TWI725623B - Point-to-point authority management method based on manager's self-issued tickets - Google Patents

Point-to-point authority management method based on manager's self-issued tickets Download PDF

Info

Publication number
TWI725623B
TWI725623B TW108141568A TW108141568A TWI725623B TW I725623 B TWI725623 B TW I725623B TW 108141568 A TW108141568 A TW 108141568A TW 108141568 A TW108141568 A TW 108141568A TW I725623 B TWI725623 B TW I725623B
Authority
TW
Taiwan
Prior art keywords
ticket
service
management
terminal device
server device
Prior art date
Application number
TW108141568A
Other languages
Chinese (zh)
Other versions
TW202121867A (en
Inventor
楊奕君
吳昕益
Original Assignee
倍加科技股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 倍加科技股份有限公司 filed Critical 倍加科技股份有限公司
Priority to TW108141568A priority Critical patent/TWI725623B/en
Application granted granted Critical
Publication of TWI725623B publication Critical patent/TWI725623B/en
Publication of TW202121867A publication Critical patent/TW202121867A/en

Links

Images

Abstract

一種基於管理者自發行票券的點對點權限管理方法,服務端裝置驗證管理端裝置傳來的第一服務指令票券並根據第一服務指令票券包含的第一指令提供相對應的服務;管理端裝置產生服務權限設定票券給第一終端裝置,使根據服務權限設定票券產生第二服務指令票券,並依序傳送服務權限設定票券及第二服務指令票券給服務端裝置;服務端裝置驗證並判斷服務權限設定票券及其中記錄的存取權限的有效性後,服務端裝置驗證第二服務指令票券並判斷其中包含的第二指令在服務權限設定票券記錄的存取權限內時,服務端裝置根據第二指令提供相對應的服務。A point-to-point authority management method based on the self-issuing of the ticket by the administrator. The server device verifies the first service instruction ticket from the management device and provides the corresponding service according to the first instruction contained in the first service instruction ticket; management; The end device generates the service authority setting ticket to the first terminal device, so that the second service instruction ticket is generated according to the service authority setting ticket, and the service authority setting ticket and the second service instruction ticket are sequentially transmitted to the server device; After the server device verifies and judges the validity of the service authority setting ticket and the access authority recorded therein, the server device verifies the second service instruction ticket and determines that the second instruction contained therein is stored in the service authority setting ticket record. When within the authority, the server device provides the corresponding service according to the second instruction.

Description

基於管理者自發行票券的點對點權限管理方法Point-to-point authority management method based on manager's self-issued tickets

本發明是有關於一種電子裝置的使用權限管理方法,特別是指一種基於管理者自發行票券的點對點權限管理方法。 The invention relates to a method for managing the use authority of an electronic device, in particular to a point-to-point authority management method based on the self-issuing of tickets by an administrator.

既有被集中化管理的電子設備,例如智慧車載系統、自動化機器、家用電器等,其系統提供者主要利用例如中心化的雲端管理中心來集中化管理該些電子設備使用者對該些電子設備的存取權限及隱私資料。 Existing centralized management of electronic equipment, such as smart car systems, automated machines, household appliances, etc., and its system providers mainly use, for example, a centralized cloud management center to centrally manage these electronic equipment users. Access rights and private information.

因此,在電子設備的存取控制機制及隱私資料被系統提供者的雲端管理中心集中控制的情況下,即使系統提供者訂定的管理規則有不透明或偏差的問題,電子設備使用者也只能接受提供者訂定的規則。此外,電子設備的使用者資料總是被以不透明且不能驗證的方式上傳到雲端資料庫,以致電子設備的使用者無法有效地保護或防止他們的隱私或保密性資料被系統提供者濫用。 Therefore, when the access control mechanism and private data of the electronic device are centrally controlled by the cloud management center of the system provider, even if the management rules set by the system provider are opaque or biased, the user of the electronic device can only Accept the rules set by the provider. In addition, user information of electronic devices is always uploaded to the cloud database in an opaque and non-verifiable manner, so that users of electronic devices cannot effectively protect or prevent their privacy or confidential information from being misused by system providers.

此外,為了與雲端管理中心連線,電子設備還需負擔高網路傳輸成本、高網路傳輸延遲以及高硬體設計成本等。再者,集中化管理的雲端管理中心難以轉移其管理權限至其它的雲端管理 中心。 In addition, in order to connect to the cloud management center, electronic devices also need to bear high network transmission costs, high network transmission delays, and high hardware design costs. Furthermore, it is difficult for a centralized management cloud management center to transfer its management authority to other cloud management center.

因此,本發明之目的,即在提供一種基於管理者自發行票券的點對點權限管理方法及系統,其能讓電子裝置的管理端裝置能藉由發行票券來管理電子裝置的使用權限及管理權限而達到去中心化管理的目的,並解決先前技術提出的問題。 Therefore, the purpose of the present invention is to provide a point-to-point authority management method and system based on the self-issuing of tickets by the administrator, which enables the management end device of the electronic device to manage the use authority and management of the electronic device by issuing tickets. To achieve the purpose of decentralized management, and to solve the problems raised by previous technologies.

於是,本發明基於管理者自發行票券的點對點權限管理方法,應用於能相互通訊的一服務端裝置、一管理該服務端裝置的管理端裝置以及一第一終端裝置之間,其中該管理端裝置具有專屬且配對的一第一公鑰及一第一私鑰,該服務端裝置具有專屬且配對的一第二公鑰及一第二私鑰,該第一終端裝置具有專屬且配對的一第三公鑰及一第三私鑰;該方法包括:該管理端裝置能產生並傳送一包含一第一指令的第一服務指令票券給該服務端裝置;該服務端裝置收到該第一服務指令票券後,以該管理端裝置的該第一公鑰驗證該第一服務指令票券的正確性,並根據該第一服務指令票券包含的該第一指令提供相對應的服務給該管理端裝置;該管理端裝置能產生一服務權限設定票券並傳送該服務權限設定票券給該第一終端裝置,該服務權限設定票券記錄該第一終端裝置對該服務端裝置的一存取權限;該第一終端裝置能根據該服務權限設定票券產生一第二服務指令票券,並依序傳送該服務權限設定票券及該第二服 務指令票券給該服務端裝置;該服務端裝置收到該服務權限設定票券後,以該管理端裝置的該第一公鑰驗證該服務權限設定票券的正確性,並判斷該服務權限設定票券記錄的該存取權限的有效性後,該服務端裝置接收該第二服務指令票券,並以該第一終端裝置的一第三公鑰驗證該第二服務指令票券的正確性,且判斷該第二服務指令票券包含的該第二指令在該服務權限設定票券記錄的該存取權限內時,該服務端裝置根據該第二指令提供相對應的服務給該第一終端裝置。 Therefore, the present invention is based on the point-to-point authority management method of self-issued tickets by the administrator, which is applied between a server device that can communicate with each other, a management device that manages the server device, and a first terminal device, wherein the management The end device has an exclusive and paired first public key and a first private key, the server device has an exclusive and paired second public key and a second private key, and the first end device has an exclusive and paired A third public key and a third private key; the method includes: the management device can generate and transmit a first service instruction ticket containing a first instruction to the server device; the server device receives the After the first service instruction ticket, the first public key of the management terminal device is used to verify the correctness of the first service instruction ticket, and the corresponding first instruction provided in the first service instruction ticket is provided Service to the management terminal device; the management terminal device can generate a service authority setting ticket and transmit the service authority setting ticket to the first terminal device, the service authority setting ticket records the first terminal device to the server An access authority for the device; the first terminal device can generate a second service instruction ticket according to the service authority setting ticket, and transmit the service authority setting ticket and the second service in sequence The service order ticket is given to the server device; after the server device receives the service authority setting ticket, it verifies the correctness of the service authority setting ticket with the first public key of the management terminal device, and judges the service After the permission setting ticket records the validity of the access permission, the server device receives the second service order ticket, and uses a third public key of the first terminal device to verify the validity of the second service order ticket Is correct, and when it is determined that the second instruction contained in the second service instruction ticket is within the access authority of the service authority setting ticket record, the server device provides the corresponding service to the second instruction according to the second instruction. The first terminal device.

在本發明的一些實施態樣中,在產生該第一服務指令票券之前,該管理端裝置會先產生一初始設定票券並傳送該初始設定票券給該服務端裝置,該服務端裝置收到該初始設定票券,並以該管理端裝置的該第一公鑰驗證該初始設定票券的正確性後,該管理端裝置將該第一公鑰記錄在其中的一管理者欄位中,而設定該管理端裝置為其管理者。 In some embodiments of the present invention, before generating the first service instruction ticket, the management terminal device first generates an initial setting ticket and transmits the initial setting ticket to the server device, the server device After receiving the initial setting ticket and verifying the correctness of the initial setting ticket with the first public key of the management terminal device, the management terminal device records the first public key in one of the administrator fields , And set the management terminal device as the manager.

在本發明的一些實施態樣中,該管理端裝置會使用該第一私鑰對該初始設定票券簽章,再將已簽章的該初始設定票券傳送給該服務端裝置,該服務端裝置收到已簽章的該初始設定票券後,以該管理端裝置的該第一公鑰驗證已簽章的該初始設定票券,以確認該初始設定票券的正確性;且該服務端裝置完成設定後,產生一包含一設定結果的狀態回報票券,並以該第二私鑰對該狀態回報票 券簽章後,將已簽章的該狀態回報票券傳送給該管理端裝置,該管理端裝置收到已簽章的該狀態回報票券並以該服務端裝置的該第二公鑰驗證該狀態回報票券的正確性,且根據該設定結果確認該服務端裝置已完成管理者的設定。 In some embodiments of the present invention, the management terminal device will use the first private key to sign the initial set ticket, and then transmit the signed initial set ticket to the server device, and the service After receiving the signed initial set ticket, the end device verifies the signed initial set ticket with the first public key of the management end device to confirm the correctness of the initial set ticket; and After the server device completes the settings, it generates a status report ticket containing a setting result, and uses the second private key to report the status ticket After the coupon is signed, the signed status report ticket is sent to the management terminal device, and the management terminal device receives the signed status report ticket and verifies it with the second public key of the server device The status reports the correctness of the ticket, and according to the setting result, it is confirmed that the server device has completed the setting of the administrator.

在本發明的一些實施態樣中,該第一服務指令票券的一服務裝置欄位中記錄該服務端裝置的該第二公鑰,該第一服務指令票券的一票券持有者欄位中記錄該第一公鑰,該第一票券的一票券產生者欄位中記錄該第一公鑰,且該管理端裝置與該服務端裝置建立一會話機制,並使用一與該服務端裝置約定的一第一會話密鑰將該第一服務指令票券內含的該一指令加密成一第一加密資料後,該管理端裝置再以該第一私鑰對內含該第一加密資料的該第一服務指令票券簽章而產生已簽章的該第一服務指令票券,再傳送已簽章的該第一服務指令票券給該服務端裝置;該服務端裝置收到已簽章的該第一服務指令票券,根據該第一服務指令票券的該服務裝置欄位中記錄的該第二公鑰,確認其為該第一服務指令票券的接收端,並根據該第一服務指令票券的該票券持有者欄位中記錄的該第一公鑰,確認該管理端裝置為提供該相對應的服務的對象,並且以該管理端裝置的該第一公鑰驗證已簽章的該第一服務指令票券的正確性後,以該第一會話密鑰解密該第一服務指令票券內含的該第一加密資料而取出該第一指令。 In some embodiments of the present invention, the second public key of the server device is recorded in a service device field of the first service order ticket, and a ticket holder of the first service order ticket The first public key is recorded in the field, the first public key is recorded in the ticket generator field of the first ticket, and the management-end device establishes a session mechanism with the server-end device, and uses a and After a first session key agreed by the server device encrypts the one command contained in the first service command ticket into a first encrypted data, the management device then uses the first private key pair to include the first private key pair. An encrypted data of the first service order ticket is signed to generate the signed first service order ticket, and then the signed first service order ticket is sent to the server device; the server device After receiving the signed first service order ticket, confirm that it is the receiving end of the first service order ticket according to the second public key recorded in the service device field of the first service order ticket , And according to the first public key recorded in the ticket holder field of the first service instruction ticket, confirm that the management terminal device is the object that provides the corresponding service, and use the management terminal device's After the first public key verifies the correctness of the signed first service order ticket, the first encrypted data contained in the first service order ticket is decrypted with the first session key to retrieve the first service order ticket. instruction.

在本發明的一些實施態樣中,該管理端裝置與該服務端裝置建立該會話機制之前,該服務端裝置與該管理端裝置之間會先進行一身份驗證(Challenge-response authentication,挑戰-響應認證)程序。 In some embodiments of the present invention, before the management-end device and the server-end device establish the session mechanism, an identity verification (Challenge-response authentication) is performed between the server-end device and the management-end device. Response authentication) procedures.

