is, when applying the system to an area which provides services to the user, the user may make a collective payment after using the service by completing an authentication procedure of the control device in at least one control allowance area. The user may use the control device, which is authenticated in the control allowance area, as a simplified payment device, thereby increasing user convenience. In addition, a control is not permitted to an unauthorized user and theft and unauthorized use can be prevented.
In addition, the gateway of the control area may provide certain information to a user based on user biological information measured by the control device, e.g., a wearable device. The information provided to the user based on the biological information may be generated and stored in the server. The control gateway receives, from the control device, biological information of the current user, and determines the information to be provided to the user based on the information stored in the server. The control gateway may transmit the determined information to the control device, and the control device, which has received certain information, may display the received information on a display unit.
In addition, the gateway of the control area may provide certain information to a user based on user biological information measured by the control device, e.g., a wearable device. The information provided to the user based on the biological information may be generated and stored in the server. The control gateway receives, from the control device, biological information of the current user, and determines the information to be provided to the user based on the information stored in the server. The control gateway may transmit the determined information to the control device, and the control device, which has received certain information, may display the received information on a display unit.
For example, when the user is in a store and the user's body temperature and heart rate, as measured by the control device, are at or above a specific numerical value, the network of the control area may receive, from the server, information on a beverage, which is effective for the body temperature and heart rate decrease, and transmit the information to the control device.
For example, when the user is in a store and the user's body temperature and heart rate, as measured by the control device, are at or above a specific numerical value, the network of the control area may receive, from the server, information on a beverage, which is effective for the body temperature and heart rate decrease, and transmit the information to the control device.
As described above, by effectively utilizing a control device, such as a wearable device, it is possible to provide separate customized service to users.
As described above, by effectively utilizing a control device, such as a wearable device, it is possible to provide separate customized service to users.
<figref idrefs="DRAWINGS">FIG. 9</figref> illustrates a server according to an embodiment of the present invention.
<figref idref="DRAWINGS">FIG. 9</figref> illustrates a server according to an embodiment of the present invention.
Referring to <figref idrefs="DRAWINGS">FIG. 9</figref>, the server includes a communication unit <b>910</b>, a storage unit <b>920</b>, and a controller <b>930</b>.
Referring to <figref idref="DRAWINGS">FIG. 9</figref>, the server includes a communication unit <b>910</b>, a storage unit <b>920</b>, and a controller <b>930</b>.
The communication unit <b>910</b> is connected to a gateway and a user terminal for each area in the system, and may transmit and receive the information. The server may be connected to the user terminal using wireless communication. The server may be connected to the gateway of each area using wired communication or wireless communication.
The communication unit <b>910</b> is connected to a gateway and a user terminal for each area in the system, and may transmit and receive the information. The server may be connected to the user terminal using wireless communication. The server may be connected to the gateway of each area using wired communication or wireless communication.
The communication unit <b>910</b> may receive an authentication key generation request that includes user account information and user information from the user terminal. Further, the communication unit <b>910</b> may transmit the authentication key generated by the controller <b>930</b> to the gateway of the registration area. In addition, the communication unit <b>910</b> may receive the connection information with the control device from the gateway of the registration area. Further, the communication unit <b>910</b> may receive a server authentication request from the gateway of the control area, and may transmit an authentication identification message as a response thereto.
The communication unit <b>910</b> may receive an authentication key generation request that includes user account information and user information from the user terminal. Further, the communication unit <b>910</b> may transmit the authentication key generated by the controller <b>930</b> to the gateway of the registration area. In addition, the communication unit <b>910</b> may receive the connection information with the control device from the gateway of the registration area. Further, the communication unit <b>910</b> may receive a server authentication request from the gateway of the control area, and may transmit an authentication identification message as a response thereto.
The storage unit <b>920</b> may store the information received from the communication unit and may transmit the information to the controller <b>930</b>. The storage unit <b>920</b> may store information on the authentication method for the control area. The authentication method may include information on the object which has to be authenticated for each of the control areas. The authentication method may include server authentication, gateway authentication, and/or equipment authentication in the control area.
The storage unit <b>920</b> may store the information received from the communication unit and may transmit the information to the controller <b>930</b>. The storage unit <b>920</b> may store information on the authentication method for the control area. The authentication method may include information on the object which has to be authenticated for each of the control areas. The authentication method may include server authentication, gateway authentication, and/or equipment authentication in the control area.
