TWI506474B - Heterogeneous information device integration method - Google Patents

Heterogeneous information device integration method Download PDF

Info

Publication number
TWI506474B
TWI506474B TW102140605A TW102140605A TWI506474B TW I506474 B TWI506474 B TW I506474B TW 102140605 A TW102140605 A TW 102140605A TW 102140605 A TW102140605 A TW 102140605A TW I506474 B TWI506474 B TW I506474B
Authority
TW
Taiwan
Prior art keywords
interface
login
code
authentication server
information
Prior art date
Application number
TW102140605A
Other languages
Chinese (zh)
Other versions
TW201518988A (en
Inventor
Kuo Hsin Chu
Po Wen Chen
Yen Liang Li
Original Assignee
Chunghwa Telecom Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Chunghwa Telecom Co Ltd filed Critical Chunghwa Telecom Co Ltd
Priority to TW102140605A priority Critical patent/TWI506474B/en
Publication of TW201518988A publication Critical patent/TW201518988A/en
Application granted granted Critical
Publication of TWI506474B publication Critical patent/TWI506474B/en

Links

Landscapes

  • Information Transfer Between Computers (AREA)

Description

異質資訊裝置整合介接方法Heterogeneous information device integration interface method

本發明是有關於一種異質資訊裝置整合介接方法,特別是有關於一種僅可短暫性及一次性地進行資訊傳遞,以提升資訊系統間進行資訊傳遞之安全性之異質資訊裝置整合介接方法。The present invention relates to a heterogeneous information device integration and interfacing method, and more particularly to a heterogeneous information device integration and interfacing method for transmitting information only temporarily and once to improve the security of information transmission between information systems. .

在社會上的各種產業之中,醫療,是一個非常重要,不可缺少的產業。以目前來說,國內之醫療機構都在積極的使用電子病歷,以取代傳統所使用之紙本病歷,以達到無紙化作業,可避免紙資源之浪費,並可有效節省成本。Among the various industries in the society, medical care is a very important and indispensable industry. At present, domestic medical institutions are actively using electronic medical records to replace the traditional paper-based medical records, in order to achieve paperless operation, avoid waste of paper resources, and effectively save costs.

為了要使用電子式病歷,在產出病歷前都需要將醫療院所內的醫療資訊系統(HIS)介接至病歷產出與管理平台。然而,醫療機構內部所使用的資訊系統大多數由不同平台與多種程式語言所建構而成,各種異質的資訊系統在資料介接與交換時都存在著被資料竊取的風險。為了滿足各資訊系統間能夠有效且安全地傳遞較隱密的使用者資訊,本發明便提出了一種異質資訊裝置整合介接方法。In order to use the electronic medical record, the medical information system (HIS) in the medical institution needs to be connected to the medical record output and management platform before the medical record is produced. However, most of the information systems used within medical institutions are constructed by different platforms and multiple programming languages. Different heterogeneous information systems are at risk of data theft during data exchange and exchange. In order to satisfy the effective and safe transmission of more confidential user information among various information systems, the present invention proposes a heterogeneous information device integration interface method.

有鑑於上述習知技藝之問題,本發明之目的就是在提供一種異質資訊裝置整合介接方法,以有效降低異質資訊系統間進行資訊傳遞時可能被竊取的風險。In view of the above problems of the prior art, the object of the present invention is to provide a heterogeneous information device integration interface method to effectively reduce the risk of being stolen when information is transmitted between heterogeneous information systems.

根據本發明之目的,提出一種異質資訊裝置整合介接方法,用以提供一使用者端電腦與一遠端伺服器安全性地連接,此方法包含下列步驟:經由一使用者端電腦發出一介接登入請求,以產生對應於一介接登入資訊之一公開金鑰及一私有金鑰,並接收一介接認證伺服器所傳送之一公鑰,以依據公鑰對介接登入資訊進行加密後產生一介接登入加密資訊; 藉由介接認證伺服器接收使用者端電腦所傳送之介接登入加密資訊及公開金鑰,並依據一私鑰對介接登入加密資訊進行解密以還原為介接登入資訊,並判斷介接登入資訊是否具有介接服務權限;若介接認證伺服器判斷介接登入加密資訊具介接服務權限,則經由介接認證伺服器產生一介接代碼,並將介接代碼傳送至使用者端電腦及遠端伺服器;以及經由使用者端電腦利用私有金鑰對介接代碼進行解碼並執行一介接登入程序,且經由遠端伺服器查詢介接代碼之有效性,並於判斷介接代碼為有效後透過介接認證伺服器將遠端伺服器所提供之登入頁面傳送至使用者端電腦,以完成介接登入程序。According to the purpose of the present invention, a heterogeneous information device integration interface method is provided for providing a user terminal computer to securely connect with a remote server. The method comprises the following steps: sending a connection through a user terminal computer The login request is generated to generate a public key and a private key corresponding to one of the login information, and receive a public key transmitted by the authentication server to encrypt the interface login information according to the public key to generate a mediation Log in to the encrypted information; Receiving login encryption information and public key transmitted by the client computer through the authentication server, and decrypting the login encryption information according to a private key to restore the login information and determining the login Whether the information has the right to interface with the service; if the authentication server determines that the login encrypted information has the service permission, the interface is generated by the authentication server, and the interface code is transmitted to the user terminal and a remote server; and decoding the interface code by using the private key via the user terminal computer and executing an interface login procedure, and querying the validity of the interface code via the remote server, and determining that the interface code is valid Afterwards, the login page provided by the remote server is transmitted to the user terminal through the interface authentication server to complete the interface login procedure.

較佳地,介接認證伺服器可透過一身份驗證資料庫來對介接登入資訊進行使用者身份驗證,以判斷介接登入資訊是否具有介接服務權限;若介接登入資訊不具介接服務權限或被列於黑名單中時,介接認證伺服器則產生一錯誤訊息並傳至使用者端電腦,反之,若介接登入資訊具有介接服務權限時,介接認證伺服器則產生介接代碼。Preferably, the authentication server can perform user authentication on the login information through an identity verification database to determine whether the login information has the service authority; if the login information does not interface with the service When the permission is listed in the blacklist, the authentication server generates an error message and transmits it to the user's computer. Otherwise, if the login information has the interface permission, the authentication server is generated. Pick up the code.

