Disclosure of Invention
The embodiment of the invention provides a safe user authentication method of industrial equipment and the industrial equipment, which are used for providing safe user authentication and a connection use mode of equipment operation software (such as a web server) for the industrial equipment in an energy industry distributed control system.
The embodiment of the invention provides a safe user authentication method of industrial equipment, wherein the industrial equipment is provided with an authentication module, an interface module and an operation software module which are connected in pairs, the operation software module is an embedded webpage server, at least one type of operation webpages with user permission levels are stored on the embedded webpage server, and the operation webpages of users with different permissions are physically and logically isolated;
the secure user authentication method includes:
acquiring at least two kinds of authentication information input by a user by using an authentication module, and verifying the at least two kinds of authentication information;
under the condition that the at least two kinds of authentication information are verified, the authentication module is used for controlling and starting the interface module so as to establish an access channel for a user;
the authentication module generates access and login information of the operation software special for the user according to the user authentication information, and the access and login information is displayed on the authentication module, so that the user can conveniently connect the operation software in a scanning mode, an identification mode and the like;
and automatically recommending and generating an operation webpage corresponding to the user for the user by using the operation software module based on the access channel, the user right authentication information and the user behavior.
In some embodiments, the interface module is controlled to disconnect or bring down the operating mode before the user successfully authenticates.
In some embodiments, establishing an access channel for the user using the interface module includes establishing a wired access channel or a wireless access channel.
In some embodiments, the access channel information and the user two-factor authentication information are utilized to classify the users into a user authority level through a collaborative filtering algorithm, and the operation web page special for the user is recommended to be generated in view of the user common operation of the user level.
In some embodiments, further comprising: and reading the authenticated user authority information by using the interface module, generating access information of the operation software module special for the user, and sending the access information to the authentication module.
In some embodiments, the access information of the user-specific operating software module includes, for example, one of: URL, barcode, two-dimensional code, RFID, etc. The authentication module displays the access information so as to facilitate user identification and fast access to the operating software module on the industrial equipment.
The present application further provides an industrial device, comprising: the system comprises an authentication module, an interface module and an operating software module;
the authentication module is configured to acquire at least two kinds of authentication information input by a user and verify the at least two kinds of authentication information; and
the authentication module displays the access information special for the user according to the user authentication result so as to connect the operation software module;
under the condition that the at least two kinds of authentication information pass verification, controlling to start the interface module;
the interface module is configured to be started according to a control instruction of the authentication module to establish an access channel for a user;
the operation software module is an embedded webpage server, at least one type of operation webpages with user permission levels are stored on the embedded webpage server, and the operation webpages of users with different permissions are physically isolated and logically isolated;
the operation software module is configured to provide a recommended operation webpage special for the user right for the user based on the access channel, the user double-factor authentication information and the user operation behavior information.
In some embodiments, the authentication module is further configured to control the interface module to disconnect or bring down the operating mode before the user successfully verifies.
In some embodiments, the interface module establishes an access channel for the user including a wired access channel or a wireless access channel.
In some embodiments, the interface module is further configured to read the authenticated user permission information, generate access information for the operating software module specific to the user, and send the access information to the authentication module.
In some embodiments, the operating software module is controlled to disconnect or bring down the operating mode before the user successfully authenticates.
In some embodiments, the access information of the user-specific operating software module includes, for example, one of: URL, barcode, and two-dimensional code.
The operation software module is an embedded webpage server, at least one type of operation webpages with user permission levels are stored on the embedded webpage server, the operation webpages of users with different permissions are physically and logically isolated, and the user access of industrial equipment and the safety performance of operation software are improved in a double authentication mode.
The foregoing description is only an overview of the technical solutions of the present invention, and the embodiments of the present invention are described below in order to make the technical means of the present invention more clearly understood and to make the above and other objects, features, and advantages of the present invention more clearly understandable.