在本發明的一些實施態樣中,該服務端裝置完成該第一服務指令票券要求的服務後,該服務端裝置的該票券處理模組會產生一狀態回報票券,該狀態回報票券內含一服務有關的資料,且該服務端裝置使用該第一會話密鑰將該狀態回報票券內含的該與服務有關的資料加密成一第二加密資料後,再以該第二私鑰對內含該第二加密資料的該狀態回報票券簽章,並傳送已簽章的該狀態回報票券給該管理端裝置;該管理端裝置收到已簽章的該狀態回報票券,並以該服務端裝置的該第二公鑰驗證已簽章的該狀態回報票券的正確性後,再以該第一會話密鑰解密該狀態回報票券內含的該第二加密資料而取出該與服務有關的資料,且根據該與服務有關的資料確定該服務端裝置已完成該第一服務指令票券要求的服務後,與該服務端裝置終止該會話機制。 In some embodiments of the present invention, after the server device completes the service required by the first service instruction ticket, the ticket processing module of the server device generates a status report ticket, and the status report ticket The coupon contains a service-related data, and the server device uses the first session key to encrypt the service-related data contained in the status report ticket into a second encrypted data, and then uses the second private The key pair contains the signature of the status report ticket of the second encrypted data, and transmits the signed status report ticket to the management terminal device; the management terminal device receives the signed status report ticket , And verify the correctness of the signed state report ticket with the second public key of the server device, and then decrypt the second encrypted data contained in the state report ticket with the first session key After taking out the service-related data, and after determining that the server device has completed the service requested by the first service order ticket based on the service-related data, the session mechanism is terminated with the server device.

在本發明的一些實施態樣中,該服務權限設定票券的一服務裝置欄位中記錄該服務端裝置的該第二公鑰,該服務權限設定票券的一票券持有者欄位中記錄該第一終端裝置的該第三公鑰,該服務權限設定票券的一票券發行者欄位中記錄該第一公鑰,且該 管理端裝置以該第一私鑰對該服務權限設定票券簽章而產生已簽章的該服務權限設定票券,再將已簽章的該服務權限設定票券傳送給該第一終端裝置;該第一終端裝置以該管理端裝置的該第一公鑰驗證已簽章的該服務權限設定票券的正確性後,將已簽章的該服務權限設定票券儲存,並且該第一終端裝置還產生一狀態回報票券,並以該第三私鑰對該狀態回報票券簽章後,傳送已簽章的該狀態回報票券給該管理端裝置,該管理端裝置收到已簽章的該狀態回報票券並以該第一終端裝置的該第三公鑰驗證該狀態回報票券的正確性。 In some embodiments of the present invention, the second public key of the server device is recorded in a service device field of the service authority setting ticket, and a ticket holder field of the service authority setting ticket The third public key of the first terminal device is recorded in the first terminal device, the first public key is recorded in a ticket issuer field of the service authority setting ticket, and the The management terminal device uses the first private key to set the ticket signature for the service authority to generate the signed service authority setting ticket, and then transmits the signed service authority setting ticket to the first terminal device After the first terminal device verifies the correctness of the signed service authority setting ticket with the first public key of the management terminal device, it stores the signed service authority setting ticket, and the first The terminal device also generates a status report ticket, and after signing the status report ticket with the third private key, transmits the signed status report ticket to the management terminal device, and the management terminal device receives the status report ticket. The status report ticket is signed and the third public key of the first terminal device is used to verify the correctness of the status report ticket.

在本發明的一些實施態樣中,該第一終端裝置將已簽章的該服務權限設定票券傳送給該服務端裝置,且該服務端裝置根據該服務權限設定票券的該服務裝置欄位中記錄的該第二公鑰,確認其為該服務權限設定票券的接收端,並以該管理端裝置的該第一公鑰驗證該已簽章的該服務權限設定票券的正確性,以及確定該服務權限設定票券中記錄的該權限資訊的有效性後,該服務端裝置會產生一內含權限確認結果的狀態回報票券,並以該第二私鑰對該狀態回報票券簽章後,將已簽章的該狀態回報票券傳送給該第一終端裝置,且該第一終端裝置收到已簽章的該回報票後,以該服務端裝置的該第二公鑰驗證已簽章的該狀態回報票券的正確性,並根據該狀態回報票券內含的該權限確認結果,確定該服務端裝置已確認該 服務權限設定票券的權限。 In some embodiments of the present invention, the first terminal device transmits the signed service authority setting ticket to the server device, and the server device sets the service device column of the ticket according to the service authority The second public key recorded in the bit confirms that it is the receiving end of the service authority setting ticket, and the correctness of the signed service authority setting ticket is verified with the first public key of the management terminal device , And after determining the validity of the permission information recorded in the service permission setting ticket, the server device will generate a status report ticket containing the permission confirmation result, and use the second private key to report the status to the ticket After the coupon is signed, the signed state return ticket is sent to the first terminal device, and after the first terminal device receives the signed return ticket, it uses the second public certificate of the server device The key verifies the correctness of the signed status report ticket, and according to the permission confirmation result contained in the status report ticket, it is determined that the server device has confirmed the The service authority sets the authority of the ticket.

在本發明的一些實施態樣中,該第一終端裝置確認該狀態回報票券的正確性後,該第一終端裝置產生該第二服務指令票券,該第二服務指令票券的一服務裝置欄位中記錄該服務端裝置的該第二公鑰,該第二服務指令票券的一票券持有者欄位中記錄該第三公鑰,該第二服務指令票券的一票券產生者欄位中記錄該第三公鑰;且該第一終端裝置與該服務端裝置建立一會話機制,並以與該服務端裝置約定的一第二會話密鑰將該第二服務指令票券內含的該第二指令加密成一第三加密資料,並以該第三私鑰對內含該第三加密資料的該第二服務指令票券簽章而產生已簽章的該第二服務指令票券,再將已簽章的該第二服務指令票券傳送給該服務端裝置;該服務端裝置收到該已簽章的該第二服務指令票券,並使用該第一終端裝置的該第三公鑰驗證已簽章的該第二服務指令票券的正確性後,再以該第二會話密鑰解密已簽章的該第二服務指令票券內含的該第三加密資料而取出該第二指令。 In some embodiments of the present invention, after the first terminal device confirms the correctness of the status report ticket, the first terminal device generates the second service instruction ticket, and a service of the second service instruction ticket The second public key of the server device is recorded in the device field, the third public key is recorded in the ticket holder field of the second service order ticket, and a ticket of the second service order ticket The third public key is recorded in the coupon generator field; and the first terminal device establishes a session mechanism with the server device, and uses a second session key agreed with the server device to the second service command The second instruction contained in the ticket is encrypted into a third encrypted data, and the second service instruction ticket containing the third encrypted data is signed with the third private key to generate the signed second The service order ticket, and then the signed second service order ticket is sent to the server device; the server device receives the signed second service order ticket and uses the first terminal After the third public key of the device verifies the correctness of the signed second service order ticket, the second session key is used to decrypt the third public key contained in the signed second service order ticket. Encrypt the data and fetch the second command.

在本發明的一些實施態樣中,該第一終端裝置與該服務端裝置建立該會話機制之前,該服務端裝置與該第一終端裝置之間會先進行一身份驗證(Challenge-response authentication,挑戰-響應認證)程序。 In some embodiments of the present invention, before the first terminal device and the server device establish the session mechanism, a challenge-response authentication (Challenge-response authentication, Challenge-response authentication) procedures.

在本發明的一些實施態樣中,該服務端裝置完成該第 二服務指令票券要求的服務後,該服務端裝置會產生一狀態回報票券,該狀態回報票券內含一與服務有關的資料,且該服務端裝置使用該第二會話密鑰將該狀態回報票券內含的該與服務有關的資料加密成一第四加密資料後,再以該第二私鑰對內含該第四加密資料的該狀態回報票券簽章,並傳送已簽章的該狀態回報票券給該第一終端裝置;該第一終端裝置收到該已簽章的該狀態回報票券,並以該服務端裝置的該第二公鑰驗證已簽章的該狀態回報票券的正確性後,再以該第二會話密鑰解密該狀態回報票券內含的該第四加密資料而取出該與服務有關的資料,且根據該與服務有關的資料確定該服務端裝置已完成該第二服務指令票券要求的服務後,與該服務端裝置終止該會話機制。 In some embodiments of the present invention, the server device completes the first 2. After the service requested by the service order ticket, the server device will generate a status report ticket. The status report ticket contains information related to the service, and the server device uses the second session key to After the service-related data contained in the status report ticket is encrypted into a fourth encrypted data, the status report ticket signature with the fourth encrypted data contained in the second private key is used, and the signed stamp is sent The status report ticket of is sent to the first terminal device; the first terminal device receives the signed status report ticket, and verifies the signed status with the second public key of the server device After reporting the correctness of the ticket, the second session key is used to decrypt the fourth encrypted data contained in the status report ticket to take out the service-related data, and determine the service based on the service-related data After the end device has completed the service required by the second service instruction ticket, the conversation mechanism with the server end device is terminated.

在本發明的一些實施態樣中,該服務端裝置及該管理端裝置還能與一第二終端裝置通訊,該第二終端裝置具有專屬且配對的一第四公鑰及一第四私鑰;且該管理端裝置還能產生一內含一管理權設定的管理權設定票券,並傳送該管理權設定票券給一第二終端裝置,該第二終端裝置將該管理權設定票券傳送給該服務端裝置後,該服務端裝置根據該管理端裝置的該第一公鑰驗證該管理權設定票券的正確性後,根據該管理權設定票券內含的該管理權設定,設定該第二終端裝置具有該服務端裝置的全部或部分管理權限;該第二終端裝置被設定為具有該服務端裝置的全部管理權限時,該服 務端裝置會將其中的該管理者欄位更新為該第二終端裝置的該第四公鑰;該第二終端裝置被設定為具有該服務端裝置的部分管理權限時,該服務端裝置將新增一第二管理者欄位及一與該第二管理者欄位相對應的第二管理權限欄位,且將該第二終端裝置的該第四公鑰記錄於該第二管理欄位,並於該第二管理權限欄位中記錄該管理權設定票券設定的部分管理權限內容,並且新增一與該管理者欄位對應的第一管理權限欄位,並於該第一管理權限欄位中記錄該管理端裝置的部分管理權限內容。 In some embodiments of the present invention, the server device and the management device can also communicate with a second terminal device, and the second terminal device has a dedicated and paired fourth public key and a fourth private key ; And the management terminal device can also generate a management right setting ticket containing a management right setting, and transmit the management right setting ticket to a second terminal device, the second terminal device setting the management right ticket After being transmitted to the server device, the server device verifies the correctness of the management right setting ticket according to the first public key of the management terminal device, and then sets the management right setting contained in the ticket according to the management right, Set the second terminal device to have all or part of the management authority of the server device; when the second terminal device is set to have all the management authority of the server device, the server The server device will update the manager field to the fourth public key of the second terminal device; when the second terminal device is set to have partial management authority of the server device, the server device will Adding a second manager field and a second management authority field corresponding to the second manager field, and recording the fourth public key of the second terminal device in the second management field, And record part of the management authority content of the management authority setting ticket setting in the second management authority field, and add a first management authority field corresponding to the manager field, and add it to the first management authority Part of the management authority content of the management terminal device is recorded in the field.

在本發明的一些實施態樣中,該管理權設定票券的一服務裝置欄位中記錄該服務端裝置的該第二公鑰,該管理權設定票券的一票券持有者欄位中記錄該第二終端裝置的該第四公鑰,該管理權設定票券的一票券發行者欄位中記錄該第一公鑰;且該管理端裝置以該第一私鑰對該管理權設定票券簽章,再將已簽章的該管理權設定票券傳送給該第二終端裝置,該第二終端裝置以該管理端裝置的該第一公鑰驗證收到的已簽章的該管理權設定票券的正確性後,儲存已簽章的該管理權設定票券,並產生一狀態回報票券,並以該第四私鑰對該狀態回報票券簽章後,傳送已簽章的該狀態回報票券給該管理端裝置,該管理端裝置收到已簽章的該狀態回報票券並以該第二終端裝置的第四公鑰驗證該狀態回報票券的正確性。 In some embodiments of the present invention, the second public key of the server device is recorded in a server device field of the management right setting ticket, and the management right sets a ticket holder field of the ticket The fourth public key of the second terminal device is recorded in the second terminal device, the first public key is recorded in a ticket issuer field of the management right setting ticket; and the management terminal device uses the first private key to manage the management The right to set the ticket signature, and then transmit the signed management right setting ticket to the second terminal device, and the second terminal device verifies the received signed stamp with the first public key of the management terminal device After the correctness of the management right to set the ticket, the signed management right to set the ticket is stored, and a status report ticket is generated, and the status report ticket is signed with the fourth private key, and then sent The signed status report ticket is sent to the management terminal device, and the management terminal device receives the signed status report ticket and verifies that the status report ticket is correct with the fourth public key of the second terminal device Sex.