較佳地,當介接認證伺服器判斷介接登入資訊不具介接服務權限,且於一時間內持續接收到使用者端電腦所發出之多個介接登入請求並超過所設定之請求次數時,介接認證伺服器係將使用者端電腦新增至黑名單中。Preferably, when the authentication server determines that the incoming login information does not have the service permission, and continuously receives the plurality of incoming login requests sent by the user's computer for a period of time and exceeds the set number of requests. The interface authentication server adds the user terminal to the blacklist.

較佳地,此異質資訊裝置整合介接方法更包含下列步驟:透過使用者端電腦將介接登入資訊重新排序與參數混淆並轉換成二進制數據碼,再依據介接認證伺服器所傳送之公鑰對介接登入資訊進行加密。Preferably, the heterogeneous information device integration interface method further comprises the steps of: reordering the interface login information by the user terminal computer and confusing the parameter into a binary data code, and then transmitting the information according to the authentication server. The key pair encrypts the login information.

較佳地,此異質資訊裝置整合介接方法更包含下列步驟:藉由介接認證伺服器依據公開金鑰對介接代碼進行加密,再將加密後之介接代碼傳至使用者端電腦。Preferably, the heterogeneous information device integration interface method further comprises the steps of: encrypting the interface code according to the public key by the interface authentication server, and transmitting the encrypted interface code to the user terminal computer.

較佳地,介接代碼係包含對應遠端伺服器之網路位置。Preferably, the interface code includes a network location corresponding to the remote server.

較佳地,此異質資訊裝置整合介接方法更包含下列步驟:經由使用者端電腦對介接代碼進行分析,以判斷介接代碼中之網路位置是否具有系統危害,若是,則中斷介接登入請求,若否,則執行介接登入程序。Preferably, the heterogeneous information device integration interface method further comprises the following steps: analyzing the interface code through the user terminal computer to determine whether the network location in the interface code has a system hazard, and if so, interrupting the interface Login request, if no, perform the login process.

較佳地,此異質資訊裝置整合介接方法更包含下列步驟:透 過介接認證伺服器對介接登入資訊進行註冊,並將介接登入資訊中所包含之伺服器名稱、使用者帳號及請求登入時間進行分類。Preferably, the heterogeneous information device integration interface method further comprises the following steps: The authentication server registers the login information and classifies the server name, user account and request login time included in the login information.

較佳地,此異質資訊裝置整合介接方法更包含下列步驟:若遠端伺服器透過介接認證伺服器判斷介接代碼不具有效性,或使用者端電腦未於對應請求登入時間之一時間區間內登入時,則透過介接認證伺服器發送一錯誤介接登入提示至使用者端電腦;反之,當遠端伺服器傳送登入頁面至使用者端電腦以完成介接登入程序時,經由遠端伺服器將介接代碼之對應狀態變更為完成介接,使介接代碼失效而無法再透過介接代碼來執行介接登入程序。Preferably, the heterogeneous information device integration interface method further comprises the following steps: if the remote server determines that the interface code is not valid through the interface authentication server, or the user terminal does not log in at the corresponding request time When logging in the interval, the error message is sent to the user's computer through the authentication server; otherwise, when the remote server sends the login page to the user's computer to complete the login process, The end server changes the corresponding state of the interface code to complete the connection, so that the interface code is invalid and the interface login program can no longer be executed through the interface code.

較佳地,介接認證伺服器於產生介接代碼時,更於介接代碼中以隨機方式加入一時序。Preferably, the authentication server adds a timing in a random manner to the interface code when the interface code is generated.

承上所述,依本發明之異質資訊裝置整合介接方法,其具有下列一或多個特點:According to the above, the heterogeneous information device integration interface method according to the present invention has one or more of the following characteristics:

1、本發明可提供使用者藉由非對稱式加解密元件加密資料後透過介接認證伺服器的身分認證元件來做使用者身分識別,不僅提升了資訊系統的安全性,同時也加強了使用者管理的功能。1. The present invention can provide a user identity identification component through an asymmetric encryption and decryption component and then identify the identity of the user through the authentication component of the authentication server, thereby improving the security of the information system and enhancing the use. Managed features.

2、本發明透過編碼管理元件會將通過身分認證元件的資料作編碼的功能,並且加入時序混合元件來做編碼轉換,提供二次編碼的強度來降低被破解的可能性以及加強了系統的時效性。2. The invention encodes the data of the identity authentication component through the coding management component, and adds the timing mixing component to perform coding conversion, providing the strength of the secondary coding to reduce the possibility of being cracked and strengthening the timeliness of the system. Sex.

3、本發明經由編碼管理元件取得回傳的資訊之後會透過介接登入元件來驗證回傳的訊息是否有遭到竄改或是無效的資訊,可確保資訊的完整性與唯一性。3. After obtaining the returned information via the encoding management component, the present invention can verify whether the returned message has been tampered with or invalidated by interfacing the login component to ensure the integrity and uniqueness of the information.

4、本發明經由介接登入元件所取得之登入資訊只能使用一次,用完即被丟棄,無法被二次使用,就算有心人士擷取到訊息透過編碼查詢元件也無法使用相同的資訊來登入系統,可確保異質系統登入流程的安全性。4. The login information obtained by the invention through the login component can only be used once, and is discarded after being used up, and cannot be used twice. Even if the interested person picks up the message, the same information can be used to log in through the code query component. The system ensures the security of the heterogeneous system login process.

5、本發明提供使用者端於接收到編碼管理元件所回傳之非對稱式加密導向網址後,需透過系統本身之非對稱式加解密元件才能將此導向網址解回,可增加系統在資料傳送時的安全性。5. The present invention provides that after receiving the asymmetric encryption-oriented webpage returned by the encoding management component, the user needs to decrypt the navigation URL through the asymmetric encryption and decryption component of the system itself, thereby increasing the system data. Security when transmitting.

6、本發明之介接認證伺服器接收到使用者透過非對稱式加解密元件所加密之結果並完成使用者認證流程後,會結合時序混合元件產出含有不可逆之介接代碼,註冊至後端介接登入資料庫,在同一時序內只會存在唯一一組介接代碼並且只能被使用一次,若此介接代碼已被登入系統使用過或超過允許登入之時間區間限制後,此介接代碼立即失效。6. The interface authentication server of the present invention receives the result encrypted by the user through the asymmetric encryption and decryption component and completes the user authentication process, and then combines the timing hybrid component to generate an irreversible interface code, and registers it later. The interface is connected to the login database. Only a single set of interface code exists in the same sequence and can only be used once. If the interface code has been used by the login system or exceeds the time limit allowed for login, this The interface code is invalid immediately.