In addition, the storage unit <b>920</b> may store user accounts and user information received from the user terminal. Further, the storage unit <b>920</b> may store the grade information included in the user information, and store information on the control allowance area determined by the grade information. In addition, the storage unit <b>920</b> may store the authentication key generated by the controller <b>930</b>. The storage unit <b>920</b> may store the connection device information of the control device that has been received from the gateway of the registration areas.
In addition, the storage unit <b>920</b> may store user accounts and user information received from the user terminal. Further, the storage unit <b>920</b> may store the grade information included in the user information, and store information on the control allowance area determined by the grade information. In addition, the storage unit <b>920</b> may store the authentication key generated by the controller <b>930</b>. The storage unit <b>920</b> may store the connection device information of the control device that has been received from the gateway of the registration areas.
In addition, the storage unit <b>920</b> may receive and store, as history information, the equipment control pattern information that corresponds to the user's unique biological information. The storage unit <b>920</b> may also store information to be provided corresponding to the user's biological information.
In addition, the storage unit <b>920</b> may receive and store, as history information, the equipment control pattern information that corresponds to the user's unique biological information. The storage unit <b>920</b> may also store information to be provided corresponding to the user's biological information.
The controller <b>930</b> may determine a control allowance area of the user terminal, in response to an authentication information generation request received from the user terminal, generate authentication information based on the pre-determined authentication method for each determined control allowance area, and control the request of the control device for registering the generated authentication information.
The controller <b>930</b> may determine a control allowance area of the user terminal, in response to an authentication information generation request received from the user terminal, generate authentication information based on the pre-determined authentication method for each determined control allowance area, and control the request of the control device for registering the generated authentication information.
The controller <b>930</b> determines the control allowance area of the user terminal based on the user information received from the user terminal.
The controller <b>930</b> determines the control allowance area of the user terminal based on the user information received from the user terminal.
In addition, in the controller <b>930</b>, generating of the authentication information includes generating authentication information corresponding to the gateway for controlling the equipment in the determined control allowance area.
In addition, in the controller <b>930</b>, generating of the authentication information includes generating authentication information corresponding to the gateway for controlling the equipment in the determined control allowance area.
In addition, in the controller <b>930</b>, generating of the authentication information includes, if the authentication method corresponds to equipment authentication, determining the equipment of the control allowance area which are involved in the authentication, and controlling the generation of the authentication information corresponding to the determined equipment.
In addition, in the controller <b>930</b>, generating of the authentication information includes, if the authentication method corresponds to equipment authentication, determining the equipment of the control allowance area which are involved in the authentication, and controlling the generation of the authentication information corresponding to the determined equipment.
In addition, when generating the authentication information corresponding to the determined equipment, if the authentication method corresponds to equipment authentication, the controller <b>930</b> may receive an equipment authentication request from the control device. When authentication information corresponding to the gateway that is included in the control device is the authentication information corresponding to the gateway of the control area, the controller <b>930</b> may control the generation of the authentication information corresponding to the determined equipment.
In addition, when generating the authentication information corresponding to the determined equipment, if the authentication method corresponds to equipment authentication, the controller <b>930</b> may receive an equipment authentication request from the control device. When authentication information corresponding to the gateway that is included in the control device is the authentication information corresponding to the gateway of the control area, the controller <b>930</b> may control the generation of the authentication information corresponding to the determined equipment.
<figref idrefs="DRAWINGS">FIG. 10</figref> illustrates a gateway according to an embodiment of the present invention.
<figref idref="DRAWINGS">FIG. 10</figref> illustrates a gateway according to an embodiment of the present invention.
Referring to <figref idrefs="DRAWINGS">FIG. 10</figref>, the gateway includes a communication unit <b>1010</b>, a storage unit <b>1020</b>, and a controller <b>1030</b>.
Referring to <figref idref="DRAWINGS">FIG. 10</figref>, the gateway includes a communication unit <b>1010</b>, a storage unit <b>1020</b>, and a controller <b>1030</b>.
The communication unit <b>1010</b> connects to a server, a user terminal, and a control device, and transmits and receives the information. The communication unit <b>1010</b> may use wireless or wired communication.