在本發明的一些實施態樣中,該第二終端裝置將已簽 章的該管理權設定票券傳送給該服務端裝置,該服務端裝置以該管理端裝置的該第一公鑰驗證收到的已簽章的該管理權設定票券的正確性;且該服務端裝置完成管理權限設定後,會產生一包含一設定結果的狀態回報票券,並以該第二私鑰對該狀態回報票券簽章後,將已簽章的該狀態回報票券傳送給該第二終端裝置,該第二終端裝置收到已簽章的該狀態回報票券並以該服務端裝置的該第二公鑰驗證該狀態回報票券的正確性,且根據該設定結果確認該服務端裝置已完成更新管理者的設定。 In some embodiments of the present invention, the second terminal device will be signed The management right setting ticket of the chapter is transmitted to the server device, and the server device verifies the correctness of the received signed management right setting ticket with the first public key of the management device; and After the server device completes the management authority setting, it will generate a status report ticket containing a setting result, and after the status report ticket is signed with the second private key, the status report ticket that has been signed is sent To the second terminal device, the second terminal device receives the signed status report ticket and verifies the correctness of the status report ticket with the second public key of the server device, and according to the setting result Confirm that the server device has completed the update manager settings.

在本發明的一些實施態樣中,該第一公鑰及該第一私鑰是該管理端裝置自行產生或者由一第一外部電腦裝置產生後再提供給該管理端裝置,或者由該第一外部電腦裝置產生後儲存在一第一外接裝置,且只有該第一外接裝置與該管理端裝置電連接時,該管理端裝置才能從該外接裝置取得該第一公鑰及該第一私鑰;該第二公鑰及與該第二公鑰配對的一第二私鑰是該服務端裝置自行產生或者由一第二外部電腦裝置產生後再提供給該服務端裝置;該第三公鑰及該第三私鑰是該第一終端裝置自行產生或者由一第三外部電腦裝置產生後再提供給該第一終端裝置,或者由該第三外部電腦裝置產生後儲存在一第二外接裝置,且當該第二外接裝置與該第一終端裝置電連接時,該第一終端裝置才能從該第二外接裝置取得該第三公鑰及該第三私鑰;該第四公鑰及該第四私鑰是該第二終 端裝置自行產生或者由一第四外部電腦裝置產生後再提供給該第二終端裝置,或者由該第四外部電腦裝置產生後儲存在一第三外接裝置,且當該第三外接裝置與該第二終端裝置電連接時,該第二終端裝置才能從該第三外接裝置取得該第四公鑰及該第四私鑰。 In some embodiments of the present invention, the first public key and the first private key are generated by the management terminal device itself, or generated by a first external computer device and then provided to the management terminal device, or by the first external computer device. An external computer device is generated and stored in a first external device, and only when the first external device is electrically connected to the management device, the management device can obtain the first public key and the first private from the external device Key; the second public key and a second private key paired with the second public key are generated by the server device itself or by a second external computer device and then provided to the server device; the third public key The key and the third private key are generated by the first terminal device, or generated by a third external computer device and then provided to the first terminal device, or generated by the third external computer device and stored in a second external Device, and when the second external device is electrically connected to the first terminal device, the first terminal device can obtain the third public key and the third private key from the second external device; the fourth public key and The fourth private key is the second terminal The end device is generated by itself or is generated by a fourth external computer device and then provided to the second terminal device, or is generated by the fourth external computer device and stored in a third external device, and when the third external device and the third external device When the second terminal device is electrically connected, the second terminal device can obtain the fourth public key and the fourth private key from the third external device.

本發明之功效在於:該管理端裝置具有能使用該服務端裝置的所有存取權限,並產生第一服務指令票券給該服務端裝置以控制或存取該服務端裝置之外,該管理端裝置還能產生服務權限設定票券給第一終端裝置,使該第一終端裝置能根據該權限票卷產生第二使用票卷給該服務端裝置,使該服務端裝置於驗證該服務權限設定票券的正確性及有效性,以及確認第二使用票卷包含的指令在該服務權限設定票券的存取權限內後,提供相對應的服務給該第一終端裝置,而以點對點方式管理第一終端裝置使用該服務端裝置的存取權限,達到去中心化管理的目的,並讓服務端裝置的使用者能自行有效地保護他們的隱私或保密性資料;且該管理端裝置還可藉由產生管理權設定票券給第二終端裝置而輕易地轉移其全部或部分的管理權限給第二終端裝置。 The effect of the present invention is that the management end device has all the access rights that can use the server end device, and generates a first service order ticket to the server end device to control or access the server end device, the management The end device can also generate a service authority setting ticket to the first terminal device, so that the first terminal device can generate a second use ticket to the server device based on the authority ticket, so that the server device can verify the service authority After setting the correctness and validity of the ticket, and confirming that the instruction contained in the second use ticket is within the access permission of the service permission setting ticket, the corresponding service is provided to the first terminal device in a point-to-point manner Manage the access authority of the first terminal device to use the server device to achieve the purpose of decentralized management, and allow the users of the server device to effectively protect their privacy or confidential data; and the management device also All or part of the management authority can be easily transferred to the second terminal device by generating the management authority setting ticket to the second terminal device.

S1~S15:步驟 S1~S15: steps

S31~S36:步驟 S31~S36: steps

1:服務端裝置 1: Server device

2:管理端裝置 2: Management device

3:第一終端裝置 3: The first terminal device

4:第二終端裝置 4: The second terminal device

5:其它終端裝置 5: Other terminal devices

本發明之其他的特徵及功效,將於參照圖式的實施方式中清楚地顯示,其中:圖1是本發明基於管理者自發行票券的點對點權限管理方法 的一實施例的主要流程圖;圖2是本實施例應用基於管理者自發行票券的點對點權限管理方法進行通訊的多個電子裝置的示意圖;及圖3是本實施例的管理端裝置轉移管理服務端裝置的管理權限給第二終端裝置的主要流程圖。 The other features and effects of the present invention will be clearly shown in the embodiments with reference to the drawings, in which: Figure 1 is a point-to-point authority management method based on the self-issued ticket of the present invention Fig. 2 is a schematic diagram of a plurality of electronic devices communicating with the point-to-point authority management method based on the self-issuing of tickets by the administrator in this embodiment; and Fig. 3 is the transfer of the management terminal device of this embodiment The main flow chart of managing the management authority of the server device to the second terminal device.

在本發明被詳細描述之前,應當注意在以下的說明內容中,類似的元件是以相同的編號來表示。 Before the present invention is described in detail, it should be noted that in the following description, similar elements are denoted by the same numbers.

參閱圖1,是本發明基於管理者自發行票券的點對點權限管理方法的一實施例的主要流程,其應用於如圖2所示之能相互通訊(例如但不限於透過現有的有線網路或無線網路進行長距離或短距離通訊)的一服務端裝置1、一管理端裝置2與一第一終端裝置3之間;該服務端裝置1可以是但不限於例如具有運算功能的智慧型家電(智慧電視、智慧冰箱...等)、智慧型汽車、智慧型門鎖...等各式各樣能提供服務、資源、資訊或資料的近端電子設備、遠端電子設備或電子化交通載具/設備等等。該管理端裝置2則為能控管該服務端裝置1且具有運算功能的電子裝置,例如但不限於桌上型電腦、平板電腦、智慧型手機或穿載式電子裝置等電子裝置。該第一終端裝置3可以是具有運算功能的一般電子裝置,例如但不限 於桌上型電腦、平板電腦、智慧型手機或穿載式電子裝置等。 Refer to FIG. 1, which is the main flow of an embodiment of the point-to-point authority management method based on the self-issued ticket of the administrator of the present invention, which is applied to the mutual communication as shown in FIG. Or a wireless network for long-distance or short-distance communication) between a server device 1, a management device 2 and a first terminal device 3; the server device 1 may be, but not limited to, for example, a smart device with a computing function. Smart home appliances (smart TVs, smart refrigerators, etc.), smart cars, smart door locks, etc. Various near-end electronic devices, remote electronic devices, or remote electronic devices that can provide services, resources, information or data Electronic transportation vehicles/equipment, etc. The management device 2 is an electronic device that can control the server device 1 and has a computing function, such as but not limited to an electronic device such as a desktop computer, a tablet computer, a smart phone, or a wearable electronic device. The first terminal device 3 may be a general electronic device with computing functions, such as but not limited to For desktop computers, tablet computers, smart phones or wearable electronic devices, etc.

且在本實施例中,該服務端裝置1、該管理端裝置2與該第一終端裝置3中皆已分別預先嵌(植)入一票券處理模組,亦即基於資訊保密與資訊安全的考量,該票券處理模組通常是在該服務端裝置1、該管理端裝置2及該第一終端裝置3出廠前即被嵌入該服務端裝置1、該管理端裝置2及該第一終端裝置3中而不能被事後異動或破解。當然該票券處理模組也可以在具備充分安全防護機制的情況下以軟體安裝或韌體燒錄的方式載入要做為該管理端裝置2或該第一終端裝置3的一既有的電子裝置中。 And in this embodiment, a ticket processing module has been pre-embedded (planted) in the server device 1, the management device 2 and the first terminal device 3, which is based on information confidentiality and information security. Considering that, the ticket processing module is usually embedded in the server device 1, the management device 2 and the first terminal device before the server device 1, the management device 2 and the first terminal device 3 leave the factory. The terminal device 3 cannot be changed or cracked afterwards. Of course, the ticket processing module can also be loaded into the management terminal device 2 or the first terminal device 3 by software installation or firmware burning with sufficient security protection mechanism. In the electronic device.

而且在實施基於管理者自發行票券的點對點權限管理方法之前,該服務端裝置1、該管理端裝置2及該第一終端裝置3皆需進行初始化設定,亦即,藉由初始化,該管理端裝置2會在初始化後產生一對金鑰,即相配對的一第一公鑰及一第一私鑰;該服務端裝置1會在初始化後產生一對金鑰,即相配對的一第二公鑰及一第二私鑰;且該第一終端裝置3亦會在初始化後產生一對金鑰,即相配對的一第三公鑰及一第三私鑰。此外,該第一公鑰及該第一私鑰也可以由一外部電腦裝置產生後再提供給該管理端裝置2,或者由該外部電腦裝置產生後儲存在一外接裝置,例如隨身碟或類似的可攜式儲存裝置,當該外接裝置與該管理端裝置2電連接時,該外接裝置驗證由該管理端裝置2輸入的密碼正確後,該外接裝置才 提供該第一公鑰及該第一私鑰給該管理端裝置2。同理,該第三公鑰與該第三私鑰也可以如同上述方式由一外部電腦裝置或一外接裝置提供給該第一終端裝置3。此外,該第二公鑰及該第二私鑰也可以是由一外部電腦裝置產生後再提供給該服務端裝置1。並且,該第一私鑰、該第二私鑰及該第三私鑰會各別被上述所屬裝置以任何方式安全地保存。 Moreover, before implementing the point-to-point authority management method based on the administrator’s self-issued ticket, the server device 1, the management device 2 and the first terminal device 3 need to be initialized, that is, by initialization, the management The end device 2 will generate a pair of keys after initialization, that is, a paired first public key and a first private key; the server device 1 will generate a pair of keys after initialization, that is, a paired first Two public keys and a second private key; and the first terminal device 3 will also generate a pair of keys after initialization, that is, a paired third public key and a third private key. In addition, the first public key and the first private key can also be generated by an external computer device and then provided to the management terminal device 2, or generated by the external computer device and stored in an external device, such as a flash drive or the like When the external device is electrically connected to the management terminal device 2 and the external device verifies that the password entered by the management terminal device 2 is correct, the external device Provide the first public key and the first private key to the management terminal device 2. Similarly, the third public key and the third private key can also be provided to the first terminal device 3 by an external computer device or an external device as described above. In addition, the second public key and the second private key may also be generated by an external computer device and then provided to the server device 1. In addition, the first private key, the second private key, and the third private key will be stored securely in any manner by the above-mentioned owning device, respectively.

而且該服務端裝置1可以藉由該管理端裝置2及該第一終端裝置3的提供或上網搜尋而獲得該第一公鑰及該第三公鑰,同理,該管理端裝置2可以藉由該服務端裝置1及該第一終端裝置3的提供或上網搜尋而獲得該第二公鑰及該第三公鑰;而該第一終端裝置3可以藉由該管理端裝置2及該服務端裝置1的提供或上網搜尋而獲得該第一公鑰及該第二公鑰。 Moreover, the server device 1 can obtain the first public key and the third public key by providing the management device 2 and the first terminal device 3 or searching on the Internet. Similarly, the management device 2 can borrow The second public key and the third public key are obtained from the provision of the server device 1 and the first terminal device 3 or by searching on the Internet; and the first terminal device 3 can use the management device 2 and the service The first public key and the second public key are obtained by providing the end device 1 or searching on the Internet.