7、本發明之介接分析元件包含異質系統介接登入分類與介接黑名單建立。以往醫療資訊系統都各自獨立,因此醫院資訊室管理人員較無法明確觀察各系統間的介接運作情況,而本發明之介接分析元件在介接登入分類部分是將各伺服器、使用者與請求介接登入之時間進行分類,透過分類找出各時間點的伺服器介接情況定期進行統計分析,將分析的結果以有線或無線的網路傳輸方式提供給系統管理人員,使系統管理人員可以透過此分析數據進行介接控管或系統調整;介接黑名單建立的情況是某使用者於特定的時間區間內連續發出介接請求,而此時間區間內的求請次數可由系統管理人員經由外部設定,若超過系統管理者所設定的請求次數則將發出介接請求之使用者帳號與Ip位置新增至介接黑名單中,待系統管理人員解除限制後,方可再次請求介接登入。7. The interface analysis component of the present invention comprises a heterogeneous system interface login classification and an interface blacklist establishment. In the past, the medical information systems were independent of each other. Therefore, the hospital information room management staff could not clearly observe the interoperability between the systems. The interface analysis component of the present invention, in the interface classification part, was to connect the servers and users. Requests the time of the login to classify, finds the server interface at each time point to conduct statistical analysis regularly, and provides the results of the analysis to the system administrators by wired or wireless network transmission, so that the system administrators The analysis data can be used for mediation control or system adjustment; the blacklist is established when a user continuously sends an interface request within a specific time interval, and the number of requests in this time interval can be determined by the system administrator. If the number of requests set by the system administrator exceeds the number of requests set by the system administrator, the user account and the IP address of the interface request are added to the blacklist. After the system administrator releases the restriction, the interface can be requested again. Sign in.

S11~S14‧‧‧步驟S11~S14‧‧‧Steps

1‧‧‧使用者端電腦1‧‧‧User computer

11‧‧‧本地端系統11‧‧‧Local System

12‧‧‧非對稱式加解密元件12‧‧‧Asymmetric encryption and decryption components

13‧‧‧介接登入元件13‧‧‧Interfaced login components

2‧‧‧遠端伺服器2‧‧‧Remote Server

21‧‧‧認證查詢元件21‧‧‧Certification query component

22‧‧‧遠端系統22‧‧‧ Remote system

3‧‧‧介接認證伺服器3‧‧‧Interface authentication server

31‧‧‧身份驗證元件31‧‧‧Identification component

32‧‧‧編碼管理元件32‧‧‧Code Management Components

33‧‧‧時序混合元件33‧‧‧Sequence mixing components

34‧‧‧介接分析元件34‧‧‧Interfacing analysis components

第1圖 係為本發明之異質資訊裝置整合介接方法之流程圖。Figure 1 is a flow chart of a method for integrating and connecting heterogeneous information devices of the present invention.

第2圖 係為本發明之異質資訊裝置整合介接方法之實施例之系統架構圖。Figure 2 is a system architecture diagram of an embodiment of a heterogeneous information device integration interface method of the present invention.

為利 貴審查員瞭解本發明之技術特徵、內容與優點及其所能達成之功效,茲將本發明配合附圖,並以實施例之表達形式詳細說明如下,而其中所使用之圖式,其主旨僅為示意及輔助說明書之用,未必為本發明實施後之真實比例與精準配置,故不應就所附之圖式的比例與配置關係解讀、侷限本發明於實際實施上的權利範圍,合先敘明。The technical features, contents, and advantages of the present invention, as well as the advantages thereof, can be understood by the present inventors, and the present invention will be described in detail with reference to the accompanying drawings. The subject matter is only for the purpose of illustration and description. It is not intended to be a true proportion and precise configuration after the implementation of the present invention. Therefore, the scope and configuration relationship of the attached drawings should not be interpreted or limited. First described.

請參閱第1圖,其係為本發明之異質資訊裝置整合介接方法之流程圖,其流程步驟包含:Please refer to FIG. 1 , which is a flowchart of a method for integrating and connecting heterogeneous information devices according to the present invention. The process steps include:

步驟S11:經由一使用者端電腦發出一介接登入請求,以產生對應於一介接登入資訊之一公開金鑰及一私有金鑰,並接收一介接認證伺服器所傳送之一公鑰,以依據公鑰對介接登入資訊進行加密後產生一介接登入加密資訊。其中,使用者端電腦係將介接登入資訊重新排序與參數混淆並轉換成二進制數據碼,再依據介接認證伺服器所傳送之公鑰對介接登入資訊進行加密。Step S11: Sending a login request via a user terminal to generate a public key and a private key corresponding to one of the login information, and receiving a public key transmitted by the authentication server, according to The public key encrypts the incoming login information to generate an encrypted login information. The user-side computer confuses the incoming login information with the parameters and converts them into binary data codes, and then encrypts the incoming login information according to the public key transmitted by the authentication server.

步驟S12:藉由介接認證伺服器接收使用者端電腦所傳送之介接登入加密資訊及公開金鑰,並依據一私鑰對介接登入加密資訊進行解密以還原為介接登入資訊,並判斷介接登入資訊是否具有介接服務權限。其中,介接認證伺服器係透過一身份驗證資料庫來對介接登入資訊進行使用者身份驗證,以判斷介接登入資訊是否具有介接服務權限;若介接登入資訊不具介接服務權限或被列於黑名單中時,介接認證伺服器則產生一錯誤訊息並傳至該使用者端電腦,反之,若介接登入資訊具有介接服務權限時,介接認證伺服器則產生介接代碼。另外,當介接認證伺服器判斷介接登入資訊不具介接服務權限,且於一時間內持續接收到使用者端電腦所發出之多個介接登入請求並超過所設定之請求次數時,介接認證伺服器係將使用者端電腦新增至黑名單中。Step S12: receiving the login login encryption information and the public key transmitted by the user terminal computer through the interface authentication server, and decrypting the login login encryption information according to a private key to restore the login information and determining Whether the login information has the ability to interface with the service. The authentication server uses an authentication database to perform user authentication on the login information to determine whether the login information has the service authority; if the login information does not interface with the service or When it is listed in the blacklist, the authentication server generates an error message and transmits it to the user's computer. Otherwise, if the login information has the interface permission, the authentication server is interfaced. Code. In addition, when the authentication server determines that the login information does not have the service permission, and continuously receives the plurality of incoming login requests sent by the user's computer for a period of time and exceeds the set number of requests, The authentication server adds the user terminal to the blacklist.

