TWI553595B - Access control system and its method - Google Patents

Access control system and its method Download PDF

Info

Publication number
TWI553595B
TWI553595B TW104116605A TW104116605A TWI553595B TW I553595 B TWI553595 B TW I553595B TW 104116605 A TW104116605 A TW 104116605A TW 104116605 A TW104116605 A TW 104116605A TW I553595 B TWI553595 B TW I553595B
Authority
TW
Taiwan
Prior art keywords
access control
visitor
mobile device
message
control management
Prior art date
Application number
TW104116605A
Other languages
Chinese (zh)
Other versions
TW201642225A (en
Inventor
Zhi-Qiang Wang
Yi-Lin Li
Zheng-Xian Lin
Bi-Wei Zhuang
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed filed Critical
Priority to TW104116605A priority Critical patent/TWI553595B/en
Application granted granted Critical
Publication of TWI553595B publication Critical patent/TWI553595B/en
Publication of TW201642225A publication Critical patent/TW201642225A/en

Links

Description

門禁管理系統及其方法 Access control management system and method thereof

本發明係關於一種門禁管理系統及其方法,特別是關於一種透過住戶與訪客間彼此的行動裝置而可互相驗證身份的門禁管理系統及其方法。 The present invention relates to an access control management system and method thereof, and more particularly to an access control management system and method thereof that can mutually authenticate each other through a mobile device between a resident and a visitor.

隨著數位生活科技日益進步,近年來有越來越多新建大廈或二代科技宅採用視訊門鈴(video doorbell,亦稱視訊對講機),以取代傳統的音訊大樓對講機。視訊門鈴的優點是屋主可以透過視訊中的影像來確認訪客的身份,可是市面上的視訊門鈴,不論是設備售價或額外的佈線施工成本,價格都比傳統音訊大樓對講機更加昂貴。昂貴成本實乃推廣視訊門鈴的最大阻力。 With the advancement of digital life technology, in recent years, more and more new buildings or second-generation technology houses have adopted video doorbells (also called video walkie-talkies) to replace the traditional audio building intercom. The advantage of the video doorbell is that the homeowner can confirm the identity of the visitor through the video in the video. However, the video doorbell on the market is more expensive than the traditional audio building intercom, regardless of the price of the equipment or the additional wiring construction cost. Expensive cost is the biggest resistance to the promotion of video doorbells.

除此之外,已經完工的大廈若要加裝視訊門鈴,其佈線施工更加困難。如果視訊門鈴的通訊訊號能夠經由大廈內既有的區域網路來傳送,其建置成本必然可以大幅降低。 In addition, if the video doorbell is to be installed in a completed building, the wiring construction is more difficult. If the communication signal of the video doorbell can be transmitted through the existing regional network in the building, the construction cost can be greatly reduced.

另一方面,目前大陸廠商(例如小米)或台灣廠商(例如華碩、鴻海)自行生產的智慧型手機不但價格便宜,而且功能完備齊全。舉例來說,市面上販售的鴻海Infocus M210 4.7吋四核心智慧型手機僅需3,288元、Turbo四核心1.5GHz的紅米手機也只要3,999元,而MT6577雙核心4.3吋的長江手機更只要2990元。預期在激烈的市場競爭下,未來智慧型手機的價格會進一步調降且在全世界的普及性也逐年攀升。根據市場調查機構Nielsen 的報告,至2012年6月底美國已經有54.9%的手機用戶都改用智慧型手機。另外,根據資策會FIND於2012年的調查,臺灣持有智慧型手機或平板電腦的族群約有707萬人;預估到2015年,臺灣智慧型手機普及率將高達56.8%。由於智慧型手機的低成本、高度普及化且具有執行視訊對話、Wi-Fi無線區域網路通訊和密碼輸入等功能,智慧型手機很適合作為視訊門鈴的對講機硬體設備。 On the other hand, smart phones made by mainland manufacturers (such as Xiaomi) or Taiwanese manufacturers (such as ASUS and Hon Hai) are not only cheap but also fully functional. For example, the Hon Hai Infocus M210 4.7 吋 four-core smart phone sold on the market only needs 3,288 yuan, the Turbo quad-core 1.5GHz red rice mobile phone is only 3,999 yuan, and the MT6577 dual-core 4.3-inch Yangtze River mobile phone is only 2990. yuan. It is expected that in the fierce market competition, the price of smart phones will be further reduced in the future and the popularity in the world will also increase year by year. According to market research agency Nielsen According to the report, by the end of June 2012, 54.9% of mobile phone users in the United States had switched to smart phones. In addition, according to the survey conducted by FIND in 2012, there are about 7.07 million people holding smart phones or tablets in Taiwan. It is estimated that by 2015, Taiwan's smart phone penetration rate will reach 56.8%. Due to the low cost, high popularity of smart phones and the functions of performing videoconferencing, Wi-Fi wireless area network communication and password input, smart phones are suitable as walkie-talkie hardware devices for video doorbells.

有鑑於此,為解決上述之問題,如何降低門禁管理系統的建置成本,而又能結合今日便利的無線通訊網路與普及的行動裝置,甚至更具有高度安全點對點的通訊驗證機制,以達到智慧化生活的目標,乃為業界亟需解決之問題。 In view of this, in order to solve the above problems, how to reduce the construction cost of the access control management system, and combine with today's convenient wireless communication network and popular mobile devices, and even more highly secure peer-to-peer communication verification mechanism to achieve wisdom The goal of a healthy life is an issue that the industry needs to solve.