然後,為了成為該服務端裝置1的第一位管理者,該管理端裝置2的該票券處理模組會產生一初始設定票券並傳送該初始設定票券給該服務端裝置1。該初始設定票券基本上至少具有一票券產生者欄位及一票券持有者欄位,且這兩個欄位中皆記錄該第一公鑰,亦即該管理端裝置2是以該第一公鑰做為其身份的代表,即身份識別碼(ID)。具體來說,為了確保票券在傳送過程中不致遭到駭客竄改內容,該管理端裝置2的該票券處理模組會使用該第一私鑰對該初始設定票券簽章,再將已簽章的該初始設定票券傳送給 該服務端裝置1。該服務端裝置1的該票券處理模組收到已簽章的該初始設定票券,並以該管理端裝置2的該第一公鑰驗證已簽章的該初始設定票券,確認該初始設定票券及其來源的正確性後,將代表該管理端裝置2的該第一公鑰記錄在其中的一(第一)管理者欄位中,而設定該管理端裝置2為其第一位管理者。然後,該服務端裝置1產生一包含一設定結果(例如完成訊息)的狀態回報票券,並以該第二私鑰對該狀態回報票券簽章後,將已簽章的該狀態回報票券傳送給該管理端裝置2,該管理端裝置2收到已簽章的該狀態回報票券並驗證已簽章的該狀態回報票券的正確性及該設定結果後,即確認該服務端裝置1已完成管理者的設定。此外,由於上述的簽章及驗證簽章的技術為習知,且非本案重點,故在此不于詳述。 Then, in order to become the first manager of the server device 1, the ticket processing module of the management device 2 will generate an initial setting ticket and transmit the initial setting ticket to the server device 1. The initial setting ticket basically has at least one ticket generator field and one ticket holder field, and both fields record the first public key, that is, the management terminal device 2 is The first public key serves as a representative of its identity, that is, an identification code (ID). Specifically, in order to ensure that the content of the ticket will not be tampered with by hackers during the transmission process, the ticket processing module of the management terminal device 2 will use the first private key to sign the initial set ticket, and then The signed initial set ticket is sent to The server device 1. The ticket processing module of the server device 1 receives the signed initial set ticket, and verifies the signed initial set ticket with the first public key of the management device 2 to confirm the After initially setting the correctness of the ticket and its source, the first public key representing the management terminal device 2 is recorded in one of the (first) manager fields, and the management terminal device 2 is set as the first public key A manager. Then, the server device 1 generates a status report ticket containing a setting result (for example, a completion message), and uses the second private key to report the status to the status report ticket, and then sends the signed status report ticket to the status report ticket. The coupon is sent to the management terminal device 2, and the management terminal device 2 receives the signed status report ticket and verifies the correctness of the signed status report ticket and the setting result, and then confirms the server Device 1 has completed the settings of the administrator. In addition, since the above-mentioned signatures and signature verification techniques are well known and not the focus of this case, they will not be detailed here.

因此,具有該服務端裝置1的管理者身份的該管理端裝置2將擁有使用該服務端裝置1的全部權限。藉此,當該管理端裝置2要存取或控制該服務端裝置1使該服務端裝置1提供服務時,如圖1的步驟S1,該管理端裝置2的該票券處理模組會產生一其中包含一第一指令(存取或控制指令)的第一服務指令票券,並執行圖1的步驟S2,傳送該第一服務指令票券給該服務端裝置1。具體而言,該第一服務指令票券中的一服務裝置欄位中記錄該服務端裝置1的一第二公鑰,該第一服務指令票券的一票券持有者欄位中記錄該第一公鑰,該第一服務指令票券的一票券產生者欄位中記 錄該第一公鑰。且為了防止傳送過程中票券內容遭到竄改並避免傳送過程中被駭客竊聽傳輸內容,該管理端裝置2的該票券處理模組服務指令票券與該服務端裝置1的該票券處理模組之間會先協商一會話機制,並約定使用一第一會話密鑰對票券內容加密後再對票券進行簽章。亦即,該管理端裝置2的該票券處理模組會先以該第一會話密鑰將已簽章的該第一服務指令票券內含的該第一指令加密成一第一加密資料後,再以該第一私鑰對內含該第一加密資料的該第一服務指令票券簽章,然後將已簽章的該第一服務指令票券傳送給該服務端裝置1。 Therefore, the management device 2 with the manager identity of the server device 1 will have all rights to use the server device 1. Thereby, when the management terminal device 2 wants to access or control the server device 1 so that the server device 1 provides services, as shown in step S1 of FIG. 1, the ticket processing module of the management terminal device 2 will generate A first service instruction ticket containing a first instruction (access or control instruction), and step S2 of FIG. 1 is executed to transmit the first service instruction ticket to the server device 1. Specifically, a second public key of the server device 1 is recorded in a service device field of the first service order ticket, and a ticket holder field of the first service order ticket is recorded The first public key is recorded in a ticket generator field of the first service instruction ticket Record the first public key. In addition, in order to prevent the content of the ticket from being tampered with during the transmission process and to prevent hackers from eavesdropping on the transmission content during the transmission process, the ticket processing module of the management terminal device 2 serves the order ticket and the ticket of the server device 1 The processing modules will first negotiate a session mechanism, and agree to use a first session key to encrypt the ticket content before signing the ticket. That is, the ticket processing module of the management terminal device 2 will first use the first session key to encrypt the first command contained in the signed first service command ticket into a first encrypted data. , And then use the first private key to sign the first service instruction ticket containing the first encrypted data, and then transmit the signed first service instruction ticket to the server device 1.

再者,該服務端裝置1在與該管理端裝置2建立會話機制之前,為了確認傳送該第一服務指令票券者是該第一服務指令票券的合法使用者(即該管理端裝置2),該服務端裝置1與該管理端裝置2之間會先進行一身份驗證(Challenge-response authentication,挑戰-響應認證)程序,亦即由該服務端裝置1隨機產生一亂數,並將該亂數傳送給該管理端裝置2,該管理端裝置2收到該亂數後,以該管理端裝置2自己持有的該第一私鑰對該亂數進行簽章後,將簽章的該亂數傳回給該服務端裝置1,該服務端裝置1收到簽章的該亂數後,以該管理端裝置2原先提供給該服務端裝置1的該第一公鑰驗證簽章的該亂數確實由該管理端裝置2所發送後,即確認該管理端裝置2是該第一服務指令票券的合法使用 者,達到身份驗證的目的,然後該服務端裝置1才與該管理端裝置2建立會話機制。 Furthermore, before the server device 1 establishes a session mechanism with the management device 2, in order to confirm that the person who transmits the first service order ticket is the legal user of the first service order ticket (that is, the management device 2 ), a challenge-response authentication (Challenge-response authentication) procedure will be performed between the server device 1 and the management device 2, that is, the server device 1 randomly generates a random number, and The random number is transmitted to the management terminal device 2. After receiving the random number, the management terminal device 2 signs the random number with the first private key held by the management terminal device 2 and then signs the random number. The random number is sent back to the server device 1. After the server device 1 receives the signed random number, it verifies the signature with the first public key originally provided by the management device 2 to the server device 1. After the random number of the chapter is indeed sent by the management terminal device 2, it is confirmed that the management terminal device 2 is a legal use of the first service order ticket Otherwise, the purpose of identity verification is achieved, and then the server device 1 and the management device 2 establish a session mechanism.

藉此,該服務端裝置1收到已簽章的該第一服務指令票券時,如圖1的步驟S3,該服務端裝置1的該票券處理模組服務指令票券根據該第一服務指令票券的該服務裝置欄位中記錄的該第二公鑰,確認其為該第一服務指令票券的接收端,並根據該第一服務指令票券的該票券持有者欄位中記錄的該第一公鑰,確認該第一服務指令票券來自該管理端裝置2,並使用該管理端裝置2的該第一公鑰驗證已簽章的該第一服務指令票券的正確性後,再以該第一會話密鑰解密該第一服務指令票券內含的該第一加密資料而取出該第一指令,然後如圖1的步驟S4,該服務端裝置1根據服務指令票券該第一指令(存取或控制指令)提供相對應的服務(給該管理端裝置2)。 Thereby, when the server device 1 receives the signed first service instruction ticket, as shown in step S3 of FIG. 1, the service instruction ticket of the ticket processing module of the server device 1 is based on the first service instruction ticket. The second public key recorded in the service device field of the service order ticket is confirmed as the receiving end of the first service order ticket, and according to the ticket holder column of the first service order ticket The first public key recorded in the bit confirms that the first service instruction ticket comes from the management terminal device 2, and uses the first public key of the management terminal device 2 to verify the signed first service instruction ticket After the correctness, use the first session key to decrypt the first encrypted data contained in the first service instruction ticket to take out the first instruction, and then step S4 in FIG. 1, the server device 1 according to The service instruction ticket provides the corresponding service (to the management terminal device 2) by the first instruction (access or control instruction).

且該服務端裝置1完成該第一服務指令票券要求的服務後,該服務端裝置1的該票券處理模組會產生一狀態回報票券,該狀態回報票券內含一與服務有關的資料(例如回報服務已完成或回傳資料),且該服務端裝置1的該票券處理模組狀態回報票券會先使用該第一會話密鑰將該狀態回報票券內含的該與服務有關的資料加密成一第二加密資料後,再以該第二私鑰對內含該第二加密資料的該狀態回報票券簽章,然後再傳送已簽章的該狀態回報票券 給該管理端裝置2。 And after the server device 1 completes the service requested by the first service instruction ticket, the ticket processing module of the server device 1 will generate a status report ticket, and the status report ticket contains a service-related Data (such as report service completed or return data), and the status report ticket of the ticket processing module of the server device 1 will first use the first session key to report the status of the ticket contained in the ticket After the service-related data is encrypted into a second encrypted data, the second private key is used to report the state of the second encrypted data with the signature of the ticket, and then the signed state report of the ticket is sent To the management terminal device 2.

因此,該管理端裝置2收到已簽章的該狀態回報票券,狀態回報票券並以該狀態回報票券中記錄的該第二公鑰驗證已簽章的該狀態回報票券的簽章無誤後,以該第一會話密鑰解密該狀態回報票券內含的該第二加密資料以取得該與服務有關的資料,且根據該與服務有關的資料確定該服務端裝置1已完成該第一服務指令票券要求的服務後,即與該服務端裝置1終止該會話機制。 Therefore, the management terminal device 2 receives the signed status report ticket, the status report ticket and uses the second public key recorded in the status report ticket to verify the signature of the signed status report ticket. After the chapter is correct, decrypt the second encrypted data contained in the status report ticket with the first session key to obtain the service-related data, and based on the service-related data, it is determined that the server device 1 is completed After the first service instructs the service requested by the ticket, the conversation mechanism with the server device 1 is terminated.

此外,該管理端裝置2除了能控管及使用該服務端裝置1外,該管理端裝置2還能授權其它終端裝置使用該服務端裝置1,亦即,如圖1的步驟S5,該管理端裝置2能產生一服務權限設定票券,並圖1的步驟S6所示,傳送該服務權限設定票券給該第一終端裝置3,該服務權限設定票券除了記錄該第一終端裝置3對該服務端裝置1的一存取權限外,該服務權限設定票券的一服務裝置欄位中記錄該服務端裝置1的一第二公鑰,該服務權限設定票券的一票券持有者欄位中記錄該第一終端裝置3的一第三公鑰,該服務權限設定票券的一票券發行者欄位中記錄該第一公鑰。具體而言,該管理端裝置2是先以該第一私鑰對該服務權限設定票券簽章,再將已簽章的該服務權限設定票券傳送給該第一終端裝置3。 In addition, in addition to controlling and using the server device 1, the management device 2 can also authorize other terminal devices to use the server device 1. That is, in step S5 of FIG. 1, the management device 2 can also authorize other terminal devices to use the server device 1. The terminal device 2 can generate a service authority setting ticket, and as shown in step S6 of FIG. 1, transmits the service authority setting ticket to the first terminal device 3. The service authority setting ticket records the first terminal device 3 In addition to an access authority to the server device 1, a second public key of the server device 1 is recorded in a service device field of the service authority setting ticket, and a ticket holder of the service authority setting ticket A third public key of the first terminal device 3 is recorded in the possessed field, and the first public key is recorded in a ticket issuer field of the service authority setting ticket. Specifically, the management terminal device 2 first sets the ticket signature for the service authority with the first private key, and then transmits the signed service authority setting ticket to the first terminal device 3.

因此,如圖1的步驟S7,該第一終端裝置3的該票券處理模組收到已簽章的該服務權限設定票券並以該管理端裝置2 的該第一公鑰驗證已簽章的該服務權限設定票券的正確性,然後,除了將已簽章的該服務權限設定票券儲存外,該第一終端裝置3的該票券處理模組還產生一狀態回報票券,並以其第三私鑰對該狀態回報票券簽章後,傳送已簽章的該狀態回報票券給該管理端裝置2,藉此,該管理端裝置2收到已簽章的該狀態回報票券並以該第一終端裝置3的第三公鑰驗證已簽章的該狀態回報票券的正確性後,即確定該第一終端裝置3已確收該服務權限設定票券。 Therefore, in step S7 of FIG. 1, the ticket processing module of the first terminal device 3 receives the signed service authority setting ticket and uses the management terminal device 2 The first public key verifies the correctness of the signed service authority setting ticket, and then, in addition to storing the signed service authority setting ticket, the ticket processing module of the first terminal device 3 The group also generates a status report ticket, and after signing the status report ticket with its third private key, transmits the signed status report ticket to the management terminal device 2, whereby the management terminal device 2 After receiving the signed status report ticket and verifying the correctness of the signed status report ticket with the third public key of the first terminal device 3, it is determined that the first terminal device 3 has confirmed Receive the service permission set ticket.