步驟S13:若介接認證伺服器判斷介接登入加密資訊具介接服務權限,則經由介接認證伺服器產生一介接代碼,並將介接代碼傳送至使用者端電腦及遠端伺服器。其中,介接認證伺服器係依據公開金鑰對介接代碼進行加密,再將加密後之介接代碼傳至使用者端電腦。另外,當介接認證伺服器判斷介接登入加密資訊具介接服務權限,係對介接登入資訊進行註冊,並將介接登入資訊中所包含之伺服器名稱、使用者帳號及請求登入時間進行分類。Step S13: If the authentication server determines that the login encrypted information interface is the service authority, an interface code is generated via the interface authentication server, and the interface code is transmitted to the user terminal computer and the remote server. The interface authentication server encrypts the interface code according to the public key, and then transmits the encrypted interface code to the user terminal computer. In addition, when the authentication server determines that the login encrypted information has the service authority, the login information is registered, and the server name, user account and request login time included in the login information are displayed. sort.

步驟S14:經由使用者端電腦利用私有金鑰對介接代碼進行解碼並執行一介接登入程序,且經由遠端伺服器查詢介接代碼之有效性,並於判斷介接代碼為有效後透過介接認證伺服器將遠端伺服器所提供之登入頁面傳送至使用者端電腦,以完成介接登入程序。其中,介接代碼係包含對應遠端伺服器之網路位置,而使用者端電腦在執行介接登入程序前係 對介接代碼進行分析,以判斷介接代碼中之網路位置是否具有系統危害,若是,則中斷介接登入請求,若否,則執行介接登入程序。其中,若遠端伺服器透過介接認證伺服器判斷介接代碼不具有效性,或使用者端電腦未於對應請求登入時間之一時間區間內登入時,則透過介接認證伺服器發送一錯誤介接登入提示至使用者端電腦;反之,當遠端伺服器傳送登入頁面至使用者端電腦以完成介接登入程序時,經由遠端伺服器將介接代碼之對應狀態變更為完成介接,使介接代碼失效而無法再透過介接代碼來執行介接登入程序。Step S14: Decoding the interface code by using the private key through the user terminal computer and executing an interface login procedure, and querying the validity of the interface code via the remote server, and after determining that the interface code is valid, The authentication server transmits the login page provided by the remote server to the user terminal computer to complete the interface login procedure. Wherein, the interface code includes a network location corresponding to the remote server, and the client computer is in front of performing the interface login procedure. The interface code is analyzed to determine whether the network location in the interface code has a system hazard, and if so, the login request is interrupted, and if not, the interface login procedure is performed. If the remote server passes the interface authentication server to determine that the interface code is not valid, or the user terminal does not log in within one of the time intervals corresponding to the requested login time, an error is sent through the interface authentication server. The login prompt is sent to the user terminal; otherwise, when the remote server transmits the login page to the client computer to complete the interface login procedure, the corresponding status of the interface code is changed to the completion interface via the remote server. , the interface code is invalidated and the interface login program can no longer be executed through the interface code.

請參閱第2圖,其係為本發明之異質資訊裝置整合介接方法之實施例之系統架構圖。本發明之異質資訊裝置整合介接方法主要是運用非對稱式加解密元件12透過介接認證伺服器3所提供之公鑰對介接登入資訊進行加密,同時結合進階加密標準與隨機時序混合產出基於介接登入資訊的公開金鑰與私有金鑰,並將加密結果(介接登入加密資訊)與此公開金鑰傳送至介接認證伺服器3。其中,加密後的結果無法透過非對稱式加解密元件12所產生之公開金鑰或介接伺服器3之公鑰還原,而在介接認證伺服器3接收到介接登入加密資訊後,再使用其自身之私鑰還原為介接登入資訊。透過此種方法將使用者之介接登入資訊進行資訊加密,之後至介接認證伺服器3認證註冊與回傳相對應之不可逆登入介接代碼,並透過介接登入元件13導往使用者欲登入之系統。其中,非對稱式加解密元件12負責將使用者傳入之介接登入資訊進行重新排序與參數混淆並轉換成非人眼可讀之二進制數據碼,並透過介接認證伺服器3之公鑰進行加密,若此二進制數據碼遭到破解也無法直接取得原有介接登入資訊之內容。介接登入元件13主要負責解析介接認證伺服器3所提供之介接代碼之有效性,此功能為防止介接代碼於傳輸途中遭到破壞與修改。Please refer to FIG. 2 , which is a system architecture diagram of an embodiment of a heterogeneous information device integration and interfacing method of the present invention. The heterogeneous information device integration interface method of the present invention mainly uses the asymmetric encryption/decryption component 12 to encrypt the interface login information through the public key provided by the authentication server 3, and combines the advanced encryption standard with the random timing. The output is based on the public key and the private key of the login information, and the encryption result (intermediate login encryption information) and the public key are transmitted to the authentication server 3. The encrypted result cannot be restored by the public key generated by the asymmetric encryption/decryption component 12 or the public key of the interface server 3, and after the authentication server 3 receives the incoming login encrypted information, Use its own private key to restore to the login information. In this way, the user's interface login information is encrypted, and then the irreversible login code corresponding to the authentication server 3 authentication registration and return is introduced, and the user is guided through the interface login component 13 Login system. The asymmetric encryption/decryption component 12 is responsible for reordering the incoming login information and confusing the parameters into a non-human-readable binary data code, and translating the public key of the authentication server 3 Encryption, if the binary data code is cracked, it is not possible to directly obtain the content of the original login information. The interface login component 13 is primarily responsible for parsing the validity of the interface code provided by the authentication server 3, which prevents the interface code from being corrupted and modified during transmission.