The communication unit <b>1010</b> connects to a server, a user terminal, and a control device, and transmits and receives the information. The communication unit <b>1010</b> may use wireless or wired communication.
In addition, the communication unit <b>1010</b> may receive, from the server, a request for registering a registration key. The communication unit <b>1010</b> may also transmit, to the control device <b>200</b>, a connection initiation request including the registration key registration request. If the connection is completed, the communication unit <b>1010</b> may receive a connection complete message from the control device and transmit the information on the connection to the server.
In addition, the communication unit <b>1010</b> may receive, from the server, a request for registering a registration key. The communication unit <b>1010</b> may also transmit, to the control device <b>200</b>, a connection initiation request including the registration key registration request. If the connection is completed, the communication unit <b>1010</b> may receive a connection complete message from the control device and transmit the information on the connection to the server.
For a gateway of the control area, the communication unit <b>1010</b> may receive the authentication identification message from one or more equipment in the control area. When the controller <b>1030</b> determines to give the control authority to a control device based on the authentication identification message, the communication unit <b>1010</b> may transmit a message that grants the control authority to the control device.
For a gateway of the control area, the communication unit <b>1010</b> may receive the authentication identification message from one or more equipment in the control area. When the controller <b>1030</b> determines to give the control authority to a control device based on the authentication identification message, the communication unit <b>1010</b> may transmit a message that grants the control authority to the control device.
In addition, the communication unit <b>1010</b> may transmit a message requesting initiation of a device authentication procedure to the control device. In addition, the communication unit <b>1010</b> may transmit a server authentication request to the server.
In addition, the communication unit <b>1010</b> may transmit a message requesting initiation of a device authentication procedure to the control device. In addition, the communication unit <b>1010</b> may transmit a server authentication request to the server.
The storage unit <b>1020</b> may store the authentication key included in the authentication key registration request received from the server. The storage unit <b>1020</b> may store the device-specific information of the control device that has been received from the control device. The storage unit <b>1020</b> may receive and store information on the authentication method for the control area.
The storage unit <b>1020</b> may store the authentication key included in the authentication key registration request received from the server. The storage unit <b>1020</b> may store the device-specific information of the control device that has been received from the control device. The storage unit <b>1020</b> may receive and store information on the authentication method for the control area.
When receiving the control request of the control device from the user terminal, the controller <b>1030</b> may determine whether authentication information corresponding to the gateway is registered in the control device, when the authentication information is registered in the control device, determine an authentication method in the area controlled by the gateway, and when the authentication method corresponds to equipment authentication, control the granting of the control authority to the control device based on the determined authentication method and the authentication identification message received from the equipment in the area controlled by the gateway.
When receiving the control request of the control device from the user terminal, the controller <b>1030</b> may determine whether authentication information corresponding to the gateway is registered in the control device, when the authentication information is registered in the control device, determine an authentication method in the area controlled by the gateway, and when the authentication method corresponds to equipment authentication, control the granting of the control authority to the control device based on the determined authentication method and the authentication identification message received from the equipment in the area controlled by the gateway.
In addition, when determining the authentication method of the area controlled by the gateway, if the authentication information is registered in the control device, the controller <b>1030</b> may transmit a security key to the user terminal. When receiving the control command corresponding to the security key, the controller <b>1030</b> may control the determination of the authentication method.
In addition, when determining the authentication method of the area controlled by the gateway, if the authentication information is registered in the control device, the controller <b>1030</b> may transmit a security key to the user terminal. When receiving the control command corresponding to the security key, the controller <b>1030</b> may control the determination of the authentication method.
In addition, when granting the control authority to the control device, if the authentication method corresponds to gateway authentication, the controller <b>1030</b> may control the granting of the control authority to the control device in response to the received control command. When granting the control authority to the control device, if the authentication method corresponds to the equipment authentication, the controller <b>1030</b> may determine the number of equipment to be authenticated. When the received authentication identification message corresponds to the determined number of equipment, the controller <b>1030</b> may control the granting of the control authority to the control device. The controller <b>1030</b> may receive, from the control device, a message requesting the granting of the control authority for the operations, determine the authentication method for the operations, and control the request of the control device for the authentication based on the determined authentication method for the operations.