因此,該第一終端裝置3需要該服務端裝置1提供服務時,如圖1的步驟S8,該第一終端裝置3將已簽章的該服務權限設定票券傳送給該服務端裝置1,然後,如圖1的步驟S9,該服務端裝置1的該票券處理模組收到已簽章的該服務權限設定票券,並根據該服務權限設定票券的該服務裝置欄位中記錄的該第二公鑰,確認其為該服務權限設定票券的接收端,並以該管理端裝置2的該第一公鑰驗證該服務權限設定票券的簽章,確認該服務權限設定票券確實由該管理端裝置2產生後,如圖1的步驟S10,該服務端裝置1的該票券處理模組接著判斷該服務權限設定票券中記錄的該存取權限的有效性,亦即該存取權限是否仍然有效,並於確認該服務權限設定票券為有效票券後,該服務端裝置1的該票券處理模組會產生一內含一權限確認結果的狀態回報票券,並以該第二私鑰對該狀態回報票券簽章後,將已簽章的該狀態回報票券傳送給該 第一終端裝置3。 Therefore, when the first terminal device 3 needs the server device 1 to provide services, as shown in step S8 in FIG. 1, the first terminal device 3 transmits the signed service authority setting ticket to the server device 1. Then, in step S9 of FIG. 1, the ticket processing module of the server device 1 receives the signed service authority setting ticket, and records in the service device field of the service authority setting ticket according to the service authority. Confirm that it is the receiving end of the service authority setting ticket, and verify the signature of the service authority setting ticket with the first public key of the management terminal device 2 to confirm the service authority setting ticket After the coupon is indeed generated by the management terminal device 2, as shown in step S10 of FIG. 1, the ticket processing module of the server device 1 then determines the validity of the access authority recorded in the service authority setting ticket, and also That is, whether the access permission is still valid, and after confirming that the service permission setting ticket is a valid ticket, the ticket processing module of the server device 1 will generate a status report ticket containing a permission confirmation result , And after signing the status report ticket with the second private key, send the signed status report ticket to the The first terminal device 3.

接著,該第一終端裝置3收到已簽章的該狀態回報票券並驗證該狀態回報票券的正確性,並根據該狀態回報票券內含的該權限確認結果,確定該服務端裝置1已確認該服務權限設定票券後,該第一終端裝置3即可使用該服務端裝置1提供的服務。因此,如圖1的步驟S11,該第一終端裝置3的該票券處理模組能產生一其中包含一第二指令(存取或控制指令)的第二服務指令票券給該服務端裝置1。此時,同樣地,該服務端裝置1為了確認傳送該第二服務指令票券者是該第二服務指令票券的合法使用者(即該第一終端裝置3),該服務端裝置1與該第一終端裝置3之間必須先進行該身份驗證(Challenge-response authentication,挑戰-響應認證)程序,然後,該第一終端裝置3才能與該服務端裝置1協商建立會話機制,並約定共同使用一次性(暫時性)的一第二會話密鑰。且該第二服務指令票券中的一服務裝置欄位中記錄該服務端裝置1的一第二公鑰,該第二服務指令票券的一票券持有者欄位中記錄該第三公鑰,該第二服務指令票券的一票券產生者欄位中記錄該第三公鑰。同理,為了防止傳送過程中票券內容(即該第二指令)遭到竄改並避免傳送過程中被駭客竊聽傳輸內容,該第一終端裝置3的該票券處理模組會先服務指令票券以該第二會話密鑰將該第二服務指令票券內含的該第二指令加密成一第三加密資料,再以該第三私 鑰對內含該第三加密資料的該第二服務指令票券簽章,然後如圖1的步驟S12,將已簽章的該第二服務指令票券傳送給該服務端裝置1。 Then, the first terminal device 3 receives the signed status report ticket and verifies the correctness of the status report ticket, and determines the server device according to the authority confirmation result contained in the status report ticket 1 After confirming the service authority setting ticket, the first terminal device 3 can use the service provided by the server device 1. Therefore, in step S11 of FIG. 1, the ticket processing module of the first terminal device 3 can generate a second service instruction ticket containing a second instruction (access or control instruction) to the server device 1. At this time, similarly, in order for the server device 1 to confirm that the person who sent the second service order ticket is a legitimate user of the second service order ticket (that is, the first terminal device 3), the server device 1 and The first terminal device 3 must first perform the challenge-response authentication (Challenge-response authentication) procedure between the first terminal device 3, and then the first terminal device 3 can negotiate with the server device 1 to establish a session mechanism, and agree to jointly Use a one-time (temporary) second session key. And a second public key of the server device 1 is recorded in a service device field in the second service order ticket, and the third public key is recorded in a ticket holder field of the second service order ticket. The public key, the third public key is recorded in a ticket generator field of the second service instruction ticket. In the same way, in order to prevent the content of the ticket (that is, the second instruction) from being tampered with during the transmission process and to avoid being intercepted by hackers during the transmission process, the ticket processing module of the first terminal device 3 will first serve the instruction The ticket uses the second session key to encrypt the second command contained in the second service command ticket into a third encrypted data, and then uses the third private The second service order ticket containing the third encrypted data is signed by the key pair, and then in step S12 of FIG. 1, the signed second service order ticket is transmitted to the server device 1.

因此,如圖1的步驟S13,該服務端裝置1收到已簽章的該第二服務指令票券,服務指令票券並使用該第一終端裝置3的該第三公鑰驗證該已簽章的該第二服務指令票券的正確性後,以該第二會話密鑰解密該第二服務指令票券內含的該第三加密資料而取出該第二指令,並且如圖1的步驟S14,判斷服務指令票券該第二指令在該服務權限設定票券記錄的該存取權限內時,如圖1的步驟S15,該服務端裝置1即根據該第二服務指令票券中包含的該第二指令提供相對應的服務給該第一終端裝置3。且該服務端裝置1完成該第二服務指令票券要求的服務後,該服務端裝置1的該票券處理模組會產生一狀態回報票券,該狀態回報票券內含一與服務有關的資料,且該服務端裝置1的該票券處理模組會狀態回報票券使用該第二會話密鑰將該狀態回報票券內含的該與服務有關的資料加密成一第四加密資料後,再以該第二私鑰對內含該第四加密資料的該狀態回報票券簽章,並傳送已簽章的該狀態回報票券給該第一終端裝置3。 Therefore, in step S13 of FIG. 1, the server device 1 receives the signed second service instruction ticket, and the service instruction ticket uses the third public key of the first terminal device 3 to verify the signed After the correctness of the second service order ticket in the chapter, use the second session key to decrypt the third encrypted data contained in the second service order ticket to take out the second instruction, and the steps shown in Figure 1 S14: When it is determined that the second instruction of the service instruction ticket is within the access authority of the service authority setting ticket record, as shown in step S15 of FIG. 1, the server device 1 is based on that the second service instruction ticket contains The second instruction of provides the corresponding service to the first terminal device 3. And after the server device 1 completes the service requested by the second service instruction ticket, the ticket processing module of the server device 1 will generate a status report ticket, and the status report ticket contains a service-related And the ticket processing module of the server device 1 will use the second session key to encrypt the service-related data contained in the status report ticket into a fourth encrypted data , And then use the second private key pair to report the status of the ticket signature containing the fourth encrypted data, and transmit the signed status report ticket to the first terminal device 3.

因此,該第一終端裝置3收到該已簽章的該狀態回報票券,狀態回報票券並以該服務端裝置1的該第二公鑰驗證已簽章 的該狀態回報票券的正確性後,以該第二會話密鑰解密該狀態回報票券內含的該第四加密資料而取出該與服務有關的資料,且根據該與服務有關的資料確定該服務端裝置1已完成該第二服務指令票券要求的服務後,即與該服務端裝置1終止該會話機制。 Therefore, the first terminal device 3 receives the signed status report ticket, and uses the second public key of the server device 1 to verify the signed status report ticket. After the correctness of the status report ticket, the second session key is used to decrypt the fourth encrypted data contained in the status report ticket to take out the service-related information, and determine according to the service-related information After the server device 1 has completed the service required by the second service instruction ticket, the conversation mechanism with the server device 1 is terminated.

再者,該管理端裝置2還可以將其對於該服務端裝置1的全部管理權或部分管理權授權給其它的終端裝置,亦即,如圖3的步驟S31,該管理端裝置2的該票卷處理模組能產生一內含一管理權設定的管理權設定票券,並如圖3的步驟S32,傳送該管理權設定票券給同樣已預先設置一票券處理模組的一第二終端裝置4。該第二終端裝置4亦具有相配對的一第四公鑰及一第四私鑰,而且該服務端裝置1及該管理端裝置2可以藉由該第二終端裝置4的提供或上網搜尋而獲得該第四公鑰。且該管理權設定票券的一服務裝置欄位中記錄該服務端裝置1的該第二公鑰,該管理權設定票券的一票券持有者欄位中記錄該第二終端裝置4的一第四公鑰,該管理權設定票券的一票券發行者欄位中記錄該第一公鑰。且該管理端裝置2以該第一私鑰對該管理權設定票券簽章,再將已簽章的該管理權設定票券傳送給該第二終端裝置4。 Furthermore, the management device 2 can also authorize all or part of its management rights for the server device 1 to other terminal devices, that is, in step S31 of FIG. 3, the management device 2 The ticket processing module can generate a management right setting ticket that contains a management right setting, and in step S32 of FIG. 3, the management right setting ticket is transmitted to a first ticket processing module that has also set a ticket processing module in advance. Two terminal device 4. The second terminal device 4 also has a matched fourth public key and a fourth private key, and the server device 1 and the management device 2 can be provided by the second terminal device 4 or searched online. Obtain the fourth public key. And the second public key of the server device 1 is recorded in a server device field of the management right setting ticket, and the second terminal device 4 is recorded in a ticket holder field of the management right setting ticket A fourth public key of the management right is set to record the first public key in a ticket issuer field of the ticket. In addition, the management terminal device 2 uses the first private key to set a ticket signature for the management right, and then transmits the signed management right setting ticket to the second terminal device 4.

因此,如圖3的步驟S33,該第二終端裝置4的該票券處理模組收到已簽章的該管理權設定票券並以該管理端裝置2的該第一公鑰驗證該管理權設定票券的正確性後,除了將已簽章的 該管理權設定票券儲存外,該第二終端裝置4的該票券處理模組還產生一狀態回報票券,並以其第四私鑰對該狀態回報票券簽章後,傳送已簽章的該狀態回報票券給該管理端裝置2,該管理端裝置2收到已簽章的該狀態回報票券並以該第二終端裝置4的第四公鑰驗證該狀態回報票券的正確性後,即確定該第二終端裝置3已確收該管理權設定票券。 Therefore, in step S33 of FIG. 3, the ticket processing module of the second terminal device 4 receives the signed management right setting ticket and verifies the management with the first public key of the management terminal device 2 After the right to set the correctness of the ticket, in addition to the signed In addition to the management right to set the ticket storage, the ticket processing module of the second terminal device 4 also generates a status report ticket, and uses its fourth private key to report the status of the ticket and then sends the signed ticket. The status report ticket of the chapter is sent to the management terminal device 2, and the management terminal device 2 receives the signed status report ticket and verifies the status of the status report ticket with the fourth public key of the second terminal device 4 After it is correct, it is determined that the second terminal device 3 has confirmed the receipt of the management right setting ticket.