介接認證伺服器3透過網際網路接收到由使用者端電腦1之非對稱式介接加解密元件12所發出之介接登入請求後,會先對使用者所傳入之介接登入資訊進行私鑰還原解析,並驗證此使用者於系統中是否有權限請求介接服務,並透過介接分析元件34查詢此介接登入資訊是否存在於黑名單中。若查無相對應之使用權限或此使用者為黑名單則取消此介接 登入請求註冊並返回錯誤訊息予使用者端電腦;反之,則透過編碼管理元件32對此介接登入資訊進行註冊,並將本次介接登入資訊所包含之目的伺服器名稱、使用者帳號與請求登入時間傳送至介接分析元件34進行分類。其中,編碼管理元件32會結合時序混合元件33對此介接登入資訊取得唯一時序,並透過介接唯一代碼產生演算法計算出屬於此介接登入資訊相對應之唯一介接代碼,再將此介接代碼結合遠端伺服器2之網路位置後利用使用者端電腦1所提供之公開金鑰進行非對稱式加密並回傳給使用者端電腦1之非對稱式加解密元件12。最後將各伺服器、使用者與請求介接登入之時間進行分類,透過分類找出各時間點的伺服器介接情況定期進行統計分析,並將分析的結果以有線或無線的網路傳輸方式提供給系統管理人員,使系統管理人員可以透過此分析數據進行介接控管或系統調整。After the authentication server 3 receives the incoming login request sent by the asymmetric interface encryption/decryption component 12 of the user computer 1 through the Internet, the incoming login information is first introduced to the user. The private key is restored and parsed, and it is verified whether the user has the right to request the interface service in the system, and the interface analysis component 34 is used to query whether the interface login information exists in the blacklist. Cancel this interface if there is no corresponding usage right or this user is blacklisted The login request is registered and an error message is returned to the user's computer; otherwise, the login information is registered through the code management component 32, and the server name and user account included in the login information are connected. The request login time is transmitted to the interface analysis component 34 for classification. The encoding management component 32 combines the timing mixing component 33 to obtain a unique timing for the login information, and calculates a unique interface code corresponding to the login information through the interface unique code generation algorithm. The interface code is combined with the network location of the remote server 2 and then asymmetrically encrypted by the public key provided by the client computer 1 and transmitted back to the asymmetric encryption/decryption component 12 of the user computer 1. Finally, the server, the user and the time of requesting the login are classified, and the server interface of each time point is found to be statistically analyzed periodically, and the analysis result is transmitted by wired or wireless network. Provided to system administrators to enable system administrators to perform control or system adjustments through this analysis data.

使用者端電腦1接受到來自介接認證伺服器3回傳之唯一介接代碼後,先利用自身之私有金鑰進行非對稱式解密還原後再呼叫介接登入元件13執行實際系統介接登入程序。介接登入元件13在啟動介接登入程序前會先分析所取得之介接代碼,嘗試對此資訊進行網路繫結,判斷此目的之有效性,若導入之登入位置被檢測出具有高度系統危害則中止本次介接登入請求服務,並提醒使用者介接代碼已遭到破壞;反之,則執行介接登入程序,而遠端伺服器2在取得介接登入之相關唯一介接代碼後,經由認證查詢元件21至介接認證伺服器3確認此唯一介接代碼之有效性。若已超過設定之有效時間區段,則導入錯誤介接登入提示頁面,反之則完成介接登入程序並導入相對應之登入頁面,並透過認證查詢元件21將此介接代碼狀態更新至完成介接登入。換言之,使用者無法再透過此唯一介接代碼進行介接登入,完成一次性介接登入流程。After receiving the unique interface code from the authentication server 3, the client computer 1 performs asymmetric decryption and restoration using its own private key, and then calls the login component 13 to perform the actual system interface login. program. The interface login component 13 analyzes the obtained interface code before initiating the login procedure, attempts to network the information, determines the validity of the purpose, and if the imported login location is detected to have a high degree of system The hazard suspends the connection request service and reminds the user that the interface code has been corrupted. Otherwise, the interface login procedure is executed, and the remote server 2 obtains the relevant unique connection code for the login. The validity of the unique interface code is confirmed via the authentication query component 21 to the authentication server 3. If the set valid time period has been exceeded, the error introduction login prompt page is imported, otherwise the login login procedure is completed and the corresponding login page is imported, and the interface status is updated to completion by the authentication query component 21. Sign in. In other words, the user can no longer perform the one-time login process through the unique connection code.

以上各組件之功能如下簡述之:The functions of the above components are as follows:

1、使用者端電腦1,包含本地端系統11、非對稱式加解密元件12及介接登入元件13。當使用者需要介接其他遠端系統時,可透過本地端系統1將介接登入資訊送至非對稱式加解密元件12進行加密,其加密方式是透過介接認證伺服器3所提供之公鑰來執行,而加密後所取得之結果無法再使用此公鑰還原。非對稱式加解密元件12在收到介接認證伺服器 3所傳包含遠端伺服器2之網路位置之唯一介接代碼後,係使用自身私有金鑰進行解密還原,再透過介接登入元件13測試連線安全性,通過後再啟動介接登入服務並透過網際網路進行資訊傳輸。1. The client computer 1 includes a local end system 11, an asymmetric encryption/decryption component 12, and an interface login component 13. When the user needs to interface with other remote systems, the local login system 1 can send the interface login information to the asymmetric encryption/decryption component 12 for encryption. The encryption method is provided by the authentication server 3. The key is executed, and the result obtained after encryption can no longer be restored using this public key. The asymmetric encryption/decryption component 12 receives the interface authentication server After the unique connection code of the network location including the remote server 2 is transmitted, the user uses the private key to decrypt and restore, and then tests the connection security through the interface login component 13, and then initiates the login through the interface. Services and information transfer via the Internet.

本發明之異質資訊裝置整合介接方法中使用者端電腦1所執行的步驟為:a、使用者端電腦1透過非對稱式加解密元件12將介接登入資訊透過進階加密標準與隨機時序混合產出基於介接登入資訊的公開金鑰與私有金鑰,同時向介接認證伺服器3請求釋出其公鑰,隨後透過介接伺服器3所提供之公鑰對介接登入資訊進行加密,最後傳送介接登入加密資訊與公開金鑰至介接認證伺服器3發出介接登入請求,請求介接認證伺服器3產出介接代碼;b、透過介接認證伺服器3內部分之身份認證元件31至身份驗證資料庫(圖未示)查詢使用者身份並於通過身份驗證後啟動編碼管理元件32產出介接代碼並儲存至介接認證資料庫(圖未示)並回傳所產出之介接代碼至使用者端電腦1;c、對介接認證伺服器3所回傳之介接代碼進行解密與驗證,確認代碼之正確性後,再啟動介接登入元件13執行介接登入程序。In the heterogeneous information device integration interface method of the present invention, the user computer 1 performs the following steps: a. The user computer 1 transmits the login information through the asymmetric encryption standard to the random encryption standard through the asymmetric encryption and decryption component 12. The hybrid output is based on the public key and the private key of the login information, and requests the authentication server 3 to release the public key, and then performs the login information through the public key provided by the server 3. Encryption, finally transmitting the login encryption information and the public key to the authentication server 3 to issue a login request, requesting the authentication server 3 to generate the interface code; b, through the interface of the authentication server 3 The identity authentication component 31 to the identity verification database (not shown) queries the identity of the user and, after passing the authentication, starts the code management component 32 to generate the interface code and stores it in the interface to the authentication database (not shown) and back Passing the interface code outputted to the user terminal computer 1; c, decrypting and verifying the interface code returned by the authentication server 3, confirming the correctness of the code, and then starting the interface login component 13 Line interfacing sign-in process.