In addition, when granting the control authority to the control device, if the authentication method corresponds to gateway authentication, the controller <b>1030</b> may control the granting of the control authority to the control device in response to the received control command. When granting the control authority to the control device, if the authentication method corresponds to the equipment authentication, the controller <b>1030</b> may determine the number of equipment to be authenticated. When the received authentication identification message corresponds to the determined number of equipment, the controller <b>1030</b> may control the granting of the control authority to the control device. The controller <b>1030</b> may receive, from the control device, a message requesting the granting of the control authority for the operations, determine the authentication method for the operations, and control the request of the control device for the authentication based on the determined authentication method for the operations.
In addition, the controller <b>1030</b> may control the granting of the control authority for the operation to the control device when the authentication is completed based on the identified authentication method for the operations. In addition, the authentication method includes at least one combination of the number of user devices that includes the control device, the type of user devices, the number of pieces of unique biological information, and the type of unique biological information. The authentication method includes an authentication method for a plurality of users of a predetermined group.
In addition, the controller <b>1030</b> may control the granting of the control authority for the operation to the control device when the authentication is completed based on the identified authentication method for the operations. In addition, the authentication method includes at least one combination of the number of user devices that includes the control device, the type of user devices, the number of pieces of unique biological information, and the type of unique biological information. The authentication method includes an authentication method for a plurality of users of a predetermined group.
<figref idrefs="DRAWINGS">FIG. 11</figref> illustrates a control device according to an embodiment of the present invention.
<figref idref="DRAWINGS">FIG. 11</figref> illustrates a control device according to an embodiment of the present invention.
Referring to <figref idrefs="DRAWINGS">FIG. 11</figref>, the control device includes a communication unit <b>1110</b>, a storage unit <b>1120</b>, a display unit <b>1130</b>, and a controller <b>1140</b>.
Referring to <figref idref="DRAWINGS">FIG. 11</figref>, the control device includes a communication unit <b>1110</b>, a storage unit <b>1120</b>, a display unit <b>1130</b>, and a controller <b>1140</b>.
The communication unit <b>1110</b> is connects with a gateway and a server, and transmits and receives the information. The communication unit <b>1110</b> may receive a connection initiation request including an authentication key registration request from the gateway of the registration area. The communication unit <b>1110</b> may receive a connection request from the gateway in the registration area.
The communication unit <b>1110</b> is connects with a gateway and a server, and transmits and receives the information. The communication unit <b>1110</b> may receive a connection initiation request including an authentication key registration request from the gateway of the registration area. The communication unit <b>1110</b> may receive a connection request from the gateway in the registration area.
In addition, the communication unit <b>1110</b> may receive a request for device information for the authentication procedures from the gateway of the control area. The communication unit <b>1110</b> may transmit device-specific information, in response to the request. The communication unit <b>1110</b> may transmit, when transmitting the device-specific information, the authentication key registered in the control device. The communication unit <b>1110</b> may transmit authentication information to terminals in the control area based on the authentication method of the control area determined by the controller <b>1140</b>.
In addition, the communication unit <b>1110</b> may receive a request for device information for the authentication procedures from the gateway of the control area. The communication unit <b>1110</b> may transmit device-specific information, in response to the request. The communication unit <b>1110</b> may transmit, when transmitting the device-specific information, the authentication key registered in the control device. The communication unit <b>1110</b> may transmit authentication information to terminals in the control area based on the authentication method of the control area determined by the controller <b>1140</b>.
In addition, the communication unit <b>1110</b> may receive, upon completing the authentication procedure, equipment control authority from the gateway of the control area.
In addition, the communication unit <b>1110</b> may receive, upon completing the authentication procedure, equipment control authority from the gateway of the control area.
In addition, the communication unit <b>1110</b> may receive, from the gateway of the control area, a device authentication request message in the authentication process. In addition, the communication unit <b>1110</b> may transmit an authentication request to the gateway of the control area.
In addition, the communication unit <b>1110</b> may receive, from the gateway of the control area, a device authentication request message in the authentication process. In addition, the communication unit <b>1110</b> may transmit an authentication request to the gateway of the control area.
The storage unit <b>1120</b> may register and store the authentication key generated by the server. The storage unit <b>1120</b> may store the device-specific information on the control device in advance. In addition, the storage unit <b>1120</b> may store the authentication identification message received from the equipment in the control area.