然後,如圖3的步驟S34,該第二終端裝置4將已簽章的該管理權設定票券傳送給該服務端裝置1,該服務端裝置1的該票券處理模組收到已簽章的該管理權設定票券後,如圖3的步驟S35,根據該管理權設定票券的該服務裝置欄位中記錄的該第二公鑰,確認其為該管理權設定票券的接收端,並以該管理端裝置2的該第一公鑰驗證已簽章的該管理權設定票券的正確性,確認該管理權設定票券確實由該管理端裝置2產生後,如圖3的步驟S36,該服務端裝置1的該票券處理模組根據該管理權設定票券內含的該管理權設定,設定該第二終端裝置4具有其全部管理權限或部分管理權限。若該第二終端裝置4被設定為具有該服務端裝置1的全部管理權限,則該服務端裝置1會將其中的該管理者欄位更新為該第四公鑰,而設定該第二終端裝置4為其全權管理者;而若該第二終端裝置4被設定為具有該服務端裝置1的部分管理權限,則該服務端裝置1會於其中新增一第二管理者欄位及一與該第二管理者欄 位相對應的第二管理權限欄位,且將該第四公鑰記錄於該第二管理欄位,並於該第二管理權限欄位中記錄該管理權設定票券設定的部分管理權限內容;同時,該服務端裝置1會新增一與原先的該(第一)管理者欄位對應的第一管理權限欄位,並於該第一管理權限欄位中記錄該管理端裝置2的部分(其餘的)管理權限內容。 Then, in step S34 of FIG. 3, the second terminal device 4 transmits the signed management right setting ticket to the server device 1, and the ticket processing module of the server device 1 receives the signed ticket. After the management right of the chapter sets the ticket, step S35 in Figure 3, according to the second public key recorded in the service device field of the management right to set the ticket, confirm that it is the receipt of the management right to set the ticket And verify the correctness of the signed management right setting ticket with the first public key of the management terminal device 2 and confirm that the management right setting ticket is indeed generated by the management terminal device 2, as shown in Figure 3. In step S36, the ticket processing module of the server device 1 sets the management right setting contained in the ticket according to the management right, and sets the second terminal device 4 to have its full management authority or part of its management authority. If the second terminal device 4 is set to have all the management authority of the server device 1, the server device 1 will update the manager field therein to the fourth public key, and set the second terminal Device 4 is its full administrator; and if the second terminal device 4 is set to have partial management authority of the server device 1, the server device 1 will add a second manager field and a With the second manager column A corresponding second management authority field, and record the fourth public key in the second management field, and record part of the management authority content set by the management authority setting ticket in the second management authority field; At the same time, the server device 1 adds a first management authority field corresponding to the original (first) manager field, and records part of the management device 2 in the first management authority field (The rest) management authority content.

且該服務端裝置1的該票券處理模組完成管理權限設定後,會產生一包含一設定結果的狀態回報票券,並以該第二私鑰對該狀態回報票券簽章後,將已簽章的該狀態回報票券傳送給該第二終端裝置3,該第二終端裝置3收到已簽章的該狀態回報票券並驗證該狀態回報票券的正確性,且根據該設定結果確認該服務端裝置1已完成更新管理者的設定後,即確認該管理權設定已完成。 And after the ticket processing module of the server device 1 completes the management authority setting, it will generate a status report ticket containing a setting result, and use the second private key to report the status to the status report ticket, and then The signed status report ticket is sent to the second terminal device 3, and the second terminal device 3 receives the signed status report ticket and verifies the correctness of the status report ticket, and according to the setting As a result, after confirming that the server device 1 has completed the update manager setting, it is confirmed that the management right setting has been completed.

藉此,若該第二終端裝置4具有該服務端裝置1的全部管理權限,則該第二終端裝置4將完全取代該管理端裝置2而成為該服務端裝置1的新的管理者,而能執行如上所述之該管理端裝置2的所有權限管理功能,包括使用該服務端裝置1、授權其它終端裝置5使用該服務端裝置1以及轉移全部或部分管理權限給其它終端裝置5等。而若該第二終端裝置4具有該服務端裝置1的部分管理權限,例如授權其它終端裝置5使用該服務端裝置1,則如上所述,該第二終端裝置4即可產生授權票券給其它終端裝置5。 Thus, if the second terminal device 4 has all the management authority of the server device 1, the second terminal device 4 will completely replace the management device 2 and become the new manager of the server device 1, and It can perform all the authority management functions of the management device 2 as described above, including using the server device 1, authorizing other terminal devices 5 to use the server device 1, and transferring all or part of the management authority to other terminal devices 5, etc. If the second terminal device 4 has part of the management authority of the server device 1, for example, other terminal devices 5 are authorized to use the server device 1, as described above, the second terminal device 4 can generate an authorization ticket to Other terminal devices 5.

綜上所述,上述實施例藉由該管理端裝置2除了具有能 使用該服務端裝置1的所有存取權限,並產生第一服務指令票券給該服務端裝置1以控制或存取該服務端裝置1之外,該管理端裝置2還能產生服務權限設定票券給第一終端裝置3,使該第一終端裝置3能根據該權限票卷產生第二使用票卷給該服務端裝置1,使該服務端裝置1於驗證該服務權限設定票券的正確性及有效性,以及確認第二使用票卷包含的指令在該服務權限設定票券的存取權限內後,提供相對應的服務給該第一終端裝置3,而以點對點方式管理第一終端裝置3使用該服務端裝置1的存取權限,達到去中心化管理的目的,並讓服務端裝置1的使用者能自行有效地保護他們的隱私或保密性資料;再者,該管理端裝置2還可藉由產生管理權設定票券給第二終端裝置4而輕易地轉移其全部或部分的管理權限給第二終端裝置4,達成本發明之功效與目的。 In summary, the above-mentioned embodiment uses the management terminal device 2 in addition to having the ability to Use all the access permissions of the server device 1 and generate a first service order ticket to the server device 1 to control or access the server device 1, and the management device 2 can also generate service permission settings The ticket is given to the first terminal device 3, so that the first terminal device 3 can generate a second use ticket to the server device 1 based on the authorization ticket, so that the server device 1 is used to verify the service authorization setting ticket After confirming the correctness and validity, and confirming that the instructions contained in the second use ticket are within the access permissions of the service permission setting ticket, the corresponding service is provided to the first terminal device 3, and the first terminal device 3 is managed in a point-to-point manner. The terminal device 3 uses the access authority of the server device 1 to achieve the purpose of decentralized management, and allows the users of the server device 1 to effectively protect their privacy or confidentiality data; in addition, the management terminal The device 2 can also easily transfer all or part of its management authority to the second terminal device 4 by generating a management right setting ticket to the second terminal device 4, so as to achieve the effect and purpose of the invention.

惟以上所述者,僅為本發明之實施例而已,當不能以此限定本發明實施之範圍,凡是依本發明申請專利範圍及專利說明書內容所作之簡單的等效變化與修飾,皆仍屬本發明專利涵蓋之範圍內。 However, the above are only examples of the present invention. When the scope of implementation of the present invention cannot be limited by this, all simple equivalent changes and modifications made in accordance with the scope of the patent application of the present invention and the content of the patent specification still belong to This invention patent covers the scope.

S1~S15:步驟 S1~S15: steps

Claims (15)