2、遠端伺服器2,包含認證查詢元件21及遠端系統22。認證查詢元件21負責向介接認證伺服器3確認介接代碼是否有效,確認其介接代碼之有效性後將使用者導入欲連接之遠端系統22頁面中,並在完成正常介接登入程序後向介接認證伺服器3變更此唯一介接代碼為已登入狀態。2. The remote server 2 includes an authentication query component 21 and a remote system 22. The authentication query component 21 is responsible for confirming to the authentication server 3 whether the interface code is valid, confirming the validity of the interface code, and then importing the user into the remote system 22 page to be connected, and completing the normal interface login procedure. The backward interface authentication server 3 changes the unique interface code to the logged in state.

本發明之異質資訊裝置整合介接方法中遠端伺服器21所執行的步驟為:a、遠端伺服器2接收到來自使用者端電腦1的介接登入請求後,透過介接代碼向介接認證伺服器3中的編碼管理元件32取得介接認證資料庫內部存在之代碼狀態並回傳;b、判斷本次介接登入請求服務之使用者是否有權限登入,若有,則透過介接認證伺服器3將遠端伺服器2所提供之登入頁面傳送至使用者端電腦1;c、在完成正常介接登入程序後,遠端伺服器2會透過介接認證伺服器3中的介接狀態更新服務,變更介接認證資料庫中相對應介接代碼為已完成介接服務。In the heterogeneous information device integration interface method of the present invention, the remote server 21 performs the following steps: a. After receiving the login request from the user terminal computer 1, the remote server 2 transmits the mediation code through the interface code. The code management component 32 in the authentication server 3 obtains the code status existing in the authentication database and returns it. b. determines whether the user who has accessed the login request service has permission to log in. If so, The authentication server 3 transmits the login page provided by the remote server 2 to the user terminal computer 1; c. After completing the normal interface login procedure, the remote server 2 transmits the authentication server 3 The status update service is interfaced, and the corresponding interface code in the change authentication database is the completed interface service.

3、介接認證伺服器3,包含身份驗證元件31、編碼管理元件32、時序混合元件33及介接分析元件34。身份驗證元件31,當使用者 透過非對稱式加解密元件12提出介接登入請求時,使用自身私鑰進行解密還原分析並進行使用者身份驗證;此身份驗證元件31將維護各系統與使用者之間的介接權限,若提出介接登入請求之使用者並沒有權限可以介接遠端伺服器2時,身份驗證元件31會返回介接錯誤訊息提示予使用者端電腦1。編碼管理元件32,負責處理所有系統之介接代碼產出與有效性註冊,若先前已產出之介接代碼於特定時間區間內並未完成介接登入程序服務,將會被此編碼管理元件32註銷。時序混合元件33,主要功能在於編碼管理元件32產出唯一介接代碼時,加入隨機的混淆時序來達成其唯一性。介接分析元件34,其功能為異質系統介接登入分類與介接黑名單建立,讓系統管理者可以透過此元件進行所分類的數據進行介接控管或系統調整,而黑名單部分則是加強介接登入的安全性並防止不當使用者透過大量使用者資料進行破解登入。3. The authentication server 3 is interfaced with an authentication component 31, an encoding management component 32, a timing mixing component 33, and an interface analysis component 34. Authentication component 31, when the user When the asynchronous login/decryption component 12 proposes the incoming login request, the decryption and restore analysis is performed using the private key of the user, and the user identity verification is performed; the identity verification component 31 maintains the interface between the system and the user. When the user who proposes the login request does not have permission to connect to the remote server 2, the authentication component 31 returns an interface error message to the user computer 1. The encoding management component 32 is responsible for processing the interfacing code output and validity registration of all systems. If the previously generated interfacing code does not complete the interrogating login service within a specific time interval, the encoding management component will be used. 32 logout. The timing mixing component 33, the main function is that when the encoding management component 32 produces a unique interface code, a random confusion timing is added to achieve its uniqueness. The analysis component 34 is configured to interface the heterogeneous system with the login and the blacklist, so that the system administrator can perform the control or system adjustment of the classified data through the component, and the blacklist is Enhance the security of the login and prevent unauthorized users from logging in through a large amount of user data.

本發明之異質資訊裝置整合介接方法中介接認證伺服器31所執行的步驟:a、接收使用者端電腦1所傳送經加密之介接登入加密資訊,並將介接登入加密資訊之二進制數據碼反轉成系統可處理之訊息格式,並依據私鑰對介接登入加密資訊進行解碼還原;b、經由身份認證元件31取得前段二進制數據碼反轉之介接登入資訊後,將相對應欄位之使用者帳號與密碼取出並至身份認證資料庫進行檢索,再將結果回應至身份認證元件31;c、使用者在通過身份驗證查核後,編碼管理元件32會先由時序混合元件33取得隨機時序並結合介接代碼後傳送至介接認證資料庫進行註冊,再將介接代碼傳至使用者端電腦1及遠端伺服器2,以完成後續之介接登入程序;d、使用者若無法通過身份驗證查核,則判斷此使用者是否在之後固定的時間內連續提出介接登入請求,若已超過系統管理者所設定之請求次數,則將此使用者新增至黑名單中,待系統管理人員解除限制後,方可再次請求介接登入。The heterogeneous information device integration interface method of the present invention mediates the steps performed by the authentication server 31: a. receiving the encrypted interface information encrypted by the user terminal computer 1, and inputting the binary data of the encrypted information. The code is reversed into a message format that can be processed by the system, and the encrypted login information is decoded and restored according to the private key; b. After the identity authentication component 31 obtains the login information of the previous binary data code inversion, the corresponding column is The user account and password are retrieved and retrieved into the identity authentication database for retrieval, and the result is returned to the identity authentication component 31; c. After the user passes the identity verification, the code management component 32 is first obtained by the timing mixing component 33. The random sequence is combined with the interface code and transmitted to the interface authentication database for registration, and then the interface code is transmitted to the user terminal computer 1 and the remote server 2 to complete the subsequent interface login procedure; d, the user If it is not possible to pass the authentication check, it is determined whether the user continuously submits the login request within a fixed time period, if the system has been exceeded. Managers of the set number of requests, this new user to the blacklist, the system manager until the lifting of restrictions, before again requesting access via sign.