Detailed Description
Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be embodied in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
The embodiment of the invention provides a safe user authentication method for industrial equipment, and the industrial equipment is provided with an authentication module 1, an interface module 2 and an operation software module 3 which are connected in pairs as shown in figures 1 and 2;
the secure user authentication method includes:
in step S101, at least two kinds of authentication information input by the user are acquired by using the authentication module 1, and the at least two kinds of authentication information are verified. In this example, the authentication module 1 completes the two-factor information input and user authentication and displays the user-specific access information through the display 14 after the user is successfully authenticated. The authentication module may in some examples be a module supporting two-factor authentication, e.g. the authentication module may comprise a touch screen display with integrated fingerprint recognition 11 (or other biometric recognition). And the user inputs the fingerprint on the touch display screen to finish the first factor authentication. The user enters a password (or a verification code) on the key area 13 of the touch display screen to complete the second factor authentication. After the two factors are successfully authenticated, the authentication module passes the user connection authentication, and then displays the user special access information after the user is successfully authenticated. Another implementation of the authentication module may also be a device integrating a touch display screen and a user key interface 12, and the authentication module performs two-factor authentication through a key and a user password (or a verification code).
In step S102, when both the at least two kinds of authentication information are verified, the authentication module is used to control and start the interface module, so as to establish an access channel for the user.
In step S103, the operating software module is used to provide the recommended special operating web page corresponding to the user based on the access channel, the user two-factor authentication information, and the user operating behavior. In this embodiment, the operating software module may be started or stopped according to the control of the authentication module, the operating software module is an embedded web server, at least one type of operating web pages with user permission levels are stored on the embedded web server, and the operating web pages of users with different permissions have physical isolation and logical isolation.
The operation software module is an embedded webpage server, at least one type of operation webpages with user permission levels are stored on the embedded webpage server, the operation webpages of users with different permissions are physically and logically isolated, and the user access of industrial equipment and the safety performance of operation software are improved in a double authentication mode.
In some embodiments, further comprising: and reading the authenticated user authority information by using the interface module, generating access information of the operation software module special for the user, and sending the access information to the authentication module. In some embodiments, the interface module is controlled to disconnect or bring down the operating mode before the user successfully authenticates.
In this example, the interface module is in a disconnected or suspended mode of operation until the user is successfully authenticated. After the user passes the two-factor authentication successfully, the authentication module controls the interface module to be switched to a connection working state. The interface module is connected with an operating software module (such as a web server) of the industrial equipment. The user interface module reads the authenticated user authority information, generates the access information of the operating software module special for the user, sends the access information to the authentication module, and displays the access information on the display screen of the authentication module. If the user connection is disconnected, the authentication module controls the interface module to be converted into a disconnection or suspension working mode, and the user needs to authenticate and connect the industrial equipment again.
In some embodiments, the access information of the user-specific operating software module includes, for example, one of: URL, barcode, and two-dimensional code. In some embodiments, establishing an access channel for the user using the interface module includes establishing a wired access channel or a wireless access channel. As shown in fig. 2, a user may use a computer 4 or a mobile device to connect to an industrial device in a wired or wireless manner, and the user inputs an access URL or scans a barcode or a two-dimensional code to log in an operating software module (e.g., a web server) to implement configuration, monitoring, operation, analysis, and maintenance of the industrial device.
The embodiment of the present application further provides a user authentication process, as shown in fig. 3, including the following steps:
1. the user enters first step authentication information, which may be one or a combination of a fingerprint, other biometric, a password, a verification code, a key, etc.
2. The user enters the second authentication information, which may be one or a combination of a fingerprint, other biometric features, a password, a verification code, a key, etc.
3. The authentication module verifies the information input by the user. And if the information authentication is successfully completed, entering the step 4. And if the information authentication is not completed successfully, returning to the step 1.
4. The authentication module displays the special connection information of the user, and comprises entry information of an operating software module in the special connection equipment of the user, such as URL (uniform resource locator), bar code, two-dimensional code, NFC (near field communication) access information, generated dynamic user name, password information and the like.