具體而言,有鑑於智慧型手機在台灣的高度普及化及未來成長趨勢,申請人研發一套成本低、實用性高且容易製作與安裝的視訊門鈴門禁系統「鈴意視見」。「鈴意視見」軟體可以被安裝在任何市售的Android智慧型手機上運行,其特色是透過大廈既有的區域網路來進行P2P視訊對話與大門電子鎖開關控制,以達到節省對講機專用線路的佈線成本以及避免施工上種種麻煩。訪客可開啟大門口室外機的「鈴意視見」軟體,然後透過軟體介面來輸入屋主居住之樓層與房號,以便啟動視訊對話。接下來,「鈴意視見」軟體會利用經濟部技術處提供的P2P互動式影音直播應用平台,和屋主的室內機連接並且啟動P2P視訊對話。一旦屋主接聽視訊對話並按下室內機軟體介面上的「開門」按鈕來開啟大門電子鎖。訪客也可以直接在室外機介面上輸入密碼來開啟大門。除了一般的視訊門禁控制功能之外,「鈴意視見」更增加了安全監控功能。只要搭配一般的資料庫系統, 「鈴意視見」更可以在訪客視訊時或在訪客輸入密碼時紀錄訪客的影像,以供日後查詢使用。 Specifically, in view of the high popularity and future growth trend of smart phones in Taiwan, the applicants have developed a set of video doorbell access control systems that are low-cost, practical, and easy to manufacture and install. The "Bell View" software can be installed on any commercially available Android smartphone. It is characterized by P2P video dialogue and gate electronic lock switch control through the existing local area network of the building to save the walkie-talkie. The wiring cost of the line and the troubles in avoiding construction. Visitors can open the "Bell View" software for the outdoor unit at the gate, and then enter the floor and room number of the homeowner through the software interface to initiate a video conversation. Next, the "Bell View" software will use the P2P interactive video live application platform provided by the Technical Department of the Ministry of Economic Affairs to connect with the home unit's indoor unit and initiate a P2P video conversation. Once the homeowner answers the video conversation and presses the "open the door" button on the indoor unit software interface to open the door electronic lock. Visitors can also open the door by entering a password directly on the outdoor unit interface. In addition to the general video access control function, "Bell View" adds security monitoring. Just match the general database system, The "Bell View" can also record the visitor's image during the visitor's video or when the visitor enters the password for future reference.

為了提升本軟體的安全性,我們加入了RSA加解密以及身份驗證機制。當屋主按下「開門」按鈕時,室內機將事先儲存的密碼以及開門當時時間一起加密,並將此開門用的加密訊息送給室外機,讓室外機驗證此開門訊息是否為大廈內的室內機所發出。因為每次加密所用的時間不同,此舉可讓不同時間下產生的加密訊息具有獨特性,使得第三方破解加密訊息的困難度增加。「鈴意視見」即利用上述機制防止有心人士藉由監聽訊息而破解開門訊息格式,進而避免未獲授權之外人偽造開門訊息來打開大門。而在訪客使用密碼開門的過程中,我們應用了OpenCV影像處理函式庫來進行人臉偵測。該函式庫是由英特爾公司發起並參與開發,可供社會大眾在商業和研究領域中免費使用。藉由OpenCV的人臉偵測功能,室外機可判斷在訪客輸入密碼的過程中是否清楚拍攝到訪客的臉部影像,並錄下當時的鏡頭畫面。在無法辨識人臉特徵的情況下,軟體將不允許訪客輸入密碼打開大門。此一功能可確保管理人員日後可查詢大樓的進出記錄並且可以調閱到足以辨識的訪客臉部錄影畫面。 In order to improve the security of this software, we have added RSA encryption and decryption and authentication mechanism. When the owner presses the "open the door" button, the indoor unit encrypts the password stored in advance and the time of opening the door, and sends the encrypted message for opening the door to the outdoor unit, so that the outdoor unit verifies whether the opening message is in the building. The indoor unit is issued. Because each encryption takes less time, this can make the encrypted messages generated at different times unique, making it more difficult for third parties to crack encrypted messages. "Bell View" uses the above mechanism to prevent people who are interested in cracking the open message format by listening to the message, thereby preventing unauthorised outsiders from forging the door opening message to open the door. In the process of using the password to open the door, we applied the OpenCV image processing library for face detection. The library is sponsored and developed by Intel Corporation and is available to the public for free in the commercial and research fields. With OpenCV's face detection function, the outdoor unit can determine whether the visitor's face image is clearly captured during the visitor's password entry and record the current lens image. In the case where the face feature cannot be recognized, the software will not allow the visitor to enter the password to open the door. This feature ensures that managers can query the building's entry and exit records in the future and can access a sufficiently visible visitor's face video.

本發明之一目的在於提供一種門禁管理系統,其可降低門禁管理系統的建置成本。 An object of the present invention is to provide an access control management system that can reduce the cost of establishing an access control management system.

為達上述目的,本發明提供一種門禁管理系統,用於提供一住戶透過一區域網路而驗證一訪客的身份,以決定對該訪客解除門禁。門禁管理系統包含一點對點影音互動平台、一第一行動裝置以及一第二行動裝置。點對點影音互動平台用以耦接區域網路,其中該點對點影音互動平台 儲存該住戶所在的一位址資訊;第一行動裝置供訪客透過區域網路而訪問點對點影音互動平台以擷取位址資訊,並根據位址資訊而發送一通知訊息;以及第二行動裝置用以接收通知訊息後,透過區域網路傳送一加密訊息至第一行動裝置,使第一行動裝置對住戶的一電子鎖發送一解鎖訊息以解除門禁,其中該加密訊息係結合當時的一解除門禁時間、一加密演算法與一預設在第二行動裝置內的一組預設密碼。如此一來,本發明透過無線區域的網路進行門禁管理,確實可大幅降低門禁管理的建置成本。 To achieve the above objective, the present invention provides an access control management system for providing a resident to verify the identity of a visitor through a regional network to decide to release the access control to the visitor. The access control system includes a point-to-point interactive platform, a first mobile device, and a second mobile device. The point-to-point audio-visual interactive platform is coupled to the regional network, wherein the point-to-point audio-visual interactive platform Storing a location information of the household; the first mobile device allows the visitor to access the peer-to-peer interactive platform through the local area network to retrieve the address information, and send a notification message according to the address information; and the second mobile device After receiving the notification message, the encrypted message is transmitted to the first mobile device through the local area network, so that the first mobile device sends an unlock message to the electronic lock of the resident to release the access control, wherein the encrypted message is combined with the release of the access control at the time. Time, an encryption algorithm and a predetermined set of passwords preset in the second mobile device. In this way, the present invention can achieve the access control management through the wireless area network, which can greatly reduce the construction cost of the access control.