綜合上述,本發明之異質資訊裝置整合介接方法係結合短暫時效性與一次性介接代碼產生方式,以及用戶本地端通用介面之非對稱式加/解密元件,讓使用者可將後端認證伺服器所提供之公鑰與欲傳輸之介接登入資訊做為非對稱式加解密元件之參數,並取得無法使用公鑰還原之加 密結果,透過此種方式可用於異質系統進行介接前提供資料安全性保密的服務。此外,本發明還透過介接分析元件在介接登入時將各伺服器、使用者與請求介接登入之時間進行分類,透過分類找出各時間點的伺服器介接情況定期進行統計分析,將分析的結果以有線或無線的網路傳輸方式提供給系統管理人員,使系統管理人員可以透過此分析數據進行介接控管或系統調整,透過此方式來改善以往醫療資訊系統都各自獨立,醫院資訊室管理人員較無法明確觀察與釐清各系統間介接運作所發生的問題。In summary, the heterogeneous information device integration interface method of the present invention combines a short-term time-sensitive and one-time interface code generation method, and an asymmetric encryption/decryption component of a user-side common interface, so that the user can authenticate the backend. The public key provided by the server and the interface information to be transmitted are used as parameters of the asymmetric encryption and decryption component, and the addition of the public key cannot be used. The secret result can be used to provide data security and confidentiality services before the heterogeneous system is interfaced. In addition, the present invention also classifies the time of each server, the user, and the request interface through the interface analysis component, and finds the server interface situation at each time point through the classification to perform statistical analysis periodically. The results of the analysis are provided to the system administrators by wired or wireless network transmission, so that the system administrator can perform the connection control or system adjustment through the analysis data, thereby improving the previous medical information systems by themselves. Hospital information room managers are less able to clearly observe and clarify the problems that occur between the various systems.

以上所述僅為舉例性,而非為限制性者。任何未脫離本發明之精神與範疇,而對其進行之等效修改或變更,均應包含於後附之申請專利範圍中。The above is intended to be illustrative only and not limiting. Any equivalent modifications or alterations to the spirit and scope of the invention are intended to be included in the scope of the appended claims.

S11~S14‧‧‧步驟S11~S14‧‧‧Steps

Claims (10)

一種異質資訊裝置整合介接方法,用以提供一使用者端電腦與一遠端伺服器安全性地連接,該方法包含下列步驟:經由一使用者端電腦發出一介接登入請求,以產生對應於一介接登入資訊之一公開金鑰及一私有金鑰,並接收一介接認證伺服器所傳送之一公鑰,以依據該公鑰對該介接登入資訊進行加密後產生一介接登入加密資訊;藉由該介接認證伺服器接收該使用者端電腦所傳送之該介接登入加密資訊及該公開金鑰,並依據一私鑰對該介接登入加密資訊進行解密以還原為該介接登入資訊,並判斷該介接登入資訊是否具有介接服務權限;若該介接認證伺服器判斷該介接登入加密資訊具介接服務權限,則經由該介接認證伺服器產生一介接代碼,並將該介接代碼傳送至該使用者端電腦及該遠端伺服器;以及經由該使用者端電腦利用該私有金鑰對該介接代碼進行解碼並執行一介接登入程序,且經由該遠端伺服器查詢該介接代碼之有效性,並於判斷該介接代碼為有效後透過該介接認證伺服器將該遠端伺服器所提供之登入頁面傳送至該使用者端電腦,以完成該介接登入程序。A heterogeneous information device integration interface method for providing a user terminal computer to securely connect with a remote server, the method comprising the steps of: sending a login request via a user terminal computer to generate a corresponding A public key and a private key are connected to one of the login information, and receive a public key transmitted by the authentication server to encrypt the interface login information according to the public key to generate an incoming login encryption information; Receiving, by the interface authentication server, the interface login encryption information and the public key transmitted by the user terminal, and decrypting the interface login encryption information according to a private key to restore the login Information, and determining whether the interface login information has an interface service authority; if the interface authentication server determines that the interface login encryption information has a service permission, generating an interface code via the interface authentication server, and Transmitting the interfacing code to the client computer and the remote server; and using the private key to connect the interfacing code via the user end computer Decoding and executing an interrogation procedure, and querying the validity of the interfacing code via the remote server, and determining that the interfacing code is valid, providing the remote server through the interfacing authentication server The login page is transmitted to the client computer to complete the interface login procedure. 如申請專利範圍第1項所述之異質資訊裝置整合介接方法,其中該介接認證伺服器係透過一身份驗證資料庫來對該介接登入資訊進行使用者身份驗證,以判斷該介接登入資訊是否具有介接服務權限;若該介接登入資訊不具介接服務權限或被列於黑名單中時,該介接認證伺服器則產生一錯誤訊息並傳至該使用者端電腦,反之,若該介接登入資訊具有介接服務權限時,該介接認證伺服器則產生該介接代碼。The heterogeneous information device integration and interfacing method according to claim 1, wherein the interface authentication server performs user authentication on the interface login information through an identity verification database to determine the interface. Whether the login information has the service permission; if the login information does not have the service permission or is listed in the blacklist, the authentication server generates an error message and transmits it to the user computer. If the interface login information has an interface service permission, the interface authentication server generates the interface code. 如申請專利範圍第2項所述之異質資訊裝置整合介接方法,其中當該介接認證伺服器判斷該介接登入資訊不具介接服務權限,且於一時間內持續接收到該使用者端電腦所發出之多個該介接登入請求並超過所設定之請求次數時,該介接認證伺服器係將該使用者端電腦新增至黑名單中。The heterogeneous information device integration and interfacing method according to claim 2, wherein the interfacing authentication server determines that the intervening login information does not have a service authority, and continuously receives the user end for a period of time. When the plurality of incoming login requests sent by the computer exceed the set number of requests, the interface authentication server adds the user terminal to the blacklist. 如申請專利範圍第1項所述之異質資訊裝置整合介接方法,其更包含下列步驟:透過該使用者端電腦將該介接登入資訊重新排序與參數混淆並轉換成二進制數據碼,再依據該介接認證伺服器所傳送之該公鑰對該介接登入資 訊進行加密。For example, the heterogeneous information device integration and interfacing method described in claim 1 further includes the following steps: reordering the interface login information by the user terminal computer and confusing the parameter into a binary data code, and then The public key transmitted by the authentication server is connected to the login key The message is encrypted. 如申請專利範圍第1項所述之異質資訊裝置整合介接方法,其更包含下列步驟:藉由該介接認證伺服器依據該公開金鑰對該介接代碼進行加密,再將加密後之該介接代碼傳至該使用者端電腦。The heterogeneous information device integration interface method according to claim 1, further comprising the step of: encrypting the interface code according to the public key by the interface authentication server, and then encrypting the interface code The interface code is passed to the user terminal computer. 如申請專利範圍第1項所述之異質資訊裝置整合介接方法,其中該介接代碼係包含對應該遠端伺服器之網路位置。The heterogeneous information device integration interface method according to claim 1, wherein the interface code includes a network location corresponding to the remote server. 如申請專利範圍第6項所述之異質資訊裝置整合介接方法,其更包含下列步驟:經由該使用者端電腦對該介接代碼進行分析,以判斷該介接代碼中之網路位置是否具有系統危害,若是,則中斷該介接登入請求,若否,則執行該介接登入程序。The heterogeneous information device integration interface method according to claim 6, further comprising the following steps: analyzing the interface code through the user terminal computer to determine whether the network location in the interface code is There is a system hazard, and if so, the interrogation request is interrupted, and if not, the interrogation procedure is executed. 如申請專利範圍第1項所述之異質資訊裝置整合介接方法,其更包含下列步驟:透過該介接認證伺服器對該介接登入資訊進行註冊,並將該介接登入資訊中所包含之伺服器名稱、使用者帳號及請求登入時間進行分類。The heterogeneous information device integration interface method of claim 1, further comprising the steps of: registering the login information through the interface authentication server, and including in the login information The server name, user account number, and request login time are classified. 如申請專利範圍第8項所述之異質資訊裝置整合介接方法,其更包含下列步驟:若該遠端伺服器透過該介接認證伺服器判斷該介接代碼不具有效性,或該使用者端電腦未於對應請求登入時間之一時間區間內登入時,則透過該介接認證伺服器發送一錯誤介接登入提示至該使用者端電腦;反之,當該遠端伺服器傳送登入頁面至該使用者端電腦以完成該介接登入程序時,經由該遠端伺服器將該介接代碼之對應狀態變更為完成介接,使該介接代碼失效而無法再透過該介接代碼來執行介接登入程序。The method for integrating and connecting a heterogeneous information device as described in claim 8 further includes the step of: if the remote server determines, by the interface authentication server, that the interface code is not valid, or the user When the terminal computer does not log in within one of the time intervals corresponding to the requested login time, an error message is sent to the user computer through the interface authentication server; otherwise, when the remote server transmits the login page to When the user terminal computer completes the interface login procedure, the corresponding state of the interface code is changed to completion through the remote server, so that the interface code is invalid and cannot be executed through the interface code. Introduce the login program. 如申請專利範圍第1項所述之異質資訊裝置整合介接方法,其中該介接認證伺服器於產生該介接代碼時,更於該介接代碼中以隨機方式加入一時序。The heterogeneous information device integration interface method of claim 1, wherein the interface authentication server adds a timing in a random manner to the interface code when the interface code is generated.
TW102140605A 2013-11-08 2013-11-08 Heterogeneous information device integration method TWI506474B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW102140605A TWI506474B (en) 2013-11-08 2013-11-08 Heterogeneous information device integration method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW102140605A TWI506474B (en) 2013-11-08 2013-11-08 Heterogeneous information device integration method