The storage unit <b>1120</b> may register and store the authentication key generated by the server. The storage unit <b>1120</b> may store the device-specific information on the control device in advance. In addition, the storage unit <b>1120</b> may store the authentication identification message received from the equipment in the control area.
The display unit <b>1130</b> may display, upon receiving a connection initiation request from the gateway of the registration area through the communication unit <b>1110</b>, a message indicating the receipt of the request. In addition, the display unit <b>1130</b> may display, upon receiving the request, a message requesting the user for the connection with the gateway of the registration area and registration approval for the authentication key generated by the server. The message requesting the registration approval displayed on the control device <b>105</b> may be in the form of a pop-up window. The display unit <b>1130</b> may include a touch pad in order to receive input from the user. The user may press a button that is included in the message requesting the registration approval and approve the connection to the gateway of the registration area and the registration of the authentication key.
The display unit <b>1130</b> may display, upon receiving a connection initiation request from the gateway of the registration area through the communication unit <b>1110</b>, a message indicating the receipt of the request. In addition, the display unit <b>1130</b> may display, upon receiving the request, a message requesting the user for the connection with the gateway of the registration area and registration approval for the authentication key generated by the server. The message requesting the registration approval displayed on the control device <b>105</b> may be in the form of a pop-up window. The display unit <b>1130</b> may include a touch pad in order to receive input from the user. The user may press a button that is included in the message requesting the registration approval and approve the connection to the gateway of the registration area and the registration of the authentication key.
In addition, the display unit <b>1130</b> may display, when receiving the authority for controlling the equipment from the gateway of the control area, a message indicating that there is a control authority. The control device <b>105</b> may display, when the control authority is granted from the control area, information on one or more equipment that can be controlled by the control area. That is, the control device may display the information on the list of the controllable equipment and the control method thereof.
In addition, the display unit <b>1130</b> may display, when receiving the authority for controlling the equipment from the gateway of the control area, a message indicating that there is a control authority. The control device <b>105</b> may display, when the control authority is granted from the control area, information on one or more equipment that can be controlled by the control area. That is, the control device may display the information on the list of the controllable equipment and the control method thereof.
When receiving the control request of the control device from the user terminal, the controller <b>1140</b> may determine whether authentication information corresponding to the gateway is registered in the control device, when the authentication information is registered in the control device, determine an authentication method in the area controlled by the gateway, and when the authentication method corresponds to the equipment authentication, control the granting of the control authority to the control device, based on the determined authentication method and the authentication identification message received from equipment in the area controlled by the gateway.
When receiving the control request of the control device from the user terminal, the controller <b>1140</b> may determine whether authentication information corresponding to the gateway is registered in the control device, when the authentication information is registered in the control device, determine an authentication method in the area controlled by the gateway, and when the authentication method corresponds to the equipment authentication, control the granting of the control authority to the control device, based on the determined authentication method and the authentication identification message received from equipment in the area controlled by the gateway.
In addition, when determining the authentication method of the area controlled by the gateway, if the authentication information is registered in the control device, the controller <b>1140</b> may transmit a security key to the user terminal. When receiving the control command corresponding to the security key, the controller <b>1140</b> may control the determination of the authentication method. In addition, when granting the control authority to the control device, and if the authentication method corresponds to gateway authentication, the controller <b>1140</b> may control the granting of the control authority to the control device in response to the received control command.
In addition, when determining the authentication method of the area controlled by the gateway, if the authentication information is registered in the control device, the controller <b>1140</b> may transmit a security key to the user terminal. When receiving the control command corresponding to the security key, the controller <b>1140</b> may control the determination of the authentication method. In addition, when granting the control authority to the control device, and if the authentication method corresponds to gateway authentication, the controller <b>1140</b> may control the granting of the control authority to the control device in response to the received control command.
When granting the control authority to the control device, and if the authentication method corresponds to the equipment authentication, the controller <b>1140</b> may determine the number of equipment to be authenticated. When the received authentication identification message corresponds to the determined number of equipment, the controller <b>1140</b> may control the granting of the control authority to the control device.
When granting the control authority to the control device, and if the authentication method corresponds to the equipment authentication, the controller <b>1140</b> may determine the number of equipment to be authenticated. When the received authentication identification message corresponds to the determined number of equipment, the controller <b>1140</b> may control the granting of the control authority to the control device.