本發明之另一目的在於提供一種門禁管理方法,其可透過區域網路進行高度安全點對點的通訊驗證機制門禁管理。 Another object of the present invention is to provide an access control management method capable of performing a highly secure peer-to-peer communication verification mechanism access control through a regional network.

為達上述目的,本發明提供一種門禁管理方法,用於提供一住戶透過一區域網路而驗證一訪客的身份,以決定對該訪客解除門禁,該門禁管理方法包含下列步驟:提供一點對點(peer to peer,P2P)影音互動平台於該區域網路中;訪問該點對點影音互動平台;擷取該點對點影音互動平台儲存該住戶所在的一位址資訊;根據該位址資訊而發送一通知訊息;接收該通知訊息後,傳送一加密訊息;以及根據該加密訊息,發送一解鎖訊息至該住戶的一電子鎖以解除門禁,其中該加密訊息係結合當時的一解除門禁時間、一加密演算法與一預設在第二行動裝置內的一組預設密碼。如此一來,本發明可在不同時間下產生的加密訊息具有獨特性,並增加第三方破解密碼的難度,以提高點對點通訊驗證機制的安全性。 To achieve the above objective, the present invention provides an access control management method for providing a resident to verify the identity of a visitor through a regional network to decide to release the access control to the visitor. The access control management method includes the following steps: providing a point-to-point ( Peer to peer, P2P) audio and video interactive platform in the regional network; access to the point-to-point audio-visual interactive platform; capture the point-to-point audio-visual interactive platform to store the address information of the household where the household is located; send a notification message according to the address information Receiving the notification message, transmitting an encrypted message; and transmitting an unlock message to the household electronic lock according to the encrypted message to release the access control, wherein the encrypted message is combined with an unlocking time, an encryption algorithm at the time And a set of preset passwords preset in the second mobile device. In this way, the encrypted message generated by the present invention at different times is unique, and the difficulty of cracking the password by the third party is increased, so as to improve the security of the peer-to-peer communication verification mechanism.

更進一步地說,本發明運用了經濟部技術處提供的P2P互動式影音直播應用平台、一般市售的低價智慧型手機、成本不超過五百元的電子鎖驅動電路、每層樓公用的無線AP(無線網路接取點),即可製作出性能媲美市面上販賣的視訊對講機系統。除了支援影像對講、無線傳輸、密碼解 鎖等功能,我們的「鈴意視見」系統更勝一籌之處在於省去對講機專線的佈線成本。此外「鈴意視見」系統的擴充性極佳而且安裝非常簡單容易。只需要在智慧型手機上下載「鈴意視見」軟體並且完成簡易的設定步驟,該軟體即可自動操作手機透過無線AP連接大廈的區域網路,加入既有的「鈴意視見」視訊門鈴門禁系統。 Furthermore, the present invention utilizes the P2P interactive video live broadcast application platform provided by the technical department of the Ministry of Economic Affairs, a generally low-priced smart mobile phone that is commercially available, an electronic lock drive circuit that costs no more than five hundred yuan, and is common to each floor. A wireless AP (wireless network access point) can produce a video walkie-talkie system that is comparable in performance to the market. In addition to supporting video intercom, wireless transmission, password resolution With the lock and other functions, our "Bell View" system is better than eliminating the wiring costs of the walkie-talkie line. In addition, the "Bell View" system is extremely expandable and easy to install. Simply download the "Bell View" software on your smartphone and complete the easy setup procedure. The software can automatically operate the mobile phone to connect to the building's regional network via wireless AP, and add the existing "Bell View" video. Doorbell access control system.

在參閱圖式及隨後描述之實施方式後,此技術領域具有通常知識者便可瞭解本發明之其他目的,以及本發明之技術手段及實施態樣。 Other objects of the present invention, as well as the technical means and implementations of the present invention, will be apparent to those skilled in the art in view of the appended claims.

1‧‧‧門禁管理系統 1‧‧‧Access Control System

10‧‧‧住戶 10‧‧‧ Households

102‧‧‧電子鎖 102‧‧‧Electronic lock

111‧‧‧位址資訊 111‧‧‧ Location Information

12‧‧‧區域網路 12‧‧‧Regional Network

14‧‧‧點對點影音互動平台 14‧‧‧ Point-to-point audio-visual interactive platform

16‧‧‧第一行動裝置(訪客) 16‧‧‧First mobile device (visitor)

161‧‧‧通知訊息 161‧‧‧Notice message

163‧‧‧解鎖訊息 163‧‧‧Unlock message

18‧‧‧第二行動裝置 18‧‧‧Second mobile device

181‧‧‧加密訊息 181‧‧‧Encrypted messages

步驟S301~步驟S325‧‧‧為第一、二行動裝置間的門禁管理方法之流程圖 Steps S301 to S325‧‧‧ are flowcharts of the access control method between the first and second mobile devices

步驟S327、步驟S329‧‧‧為發送加密訊息之流程圖 Step S327, step S329‧‧‧ is a flow chart for transmitting an encrypted message

第1圖係為本發明一實施例的門禁管理系統之示意圖。 1 is a schematic diagram of an access control management system according to an embodiment of the present invention.

第2圖係為本發明一實施例的第一、二行動裝置的模組示意圖。 FIG. 2 is a schematic diagram of a module of the first and second mobile devices according to an embodiment of the present invention.

第3A圖係為本發明一實施例的第一、二行動裝置間的門禁管理方法之流程圖;以及第3B圖係為本發明一實施例的發送加密訊息之流程圖;以及第4圖係為本發明一實施例的門禁管理系統之另一示意圖。 3A is a flowchart of a method for managing an access control between first and second mobile devices according to an embodiment of the present invention; and FIG. 3B is a flowchart of transmitting an encrypted message according to an embodiment of the present invention; and FIG. Another schematic diagram of an access control management system according to an embodiment of the present invention.

