Specific embodiment
In order to which technical problems, technical solutions and advantageous effects to be solved by the present invention are more clearly understood, below in conjunction with
Accompanying drawings and embodiments, the present invention will be described in further detail.It should be appreciated that specific embodiment described herein is only used
To explain the present invention, it is not intended to limit the present invention.
Fig. 1 is the schematic diagram for the system that mobile terminal provided in an embodiment of the present invention and attendance recorder are constituted, for the ease of saying
Bright, only the parts related to this embodiment are shown.
As shown in Figure 1, the system includes mobile terminal 11 and one or more attendance recorder 12.Wherein, mobile terminal 11 can
Think that laptop, tablet computer or mobile phone etc. have the terminal device of network access facility.
The embodiment of the invention provides a kind of activating method of administrator right, Fig. 2 is pipe provided in an embodiment of the present invention
The flow chart of the activating method of reason person's permission, as shown in Fig. 2, this approach includes the following steps S210 to step S240.
Step S210, attendance recorder and mobile terminal establish connection by Handshake Protocol.
The mobile terminal for meeting preset condition refers to the mobile terminal for being mounted with management system corresponding with attendance recorder, in this way
Mobile terminal and attendance recorder use identical Encryption Algorithm, both sides when transmit data by identical algorithm to data progress
Encryption and decryption, therefore ensure that the safety of data.
Specifically, can be judged by the following manner whether mobile terminal meets condition, and built when meeting condition determining
Vertical connection:
Step S01, attendance recorder receive the encrypted result that mobile terminal is sent, and mobile terminal is encrypted by the first Encryption Algorithm
First random parameter is to obtain encrypted result.
Step S02, attendance recorder decrypts encrypted result by the first Encryption Algorithm, to obtain the second random parameter.
Second random parameter is sent to mobile terminal by step S03, attendance recorder.
Step S04, after mobile terminal determines the first random parameter and the second random parameter is equal, attendance recorder and movement are eventually
End is established.
Such as above-mentioned example, Y=AX is exactly an algorithm, and mobile terminal finds out Y by A and X, and A therein and Y is sent
To attendance recorder, attendance recorder is decrypted based on Y and A according to the algorithm of oneself, an available X.If X value is equal, say
Bright mobile terminal and attendance recorder using it is identical calculate be encrypted and decrypted, therefore attendance recorder can determine that the mobile terminal is symbol
Desired mobile terminal is closed, so as to establish connection with the mobile terminal.
In order to reach better secrecy effect, mobile terminal can pass through different algorithms with attendance recorder interactive process
Repeatedly encrypted.Fig. 3 is the flow chart that attendance recorder provided in an embodiment of the present invention and mobile terminal establish connection, such as Fig. 3 institute
Show, this method comprises:
Step S310, attendance recorder receive the encryption factor A and encrypted result Y that mobile terminal is sent, wherein mobile terminal is raw
At encryption factor A and random number X, encryption factor A is encrypted to generate code key B using the second Encryption Algorithm, and add using third
Close algorithm generates encrypted result Y according to encryption code key B and random number X.
Encryption factor A is encrypted using the second Encryption Algorithm, key B can be produced.
By third Encryption Algorithm, Advanced Encryption Standard (Advanced Encryption can be in the present embodiment
Standard, referred to as AES) after algorithm for encryption random number X, obtain the encryption data Y of random number X.
Step S320, attendance recorder generate key B using the second Encryption Algorithm.
After attendance recorder receives the encryption factor A and Y of mobile terminal transmission, code key B is generated according to encryption factor A.
Step S330, attendance recorder utilize third Encryption Algorithm, generate random number X according to key B and encrypted result Y.
After encrypted result is decrypted by code key B, random number X can be generated.
Step S340, attendance recorder utilize the 4th Encryption Algorithm, generate X0 according to random number X.
The 4th Encryption Algorithm in the present embodiment can be a kind of non-reversible algorithm, available by the non-reversible algorithm
The correspondence parameter of random number.
Step S350, attendance recorder utilize the second Encryption Algorithm, generate Y0 according to X0 and encryption code key B, and Y0 is sent to
Mobile terminal, mobile terminal utilize third Encryption Algorithm, are decrypted according to decruption key B and Y0 and generate X0, and utilize the 4th encryption
Algorithm for encryption random number X is to generate X1.
Step S360, after mobile terminal determines that X0 is equal with X1, attendance recorder and mobile terminal establish connection.
When X0 is equal with X1, attendance recorder thinks that the mobile terminal is qualified, therefore can be with the mobile terminal
Establish connection.
This process can be called recognition methods of shaking hands, and Fig. 4 is the stream of recognition methods provided in an embodiment of the present invention of shaking hands
Cheng Tu, comprising the following steps:
Step S401, mobile device generates encryption factor A and random number X, and obtains code key B according to encryption factor A.
Step S402, mobile terminal are that encryption secret room obtains processing result Y by aes algorithm encrypted random number X with B.
A and Y are sent to attendance recorder by step S403, mobile terminal.