In addition, the controller <b>1140</b> may transmit a message requesting the granting of the control authority for the operations to the gateway, and further control the receiving of a message requesting authentication based on the authentication method for the operations of the gateway.
In addition, the controller <b>1140</b> may transmit a message requesting the granting of the control authority for the operations to the gateway, and further control the receiving of a message requesting authentication based on the authentication method for the operations of the gateway.
Further, the controller <b>1140</b> may control the granting of the control authority for the operation to the control device, when the authentication is completed based on the identified authentication method for the operations. The authentication method may include at least one combination of the number of user devices that includes the control device, the type of user devices, the number of pieces of unique biological information, and the type of unique biological information. The authentication method may also include an authentication method for a plurality of users of a predetermined group.
Further, the controller <b>1140</b> may control the granting of the control authority for the operation to the control device, when the authentication is completed based on the identified authentication method for the operations. The authentication method may include at least one combination of the number of user devices that includes the control device, the type of user devices, the number of pieces of unique biological information, and the type of unique biological information. The authentication method may also include an authentication method for a plurality of users of a predetermined group.
According to the above-described embodiments of the present invention, when performing an authentication procedure for a control device for controlling equipment in a control area, an authentication key to be registered in the control device is generated based on user information and characteristics of the control area, and thus can adjust the degree of the authority to be granted to the control device. Therefore, embodiments of the present invention can provide a differentiated service for each user and apply the differentiated security criterion for each area.
According to the above-described embodiments of the present invention, when performing an authentication procedure for a control device for controlling equipment in a control area, an authentication key to be registered in the control device is generated based on user information and characteristics of the control area, and thus can adjust the degree of the authority to be granted to the control device. Therefore, embodiments of the present invention can provide a differentiated service for each user and apply the differentiated security criterion for each area.
While the present invention has been particularly shown and described with reference to certain embodiments thereof, it will be understood by those of ordinary skill in the art that various changes in form and details may be made therein without departing from the spirit and scope of the present invention as defined by the following claims and their equivalents.
While the present invention has been particularly shown and described with reference to certain embodiments thereof, it will be understood by those of ordinary skill in the art that various changes in form and details may be made therein without departing from the spirit and scope of the present invention as defined by the following claims and their equivalents.
Contents10
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US10306705B2 | Cited by | United States of America | – | Search report | – |
| US2018041511A1 | Cited by | United States of America | – | Search report | – |
| US10650621B1 | Cited by | United States of America | – | Applicant | – |
| US11395142B2 | Cited by | United States of America | – | Applicant | – |
| US2023094085A1 | Cited by | United States of America | – | Search report | – |
| US10581853B2 | Cited by | United States of America | – | Search report | – |
| US10055977B2 | Cited by | United States of America | – | Search report | – |
| US10701561B1 | Cited by | United States of America | – | Search report | – |
| US2017124857A1 | Cited by | United States of America | – | Pre-grant | – |
| US2016165663A1 | Cited by | United States of America | – | Pre-grant | – |
| JP2019012887A | Cited by | Japan | – | Search report | – |
| US10397782B2 | Cited by | United States of America | – | Search report | – |
| US11621956B2 | Cited by | United States of America | – | Applicant | – |
| US10951601B2 | Cited by | United States of America | – | Search report | – |
| US11012227B2 | Cited by | United States of America | – | Search report | – |
| CN112134767A | Cited by | China | – | Search report | – |
| US2016165663A1 | Cited by | United States of America | – | Search report | – |
| US2018041511A1 | Cited by | United States of America | – | Search report | – |
| US2022278851A1 | Cited by | United States of America | – | Search report | – |