以下將透過數個實施例與數個圖式來解釋本發明內容,然而,本發明的實施例以及圖式所示之結構外型、尺寸僅用以闡釋本發明,並非用以限制本發明需在如實施例所述之任何特定的環境、應用或特殊方式方能實施。 The present invention will be explained by way of several embodiments and several drawings. However, the embodiments and the shapes and sizes of the embodiments shown in the drawings are only for explaining the present invention, and are not intended to limit the present invention. It can be implemented in any particular environment, application or special manner as described in the embodiments.

請參考第1圖所示,其係為本發明一實施例的門禁管理系統之示意圖。門禁管理系統1用於提供一住戶10透過一區域網路12而驗證一訪客的身份,以決定對訪客解除門禁。門禁管理系統1包含一點對點影音互動平台14、一第一行動裝置16以及一第二行動裝置18。 Please refer to FIG. 1 , which is a schematic diagram of an access control management system according to an embodiment of the present invention. The access control system 1 is used to provide a resident 10 to verify the identity of a visitor through a regional network 12 to determine the release of the access control to the visitor. The access control management system 1 includes a point-to-point audio-visual interactive platform 14, a first mobile device 16, and a second mobile device 18.

點對點影音互動平台14用以耦接區域網路12,其中點對點影音互動平台14儲存住戶10所在的一位址資訊111。此處的點對點影音互動平台14可為台灣經濟部所提供的P2P互動式影音直播應用平台。 The point-to-point audio-visual interactive platform 14 is used to couple the local area network 12, wherein the point-to-point audio-visual interactive platform 14 stores the address information 111 where the tenant 10 is located. The peer-to-peer interactive platform 14 here can provide the P2P interactive video live application platform provided by the Taiwan Ministry of Economic Affairs.

第一行動裝置16可為搭載Android系統的智慧型手機,但不以Android系統及智慧型手機限制本發明。實施時,若使用如iOS系統也不脫離本發明之精神;又或者,若使用平板電腦、筆記型電腦等行動裝置也不脫離本發明之精神。第一行動裝置16可供訪客透過住戶10所在的區域網路12而可訪問點對點影音互動平台14,以擷取其位址資訊111。當第一行動裝置16接收位址資訊111後,便根據位址資訊111而發送一通知訊息161。前述的位址資訊111包含住戶10的樓層、房號及/或門號之類的相關資訊。 The first mobile device 16 may be a smart phone equipped with an Android system, but does not limit the present invention by the Android system and the smart phone. In the implementation, the use of the iOS system does not depart from the spirit of the present invention; or, if a mobile device such as a tablet or a notebook computer is used, the spirit of the present invention is not deviated. The first mobile device 16 can be accessed by the visitor through the local area network 12 where the tenant 10 is located to access the peer-to-peer interactive platform 14 to retrieve the address information 111. When the first mobile device 16 receives the address information 111, it sends a notification message 161 based on the address information 111. The aforementioned address information 111 contains related information such as the floor, room number and/or door number of the tenant 10.

第二行動裝置19也可為搭載Android系統的智慧型手機,但不以Android系統及智慧型手機限制本發明。實施時,若使用如iOS系統也不脫離本發明之精神;又或者,若使用平板電腦、筆記型電腦等行動裝置也不脫離本發明之精神。第二行動裝置18用以接收通知訊息161後,透過區域網路12傳送一加密訊息181至第一行動裝置16,使第一行動裝置16對住戶10的一電子鎖102發送一解鎖訊息163以解除門禁,其中解鎖訊息163透過第一行動裝置16的一耳機孔(圖未示)傳送至住戶10的電子鎖102以解除門禁。本發明的技術特徵在於,加密訊息181係結合當時的一解除門禁時間。也就是說本發明在不同時間下產生的加密訊息181具有獨特性,並增加第三方破解密碼的難度,以提高點對點通訊驗證機制的安全性。而前述的加密訊息可為一RSA加密演算法。 The second mobile device 19 may also be a smart phone equipped with an Android system, but the present invention is not limited by the Android system and the smart phone. In the implementation, the use of the iOS system does not depart from the spirit of the present invention; or, if a mobile device such as a tablet or a notebook computer is used, the spirit of the present invention is not deviated. After receiving the notification message 161, the second mobile device 18 transmits an encrypted message 181 to the first mobile device 16 through the area network 12, so that the first mobile device 16 sends an unlock message 163 to an electronic lock 102 of the household 10. The access control is released, wherein the unlocking message 163 is transmitted to the electronic lock 102 of the household 10 through an earphone hole (not shown) of the first mobile device 16 to release the access control. The technical feature of the present invention is that the encrypted message 181 is combined with an unlocking time at that time. That is to say, the encrypted message 181 generated by the present invention at different times is unique, and the difficulty of cracking the password by the third party is increased to improve the security of the peer-to-peer communication verification mechanism. The aforementioned encrypted message can be an RSA encryption algorithm.

請參考第2圖,其係為本發明一實施例的第一、二行動裝置的模組示意圖。實施本發明時,第一行動裝置16需包含一室外機模組201、一第操作介面模組203、一人臉偵測模組205以及一身份驗證解密模組207。第二行動裝置18包含一室內機模組209、一身份驗證加密模組211以及一第二操作介面模組213。 Please refer to FIG. 2, which is a schematic diagram of a module of the first and second mobile devices according to an embodiment of the present invention. In the implementation of the present invention, the first mobile device 16 needs to include an outdoor unit module 201, a first operation interface module 203, a face detection module 205, and an identity verification decryption module 207. The second mobile device 18 includes an indoor unit module 209, an identity verification encryption module 211, and a second operation interface module 213.

第一行動裝置16的室外機模組201用以訪問點對點影音互動平台14以擷取位址資訊111後發送通知訊息161至第二行動裝置18的室內機模組209,以使室內機模組209接收來自第一行動裝置16的通知訊息161。通知訊息161的目的主要是讓第一行動裝置16與第二行動裝置18之間清楚確認彼此已連線。 The outdoor unit module 201 of the first mobile device 16 is configured to access the peer-to-peer interactive platform 14 to retrieve the address information 111 and then send the notification message 161 to the indoor unit module 209 of the second mobile device 18 to enable the indoor unit module 209 receives the notification message 161 from the first mobile device 16. The purpose of the notification message 161 is primarily to allow the first mobile device 16 and the second mobile device 18 to clearly confirm that they are connected to each other.