一種基於管理者自發行票券的點對點權限管理方法,應用於能相互通訊的一服務端裝置、一管理該服務端裝置的管理端裝置以及一第一終端裝置之間,其中該管理端裝置具有專屬且配對的一第一公鑰及一第一私鑰,該服務端裝置具有專屬且配對的一第二公鑰及一第二私鑰,該第一終端裝置具有專屬且配對的一第三公鑰及一第三私鑰;該方法包括: 該管理端裝置能產生並傳送一包含一第一指令的第一服務指令票券給該服務端裝置; 該服務端裝置收到該第一服務指令票券後,以該管理端裝置的該第一公鑰驗證該第一服務指令票券的正確性,並根據該第一服務指令票券包含的該第一指令提供相對應的服務給該管理端裝置; 該管理端裝置能產生一服務權限設定票券並傳送該服務權限設定票券給該第一終端裝置,該服務權限設定票券記錄該第一終端裝置對該服務端裝置的一存取權限; 該第一終端裝置能根據該服務權限設定票券產生一第二服務指令票券,並依序傳送該服務權限設定票券及該第二服務指令票券給該服務端裝置; 該服務端裝置收到該服務權限設定票券後,以該管理端裝置的該第一公鑰驗證該服務權限設定票券的正確性,並判斷該服務權限設定票券記錄的該存取權限的有效性後,該服務端裝置接收該第二服務指令票券,並以該第一終端裝置的一第三公鑰驗證該第二服務指令票券的正確性,且判斷該第二服務指令票券包含的該第二指令在該服務權限設定票券記錄的該存取權限內時,該服務端裝置根據該第二指令提供相對應的服務給該第一終端裝置。 A point-to-point authority management method based on the self-issuing of tickets by a manager is applied between a server device that can communicate with each other, a management device that manages the server device, and a first terminal device, wherein the management device has A first public key and a first private key are exclusive and paired, the server device has a second public key and a second private key that are exclusive and paired, and the first terminal device has a third that is exclusive and paired Public key and a third private key; the method includes: The management-end device can generate and transmit a first service instruction ticket containing a first instruction to the server-end device; After the server device receives the first service instruction ticket, it verifies the correctness of the first service instruction ticket with the first public key of the management device, and then uses the first service instruction ticket to verify the correctness of the first service instruction ticket. The first instruction provides the corresponding service to the management terminal device; The management terminal device can generate a service authority setting ticket and transmit the service authority setting ticket to the first terminal device. The service authority setting ticket records an access authority of the first terminal device to the server device; The first terminal device can generate a second service instruction ticket according to the service authority setting ticket, and sequentially transmit the service authority setting ticket and the second service instruction ticket to the server device; After the server device receives the service permission setting ticket, it verifies the correctness of the service permission setting ticket with the first public key of the management device, and judges the access permission of the service permission setting ticket record After the validity, the server device receives the second service instruction ticket, verifies the correctness of the second service instruction ticket with a third public key of the first terminal device, and determines the second service instruction When the second instruction contained in the ticket is within the access authority of the service authority setting ticket record, the server device provides the corresponding service to the first terminal device according to the second instruction. 如請求項1所述基於管理者自發行票券的點對點權限管理方法,其中,在產生該第一服務指令票券之前,該管理端裝置會先產生一初始設定票券並傳送該初始設定票券給該服務端裝置,該服務端裝置收到該初始設定票券,並以該管理端裝置的該第一公鑰驗證該初始設定票券的正確性後,該管理端裝置將該第一公鑰記錄在其中的一管理者欄位中,而設定該管理端裝置為其管理者。As described in claim 1, the point-to-point authority management method based on the self-issued ticket by the administrator, wherein, before generating the first service order ticket, the management terminal device will first generate an initial setting ticket and transmit the initial setting ticket To the server device, the server device receives the initial setting ticket and verifies the correctness of the initial setting ticket with the first public key of the management device, the management device sends the first The public key is recorded in one of the manager fields, and the manager device is set as the manager. 如請求項2所述基於管理者自發行票券的點對點權限管理方法,其中該管理端裝置會使用該第一私鑰對該初始設定票券簽章,再將已簽章的該初始設定票券傳送給該服務端裝置,該服務端裝置收到已簽章的該初始設定票券後,以該管理端裝置的該第一公鑰驗證已簽章的該初始設定票券,以確認該初始設定票券的正確性;且該服務端裝置完成設定後,產生一包含一設定結果的狀態回報票券,並以該第二私鑰對該狀態回報票券簽章後,將已簽章的該狀態回報票券傳送給該管理端裝置,該管理端裝置收到已簽章的該狀態回報票券並以該服務端裝置的該第二公鑰驗證該狀態回報票券的正確性,且根據該設定結果確認該服務端裝置已完成管理者的設定。For example, the point-to-point authority management method based on the manager's self-issued ticket as described in claim 2, wherein the management terminal device will use the first private key to sign the initial set ticket, and then the signed initial set ticket The coupon is sent to the server device. After the server device receives the signed initial set ticket, it verifies the signed initial set ticket with the first public key of the management device to confirm the Initially set the correctness of the ticket; and after the server device completes the setting, it generates a status report ticket containing a setting result, and uses the second private key to report the status of the ticket and then the ticket will be signed The status report ticket of is sent to the management terminal device, and the management terminal device receives the signed status report ticket and verifies the correctness of the status report ticket with the second public key of the server device, And according to the setting result, it is confirmed that the server device has completed the setting of the administrator. 如請求項1所述基於管理者自發行票券的點對點權限管理方法,其中該第一服務指令票券的一服務裝置欄位中記錄該服務端裝置的該第二公鑰,該第一服務指令票券的一票券持有者欄位中記錄該第一公鑰,該第一票券的一票券產生者欄位中記錄該第一公鑰,服務指令票券服務指令票券且該管理端裝置與該服務端裝置建立一會話機制,並使用一與該服務端裝置約定的一第一會話密鑰將該第一服務指令票券內含的該一指令加密成一第一加密資料後,該管理端裝置再以該第一私鑰對內含該第一加密資料的該第一服務指令票券簽章而產生已簽章的該第一服務指令票券,再傳送已簽章的該第一服務指令票券給該服務端裝置;該服務端裝置收到已簽章的該第一服務指令票券,服務指令票券根據該第一服務指令票券的該服務裝置欄位中記錄的該第二公鑰,確認其為該第一服務指令票券的接收端,並根據該第一服務指令票券的該票券持有者欄位中記錄的該第一公鑰,確認該管理端裝置為提供該相對應的服務的對象,並且以該管理端裝置的該第一公鑰驗證已簽章的該第一服務指令票券的正確性後,以該第一會話密鑰解密該第一服務指令票券內含的該第一加密資料而取出該第一指令。As described in claim 1, the point-to-point authority management method based on the self-issued ticket by the administrator, wherein the second public key of the server device is recorded in a service device field of the first service instruction ticket, and the first service The first public key is recorded in a ticket holder field of the order ticket, the first public key is recorded in a ticket generator field of the first ticket, the service order ticket serves the order ticket and The management device establishes a session mechanism with the server device, and uses a first session key agreed with the server device to encrypt the command contained in the first service command ticket into a first encrypted data Then, the management terminal device uses the first private key to sign the first service order ticket containing the first encrypted data to generate the signed first service order ticket, and then transmits the signed first service order ticket. The first service instruction ticket to the server device; the server device receives the signed first service instruction ticket, and the service instruction ticket is based on the service device field of the first service instruction ticket Confirm that it is the receiving end of the first service order ticket, and according to the first public key recorded in the ticket holder field of the first service order ticket, After confirming that the management terminal device is the object that provides the corresponding service, and verifying the correctness of the signed first service instruction ticket with the first public key of the management terminal device, use the first session secret The key decrypts the first encrypted data contained in the first service order ticket to retrieve the first order. 如請求項4所述基於管理者自發行票券的點對點權限管理方法,其中,該管理端裝置與該服務端裝置建立該會話機制之前,該服務端裝置與該管理端裝置之間會先進行一身份驗證 (Challenge-response authentication,挑戰-響應認證)程序。For the point-to-point authority management method based on the self-issued ticket of the administrator as described in claim 4, before the management-end device and the server-end device establish the session mechanism, the server-end device and the management-end device will first An identity verification (Challenge-response authentication, challenge-response authentication) procedure. 如請求項4所述基於管理者自發行票券的點對點權限管理方法,其中,該服務端裝置完成該第一服務指令票券要求的服務後,該服務端裝置的該票券處理模組會產生一狀態回報票券,該狀態回報票券內含一服務有關的資料,且該服務端裝置狀態回報票券使用該第一會話密鑰將該狀態回報票券內含的該與服務有關的資料加密成一第二加密資料後,再以該第二私鑰對內含該第二加密資料的該狀態回報票券簽章,並傳送已簽章的該狀態回報票券給該管理端裝置;該管理端裝置收到已簽章的該狀態回報票券,狀態回報票券並以該服務端裝置的該第二公鑰驗證已簽章的該狀態回報票券的正確性後,再以該第一會話密鑰解密該狀態回報票券內含的該第二加密資料而取出該與服務有關的資料,且根據該與服務有關的資料確定該服務端裝置已完成該第一服務指令票券要求的服務後,與該服務端裝置終止該會話機制。For example, the point-to-point authority management method based on the self-issued ticket of the manager according to claim 4, wherein, after the server device completes the service required by the first service instruction ticket, the ticket processing module of the server device will Generate a status report ticket, the status report ticket contains information related to a service, and the server device status report ticket uses the first session key to report the status report to the service-related information contained in the ticket After the data is encrypted into a second encrypted data, the second private key pair is used to report the status of the ticket signature containing the second encrypted data, and the signed status report ticket is sent to the management terminal device; After the management device receives the signed status report ticket, the status report ticket uses the second public key of the server device to verify the correctness of the signed status report ticket, and then uses the The first session key decrypts the second encrypted data contained in the status report ticket to retrieve the service-related data, and based on the service-related data, it is determined that the server device has completed the first service order ticket After the requested service, terminate the session mechanism with the server device. 如請求項1所述基於管理者自發行票券的點對點權限管理方法,其中該服務權限設定票券的一服務裝置欄位中記錄該服務端裝置的該第二公鑰,該服務權限設定票券的一票券持有者欄位中記錄該第一終端裝置的該第三公鑰,該服務權限設定票券的一票券發行者欄位中記錄該第一公鑰,且該管理端裝置以該第一私鑰對該服務權限設定票券簽章而產生已簽章的該服務權限設定票券,再將已簽章的該服務權限設定票券傳送給該第一終端裝置;該第一終端裝置以該管理端裝置的該第一公鑰驗證已簽章的該服務權限設定票券的正確性後,將已簽章的該服務權限設定票券儲存,並且該第一終端裝置還產生一狀態回報票券,並以該第三私鑰對該狀態回報票券簽章後,傳送已簽章的該狀態回報票券給該管理端裝置,該管理端裝置收到已簽章的該狀態回報票券並以該第一終端裝置的該第三公鑰驗證該狀態回報票券的正確性。As described in claim 1, the point-to-point authority management method based on the self-issued ticket by the administrator, wherein the second public key of the server device is recorded in a service device field of the service authority setting ticket, and the service authority setting ticket The third public key of the first terminal device is recorded in a ticket holder field of the ticket, the first public key is recorded in a ticket issuer field of the service authority setting ticket, and the management terminal The device uses the first private key to set the ticket signature for the service authority to generate the signed service authority setting ticket, and then transmits the signed service authority setting ticket to the first terminal device; After verifying the correctness of the signed service authority setting ticket with the first public key of the management terminal device, the first terminal device stores the signed service authority setting ticket, and the first terminal device A status report ticket is also generated, and after the status report ticket is signed with the third private key, the signed status report ticket is sent to the management terminal device, and the management terminal device receives the signed stamp And verify the correctness of the status report ticket with the third public key of the first terminal device. 如請求項7所述基於管理者自發行票券的點對點權限管理方法,其中該第一終端裝置將已簽章的該服務權限設定票券傳送給該服務端裝置,且該服務端裝置根據該服務權限設定票券的該服務裝置欄位中記錄的該第二公鑰,確認其為該服務權限設定票券的接收端,並以該管理端裝置的該第一公鑰驗證該已簽章的該服務權限設定票券的正確性,以及確定該服務權限設定票券中記錄的該權限資訊的有效性後,該服務端裝置會產生一內含權限確認結果的狀態回報票券,並以該第二私鑰對該狀態回報票券簽章後,將已簽章的該狀態回報票券傳送給該第一終端裝置,且該第一終端裝置收到已簽章的該回報票後,以該服務端裝置的該第二公鑰驗證已簽章的該狀態回報票券的正確性,並根據該狀態回報票券內含的該權限確認結果,確定該服務端裝置已確認該服務權限設定票券的權限。As described in claim 7, the point-to-point authority management method based on the manager's self-issued ticket, wherein the first terminal device transmits the signed service authority setting ticket to the server device, and the server device according to the The second public key recorded in the service device field of the service authority setting ticket is confirmed to be the receiving end of the service authority setting ticket, and the first public key of the management terminal device is used to verify the signed seal After confirming the validity of the service permission setting ticket and determining the validity of the permission information recorded in the service permission setting ticket, the server device will generate a status report ticket containing the permission confirmation result, and report it with After the second private key signs the status report ticket, the signed status report ticket is transmitted to the first terminal device, and after the first terminal device receives the signed report ticket, Use the second public key of the server device to verify the correctness of the signed status report ticket, and according to the permission confirmation result contained in the status report ticket, it is determined that the server device has confirmed the service permission Set the permissions of the ticket. 如請求項7所述基於管理者自發行票券的點對點權限管理方法,其中,該第一終端裝置確認該狀態回報票券的正確性後,該第一終端裝置產生該第二服務指令票券,該第二服務指令票券的一服務裝置欄位中記錄該服務端裝置的該第二公鑰,該第二服務指令票券的一票券持有者欄位中記錄該第三公鑰,該第二服務指令票券的一票券產生者欄位中記錄該第三公鑰;服務指令票券服務指令票券且該第一終端裝置與該服務端裝置建立一會話機制,並以與該服務端裝置約定的一第二會話密鑰將該第二服務指令票券內含的該第二指令加密成一第三加密資料,並以該第三私鑰對內含該第三加密資料的該第二服務指令票券簽章而產生已簽章的該第二服務指令票券,再將已簽章的該第二服務指令票券傳送給該服務端裝置;該服務端裝置收到該已簽章的該第二服務指令票券,服務指令票券並使用該第一終端裝置的該第三公鑰驗證已簽章的該第二服務指令票券的正確性後,再以該第二會話密鑰解密已簽章的該第二服務指令票券內含的該第三加密資料而取出該第二指令。As described in claim 7, the point-to-point authority management method based on the self-issued ticket by the administrator, wherein, after the first terminal device confirms the correctness of the status report ticket, the first terminal device generates the second service instruction ticket , The second public key of the server device is recorded in a service device field of the second service order ticket, and the third public key is recorded in a ticket holder field of the second service order ticket , The third public key is recorded in a ticket generator field of the second service order ticket; the service order ticket service order ticket and the first terminal device establishes a conversation mechanism with the server device, and A second session key agreed with the server device encrypts the second command contained in the second service command ticket into a third encrypted data, and contains the third encrypted data with the third private key pair The second service order ticket is signed to generate the signed second service order ticket, and then the signed second service order ticket is sent to the server device; the server device receives After the signed second service order ticket, the service order ticket and the third public key of the first terminal device are used to verify the correctness of the signed second service order ticket, use the The second session key decrypts the third encrypted data contained in the signed second service order ticket to extract the second order. 如請求項9所述基於管理者自發行票券的點對點權限管理方法,其中,該第一終端裝置與該服務端裝置建立該會話機制之前,該服務端裝置與該第一終端裝置之間會先進行一身份驗證 (Challenge-response authentication,挑戰-響應認證)程序。For example, the point-to-point authority management method based on the self-issuing ticket of the administrator according to claim 9, wherein, before the first terminal device and the server device establish the session mechanism, the server device and the first terminal device meet First perform an identity verification (Challenge-response authentication, challenge-response authentication) procedure. 如請求項9所述基於管理者自發行票券的點對點權限管理方法,其中該服務端裝置完成該第二服務指令票券要求的服務後,該服務端裝置會產生一狀態回報票券,該狀態回報票券內含一與服務有關的資料,且該服務端裝置狀態回報票券使用該第二會話密鑰將該狀態回報票券內含的該與服務有關的資料加密成一第四加密資料後,再以該第二私鑰對內含該第四加密資料的該狀態回報票券簽章,並傳送已簽章的該狀態回報票券給該第一終端裝置;該第一終端裝置收到該已簽章的該狀態回報票券,狀態回報票券並以該服務端裝置的該第二公鑰驗證已簽章的該狀態回報票券的正確性後,再以該第二會話密鑰解密該狀態回報票券內含的該第四加密資料而取出該與服務有關的資料,且根據該與服務有關的資料確定該服務端裝置已完成該第二服務指令票券要求的服務後,與該服務端裝置終止該會話機制。For example, the point-to-point authority management method based on the manager's self-issued ticket as described in claim 9, wherein after the server device completes the service required by the second service instruction ticket, the server device will generate a status report ticket, the The status report ticket contains a service-related data, and the server device status report ticket uses the second session key to encrypt the service-related data contained in the status report ticket into a fourth encrypted data Then, use the second private key pair to report the status of the ticket signature containing the fourth encrypted data, and transmit the signed status report ticket to the first terminal device; the first terminal device receives After the signed state report ticket is reached, the state report ticket is verified with the second public key of the server device to verify the correctness of the signed state report ticket, and then the second session secret is used. The key decrypts the fourth encrypted data contained in the status report ticket to extract the service-related data, and after determining, based on the service-related data, that the server device has completed the service requested by the second service order ticket , Terminate the session mechanism with the server device. 如請求項1所述基於管理者自發行票券的點對點權限管理方法,其中該服務端裝置及該管理端裝置還能與一第二終端裝置通訊,該第二終端裝置具有專屬且配對的一第四公鑰及一第四私鑰;且該管理端裝置還能產生一內含一管理權設定的管理權設定票券,並傳送該管理權設定票券給一第二終端裝置,該第二終端裝置將該管理權設定票券傳送給該服務端裝置後,該服務端裝置根據該管理端裝置的該第一公鑰驗證該管理權設定票券的正確性後,根據該管理權設定票券內含的該管理權設定,設定該第二終端裝置具有該服務端裝置的全部或部分管理權限;該第二終端裝置被設定為具有該服務端裝置的全部管理權限時,該服務端裝置會將其中的該管理者欄位更新為該第二終端裝置的該第四公鑰;該第二終端裝置被設定為具有該服務端裝置的部分管理權限時,該服務端裝置將新增一第二管理者欄位及一與該第二管理者欄位相對應的第二管理權限欄位,且將該第二終端裝置的該第四公鑰記錄於該第二管理欄位,並於該第二管理權限欄位中記錄該管理權設定票券設定的部分管理權限內容,並且新增一與該管理者欄位對應的第一管理權限欄位,並於該第一管理權限欄位中記錄該管理端裝置的部分管理權限內容。As described in claim 1, the point-to-point authority management method based on the self-issued ticket by the administrator, wherein the server device and the management device can also communicate with a second terminal device, and the second terminal device has a dedicated and paired one A fourth public key and a fourth private key; and the management terminal device can also generate a management right setting ticket containing a management right setting, and transmit the management right setting ticket to a second terminal device, the first After the second terminal device transmits the management right setting ticket to the server device, the server device verifies the correctness of the management right setting ticket according to the first public key of the management device, and then sets it according to the management right The management authority setting contained in the ticket sets the second terminal device to have all or part of the management authority of the server device; when the second terminal device is set to have all the management authority of the server device, the server device The device will update the manager field to the fourth public key of the second terminal device; when the second terminal device is set to have part of the management authority of the server device, the server device will add A second manager field and a second management authority field corresponding to the second manager field, and the fourth public key of the second terminal device is recorded in the second management field, and in The second management authority field records part of the management authority content set by the management authority setting ticket, and a first management authority field corresponding to the manager field is added, and the first management authority field is added to the first management authority field. Part of the management authority content of the management terminal device is recorded in. 如請求項12所述基於管理者自發行票券的點對點權限管理方法,其中該管理權設定票券的一服務裝置欄位中記錄該服務端裝置的該第二公鑰,該管理權設定票券的一票券持有者欄位中記錄該第二終端裝置的該第四公鑰,該管理權設定票券的一票券發行者欄位中記錄該第一公鑰;且該管理端裝置以該第一私鑰對該管理權設定票券簽章,再將已簽章的該管理權設定票券傳送給該第二終端裝置,該第二終端裝置以該管理端裝置的該第一公鑰驗證收到的已簽章的該管理權設定票券的正確性後,儲存已簽章的該管理權設定票券,並產生一狀態回報票券,並以該第四私鑰對該狀態回報票券簽章後,傳送已簽章的該狀態回報票券給該管理端裝置,該管理端裝置收到已簽章的該狀態回報票券並以該第二終端裝置的第四公鑰驗證該狀態回報票券的正確性。For example, the point-to-point authority management method based on the self-issued ticket of the manager as described in claim 12, wherein the second public key of the server device is recorded in a server device field of the management right setting ticket, and the management right setting ticket The fourth public key of the second terminal device is recorded in a ticket holder field of the ticket, and the first public key is recorded in a ticket issuer field of the management right setting ticket; and the management terminal The device uses the first private key to set the ticket signature for the management right, and then transmits the signed management right setting ticket to the second terminal device, and the second terminal device uses the second terminal device of the management terminal device to sign the ticket. After a public key verifies the correctness of the received signed management right setting ticket, the signed management right setting ticket is stored, and a status report ticket is generated, and the fourth private key pair is used After the status report ticket is signed, it transmits the signed status report ticket to the management terminal device, and the management terminal device receives the signed status report ticket and sends it to the fourth terminal of the second terminal device. The public key verifies the correctness of the status report ticket. 如請求項13所述基於管理者自發行票券的點對點權限管理方法,其中該第二終端裝置將已簽章的該管理權設定票券傳送給該服務端裝置,該服務端裝置以該管理端裝置的該第一公鑰驗證收到的已簽章的該管理權設定票券的正確性;且該服務端裝置完成管理權限設定後,會產生一包含一設定結果的狀態回報票券,並以該第二私鑰對該狀態回報票券簽章後,將已簽章的該狀態回報票券傳送給該第二終端裝置,該第二終端裝置收到已簽章的該狀態回報票券並以該服務端裝置的該第二公鑰驗證該狀態回報票券的正確性,且根據該設定結果確認該服務端裝置已完成更新管理者的設定。For example, the point-to-point authority management method based on the manager's self-issued ticket according to claim 13, wherein the second terminal device transmits the signed management right setting ticket to the server device, and the server device uses the management The first public key of the end device verifies the correctness of the received signed management right setting ticket; and after the server device completes the management authority setting, a status report ticket containing a setting result will be generated, And after signing the status report ticket with the second private key, the signed status report ticket is transmitted to the second terminal device, and the second terminal device receives the signed status report ticket The second public key of the server device verifies the correctness of the status report ticket, and confirms that the server device has completed the setting of the update manager according to the setting result. 如請求項12所述基於管理者自發行票券的點對點權限管理方法,其中該第一公鑰及該第一私鑰是該管理端裝置自行產生或者由一第一外部電腦裝置產生後再提供給該管理端裝置,或者由該第一外部電腦裝置產生後儲存在一第一外接裝置,且只有該第一外接裝置與該管理端裝置電連接時,該管理端裝置才能從該外接裝置取得該第一公鑰及該第一私鑰;該第二公鑰及與該第二公鑰配對的一第二私鑰是該服務端裝置自行產生或者由一第二外部電腦裝置產生後再提供給該服務端裝置;該第三公鑰及該第三私鑰是該第一終端裝置自行產生或者由一第三外部電腦裝置產生後再提供給該第一終端裝置,或者由該第三外部電腦裝置產生後儲存在一第二外接裝置,且當該第二外接裝置與該第一終端裝置電連接時,該第一終端裝置才能從該第二外接裝置取得該第三公鑰及該第三私鑰;該第四公鑰及該第四私鑰是該第二終端裝置自行產生或者由一第四外部電腦裝置產生後再提供給該第二終端裝置,或者由該第四外部電腦裝置產生後儲存在一第三外接裝置,且當該第三外接裝置與該第二終端裝置電連接時,該第二終端裝置才能從該第三外接裝置取得該第四公鑰及該第四私鑰。For example, the point-to-point authority management method based on the manager's self-issued ticket according to claim 12, wherein the first public key and the first private key are generated by the management terminal device or provided after being generated by a first external computer device For the management end device, or generated by the first external computer device and stored in a first external device, and only when the first external device is electrically connected to the management end device, the management end device can obtain from the external device The first public key and the first private key; the second public key and a second private key paired with the second public key are generated by the server device or provided after being generated by a second external computer device To the server device; the third public key and the third private key are generated by the first terminal device itself or generated by a third external computer device and then provided to the first terminal device, or by the third external The computer device is generated and stored in a second external device, and when the second external device is electrically connected to the first terminal device, the first terminal device can obtain the third public key and the first terminal device from the second external device. Three private keys; the fourth public key and the fourth private key are generated by the second terminal device itself or generated by a fourth external computer device and then provided to the second terminal device, or by the fourth external computer device After generation, it is stored in a third external device, and when the third external device is electrically connected to the second terminal device, the second terminal device can obtain the fourth public key and the fourth private key from the third external device. key.
TW108141568A 2019-11-15 2019-11-15 Point-to-point authority management method based on manager's self-issued tickets TWI725623B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW108141568A TWI725623B (en) 2019-11-15 2019-11-15 Point-to-point authority management method based on manager's self-issued tickets