| US11232655B2 | Cited by | United States of America | – | Applicant | – |
| US10432625B2 | Cited by | United States of America | – | Search report | – |
| US11831636B2 | Cited by | United States of America | – | Applicant | – |
| US2002031228A1 | Cites | United States of America | A | Search report | – |
| US2006069911A1 | Cites | United States of America | A | Search report | – |
| US2009019134A1 | Cites | United States of America | A | Search report | – |
| US2009129745A1 | Cites | United States of America | Y | Search report | 1, 3-6, 8-16, 18-23, 25-28, 30-38, 40-44 |
| US2009239502A1 | Cites | United States of America | A | Search report | – |
| US2010071053A1 | Cites | United States of America | A | Search report | – |
| US2010162328A1 | Cites | United States of America | A | Search report | – |
| US2010164720A1 | Cites | United States of America | A | Search report | – |
| US2011074555A1 | Cites | United States of America | Y | Search report | 8-10, 30-32 |
| US2012146761A1 | Cites | United States of America | A | Search report | – |
| US2013061291A1 | Cites | United States of America | A | Search report | – |
| US2014067094A1 | Cites | United States of America | A | Search report | – |
| US2015006695A1 | Cites | United States of America | Y | Search report | 1, 3-6, 8-16, 18-23, 25-28, 30-38, 40-44 |
| US2016021081A1 | Cites | United States of America | A | Search report | – |
| US6563730B1 | Cites | United States of America | A | Search report | – |
| US7110761B2 | Cites | United States of America | A | Search report | – |
| US7289014B2 | Cites | United States of America | A | Search report | – |
| US7683754B2 | Cites | United States of America | A | Search report | – |
| US7724687B2 | Cites | United States of America | A | Search report | – |
8 members in 5 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 1020140159086 | Republic of Korea | – | |
| 20140159086 | Republic of Korea | A | |
| 20140159086 | Republic of Korea | A | |
| 1020140159086 | – | – | – |
| KR20140159086 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| US2016142402A1 | United States of America | A1 | |
| WO2016076641A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20160058044A | Republic of Korea | A | |
| CN105610786A | China | A | |
| EP3219046A1 | European Patent Office (EPO) | A1 | |
| EP3219046A4 | European Patent Office (EPO) | A4 | |
| US10757096B2 | United States of America | B2 | |
| CN105610786B | China | B |
90 transactions on the USPTO file
Allowed after 3 non-final rejections, 2 final rejections and 2 RCEs.
- Non-final rejections
- 3
- Final rejections
- 2
- RCEs
- 2
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Printer Rush- No mailingTCPB | TCPB | |
| Printer Rush- No mailingTCPB | TCPB | |
| Printer Rush- No mailingTCPB | TCPB | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Priority document has successfully retrieved via PDX/DASPD.RECVD | PD.RECVD | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Sent to Classification ContractorPGPC | PGPC | |
| FITF set to YES - revise initial settingFTFS | FTFS | |
| Letter Accepting Permission for Application Access by Foreign IPOSB39ACPR | SB39ACPR | |
| Application Is Now CompleteCOMP | COMP | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Cleared by OIPE CSRL194 | L194 | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Patent Term Adjustment - Ready for ExaminationPTA.RFE | PTA.RFE | |
| Request from applicant for the USPTO to retrieve the Priority DocumentPDREQUST | PDREQUST | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Information on status: patent application and granting procedure in generalPUBLICATIONS -- ISSUE FEE PAYMENT VERIFIEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONSSTPP | STPP | |
| Information on status: patent application and granting procedure in generalRESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINERSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNON FINAL ACTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalDOCKETED NEW CASE - READY FOR EXAMINATIONSTPP | STPP | |
| Information on status: patent application and granting procedure in generalADVISORY ACTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalFINAL REJECTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalRESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINERSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNON FINAL ACTION MAILEDSTPP | STPP | |
| AssignmentAS | AS |
Numbers
- Publication
- 20160142402
- Publication, DOCDB
- 2016142402
- Publication, EPODOC
- US2016142402
- Application
- 14942496
- Application, DOCDB
- 201514942496
- Application, EPODOC
- US201514942496
Titles
- English
- METHOD AND APPARATUS FOR REGISTERING A DEVICE FOR USE
Patent term adjustment
- A delay
- +346 daysthe office missed an examination deadline
- B delay
- +39 dayspendency past three years
- Net adjustment
- 385 days
Classification
- CPC, 18
- H04L63/0853
- H04L65/1073
- H04W12/64
- H04L63/08
- H04L63/10
- H04L12/2809
- H04L63/105
- H04L63/107
- H04W4/02
- H04W4/70
- H04W4/021
- H04W12/003
- H04W12/06
- H04W12/00503
- H04W84/12
- H04W12/00505
- H04W12/67
- H04W12/50
- IPC, 1
- H04L29 06
- USPC, 1
- 726004000