Step S404, attendance recorder generate code key B according to encryption factor A, and using B as decruption key, using whole with movement
It holds identical aes algorithm to decrypt encryption data Y, obtains the random number X that above-mentioned mobile terminal generates.
Step S405, attendance recorder carry out calculation processing to random number X using non-reversible algorithm, obtain random number X in movement
Second processing data X0 in terminal.
Step S406, attendance recorder is using B as encryption key, by aes algorithm identical with mobile terminal to second processing
Data X0 is encrypted, and the encryption data of Y0 is obtained.
Y0 is back to mobile terminal by step S407, attendance recorder.
Step S408, mobile terminal decrypt Y0 by aes algorithm and obtain X0.
Step S409, mobile terminal directly are encrypted to obtain X1 by non-reversible algorithm to random number X again
Step S410, mobile terminal judge whether X0 is equal to X1, so that it is determined that whether the attendance recorder matches.
Pass through the identification method of shaking hands, it is ensured that mobile terminal is qualified.
Step S220, the biological characteristic that attendance recorder receives the work number of input and mobile terminal is read.
After determining that mobile terminal is eligible, in order to further ensure safety, it is also necessary to determine and use the movement
The user of terminal is qualified people, the people with associated rights that qualified people can pre-register.For
Qualified people, biological characteristic, such as fingerprint, face, iris etc. are crossed in typing in advance.
Only pass through compared with the prior art and input the identity that work number confirms user, in this step, mobile terminal can be read
The corresponding biological characteristic of user, and biological characteristic is sent to attendance recorder, so that attendance recorder is by the biological characteristic and the life that prestores
Object feature is compared.
Since work number relevant information is easy to be stolen by others and usurps, safety is lower, and the embodiment of the present invention can pass through
The identity of biological characteristic validation user since biological characteristic is unique, and can not be stolen by others and usurp, therefore
Raising safety that can be very big by the identity of biological characteristic validation user.
Step S230, attendance recorder compare received biological characteristic with the biological characteristic that prestores to calculate matching degree.
The biology read can be calculated using matching degree computational algorithm according to the characteristic extracted in biological characteristic
The matching degree of feature and registered biological characteristic.Registered biological characteristic can store in attendance recorder local, can also deposit
In the server, there are attendance recorders can locally guarantee faster reading speed, can guarantee in presence server bigger for storage
Amount of storage and higher safety.Different storage methods can be used in different scenes or different attendance recorders.
In one implementation, attendance recorder compares received biological characteristic with local biological characteristic is pre-stored in
It is right.The biological characteristic of user registration, which is stored in, locally can guarantee higher response speed, after user inputs biological characteristic
It can compare as early as possible and obtain matching degree.
In another implementation, attendance recorder carries out received biological characteristic with the biological characteristic for being pre-stored in server
It compares.The biological characteristic of user registration is stored in server, on the one hand can reduce the cost of attendance recorder on a memory;Separately
On the one hand it can guarantee the safety of data, in order to avoid biological characteristic therein can be obtained after attendance recorder is stolen.
Step S240, when confirming that work number is correct and matching degree is higher than preset value, attendance recorder opens management to mobile terminal
Member's permission.
Different matching degrees may will be calculated in different algorithms, and two biological characteristics are in rings such as different light
The matching degree gone out calculated under border may also be different, it is however generally that, it, can be with when the matching degree of two biological characteristics is higher than 80%
Think that the two biological characteristics are the same persons.Therefore, in the present embodiment, if matching degree is higher than 80%, and abovementioned steps
Have confirmed that mobile terminal meets preset condition, then this step can determine that the mobile terminal is manager device.
Verifying of the present embodiment to mobile terminal and the confirmation to user, it is ensured that mobile terminal is to meet setting for safety condition
Standby, user is the people for having obtained authorization, to ensure that the safety by mobile terminal administration attendance recorder.
The embodiment of the invention also provides a kind of device of opening of administrator right, Fig. 5 is provided in an embodiment of the present invention
The structural block diagram for opening device of administrator right, as shown in figure 5, the device includes connection unit 510, receiving unit 520,
One determination unit 530 and the second determination unit 540.
Connection unit 510 is used to establish connection by Handshake Protocol with mobile terminal.
The biological characteristic that the work number for receiving input of receiving unit 520 and mobile terminal are read.
Biological characteristic of first determination unit 530 for comparing received biological characteristic and prestoring is to calculate matching degree.
Second determination unit 540 is used for when confirming that work number is correct and matching degree is higher than preset value, and attendance recorder determines movement
Terminal is manager device.
Preferably, connection unit 510 includes:
First receiving module, for receiving the encrypted result of mobile terminal transmission, mobile terminal passes through the first Encryption Algorithm
The first random parameter is encrypted to obtain encrypted result.
Module is obtained, encrypted result is decrypted by the first Encryption Algorithm for attendance recorder, to obtain the second random parameter.
Sending module, for the second random parameter to be sent to mobile terminal.