接著,第一行動裝置16引導訪客進入第一操作介面模組203。具體而言,此時的第一行動裝置16的使用者介面便出現由第一操作介面模組203所包含的「密碼開門」與「視訊對講」的選單,供訪客選擇要以何種方式和欲拜訪的住戶取得聯繫。 Next, the first mobile device 16 directs the visitor to the first operational interface module 203. Specifically, at this time, the user interface of the first mobile device 16 displays a menu of "password open" and "video intercom" included in the first operation interface module 203 for the visitor to select. Get in touch with the residents you want to visit.

舉例來說,當訪客選擇「密碼開門」時,第一行動裝置16上的鏡頭被開啟並啟動人臉偵測模組205以偵測訪客的臉部特徵。偵測臉部特徵的期間,人臉偵測模組205會不時地回傳該訪客的臉部特徵至第二行動裝置18。若未偵測到訪客的臉部特徵,則在第一行動裝置16的螢幕上提示訪客要正視鏡頭,並重新偵測;若在五秒內持續偵測不到人臉則返回主畫面。若成功偵測到臉部特徵,則在第一行動裝置16的螢幕上顯示虛擬數字鍵盤以供訪客輸入密碼。關於訪客如何獲得輸入密碼將在稍後說明第二行動裝置18時予以詳述。 For example, when the visitor selects "Password Open", the lens on the first mobile device 16 is turned on and the face detection module 205 is activated to detect the facial features of the visitor. During the detection of facial features, the face detection module 205 may return the facial features of the visitor to the second mobile device 18 from time to time. If the facial feature of the visitor is not detected, the visitor of the first mobile device 16 is prompted to face the lens and re-detect; if the face is not detected continuously within five seconds, the main screen is returned. If the facial feature is successfully detected, a virtual numeric keypad is displayed on the screen of the first mobile device 16 for the visitor to enter the password. How the visitor obtains the input password will be described in detail later when the second mobile device 18 is explained.

當訪客選擇「視訊對講」時,第一行動裝置16的螢幕上顯示虛擬數字鍵盤並要求訪客輸入位址資訊111,例如樓層、房號及/或門號,藉此開啟P2P視訊對話。接著,住戶透過第二行動裝置18選擇「接聽」或「掛斷」。若選擇「掛斷」,則結束彼此間的通訊;若選擇「接聽」,則進入下一個動作。亦即,若欲拜訪的住戶同意訪客進入,則透過第二行動裝置18發送加密訊息181至第一行動裝置16,並讓第一行動裝置16的身份驗證解密模組207對加密訊息181進行解密,然後第一行動裝置16對住戶的電子鎖102發送解鎖訊息163以解除門禁。 When the visitor selects "video intercom", the first mobile device 16 displays a virtual numeric keypad on the screen and asks the visitor to enter the address information 111, such as the floor, room number and/or door number, thereby opening the P2P video session. Then, the resident selects "answer" or "hang up" through the second mobile device 18. If you select "Hang Up", the communication between them will end; if you select "Receive", the next action will be entered. That is, if the resident who wants to visit agrees to the visitor, the encrypted message 181 is sent to the first mobile device 16 via the second mobile device 18, and the authentication decryption module 207 of the first mobile device 16 decrypts the encrypted message 181. The first mobile device 16 then sends an unlock message 163 to the household's electronic lock 102 to release the access control.

需更進一步說明的是,室內機模組209接收並驗證過來自第一行動裝置16的「密碼開門」或「視訊對講」的指令後,身份驗證加密模組211就開始執行對第一行動裝置16欲發送的資料進行加密以形成加密訊息181。本發明的加密訊息181係結合當下的一解除門禁時間、一RSA加密演算法與一預設在該第二行動裝置內的一組預設密碼。如此一來,加密訊息181具有獨特性,並增加第三方破解密碼的難度,以提高點對點通訊驗證機制的安全性。 It should be further explained that after the indoor unit module 209 receives and verifies the "password opening" or "video intercom" command from the first mobile device 16, the authentication and encryption module 211 starts performing the first action. The data to be transmitted by device 16 is encrypted to form encrypted message 181. The encrypted message 181 of the present invention is combined with a current unlocking time, an RSA encryption algorithm and a predetermined set of passwords preset in the second mobile device. In this way, the encrypted message 181 is unique and increases the difficulty of the third party to crack the password to improve the security of the peer-to-peer communication verification mechanism.

最後,進入執行第二操作介面模組213,也就是說,此時的第二行動裝置18的使用者介面出現供住戶決定是否對第一行動裝置16發送加密訊息181。若住戶的決定為「是」,則第二行動裝置18便發送加密訊息181給第一行動裝置16,進而讓身份驗證解密模組207對加密訊息181進行解密,然後對住戶的電子鎖102發送解鎖訊息163以解除門禁。若住戶的決定為「否」,則第二行動裝置18等待接收下一個通知訊息。 Finally, the second operation interface module 213 is executed, that is, the user interface of the second mobile device 18 at this time appears for the user to decide whether to send the encrypted message 181 to the first mobile device 16. If the decision of the resident is "Yes", the second mobile device 18 sends an encrypted message 181 to the first mobile device 16, and then causes the authentication decryption module 207 to decrypt the encrypted message 181 and then sends the electronic lock 102 to the resident. Unlock message 163 to unlock the door. If the household's decision is "NO", the second mobile device 18 waits to receive the next notification message.

請參考第3A圖,其係為本發明一實施例的第一、二行動裝置間的門禁管理方法之流程圖。其中第一、二行動裝置可為搭載Android系統 的智慧型手機,但不以Android系統及智慧型手機限制本發明。本發明的門禁管理方法用於提供一住戶透過一區域網路而驗證一訪客的身份,以決定對訪客解除門禁,該門禁管理方法包含下列步驟。 Please refer to FIG. 3A, which is a flowchart of a method for managing access control between first and second mobile devices according to an embodiment of the present invention. The first and second mobile devices can be equipped with an Android system. The smart phone, but does not limit the invention by Android system and smart phone. The access control management method of the present invention is for providing a resident to verify the identity of a visitor through a regional network to decide to release the access control to the visitor. The access control management method comprises the following steps.