5. The authentication module controls an operating software module in the starting device, and the operating software module runs a special operating software version of the user authorization type. The authentication module controls the opening of an operating software interface module (in a wired or wireless interface mode).
6. The user's computer or mobile device is connected to the operating software module of the device, using the user's dedicated operating interface and functions.
According to the scheme, the information input, the authentication check and the access information display of the user are integrated in one module, so that the safety and the usability of the user accessing the industrial equipment of the energy centralized control system are improved. The authentication module is used for controlling the starting and closing of the operation software and the operation interface of the industrial equipment, so that the physical safety of a connecting channel of the industrial equipment is improved. The authentication module is used for controlling the operating software of the industrial equipment, and the user operating software of the type is loaded according to the authorization type of the authenticated user, so that the physical isolation and the logical isolation among different operating software versions of different types are ensured, and the information safety of the operating software of the industrial equipment is improved.
The present application further provides an industrial apparatus comprising: the system comprises an authentication module, an interface module and an operating software module;
the authentication module is configured to acquire at least two kinds of authentication information input by a user and verify the at least two kinds of authentication information; and
under the condition that the at least two kinds of authentication information are verified, controlling to start the interface module; in this example, the authentication module completes the two-factor information input and the user authentication, and displays the user-specific access information after the user is successfully authenticated. The authentication module may be a module that supports two-factor authentication in some examples, for example the authentication module may contain an integrated fingerprint (or other biometric) touch display screen. And the user inputs the fingerprint on the touch display screen to finish the first factor authentication. And the user inputs a password (or a verification code) on the touch display screen to finish the authentication of the second factor. After the two factors are successfully authenticated, the authentication module passes the user connection authentication, and then displays the user special access information after the user is successfully authenticated. Another implementation manner of the authentication module may also be an apparatus integrating a touch display screen and a user key interface, where the authentication module completes two-factor authentication through a key and a user password (or a verification code).
The interface module is configured to be started according to the control instruction of the authentication module so as to establish an access channel for a user;
the operation software module is an embedded webpage server, at least one type of operation webpage with user permission levels is stored on the operation software module, and the operation webpages of users with different permissions are physically and logically isolated;
and the operating software module is configured to provide the user with an operating webpage corresponding to the user permission level based on the access channel.
In some embodiments, the authentication module is further configured to control the interface module to disconnect or bring down the operating mode before the user successfully verifies.
In some embodiments, the interface module establishes an access channel for the user including a wired access channel or a wireless access channel.
In some embodiments, the interface module is further configured to read the authenticated user permission information, generate access information for the operating software module specific to the user, and send the access information to the authentication module.
In some embodiments, the access information of the user-specific operating software module includes, for example, one of: URL, barcode, and two-dimensional code.
The operation software module is an embedded webpage server, at least one type of operation webpages with user permission levels are stored on the embedded webpage server, the operation webpages of users with different permissions are physically and logically isolated, and the user access of industrial equipment and the safety performance of operation software are improved in a double authentication mode.
It should be noted that, in this document, the terms "comprises," "comprising," or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but may include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising an … …" does not exclude the presence of other like elements in a process, method, article, or apparatus that comprises the element.
The above-mentioned serial numbers of the embodiments of the present invention are merely for description and do not represent the merits of the embodiments.
Through the description of the foregoing embodiments, it is clear to those skilled in the art that the method of the foregoing embodiments may be implemented by software plus a necessary general hardware platform, and certainly may also be implemented by hardware, but in many cases, the former is a better implementation. Based on such understanding, the technical solutions of the present invention may be embodied in the form of a software product, which is stored in a storage medium (such as ROM/RAM, magnetic disk, optical disk) and includes instructions for enabling a terminal (such as a mobile phone, a computer, a server, or a network device) to execute the method according to the embodiments of the present invention.
While the present invention has been described with reference to the embodiments shown in the drawings, the present invention is not limited to the embodiments, which are illustrative and not restrictive, and it will be apparent to those skilled in the art that various changes and modifications can be made therein without departing from the spirit and scope of the invention as defined in the appended claims.