First link block, for after mobile terminal determines the first random parameter and the second random parameter is equal, with shifting
Dynamic terminal establishes connection.
Preferably, connection unit 510 includes:
Second receiving module, for receiving the encryption factor A and encrypted result Y of mobile terminal transmission, wherein mobile terminal
Encryption factor A and random number X is generated, using the second Encryption Algorithm encrypting factors A to generate code key B, and is added using third
Close algorithm generates encrypted result Y according to code key B and random number X.
First generation module, for generating key B using the second Encryption Algorithm.
Second generation module generates random number X according to key B and encrypted result Y for utilizing third Encryption Algorithm.
Third generation module generates X0 according to random number X for utilizing the 4th Encryption Algorithm.
4th generation module states B according to X0 and institute's key and generates Y0, and Y0 is sent for utilizing the second Encryption Algorithm
To mobile terminal, mobile terminal utilizes third Encryption Algorithm, is decrypted according to key B and Y0 and generates X0, and is calculated using the 4th encryption
Method encrypted random number X is to generate X1.
Second link block, for establishing connection with mobile terminal after mobile terminal determines that X0 is equal with X1.
Preferably, the first determination unit is also used to: compare received biological characteristic and be pre-stored in local biological characteristic with
Determine matching degree.
Preferably, the first determination unit is also used to: comparing received biological characteristic and the biological characteristic for being pre-stored in server
To determine matching degree.
It is apparent to those skilled in the art that for convenience of description and succinctly, only with above-mentioned each function
Can unit division progress for example, in practical application, can according to need and by above-mentioned function distribution by different functions
Unit is completed, i.e., the internal structure of device is divided into different functional unit or module, with complete it is described above whole or
Person's partial function.Each functional unit in embodiment can integrate in one processing unit, and it is independent to be also possible to each unit
It is physically present, can also be integrated in one unit with two or more units, above-mentioned integrated unit both can be using hard
The form of part is realized, can also be realized in the form of software functional units.In addition, the specific name of each functional unit is also
For the ease of mutually distinguishing, the protection scope being not intended to limit this application.The specific work process of unit in above-mentioned apparatus, can
With with reference to the corresponding process in aforementioned device embodiment, details are not described herein.
Those of ordinary skill in the art may be aware that list described in conjunction with the examples disclosed in the embodiments of the present disclosure
Member and algorithm steps can be realized with the combination of electronic hardware or computer software and electronic hardware.These functions are actually
It is implemented in hardware or software, the specific application and design constraint depending on technical solution.Professional technician
Described function can be realized using different device to each specific application, but this realization is it is not considered that exceed
The scope of the present invention.
In embodiment provided by the present invention, it should be understood that disclosed device and device can pass through others
Mode is realized.For example, the apparatus embodiments described above are merely exemplary, for example, the division of module or unit, only
For a kind of logical function partition, there may be another division manner in actual implementation, such as multiple units or components can combine
Or it is desirably integrated into another system, or some features can be ignored or not executed.Another point, shown or discussed phase
Coupling or direct-coupling or communication connection between mutually can be through some interfaces, the INDIRECT COUPLING or communication of device or unit
Connection can be electrical property, mechanical or other forms.
Unit may or may not be physically separated as illustrated by the separation member, shown as a unit
Component may or may not be physical unit, it can and it is in one place, or may be distributed over multiple networks
On unit.It can some or all of the units may be selected to achieve the purpose of the solution of this embodiment according to the actual needs.
It, can also be in addition, the functional units in various embodiments of the present invention may be integrated into one processing unit
It is that each unit physically exists alone, can also be integrated in one unit with two or more units.Above-mentioned integrated list
Member both can take the form of hardware realization, can also realize in the form of software functional units.
It, can if integrated unit is realized in the form of SFU software functional unit and when sold or used as an independent product
To be stored in a computer readable storage medium.Based on this understanding, the technical solution essence of the embodiment of the present invention
On all or part of the part that contributes to existing technology or the technical solution can be with the shape of software product in other words
Formula embodies, which is stored in a storage medium, including some instructions are used so that a calculating
It is real that machine equipment (can be personal computer, server or the network equipment etc.) or processor (processor) execute the present invention
Apply all or part of the steps of each embodiment device of example.And storage medium above-mentioned includes: USB flash disk, mobile hard disk, read-only storage
Device (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disk or light
The various media that can store program code such as disk.
The above embodiments are merely illustrative of the technical solutions of the present invention, rather than its limitations;Although with reference to the foregoing embodiments
Invention is explained in detail, those skilled in the art should understand that: it still can be to aforementioned each implementation
Technical solution documented by example is modified or equivalent replacement of some of the technical features;And these modification or
Replacement, the spirit and scope of each embodiment technical solution of the embodiment of the present invention that it does not separate the essence of the corresponding technical solution.
The above is merely preferred embodiments of the present invention, be not intended to limit the invention, it is all in spirit of the invention and
Made any modifications, equivalent replacements, and improvements etc., should all be included in the protection scope of the present invention within principle.