Publications (2)

Publication Number Publication Date
TW201518988A TW201518988A (en) 2015-05-16
TWI506474B true TWI506474B (en) 2015-11-01

Family

ID=53720947

Family Applications (1)

Application Number Title Priority Date Filing Date
TW102140605A TWI506474B (en) 2013-11-08 2013-11-08 Heterogeneous information device integration method

Country Status (1)

Country Link
TW (1) TWI506474B (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060206932A1 (en) * 2005-03-14 2006-09-14 Microsoft Corporation Trusted third party authentication for web services
TW200814703A (en) * 2006-09-12 2008-03-16 Xin-Yuan Ye Method and system of authenticating the identity of the client
TW200920066A (en) * 2007-10-17 2009-05-01 Stars Technology Ltd Information security transmission system

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060206932A1 (en) * 2005-03-14 2006-09-14 Microsoft Corporation Trusted third party authentication for web services
TW200814703A (en) * 2006-09-12 2008-03-16 Xin-Yuan Ye Method and system of authenticating the identity of the client
TW200920066A (en) * 2007-10-17 2009-05-01 Stars Technology Ltd Information security transmission system

Also Published As

Publication number Publication date
TW201518988A (en) 2015-05-16

Similar Documents

Publication Publication Date Title
TWI519992B (en) Method and system of login authentication, and computer storage medium
AU2017204853B2 (en) Data security service
CN102624740B (en) A kind of data interactive method and client, server
CN104468115B (en) information system access authentication method and device
US20180159694A1 (en) Wireless Connections to a Wireless Access Point
US10637650B2 (en) Active authentication session transfer
AU2008344384B2 (en) Information distribution system and program for the same
US20120266224A1 (en) Method and system for user authentication
CN103986584A (en) Double-factor identity verification method based on intelligent equipment
US9954853B2 (en) Network security
KR20180080183A (en) Systems and methods for biometric protocol standards
JP2016521029A (en) Network system comprising security management server and home network, and method for including a device in the network system
JP2001186122A (en) Authentication system and authentication method
US20230299973A1 (en) Service registration method and device
CN112383401B (en) User name generation method and system for providing identity authentication service
KR20130039745A (en) System and method for authentication interworking
CN109495458A (en) A kind of method, system and the associated component of data transmission
JP6199506B2 (en) Server system and method for controlling a plurality of service systems
CN109460647B (en) Multi-device secure login method
CN116668190A (en) Cross-domain single sign-on method and system based on browser fingerprint
CN116108416A (en) Application program interface safety protection method and system
RU2698424C1 (en) Authorization control method
KR20140011542A (en) Log in system and method
TWI506474B (en) Heterogeneous information device integration method
JP5665592B2 (en) Server apparatus, computer system, and login method thereof