首先,於步驟S301提供一點對點影音互動平台於區域網路中,此處的點對點影音互動平台係為經濟部所提供的P2P互動式影音直播應用平台。然而,實施本發明時並以此平台為限。接著,進行步驟S303,第一行動裝置可供訪客透過住戶所在的區域網路而可訪問點對點影音互動平台。然後,進行步驟S305,第一行動裝置擷取點對點影音互動平台的一位址資訊。當第一行動裝置接收位址資訊後,再進行步驟S307,根據位址資訊而發送一通知訊息,其中通知訊息的目的主要是讓第一行動裝置與第二行動裝置之間清楚確認彼此已連線,而前述的位址資訊包含住戶的樓層、房號及/或門號之類的相關資訊。 First, in step S301, a point-to-point audio-visual interactive platform is provided in the regional network, where the point-to-point audio-visual interactive platform is a P2P interactive video live application platform provided by the Ministry of Economic Affairs. However, the implementation of the present invention is limited to this platform. Next, proceeding to step S303, the first mobile device is provided for the visitor to access the peer-to-peer interactive platform through the local area network of the resident. Then, in step S305, the first mobile device captures the address information of the peer-to-peer interactive platform. After the first mobile device receives the address information, proceeding to step S307, sending a notification message according to the address information, wherein the purpose of the notification message is mainly to make the first mobile device and the second mobile device clearly confirm that they are connected to each other. Line, and the aforementioned address information includes information such as the floor, room number and/or door number of the resident.

在通知訊息被第一行動裝置發送之前,會先執行步驟S309,提供包含一密碼開門與一視訊對講的選單。也就是說,第一行動裝置會引導訪客進入使用者介面選擇「密碼開門」與「視訊對講」其中之一選項。 Before the notification message is sent by the first mobile device, step S309 is performed first, and a menu including a password opening and a video intercom is provided. In other words, the first mobile device will guide the visitor to the user interface to select one of the options of "password open" and "video intercom".

當訪客選擇「密碼開門」的選項時,則進入步驟S311,第一行動裝置對訪客開啟鏡頭並回傳訪客的臉部特徵至第二行動裝置。然後執行步驟S313,第二行動裝置根據訪客的臉部特徵而輸出一判斷結果,若該判斷結果為「成功」,則執行步驟S315,傳送一加密訊息至訪客(或者說訪客的第一行動裝置)。若該判斷結果為「失敗」,則執行步驟S321,等待下一個通知訊息。 When the visitor selects the "Password Open" option, the process proceeds to step S311, where the first mobile device opens the lens to the visitor and returns the facial features of the visitor to the second mobile device. Then, in step S313, the second mobile device outputs a determination result according to the facial features of the visitor. If the determination result is "successful", step S315 is performed to transmit an encrypted message to the visitor (or the first mobile device of the visitor). ). If the result of the determination is "failure", step S321 is performed to wait for the next notification message.

完成步驟S315後,接續執行步驟S317,第一行動裝置接收該加密訊息並進行解密。最後,執行步驟S319,第一行動裝置發送一解鎖訊息 至住戶的一電子鎖以解除門禁。需特別說明的是,本發明的技術特徵在於,透過該加密訊息係結合當時的一解除門禁時間、一加密演算法與一預設在該第二行動裝置內的一組預設密碼,以使加密訊息不僅具有獨特性,而且增加第三方破解密碼的難度,以提高點對點通訊驗證機制的安全性。 After step S315 is completed, step S317 is performed, and the first mobile device receives the encrypted message and decrypts it. Finally, in step S319, the first mobile device sends an unlock message. An electronic lock to the household to unlock the door. It should be particularly noted that the technical feature of the present invention is that the encrypted message is combined with a release time, an encryption algorithm, and a preset set of preset passwords in the second mobile device. Encrypted messages are not only unique, but also increase the difficulty of third-party password cracking to improve the security of the peer-to-peer communication verification mechanism.

請參考第3B圖,其係為本發明一實施例的發送加密訊息之流程圖。若步驟S313中的判斷結果為「成功」,則進入步驟S327,於第二行動裝置中形成加密訊息。然後,執行步驟S329,第二行動裝置的螢幕上提供該住戶決定是否發送該加密訊息。若判斷為「是」,則進行步驟S315;若判斷為「否」,則回到步驟S321。 Please refer to FIG. 3B, which is a flowchart of sending an encrypted message according to an embodiment of the present invention. If the result of the determination in step S313 is "success", the process proceeds to step S327, where an encrypted message is formed in the second mobile device. Then, step S329 is performed, and the resident of the second mobile device is provided to decide whether to send the encrypted message. If the determination is YES, the process proceeds to step S315. If the determination is "NO", the process returns to step S321.

承上所述,實施本發明時,其步驟S327與步驟S329的次序可予以對調,其對調後的執行結果並不影響門禁管理方法所產生的效能。 As described above, when the present invention is implemented, the order of step S327 and step S329 can be reversed, and the effect of the adjusted execution does not affect the performance of the access control management method.

再回到第3A圖,並參考第4圖,其係為本發明一實施例的門禁管理系統之另一示意圖。當訪客選擇「視訊對講」時,則進入步驟S323,第一行動裝置的螢幕上顯示虛擬數字鍵盤並要求訪客輸入位址資訊,例如樓層、房號及/或門號。然後進入步驟S325,第二行動裝置收到訪客的位址資訊而與第一行動裝置建立P2P視訊對話。然後再依序進入步驟S327、步驟S329。至於其後的執行步驟與前述的「密碼開門」無異,於此不予贅述。 Returning to FIG. 3A and referring to FIG. 4, it is another schematic diagram of the access control management system according to an embodiment of the present invention. When the visitor selects "video intercom", the process proceeds to step S323, where the virtual number keypad is displayed on the screen of the first mobile device and the visitor is required to input address information such as floor, room number and/or door number. Then, proceeding to step S325, the second mobile device receives the address information of the visitor and establishes a P2P video conversation with the first mobile device. Then, the process proceeds to step S327 and step S329. The subsequent execution steps are the same as the aforementioned "password opening", and will not be described here.