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW108141568A TWI725623B (en) 2019-11-15 2019-11-15 Point-to-point authority management method based on manager's self-issued tickets

Publications (2)

Publication Number Publication Date
TWI725623B true TWI725623B (en) 2021-04-21
TW202121867A TW202121867A (en) 2021-06-01

Family

ID=76605003

Family Applications (1)

Application Number Title Priority Date Filing Date
TW108141568A TWI725623B (en) 2019-11-15 2019-11-15 Point-to-point authority management method based on manager's self-issued tickets

Country Status (1)

Country Link
TW (1) TWI725623B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI823673B (en) * 2022-11-11 2023-11-21 國立雲林科技大學 A password encryption management system

Citations (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6330670B1 (en) * 1998-10-26 2001-12-11 Microsoft Corporation Digital rights management operating system
US20030177361A1 (en) * 2000-08-04 2003-09-18 Wheeler Lynn Henry Method and system for using electronic communications for an electronic contract
US6820063B1 (en) * 1998-10-26 2004-11-16 Microsoft Corporation Controlling access to content based on certificates and access predicates
US20050195975A1 (en) * 2003-01-21 2005-09-08 Kevin Kawakita Digital media distribution cryptography using media ticket smart cards
US20050223415A1 (en) * 2004-03-31 2005-10-06 Masahiro Oho Rights management terminal, server apparatus and usage information collection system
TW201012166A (en) * 2007-09-19 2010-03-16 Interdigital Patent Holdings Virtual subscriber identity module
US20130159186A1 (en) * 2011-12-19 2013-06-20 Sequent Software Inc. System and Method for One-Time Payment Authorization in a Portable Communication Device
CN104200153A (en) * 2014-09-12 2014-12-10 北京赛科世纪数码科技有限公司 Start verification method and system
WO2014201149A1 (en) * 2013-06-12 2014-12-18 Sequent Software, Inc. System and method for initially establishing and periodically confirming trust in a software application
US20150222436A1 (en) * 2014-02-06 2015-08-06 Nagravision S.A. Techniques for securing networked access systems
TW201719483A (en) * 2015-11-27 2017-06-01 財團法人工業技術研究院 Image certificate processing system, image certificate generating apparatus, image certificate authenticating apparatus and method thereof
WO2018166163A1 (en) * 2017-03-14 2018-09-20 万达百汇科技(深圳)有限公司 Pos terminal control method, pos terminal, server and storage medium
CN109889495A (en) * 2019-01-10 2019-06-14 如般量子科技有限公司 Anti- quantum calculation electronic seal method and system based on multiple unsymmetrical key ponds

Patent Citations (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6330670B1 (en) * 1998-10-26 2001-12-11 Microsoft Corporation Digital rights management operating system
US6820063B1 (en) * 1998-10-26 2004-11-16 Microsoft Corporation Controlling access to content based on certificates and access predicates
US20030177361A1 (en) * 2000-08-04 2003-09-18 Wheeler Lynn Henry Method and system for using electronic communications for an electronic contract
US20050195975A1 (en) * 2003-01-21 2005-09-08 Kevin Kawakita Digital media distribution cryptography using media ticket smart cards
US20050223415A1 (en) * 2004-03-31 2005-10-06 Masahiro Oho Rights management terminal, server apparatus and usage information collection system
US7571488B2 (en) * 2004-03-31 2009-08-04 Panasonic Corporation Rights management terminal, server apparatus and usage information collection system
TW201012166A (en) * 2007-09-19 2010-03-16 Interdigital Patent Holdings Virtual subscriber identity module
US20130159186A1 (en) * 2011-12-19 2013-06-20 Sequent Software Inc. System and Method for One-Time Payment Authorization in a Portable Communication Device
EP2945111A1 (en) * 2011-12-19 2015-11-18 Sequent Software Inc. System and method for dynamic temporary payment authorization in a portable communication device
WO2014201149A1 (en) * 2013-06-12 2014-12-18 Sequent Software, Inc. System and method for initially establishing and periodically confirming trust in a software application
US20150222436A1 (en) * 2014-02-06 2015-08-06 Nagravision S.A. Techniques for securing networked access systems
CN104200153A (en) * 2014-09-12 2014-12-10 北京赛科世纪数码科技有限公司 Start verification method and system
TW201719483A (en) * 2015-11-27 2017-06-01 財團法人工業技術研究院 Image certificate processing system, image certificate generating apparatus, image certificate authenticating apparatus and method thereof
WO2018166163A1 (en) * 2017-03-14 2018-09-20 万达百汇科技(深圳)有限公司 Pos terminal control method, pos terminal, server and storage medium
CN109889495A (en) * 2019-01-10 2019-06-14 如般量子科技有限公司 Anti- quantum calculation electronic seal method and system based on multiple unsymmetrical key ponds

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI823673B (en) * 2022-11-11 2023-11-21 國立雲林科技大學 A password encryption management system

Also Published As

Publication number Publication date
TW202121867A (en) 2021-06-01

Similar Documents

Publication Publication Date Title
CN102217277B (en) Method and system for token-based authentication
US10567370B2 (en) Certificate authority
CN106888084B (en) Quantum fort machine system and authentication method thereof
US7155616B1 (en) Computer network comprising network authentication facilities implemented in a disk drive
JP6586446B2 (en) Method for confirming identification information of user of communication terminal and related system
KR102202547B1 (en) Method and system for verifying an access request
KR102307574B1 (en) Cloud data storage system based on blockchain and method for storing in cloud
US20050149722A1 (en) Session key exchange
CN109410406A (en) A kind of authorization method, device and system
KR101452708B1 (en) CE device management server, method for issuing DRM key using CE device management server, and computer readable medium
KR20070097736A (en) Method and apparatus for local domain management using device with local domain authority module
CN109962890A (en) A kind of the authentication service device and node access, user authen method of block chain
JP5992535B2 (en) Apparatus and method for performing wireless ID provisioning
US20110162053A1 (en) Service assisted secret provisioning
JPH10336172A (en) Managing method of public key for electronic authentication
KR20180087543A (en) Key management method and fido authenticator software authenticator
JP2023548415A (en) How to stop the protection of objects achieved by protective devices
CN114091009A (en) Method for establishing secure link by using distributed identity
TWI725623B (en) Point-to-point authority management method based on manager's self-issued tickets
WO2018207174A1 (en) Method and system for sharing a network enabled entity
KR101996317B1 (en) Block chain based user authentication system using authentication variable and method thereof
KR20090065336A (en) Method and system for device authentication
JP4499575B2 (en) Network security method and network security system
KR102053993B1 (en) Method for Authenticating by using Certificate
CN102882882B (en) A kind of user resources authorization method