綜上所述,本發明透過無線區域的門禁管理系統及其方法不僅可大幅降低門禁管理的建置成本,而且在不同時間下產生的加密訊息具有獨特性,並增加第三方破解密碼的難度,以提高點對點通訊驗證機制的安全性。 In summary, the access control management system and the method thereof in the wireless area of the present invention can not only greatly reduce the construction cost of the access control management, but also have the uniqueness of the encrypted information generated at different times and increase the difficulty of the third party to crack the password. To improve the security of the peer-to-peer communication verification mechanism.

1‧‧‧門禁管理系統 1‧‧‧Access Control System

10‧‧‧住戶 10‧‧‧ Households

102‧‧‧電子鎖 102‧‧‧Electronic lock

111‧‧‧位址資訊 111‧‧‧ Location Information

12‧‧‧區域網路 12‧‧‧Regional Network

14‧‧‧點對點影音互動平台 14‧‧‧ Point-to-point audio-visual interactive platform

16‧‧‧第一行動裝置(訪客) 16‧‧‧First mobile device (visitor)

161‧‧‧通知訊息 161‧‧‧Notice message

163‧‧‧解鎖訊息 163‧‧‧Unlock message

18‧‧‧第二行動裝置 18‧‧‧Second mobile device

181‧‧‧加密訊息 181‧‧‧Encrypted messages

Claims (10)

一種門禁管理系統,用於提供一住戶透過一區域網路而驗證一訪客的身份,以決定對該訪客解除門禁,該門禁管理系統包含:一點對點(peer to peer,P2P)影音互動平台,用以耦接該區域網路,其中該點對點影音互動平台儲存該住戶所在的一位址資訊;一第一行動裝置,供該訪客透過該區域網路而訪問該點對點影音互動平台以擷取該位址資訊,並根據該位址資訊而發送一通知訊息;以及一第二行動裝置,用以接收該通知訊息後,透過該區域網路傳送一加密訊息至該第一行動裝置,使該第一行動裝置對該住戶的一電子鎖發送一解鎖訊息以解除門禁,其中該加密訊息係結合當時的一解除門禁時間、一加密演算法與一預設在該第二行動裝置內的一組預設密碼。 An access control management system for providing a resident to verify the identity of a visitor through a regional network to decide to release the access control to the visitor. The access control management system includes: a peer-to-peer (P2P) audio-visual interactive platform, The point-to-point audio-visual interactive platform stores the address information of the household where the household is located; and a first mobile device for the visitor to access the point-to-point interactive platform through the regional network to capture the location Address information, and sending a notification message according to the address information; and a second mobile device, after receiving the notification message, transmitting an encrypted message to the first mobile device through the local area network, so that the first The mobile device sends an unlock message to the electronic lock of the resident to cancel the access control, wherein the encrypted message is combined with a release time at the time, an encryption algorithm and a preset set in the second mobile device. password. 如請求項1所述之門禁管理系統,其中該第一行動裝置更包含:一室外機模組,用以訪問該點對點影音互動平台以擷取該位址資訊後發送該通知訊息;一第一操作介面模組,包含一密碼開門與一視訊對講的選單,當該通知訊息被發送後,用以引導該訪客選擇該密碼開門及該視訊對講其中之一;以及一人臉偵測模組,用以當該訪客選定該密碼開門的選項時,回傳該訪客的臉部特徵至該第二行動裝置;以及一身份驗證解密模組,用以確認該訪客的臉部特徵後,解密來自該第二行動裝置所傳送的該加密訊息,然後該第一行動裝置對該住戶的該電子鎖發送該解鎖訊息以解除門禁。 The access control management system of claim 1, wherein the first mobile device further comprises: an outdoor unit module, configured to access the point-to-point audio-visual interactive platform to retrieve the address information and send the notification message; The operation interface module includes a password opening and a video intercom menu, and when the notification message is sent, is used to guide the visitor to select the password to open the door and the video intercom; and a face detection module And when the visitor selects the password to open the door, the facial feature of the visitor is returned to the second mobile device; and an authentication and decryption module is used to confirm the facial feature of the visitor, and the decryption comes from The encrypted message transmitted by the second mobile device, and then the first mobile device sends the unlock message to the electronic lock of the resident to release the access control. 如請求項2所述之門禁管理系統,其中該第一操作介面模組更包含:當該訪客選定該視訊對講的選項時,則要求該訪客輸入該位址資訊。 The access control management system of claim 2, wherein the first operation interface module further comprises: when the visitor selects the video intercom option, the visitor is required to input the address information. 如請求項2所述之門禁管理系統,其中該第二行動裝置更包含: 一室內機模組,用以接收來自該第一行動裝置的該通知訊息;一身份驗證加密模組,根據該通知訊息而形成該加密訊息;以及一第二操作介面模組,供該住戶決定是否對該第一行動裝置發送該加密訊息。 The access control management system of claim 2, wherein the second mobile device further comprises: An indoor unit module for receiving the notification message from the first mobile device; an identity verification encryption module forming the encrypted message according to the notification message; and a second operation interface module for the household to decide Whether the encrypted message is sent to the first mobile device. 如請求項1所述之門禁管理系統,其中該解鎖訊息透過該第一行動裝置的一耳機孔傳送至該住戶的該電子鎖以解除門禁。 The access control management system of claim 1, wherein the unlocking message is transmitted to the electronic lock of the household through an earphone hole of the first mobile device to release the access control. 一種門禁管理方法,用於提供一住戶透過一區域網路而驗證一訪客的身份,以決定對該訪客解除門禁,該門禁管理方法包含下列步驟:提供一點對點(peer to peer,P2P)影音互動平台於該區域網中;訪問該點對點影音互動平台;擷取該點對點影音互動平台儲存該住戶所在的一位址資訊;根據該位址資訊而發送一通知訊息;接收該通知訊息後,傳送一加密訊息至該訪客;以及根據該加密訊息,發送一解鎖訊息至該住戶的一電子鎖以解除門禁,其中該加密訊息係結合當時的一解除門禁時間、一加密演算法與一組預設密碼。 An access control management method for providing a resident to verify the identity of a visitor through a regional network to decide to release the access control to the visitor. The access control management method comprises the following steps: providing peer-to-peer (P2P) video and audio interaction The platform is in the regional network; accessing the point-to-point audio-visual interactive platform; capturing the point-to-point audio-visual interactive platform to store the address information of the household where the household is located; sending a notification message according to the address information; receiving the notification message, transmitting one Encrypting the message to the visitor; and, according to the encrypted message, sending an unlock message to the electronic lock of the resident to cancel the access control, wherein the encrypted message is combined with an unlocking time, an encryption algorithm and a predetermined set of passwords at the time . 如請求項6所述之門禁管理方法,其中執行該「根據該位址資訊而發送一通知訊息」後,更包含下列步驟:提供包含一密碼開門與一視訊對講的選單;當該通知訊息被發送後,引導該訪客選擇該密碼開門及該視訊對講其中之一;當該訪客選定該密碼開門的選項時,回傳該訪客的臉部特徵;根據該訪客的臉部特徵而輸出一判斷結果,若該判斷結果為「成功」,則傳送該加密訊息;以及接收該加密訊息並進行解密。 The access control management method of claim 6, wherein the performing the "sending a notification message according to the address information" further comprises the steps of: providing a menu including a password opening and a video intercom; and the notification message After being sent, the visitor is guided to select the password to open the door and one of the video intercom; when the visitor selects the option to open the password, the facial feature of the visitor is returned; and a facial feature is output according to the facial feature of the visitor. If the result of the determination is "success", the encrypted message is transmitted; and the encrypted message is received and decrypted. 如請求項7所述之門禁管理方法,更包含下列步驟:當該訪客選定該視訊對講的選項時,則要求該訪客輸入該位址資訊。 The access control management method of claim 7, further comprising the step of: when the visitor selects the video intercom option, the visitor is required to input the address information. 如請求項7所述之門禁管理方法,更包含下列步驟: 根據該判斷結果為「成功」而形成該加密訊息;以及提供該住戶決定是否發送該加密訊息。 The access control management method described in claim 7 further includes the following steps: Forming the encrypted message according to the result of the determination as "success"; and providing the household to decide whether to send the encrypted message. 如請求項7所述之門禁管理方法,其中若該判斷結果為「失敗」,則等待下一個通知訊息。 The access control management method of claim 7, wherein if the determination result is "failed", the next notification message is awaited.
TW104116605A 2015-05-22 2015-05-22 Access control system and its method TWI553595B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW104116605A TWI553595B (en) 2015-05-22 2015-05-22 Access control system and its method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW104116605A TWI553595B (en) 2015-05-22 2015-05-22 Access control system and its method

Publications (2)

Publication Number Publication Date
TWI553595B true TWI553595B (en) 2016-10-11
TW201642225A TW201642225A (en) 2016-12-01

Family

ID=57848280

Family Applications (1)

Application Number Title Priority Date Filing Date
TW104116605A TWI553595B (en) 2015-05-22 2015-05-22 Access control system and its method

Country Status (1)

Country Link
TW (1) TWI553595B (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TW201107577A (en) * 2010-11-12 2011-03-01 xian-tang Lin Intelligent gate security system with one-time password function
CN204102215U (en) * 2014-09-23 2015-01-14 昆山五昌新精密电子工业有限公司 The management system of far-end access control
WO2015031812A1 (en) * 2013-08-30 2015-03-05 SkyBell Technologies, Inc. Doorbell communication systems and methods

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TW201107577A (en) * 2010-11-12 2011-03-01 xian-tang Lin Intelligent gate security system with one-time password function
WO2015031812A1 (en) * 2013-08-30 2015-03-05 SkyBell Technologies, Inc. Doorbell communication systems and methods
CN204102215U (en) * 2014-09-23 2015-01-14 昆山五昌新精密电子工业有限公司 The management system of far-end access control

Also Published As

Publication number Publication date
TW201642225A (en) 2016-12-01

Similar Documents

Publication Publication Date Title
US11055392B2 (en) Proximity unlock and lock operations for electronic devices
CN107683601B (en) Relay services for the communication between controller and attachment
CN104202306B (en) Access authentication method, Apparatus and system
KR101693130B1 (en) Information interaction method and device
TWI544778B (en) Remote doorbell control system and its samrt doorbell device
WO2016201811A1 (en) Identity authentication method, apparatus and system
CN105393564A (en) Communication between host and accessory devices using accessory protocols via wireless transport
CN106664226A (en) Controller networks for an accessory management system
CN104503688A (en) Intelligent hardware device control achieving method and device
CN104869612A (en) Method and device for accessing network
CN104091376A (en) Intelligent lock control method and apparatus thereof
WO2015035936A1 (en) Identity authentication method, identity authentication apparatus, and identity authentication system
CN104158659B (en) Anti-counterfeit authentication method, device and system
CN106888206A (en) Key exchange method, apparatus and system
CN106961334A (en) Secure wireless communication between controller and annex
US20190089693A1 (en) Systems and methods for authenticating internet-of-things devices
CN105491229A (en) Method and device for remotely controlling mobile terminal
TW201800653A (en) Bluetooth door lock system with emergency reporting function and method for operating the same capable of correctly and instantly reporting emergency conditions
CN105791309A (en) Method, device and system for executing business processing
CN104780045A (en) Management method and management device for intelligent devices
TWM449319U (en) Remote doorbell control system and its smart doorbell device
CN104378596A (en) Method and device for conducting remote conversation with camera
KR102459799B1 (en) System and method for managing entrance and exit of common entrance door
TWI553595B (en) Access control system and its method
CN105809052A (en) Binding information recording method and apparatus

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees