WO2017200273A1 - 카드 정보 및 단말 정보를 기반으로 출입을 제어하는 장치, 시스템 및 방법 - Google Patents

카드 정보 및 단말 정보를 기반으로 출입을 제어하는 장치, 시스템 및 방법 Download PDF

Info

Publication number
WO2017200273A1
WO2017200273A1 PCT/KR2017/005072 KR2017005072W WO2017200273A1 WO 2017200273 A1 WO2017200273 A1 WO 2017200273A1 KR 2017005072 W KR2017005072 W KR 2017005072W WO 2017200273 A1 WO2017200273 A1 WO 2017200273A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
terminal
authentication
card
access
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/KR2017/005072
Other languages
English (en)
French (fr)
Inventor
김태균
손인호
신명순
이정일
조대성
강봉권
이인수
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
KT Corp
Original Assignee
KT Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by KT Corp filed Critical KT Corp
Publication of WO2017200273A1 publication Critical patent/WO2017200273A1/ko
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/20Individual registration on entry or exit involving the use of a pass
    • G07C9/22Individual registration on entry or exit involving the use of a pass in combination with an identity check of the pass holder
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06KGRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
    • G06K19/00Record carriers for use with machines and with at least a part designed to carry digital markings
    • G06K19/06Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
    • G06K19/067Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components
    • G06K19/07Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components with integrated circuit chips
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06KGRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
    • G06K19/00Record carriers for use with machines and with at least a part designed to carry digital markings
    • G06K19/06Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
    • G06K19/067Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components
    • G06K19/07Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components with integrated circuit chips
    • G06K19/0723Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components with integrated circuit chips the record carrier comprising an arrangement for non-contact communication, e.g. wireless communication circuits on transponder cards, non-contact smart cards or RFIDs
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06KGRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
    • G06K7/00Methods or arrangements for sensing record carriers, e.g. for reading patterns
    • G06K7/10Methods or arrangements for sensing record carriers, e.g. for reading patterns by electromagnetic radiation, e.g. optical sensing; by corpuscular radiation
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06KGRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
    • G06K7/00Methods or arrangements for sensing record carriers, e.g. for reading patterns
    • G06K7/10Methods or arrangements for sensing record carriers, e.g. for reading patterns by electromagnetic radiation, e.g. optical sensing; by corpuscular radiation
    • G06K7/10009Methods or arrangements for sensing record carriers, e.g. for reading patterns by electromagnetic radiation, e.g. optical sensing; by corpuscular radiation sensing by radiation using wavelengths larger than 0.1 mm, e.g. radio-waves or microwaves
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/20Individual registration on entry or exit involving the use of a pass
    • G07C9/27Individual registration on entry or exit involving the use of a pass with central registration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities

Definitions

  • the present invention is a technology of access control, and more specifically, when collecting the terminal information of the user, when receiving a request for access authentication including the user's card information, the collected terminal information and the requested card information is authenticated to the user's An apparatus, system, and method for controlling access.
  • a user is authenticated using biometric information or a password such as a user's fingerprint, iris, and the like, and the user's access is selectively allowed according to the authentication result.
  • the access management technology using the RFID authenticates whether the RFID received from the user's terminal or the card is registered identification information, and permits the user's access.
  • MFA Multi Factor Authentication
  • the present invention was created under the recognition of the prior art as described above, an apparatus, system and method for authenticating card ID and terminal information of a user who is requested for access authentication based on MFA, and allowing access of a successful authentication user.
  • the purpose is to provide.
  • the present invention collects the location information of the user terminal by dividing the peripheral area where the access device is located in a Wi-Fi zone, the location information of the access device and the terminal information collected the authentication of the card ID is Upon confirming a match, another purpose is to control the opening and closing of the access device through which the user passes by the success of the access authentication.
  • an apparatus for controlling access based on card information and terminal information may include: a collector configured to collect terminal information of a user terminal received by an access point (AP) device around an access device; A receiving unit which receives a request for access authentication including card information of a user read by the access device; Determining an authentication result of multi factor authentication (MFA) including card authentication for determining whether card information for which authentication is requested is registered card information and terminal authentication for determining whether terminal information of received card information is the collected terminal information. Determination unit; And a control unit which transmits control information for which the determined authentication result is successful to the access device to control an access permission of the user.
  • MFA multi factor authentication
  • the collection unit collects, as the terminal information, terminal identification information received by the AP device through Wi-Fi communication or beacon communication.
  • the collecting unit collects the terminal information by executing Wi-Fi of the user terminal in which the function of always searching for the AP device is executed even when the Wi-Fi receiving function is turned off.
  • the receiving unit receives, as the card information, RFID (Radio Frequency IDentification) of the access card read by the reader of the access device.
  • RFID Radio Frequency IDentification
  • the apparatus further includes a DB (DataBase) for storing the card ID of the user's access card and the terminal identification information of the matched user terminal, the determination unit, the card ID of the card information requested for authentication as a key from the DB
  • the card authentication is determined to be successful. If the inquired terminal identification information is the collected terminal identification information, the terminal authentication is determined to be successful. The MFA authentication result is determined to be success.
  • the control unit transmits access control information of the access permission to the gate controller of the access device, and the gate controller controls the gate device through which the user passes by access control by the transmitted control information.
  • the device may include a DB in which a peripheral area of the access device is divided into a plurality of unit areas, and the strength of a wireless signal received from neighboring AP devices in each unit area is stored as location information for each unit area.
  • the collection unit collects the terminal information including the terminal identification information of the user terminal and the strength of each radio signal received in the unit area through the AP device.
  • the determination unit inquires of the position information most matched from the DB using the strength of the collected wireless signal as a key, and determines the unit area of the inquired location area as the unit area where the user terminal is located.
  • the DB further stores the unit area information where the access device is located,
  • the determination unit determines that the terminal authentication is successful when querying the unit region information of the access device from the DB using the unit region information of the collected terminal information as a key.
  • a system for controlling access based on card information and terminal information includes: a user terminal receiving a wireless signal from each AP device and transmitting terminal information in response; An AP device installed around each access device and receiving the terminal information from a user terminal receiving the wireless signal and transmitting the terminal information to a control device; An access device that reads card information of a user requesting access permission, requests access authentication including the card information, receives control information of an authentication result, and permits or disables user access; And collecting the terminal information through the AP device, receiving the authentication request from the access device, and determining whether the received card information is registered card information and the terminal information of the received card information and the card authentication. And a control device for determining an authentication result of the MFA including terminal authentication for determining whether the information is information and transmitting control information for which the determined authentication result is successful to the access device.
  • a method of controlling an access based on card information and terminal information comprising: collecting terminal information of a user terminal received by an AP device around an access device; Receiving an access authentication request including card information of a user read by the access device; Determining an authentication result of the MFA including card authentication for determining whether the card information requested for authentication is registered card information and terminal authentication for determining whether the terminal information of the received card information is the collected terminal information; And controlling the access permission of the user by transmitting control information having a successful authentication result to the access device.
  • the present invention has an advantage of improving the security of access management by granting access to a user only when both card authentication and terminal authentication are successful based on MFA.
  • FIG. 1 is a schematic structural diagram of a system according to an embodiment of the present invention.
  • FIG. 2 is a schematic internal configuration diagram of the control server of FIG. 1.
  • FIG. 3 is a signal flow diagram of an MFA authentication process according to an embodiment of the present invention.
  • RSSI 4 is an exemplary diagram of location information based on Received Signal Strength Identification (RSSI) according to another embodiment of the present invention.
  • FIG. 5 is an exemplary diagram in which location information of a unit area of FIG. 4 is stored.
  • FIG. 6 is an exemplary diagram of a control server collecting RSSI based location information of FIG. 4.
  • FIG. 7 is a signal flow diagram of an MFA authentication process according to another embodiment of the present invention.
  • FIG. 1 is a schematic structural diagram of a system 100 according to an embodiment of the present invention.
  • System 100 is an AP device 130 for receiving the terminal information of the user terminal 110, the card information is read access card 111, the terminal information of the user terminal 110, the terminal information is collected; ), The control server 150 for MFA authentication of the user's access based on the terminal information and the card information, and reads the card information of the access card 111 to request the access authentication to the control server 150, the control server 150 It is configured to include an access device 170 for receiving or permitting the user's access to receive the MFA authentication result from.
  • the user terminal 110 includes a smart terminal (eg, a smart phone) that receives a wireless communication service through the AP device 130.
  • the user terminal 110 may receive respective wireless signals from a plurality of AP devices 130 installed in the vicinity. When each wireless signal is received, the user terminal 110 selects the primary AP device 130 to receive a wireless communication service.
  • the user terminal 110 receives a wireless signal based on the beacon communication and Wi-Fi communication from the AP device 130, and the terminal information such as MAC address, USIM identification information, IMSI, etc. as the response information of the received wireless signal, AP Transmitted to the device 130 to receive a wireless communication service.
  • the terminal information is not particularly limited as long as it includes information uniquely identifying the user terminal 110.
  • the user terminal 110 should have a communication function for receiving a radio signal and a response of the terminal information.
  • the user terminal 110 is configured to always search for nearby AP devices 130. That is, the user terminal 110 is set to the "Always search allowed" function (for example, Android version 4.3 (SDK 18) or more) to the reception function of the Wi-Fi. Then, the user terminal 110 may scan the surrounding AP device 130 even when the Wi-Fi receiving function is turned off.
  • the "Always search allowed" function for example, Android version 4.3 (SDK 18) or more
  • the smart phone when the user terminal 110 is set as the "Always search" function is set as a smart phone, when a specific SSID is scanned as a background function supported by the Android OS, the smart phone automatically activates the Wi-Fi function.
  • the smart phone monitors the SSID transmitted from the AP device 130 or the base station, and activates the Wi-Fi function when the specific SSID transmitted by the AP device 130 around the access device 170 is scanned.
  • the AP device 130 may receive the terminal information of the smart phone and transmit it to the control server 150 in the process of processing the SSID-based connection from the smart phone. Then, the control server 150 may collect the terminal information of the smart phone in proximity to the access device 170 through the AP device 130.
  • the AP device 130 is installed in a plurality of peripheral areas where the access device 130 is located, transmits the wireless signal to the surrounding user terminals 110, establishes a wireless communication service, and provides a wireless Internet service. .
  • the AP device 130 receives terminal information from the user terminal 110 that has received the transmitted radio signal (1), and receives the received terminal information for the control server 150 for MFA authentication. (2).
  • the access card 111 is a card (for example, an RF card) possessed by the user for access authentication, and stores a card ID such as RFID in an internal storage. Access card 111 may be applied to a variety of communication methods for the transmission of the card ID is not necessarily limited to RF communication.
  • the user terminal 110 stores the card information of the mobile card, and supports various communication methods (eg, Wi-Fi, Bluetooth, NFC, etc.) supported by the user terminal 110. Card information can be sent.
  • various communication methods eg, Wi-Fi, Bluetooth, NFC, etc.
  • the access device 170 is configured to include a reader 171, a controller 173 and a gate 175 to permit and disallow the user's access according to the authentication process. Assuming that the access device 170 is installed in the office, the user enters the office area through the access device 170 in the external area. In addition, the user passes through the access device 170 in the office area and exits to the outside area.
  • the control server 150 is an apparatus for controlling access to a user by performing authentication processing based on the card information and the terminal information of the present invention.
  • the control server 150 performs wired and wireless communication with the AP device 130 and the access device 170 to provide an access control service.
  • a user uses the access control service using an RF access card 111 made of a plastic material.
  • the user tags the access card 111 to the reader 171, and the reader 171 reads card information including the RFID of the access card 111 (2).
  • the controller 173 receives the card information of the RFID from the reader 171 and transmits the card information of the RFID to the control server 150 to request access authentication of the user (5).
  • the control server 150 receives a request for access authentication, and if the received RFID matches the pre-stored RFID, it determines the card authentication as a success. If the card authentication is successful, the control server 150 inquires the terminal information pre-stored by the RFID, and if the inquiry terminal information matches the terminal information received from the AP device 130, the control server 150 determines that the terminal authentication is successful. MFA authentication includes the card authentication and the terminal authentication. If both the card authentication and the terminal authentication are successful, the control server 150 determines that the MFA authentication is successful, and transmits the authentication result of the control information to allow the user's access to the controller 173 (6). That is, MFA authentication is to confirm whether the user of the received RFID and the user of the terminal information collected. If one of the card authentication and the terminal authentication fails, the control server 150 transmits an authentication result of the control information that does not allow the user to access the controller 173.
  • the controller 173 receives the authentication result from the control server 150 and controls the opening / closing operation of the gate 175 according to the received authentication result (7).
  • the controller 173 controls the operation of the gate 175 such that the user is not allowed to enter or exit.
  • the gate 175 permits or disallows the user's access by an operation such as screen output, voice output, and access bar blocking according to the opening / closing control received from the controller 173.
  • FIG. 2 is a schematic internal configuration diagram of the control server 150 of FIG.
  • the control server 150 may include a memory, a memory controller, one or more processors (CPUs), peripheral interfaces, input / output (I / O) subsystems, display devices, input devices, and communication circuits.
  • the memory may include fast random access memory, and may also include one or more magnetic disk storage devices, nonvolatile memory such as flash memory devices, or other nonvolatile semiconductor memory devices. Access to memory by other components such as processors and peripheral interfaces may be controlled by the memory controller.
  • the memory may store various information and program instructions, and the program is executed by the processor.
  • the peripheral interface connects an input / output peripheral of the control server 150 with a processor and a memory.
  • One or more processors execute various instruction sets stored in various software programs and / or memories to perform various functions for the control server 150 and to process data.
  • I / O subsystems provide an interface between input and output peripherals, such as display devices and input devices, and peripheral interfaces.
  • the display device may use liquid crystal display (LCD) technology or light emitting polymer display (LPD) technology.
  • the processor is a processor configured to perform operations associated with the control server 150 and to perform instructions, for example, using instructions retrieved from a memory, to receive and manipulate input and output data between components of the control server 150. Can be controlled.
  • the communication circuit performs communication via an external port or communication by an RF signal.
  • the communication circuit converts an electrical signal into an RF signal and vice versa and can communicate with the communication network, other mobile gateway devices and communication devices through the RF signal.
  • the control server 150 includes a terminal information collecting unit 251, a card information receiving unit 253, a determining unit 255, a control unit 257, and a DB 259. It includes. Such components may be implemented in software, stored in memory, executed by a processor, or may be implemented in a combination of software and hardware.
  • the terminal information collecting unit 251 collects terminal information of the user terminal 110 through the AP device 130 around the access device 170.
  • a user having the user terminal 110 enters a predetermined area from the access device 170 and the user terminal 110 is in the area of the access device 170.
  • the AP device 130 around the access device 170 periodically transmits a wireless signal of a Wi-Fi or beacon frame to the user terminals 110 in the communication coverage area.
  • the communication coverage area corresponds to an area where the access device 170 is located.
  • the user terminal 110 receives the transmitted radio signal and responds with the terminal information to the AP device 130.
  • the AP device 130 transmits the terminal information replied to the terminal information collection unit 251. Then, the terminal information collecting unit 251 collects terminal information through the AP device 130.
  • the card information receiver 253 receives from the controller 173 a request for access authentication including card information of an access card 111 tagged by a user who enters and exits through the access device 170.
  • the card information received by the request for access authentication may include a card ID (eg, RFID), classification of entry or exit, information of an entrance gate, and the like.
  • the determination unit 255 queries the DB 259 to process the MFA authentication including card authentication and terminal authentication.
  • the DB 259 includes a card ID (eg, RFID) of an access card 111 of each user whose access registration is completed, and terminal identification information (eg, MAC address, USIM information) of the user terminal 110 matched to the card ID. Etc.).
  • the DB 259 is composed of a plurality of DBs 259 according to the stored information.
  • the determination unit 255 inquires the matching card ID and the matched terminal identification information from the DB 259 using the card ID requested for authentication as a key.
  • the determination unit 255 determines that authentication is requested with a valid access card 111 and processes the card authentication as a success.
  • the determination unit 255 compares whether the terminal identification information inquired from the DB 259 matches the terminal information recently received by the terminal information collection unit 251. When it is determined that matching terminal information is received, the determination unit 255 determines that the user having the user terminal 110 has requested access authentication in the area of the access device 170 and processes the terminal authentication as success. If both card authentication and terminal authentication succeed, the MFA-based authentication is treated as a success.
  • the control unit 257 transmits the control information according to the MFA-based authentication result to the access device 170 to control the access of the user. If the MFA authentication is successful, control information allowing the user's access is transmitted to the access device 170. Of course, if the MFA authentication fails, control information that is not allowed to access the user is transmitted to the access device 170.
  • FIG. 3 is a signal flow diagram of an MFA authentication process according to an embodiment of the present invention.
  • the control server 150 receives the information of the user terminal 110 of the user who enters and exits through the access device 170 and registers in the DB 259.
  • the user terminal 110 requests the authentication of the terminal registration by connecting to the control server 150 and transmits the terminal information (S301).
  • the control server 150 may be accompanied by login authentication of the ID and password received from the user terminal 110, and if the authentication is successful, the control server 150 may register the received terminal information in the DB 259.
  • the control server 150 responds to the user terminal 110 with the registration authentication result (S303).
  • the control server 150 may provide an access authentication service.
  • Each AP device 130 of the access device 170 transmits a radio signal to the user terminal 110 located within the coverage of the wireless communication. Then, the user terminal 110 receives the transmitted radio signal to scan the AP device (130) (S311).
  • the terminal information of the user terminal 110 is transmitted to the AP device 130 selected as the primary device. Answer (S313). Then, the AP device 130 transmits the terminal information responsive to the control server 150, and the control server 150 collects the terminal information through the AP device 130 (S315).
  • the access device 170 reads card information of the tagged access card 111 (S321).
  • the control server 150 receives the card information from the access device 170 receives a request for access authentication (S323).
  • the control server 150 processes the card authentication for the card information requested for authentication, and performs terminal authentication on the terminal information corresponding to the card information to perform MFA authentication (S325).
  • the control server 150 transmits the control information according to the authentication result to the access device 170 (S327).
  • RSSI 4 is an exemplary diagram of location information based on Received Signal Strength Identification (RSSI) according to another embodiment of the present invention.
  • each AP device 430 around the access device 470 receives the terminal information further including the location information of the user terminal 110, the received terminal information to the control server 150 send.
  • the neighboring area where the access device 470 is located is divided into a plurality of grid areas and divided into unit areas 401.
  • Each divided unit area 401 is provided with an AP device 430 to receive a wireless signal from a plurality of AP devices 430.
  • each unit area 401 is unique in strength (eg, RSSI) of each radio signal received from a plurality of neighboring AP devices 430, it may be identified as location information.
  • RSS Receiveived Signal Strength
  • the measured RSS values are averaged and stored in the DB 259 as unique location information identifying the unit area 401.
  • the location information of each unit area 401 stored in the DB 259 corresponds to a score map of RSS values.
  • the control server 150 receives the terminal information including the location information of the user terminal 110 through the AP device 430, inquires the location information stored in the DB 259 by using the received location information as a key, The unit area of the location information inquired as matching is the unit area where the user terminal 110 is located, and the location of the user is identified.
  • the user enters the office from the 5 or 8 unit area, which is an external area, to the 4 or 7 unit area, which is an office area. Also, a user moving from an office area of 4 or 7 unit areas to an external area of 5 or 8 unit areas is an exit from the office.
  • the control server 150 stores the 5 and 8 unit areas as the location information of the entrance and exit device 470 in the DB 259 for valid authentication of the entrance, and stores the 4 and 7 unit areas for the valid authentication of the exit. (259).
  • the control server 150 receives an authentication request for entrance to the office from the access device 470 and confirms through the DB 259 that the corresponding user terminal 110 is located in a 5 or 8 unit area, Allow entry.
  • the control server 150 receives an authentication request for exit from the office from the access device 470, and if the corresponding user terminal 110 is determined to be located in the 4 or 7 unit area, the user permits the exit of the user do.
  • control server 150 checks the unit area where the user terminal 110 is located from the terminal information collected from the user terminal 110 of the user whose card authentication is successful, and the unit area where the user terminal 110 is located is determined. If the access device 470 is confirmed as a unit area in which the access device is installed, it is determined that the user has requested access authentication in a valid unit area, and MFA authentication is processed as success.
  • the control server 150 stores a valid movement path in the DB 259 for the unit areas 4, 5, 7, and 8 where the access device 470 is located. For example, five valid travel paths for positioning in the unit region 5 are 2-> 5, 3-> 5, 6-> 5, 9-> 5 and 8-> 5.
  • the control server 150 is a movement path of the terminal information collected through the AP device 430 from any one of five movement paths stored in the DB 259 for the five unit area where the user terminal 110 is currently located. If confirmed, it is processed as a successful MFA authentication to permit the user's entry.
  • FIG. 5 is an exemplary diagram in which location information of the unit area 401 of FIG. 4 is stored.
  • the location information is a vector value 503 of the RSSI received from the four AP devices 430 of a, b, c, and d with respect to the location coordinates 501 of the unit region 401, and an error range of each vector value. 505 is stored in the DB 259 as table information.
  • the position information for each unit region 401 is not necessarily limited to the vector value and the error range.
  • Various signal pattern information based on the RSSI signal may be location information of the unit region 401.
  • the signal strength received from each AP device 430 may be converted into fingerprint information of the unit region 401 by the set conversion scheme and stored in the DB 259.
  • FIG. 6 is an exemplary diagram of a control server 450 collecting RSSI based location information of FIG. 4.
  • Each AP device 430 installed in the access area including the unit areas 401 periodically transmits a radio signal (eg, a beacon frame) to inform the operation information and coverage of the AP.
  • a radio signal eg, a beacon frame
  • a beacon frame is received from each AP device 430 every transmission interval (for example, 100 ms), and RSSI-based location information and terminal identification information according to the received signal strength are received.
  • the terminal information is transmitted to the AP device 430.
  • the user terminal 410 may be installed with the application 610 to generate the RSSI-based location information to the AP device 430.
  • the application 610 executed in the user terminal 410 transmits terminal information including terminal identification information and RSSI information to the AP device 430.
  • the terminal information collection unit 251 of the control server 450 collects the terminal information including the location information of the user terminal 410 through the AP device 430.
  • the determination unit 255 processes card authentication and processes terminal authentication for the user whose card authentication is successful. In the process of terminal authentication, the determination unit 255 determines that the terminal authentication is successful if the unit area where the user terminal 410 is located is the unit area where the access device 470 is located using the collected location information. If both card authentication and terminal authentication succeed, then MFA authentication is treated as success.
  • FIG. 7 is a signal flow diagram of an MFA authentication process according to another embodiment of the present invention.
  • a plurality of AP devices 430 are installed in the peripheral area of the access device 470 so that a plurality of AP signals are received for each unit area 401.
  • the AP signal may be a beacon frame based on a beacon communication or an SSID based on a Wi-Fi communication according to a service method, and there is no particular limitation.
  • RSSI-based signal strengths received from neighboring AP devices 430 are measured for each unit area 401, and the measured information is RSSI-based location information for each unit area 401 in the DB 259. Pre-stored as.
  • the plurality of AP devices 430 transmits a wireless signal to the surrounding user terminals 410 in the peripheral area of the access device 470 (S701).
  • a plurality of AP devices 430 receives radio signals such as beacon frames and SSIDs.
  • the user terminal 410 transmits terminal information including terminal identification information and RSSI-based location information to the AP device 430 (S703), and the AP device 430 controls the control server 450.
  • the terminal information is transmitted.
  • the control server 450 collects the terminal information including the location information of the user terminal 410 through the AP device 430.
  • the access device 470 reads the card information including the card ID and transmits it to the control server 450 (S707). ).
  • the control server 450 performs MFA authentication including card authentication and terminal authentication (S709).
  • the control server 450 inquires the DB 259 using the received card ID as a key.
  • the access user determines that the registered user is a registered user and processes the card authentication as a success.
  • the control server 450 compares the location information of the terminal information collected corresponding to the terminal identification information of the user whose card authentication is successful with the unit area 401 of the access device 470 inquired from the DB 259. If the match is found, the terminal is determined to be located in the valid unit area and the terminal authentication is successful. If the card authentication and the terminal authentication are successful, the control server 450 processes the MFA authentication as success.
  • the control server 450 transmits the control information according to the MFA authentication result to the access device (470) (S711).
  • the access device 470 permits or disallows access of the user according to the transmitted control information.

Landscapes

  • Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Signal Processing (AREA)
  • Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Toxicology (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Electromagnetism (AREA)
  • General Health & Medical Sciences (AREA)
  • Artificial Intelligence (AREA)
  • Computer Vision & Pattern Recognition (AREA)
  • Environmental & Geological Engineering (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

카드 정보 및 단말 정보를 기반으로 인증이 성공된 사용자의 출입을 허가로 제어하는 장치, 시스템 및 방법을 제공한다. 본 발명의 장치는, 출입 장치 주변의 AP(Access Point) 장치가 수신한 사용자 단말의 단말 정보를 수집하는 수집부; 출입 장치가 읽어들인 사용자의 카드 정보를 포함하는 출입 인증의 요청을 수신하는 수신부; 인증이 요청된 카드 정보가 등록된 카드 정보인지 판단하는 카드 인증 및 수신된 카드 정보의 단말 정보가 수집부에서 수집된 단말 정보인지 판단하는 단말 인증을 포함하는 MFA(Multi Factor Authentification)의 인증 결과를 판단하는 판단부; 및 판단된 인증 결과가 성공인 제어 정보를 출입 장치로 전송하여 사용자의 출입 허가를 제어하는 제어부를 포함한다.

Description

카드 정보 및 단말 정보를 기반으로 출입을 제어하는 장치, 시스템 및 방법
본 출원은 2016년 5월 16일에 출원된 한국특허출원 10-2016-0059832호에 기초한 우선권을 주장하며, 해당 출원의 명세서 및 도면에 개시된 모든 내용은 본 출원에 원용된다.
본 발명은 출입 제어의 기술로서, 보다 구체적으로, 사용자의 단말 정보를 수집하고, 사용자의 카드 정보가 포함된 출입 인증의 요청을 수신하면, 수집된 단말 정보 및 요청된 카드 정보를 인증하여 사용자의 출입 여부를 제어하는 장치, 시스템 및 방법에 관한 것이다.
종래에는 사용자의 지문, 홍체 등과 같은 생체 정보, 또는 비밀 번호를 이용하여 사용자를 인증하고, 이 인증 결과에 따라 사용자의 출입을 선택적으로 허락한다.
이에 더 나아가, RFID(Radio Frequency Identification) 기반으로 출입 관리를 행하는 기술이 개발되었다. 상기 RFID를 이용한 출입 관리 기술은, 사용자의 단말 또는 카드로부터 수신된 RFID가 등록된 식별 정보인지 여부를 인증하여, 사용자의 출입을 허락한다.
그런데 이러한 RFID를 이용한 출입 관리 기술은, 사용자가 RFID가 등록된 단말 또는 카드를 분실하거나 타인에게 대여한 경우, 타 사용자가 사용자의 단말 또는 카드를 이용하여 사용자로 위장하여 출입 인증을 성공할 수 있는 보안상의 취약점을 가지고 있다. 즉, 사용자의 RFID 수단을 확보한 타 사용자는 사용자의 출입으로 언제든지 인증이 성공된다.
여기서, MFA(Multi Factor Authentication)는 다중 요소를 인증에 활용하여 인증을 강화한 것이다. MFA를 기반으로 상기 RFID에 인증 요소가 더 추가될 경우, RFID 인증에 성공되더라도 추가된 인증 요소가 실패되어 타 사용자가 사용자로 가장하여 출입하는 것은 인증이 실패된다.
본 발명은 상기와 같은 종래 기술의 인식하에 창출된 것으로서, 출입 인증이 요청된 사용자의 카드 아이디 및 단말 정보를 MFA를 기반으로 인증하고, 인증이 성공된 사용자의 출입을 허가하는 장치, 시스템 및 방법을 제공하는 것을 목적으로 한다.
또한, 본 발명은 출입 장치가 위치하는 주변 영역을 와이파이 존(wifi zone)으로 구분하여 사용자 단말의 위치 정보를 수집하고, 카드 아이디의 인증이 요청된 출입 장치의 위치 및 수집된 단말의 위치 정보가 일치하는 것을 확인하면, 출입 인증의 성공에 의해 사용자가 통과하는 출입 장치의 개폐를 제어하는데 다른 목적이 있다.
일 측면에 따른, 카드 정보 및 단말 정보를 기반으로 출입을 제어하는 장치는, 출입 장치 주변의 AP(Access Point) 장치가 수신한 사용자 단말의 단말 정보를 수집하는 수집부; 상기 출입 장치가 읽어들인 사용자의 카드 정보를 포함하는 출입 인증의 요청을 수신하는 수신부; 인증이 요청된 카드 정보가 등록된 카드 정보인지 판단하는 카드 인증 및 수신된 카드 정보의 단말 정보가 상기 수집된 단말 정보인지 판단하는 단말 인증을 포함하는 MFA(Multi Factor Authentification)의 인증 결과를 판단하는 판단부; 및 판단된 인증 결과가 성공인 제어 정보를 상기 출입 장치로 전송하여 사용자의 출입 허가를 제어하는 제어부를 포함한다.
상기 수집부는, 상기 AP 장치가 와이파이 통신 또는 비콘 통신을 통해 수신한 단말 식별 정보를 상기 단말 정보로서 수집한다.
상기 수집부는, 와이파이 수신 기능이 꺼진 상태에서도 상기 AP 장치를 항상 검색하는 기능이 실행된 사용자 단말의 와이파이 실행에 의해, 상기 단말 정보를 수집한다.
상기 수신부는, 상기 출입 장치의 리더기가 읽어들인 출입 카드의 RFID(Radio Frequency IDentification)를 상기 카드 정보로서 수신한다.
상기 장치는 사용자의 출입 카드의 카드 아이디 및 매칭된 사용자 단말의 단말 식별 정보를 저장하는 DB(DataBase)를 더 포함하고, 상기 판단부는, 인증이 요청된 카드 정보의 카드 아이디를 키로 하여 DB로부터 상기 저장된 카드 아이디 및 단말 식별 정보를 조회하면, 상기 카드 인증을 성공으로 판단하고, 조회된 단말 식별 정보가 상기 수집된 단말 식별 정보이면 상기 단말 인증을 성공으로 판단하고, 카드 인증 및 단말 인증이 성공이면 상기 MFA의 인증 결과를 성공으로 판단한다.
상기 제어부는, 상기 출입 장치의 게이트 콘트롤러로 출입 허가의 제어 정보를 전송하고, 상기 게이트 콘트롤러는 전송된 제어 정보에 의해 사용자가 통과하는 게이트 장치를 출입 허가로 제어한다.
상기 장치는, 상기 출입 장치의 주변 영역이 복수개의 단위 영역으로 구분되고, 각 단위 영역에서 주변의 AP 장치들로부터 각각 수신되는 무선 신호의 세기가 단위 영역별 위치 정보로서 저장되는 DB를 포함하고, 상기 수집부는, 상기 사용자 단말의 단말 식별 정보 및 상기 단위 영역에서 수신된 각각의 무선 신호의 세기를 포함하는 상기 단말 정보를 AP 장치를 통해 수집한다.
상기 판단부는, 수집된 무선 신호의 세기를 키로 하여 상기 DB로부터 가장 일치하는 위치 정보를 조회하고, 조회된 위치 영역의 단위 영역을 사용자 단말이 위치하는 단위 영역으로 판단한다.
상기 DB는 상기 출입 장치가 위치하는 상기 단위 영역 정보를 더 저장하고,
상기 판단부는, 수집된 단말 정보의 단위 영역 정보를 키로 하여 상기 DB로부터 출입 장치의 단위 영역 정보를 조회하면, 상기 단말 인증을 성공으로 판단한다.
다른 측면에 따른, 카드 정보 및 단말 정보를 기반으로 출입을 제어하는 시스템은, 각각의 AP 장치로부터 무선 신호를 수신하고, 단말 정보를 응답 전송하는 사용자 단말; 출입 장치의 주변에 각각 설치되고, 상기 무선 신호를 수신한 사용자 단말로부터 상기 단말 정보를 전송받아 제어 장치로 전송하는 AP 장치; 출입 허가를 요청하는 사용자의 카드 정보를 읽어들이고, 상기 카드 정보를 포함하는 출입 인증을 요청하고, 인증 결과의 제어 정보를 수신하여 사용자 출입을 허가 또는 불허로 동작하는 출입 장치; 및 상기 AP 장치를 통해 단말 정보를 수집하고, 상기 출입 장치로부터 상기 인증 요청을 수신하고, 수신된 카드 정보가 등록된 카드 정보인지 판단하는 카드 인증 및 수신된 카드 정보의 단말 정보가 상기 수집된 단말 정보인지 판단하는 단말 인증을 포함하는 MFA의 인증 결과를 판단하고, 판단된 인증 결과가 성공인 제어 정보를 상기 출입 장치로 전송하는 제어 장치를 포함한다.
또 다른 측면에 따른, 장치가 카드 정보 및 단말 정보를 기반으로 출입을 제어하는 방법은, 출입 장치 주변의 AP 장치가 수신한 사용자 단말의 단말 정보를 수집하는 단계; 상기 출입 장치가 읽어들인 사용자의 카드 정보를 포함하는 출입 인증의 요청을 수신하는 단계; 인증이 요청된 카드 정보가 등록된 카드 정보인지 판단하는 카드 인증 및 수신된 카드 정보의 단말 정보가 상기 수집된 단말 정보인지 판단하는 단말 인증을 포함하는 MFA의 인증 결과를 판단하는 단계; 및 판단된 인증 결과가 성공인 제어 정보를 상기 출입 장치로 전송하여 사용자의 출입 허가를 제어하는 단계를 포함한다.
본 발명은 MFA 기반으로 카드 인증 및 단말 인증이 모두 성공되어야만 사용자의 출입을 허가하여 출입 관리의 보안성을 향상시키는 장점이 있다.
또한, 본 발명은 탈취된 출입 카드를 가진 제 3자가 출입 카드의 사용자로 가장하여 출입 인증을 요청하면, 단말 인증에 실패되어 출입이 불허되고, 제 3자가 출입 인증에 성공하려면, 사용자의 단말까지 탈취해야 하므로 출입 인증이 강화된다.
본 명세서에 첨부되는 다음의 도면들은 본 발명의 바람직한 실시예를 예시하는 것이며, 후술한 발명의 상세한 설명과 함께 본 발명의 기술사상을 더욱 이해시키는 역할을 하는 것이므로, 본 발명은 그러한 도면에 기재된 사항에만 한정되어 해석되지 않아야 한다.
도 1은 본 발명의 일 실시예에 따른 시스템의 개략적인 구성도이다.
도 2는 도 1의 제어 서버의 개략적 내부 구성도이다.
도 3은 본 발명의 일 실시예에 따른 MFA 인증 처리의 신호 흐름도이다.
도 4는 본 발명의 다른 실시예에 따른 RSSI(Received Signal Strength Identification)기반의 위치 정보의 예시도이다.
도 5는 도 4의 단위 영역의 위치 정보가 저장되는 예시도이다.
도 6은 도 4의 RSSI 기반의 위치 정보를 수집하는 제어 서버의 예시도이다.
도 7은 본 발명의 다른 실시예에 따른 MFA 인증 처리의 신호 흐름도이다.
이하, 첨부된 도면을 참조하여 본 발명의 바람직한 실시예를 상세히 설명하기로 한다. 이에 앞서, 본 명세서 및 청구 범위에 사용된 용어나 단어는 통상적이거나 사전적인 의미로 한정해서 해석되어서는 아니되며, 발명자는 그 자신의 발명을 가장 최선의 방법으로 설명하기 위해 용어의 개념을 적절하게 정의할 수 있다는 원칙에 입각하여 본 발명의 기술적 사상에 부합하는 의미와 개념으로 해석되어야만 한다. 따라서, 본 명세서에 기재된 실시예와 도면에 도시된 구성은 본 발명의 가장 바람직한 일 실시예에 불과할 뿐이고 본 발명의 기술적 사상에 모두 대변하는 것은 아니므로, 본 출원 시점에 있어서 이들을 대체할 수 있는 다양한 균등물과 변형예들이 있을 수 있음을 이해하여야 한다.
도 1은 본 발명의 일 실시예에 따른 시스템(100)의 개략적인 구성도이다.
본 발명의 일 실시예에 따른 시스템(100)은 단말 정보가 수집되는 사용자 단말(110), 카드 정보가 읽혀지는 출입 카드(111), 사용자 단말(110)의 단말 정보를 수신하는 AP 장치(130), 단말 정보 및 카드 정보를 기반으로 사용자의 출입을 MFA 인증하는 제어 서버(150), 출입 카드(111)의 카드 정보를 읽어서 제어 서버(150)로 출입 인증을 요청하고, 제어 서버(150)로부터 MFA 인증 결과를 수신하여 사용자의 출입을 허가 또는 불허하는 출입 장치(170)를 포함하여 구성된다.
상기 사용자 단말(110)은 AP 장치(130)를 통해 무선 통신 서비스를 제공받는 스마트 단말(예 : 스마트 폰)을 포함한다. 사용자 단말(110)은 주변에 설치된 복수의 AP 장치(130)들로부터 각각의 무선 신호를 수신할 수 있다. 각각의 무선 신호가 수신되면, 사용자 단말(110)은 프라이머리 AP 장치(130)를 선정하여 무선 통신 서비스를 제공받는다.
여기서, 사용자 단말(110)은 비콘 통신 및 와이파이 통신 등에 기반된 무선 신호를 AP 장치(130)로부터 수신하고, 수신된 무선 신호의 응답 정보로서 MAC 주소, USIM 식별 정보, IMSI 등의 단말 정보를 AP 장치(130)로 전송하여 무선 통신 서비스를 제공받는다. 상기 단말 정보는 사용자 단말(110)을 고유하게 식별하는 정보가 포함되기만 하면 특별한 제한을 두지 않는다.
또한, 사용자 단말(110)은 무선 신호의 수신 및 단말 정보의 응답을 위한 통신 기능이 활성화되어 있어야 한다. 와이파이 통신의 경우, 사용자 단말(110)은 주변의 AP 장치(130)를 항상 검색하는 기능이 설정되는 것이 바람직하다. 즉, 사용자 단말(110)에서 와이파이의 수신 기능에 "항상 검색 허용" 기능(예 : Android 버전 4.3(SDK 18) 이상)이 설정된다. 그러면, 사용자 단말(110)은 와이파이 수신 기능이 꺼진 상태에서도 주변의 AP 장치(130)를 스캐닝할 수 있다.
예를 들면, 사용자 단말(110)이 스마트 폰으로서 "항상 검색 허용" 기능이 설정된 경우, 안드로이드 OS가 지원하는 백그라운드 기능으로 특정 SSID가 스캐닝되면, 스마트 폰은 와이파이 기능을 자동 활성화시킨다. 스마트 폰은 AP 장치(130) 또는 기지국에서 송출되는 SSID를 모니터링하되, 출입 장치(170) 주변의 AP 장치(130)가 송출하는 특정 SSID를 스캔하면 와이파이 기능을 활성화시킨다. 스마트 폰에서 와이파이 기능이 활성화되면, AP 장치(130)는 스마트 폰으로부터 SSID 기반의 접속을 처리하는 과정에서, 스마트 폰의 단말 정보를 수신하여 제어 서버(150)로 전송할 수 있다. 그러면, 제어 서버(150)는 AP 장치(130)를 통해 출입 장치(170)에 근접하는 스마트 폰의 단말 정보를 수집할 수 있다.
상기 AP 장치(130)는 출입 장치(130)가 위치하는 주변 영역에 복수개 설치되고, 주변의 사용자 단말(110)들로 상기 무선 신호를 송출하여 무선 통신 서비스의 설정을 맺고 무선 인터넷 서비스를 제공한다.
상기 무선 통신 서비스의 설정 과정에서, AP 장치(130)는 송출된 무선 신호를 수신한 사용자 단말(110)로부터 단말 정보를 수신하고(①), 수신된 단말 정보를 MFA 인증을 위해 제어 서버(150)로 전송한다(②).
상기 출입 카드(111)는 사용자가 출입 인증을 위해 소지하는 카드(예 : RF 카드)이고, 내부 저장소에 RFID와 같은 카드 아이디를 저장한다. 출입 카드(111)는 카드 아이디의 송출을 위해 다양한 통신 방식이 적용될 수 있고 반드시 RF 통신으로 제한되는 것은 아니다.
여기서, 출입 카드(111)가 모바일 카드일 경우, 사용자 단말(110)은 모바일 카드의 카드 정보를 저장하고, 사용자 단말(110)에서 지원되는 각종 통신 방식(예 : 와이파이, 블루투스, NFC 등)으로 카드 정보를 송출할 수 있다.
상기 출입 장치(170)는 사용자의 출입을 인증 처리에 따라 허가 및 불허하기 위해 리더기(171), 콘트롤러(173) 및 게이트(175)를 포함하여 구성된다. 출입 장치(170)가 사무실에 설치된 것이라 가정하면, 사용자는 외부 영역에서 출입 장치(170)를 통과하여 사무실 영역으로 입장한다. 또한, 사용자는 사무실 영역에서 출입 장치(170)를 통과하여 외부 영역으로 퇴장한다.
상기 제어 서버(150)는 본 발명의 카드 정보 및 단말 정보를 기반으로 인증 처리하여 사용자의 출입을 제어하는 장치이다. 제어 서버(150)는 AP 장치(130) 및 출입 장치(170)와 유, 무선 통신을 수행하여 출입 제어 서비스를 제공한다.
사용자가 플라스틱 재질로 제작된 RF 방식의 출입 카드(111)를 이용하여 상기 출입 제어 서비스를 이용하는 것이라 가정한다. 사용자는 출입 카드(111)를 리더기(171)에 태깅하고, 리더기(171)는 출입 카드(111)의 RFID가 포함된 카드 정보를 읽어들인다(②). 콘트롤러(173)는 리더기(171)로부터 RFID의 카드 정보를 수신하고 제어 서버(150)로 전송하여 사용자의 출입 인증을 요청한다(⑤).
그러면, 제어 서버(150)는 출입 인증의 요청을 수신하고, 수신된 RFID가 기 저장된 RFID와 일치하면 카드 인증을 성공으로 판단한다. 카드 인증이 성공되면, 제어 서버(150)는 RFID로 기 저장된 단말 정보를 조회하고, 조회된 단말 정보가 AP 장치(130)로부터 수신된 단말 정보와 일치하면 단말 인증을 성공으로 판단한다. MFA 인증은 상기 카드 인증 및 상기 단말 인증을 포함한다. 카드 인증 및 단말 인증이 모두 성공이면, 제어 서버(150)는 MFA 인증을 성공으로 판단하여 사용자의 출입을 허가하는 제어 정보의 인증 결과를 콘트롤러(173)로 전송한다(⑥). 즉, MFA 인증은 수신된 RFID의 사용자와 수집된 단말 정보의 사용자가 일치하는지를 확인하는 것이다. 만약, 카드 인증 및 단말 인증 중 어느 하나라고 실패이면, 제어 서버(150)는 사용자의 출입을 불허하는 제어 정보의 인증 결과를 콘트롤러(173)로 전송한다.
콘트롤러(173)는 제어 서버(150)로부터 인증 결과를 수신하고, 수신된 인증 결과에 따라 게이트(175)의 개폐 동작을 제어한다(⑦). 물론, 성공의 인증 결과가 수신될 경우, 콘트롤러(173)는 사용자의 출입이 불허되도록 게이트(175)의 동작을 제어한다. 여기서, 게이트(175)는 콘트롤러(173)로부터 수신된 개폐 제어에 따라 화면 출력, 음성 출력 및 출입 바(bar) 차단 등의 동작으로 사용자의 출입을 허가 또는 불허한다.
도 2는 도 1의 제어 서버(150)의 개략적 내부 구성도이다.
제어 서버(150)는, 메모리, 메모리 제어기, 하나 이상의 프로세서(CPU), 주변 인터페이스, 입출력(I/O) 서브시스템, 디스플레이 장치, 입력 장치 및 통신 회로를 포함할 수 있다. 메모리는 고속 랜덤 액세스 메모리를 포함할 수 있고, 또한 하나 이상의 자기 디스크 저장 장치, 플래시 메모리 장치와 같은 불휘발성 메모리, 또는 다른 불휘발성 반도체 메모리 장치를 포함할 수 있다. 프로세서 및 주변 인터페이스와 같은 다른 구성요소에 의한 메모리로의 액세스는 메모리 제어기에 의하여 제어될 수 있다. 메모리는 각종 정보와 프로그램 명령어를 저장할 수 있고, 프로그램은 프로세서에 의해 실행된다.
주변 인터페이스는 제어 서버(150)의 입출력 주변 장치를 프로세서 및 메모리와 연결한다. 하나 이상의 프로세서는 다양한 소프트웨어 프로그램 및/또는 메모리에 저장되어 있는 명령어 세트를 실행하여 제어 서버(150)를 위한 여러 기능을 수행하고 데이터를 처리한다. I/O 서브시스템은 디스플레이 장치, 입력 장치와 같은 입출력 주변장치와 주변 인터페이스 사이에 인터페이스를 제공한다. 디스플레이 장치는 LCD(liquid crystal display) 기술 또는 LPD(light emitting polymer display) 기술을 사용할 수 있다.
프로세서는 제어 서버(150)에 연관된 동작을 수행하고 명령어들을 수행하도록 구성된 프로세서로서, 예를 들어, 메모리로부터 검색된 명령어들을 이용하여, 제어 서버(150)의 컴포넌트 간의 입력 및 출력 데이터의 수신과 조작을 제어할 수 있다. 통신 회로는 외부 포트를 통한 통신 또는 RF 신호에 의한 통신을 수행한다. 통신 회로는 전기 신호를 RF 신호로 또는 그 반대로 변환하며 이 RF 신호를 통하여 통신 네트워크, 다른 이동형 게이트웨이 장치 및 통신 장치와 통신할 수 있다.
도 2를 참조하면, 본 발명의 일 실시예에 따른 제어 서버(150)는 단말 정보 수집부(251), 카드 정보 수신부(253), 판단부(255), 제어부(257) 및 DB(259)를 포함한다. 이러한 구성 요소들은 소프트웨어로 구현되어 메모리에 저장되어 프로세서에 의해 실행될 수 있고, 또는 소프트웨어와 하드웨어의 조합으로 구현될 수도 있다.
상기 단말 정보 수집부(251)는 출입 장치(170) 주변의 AP 장치(130)를 통해 사용자 단말(110)의 단말 정보를 수집한다.
여기서, 사용자 단말(110)을 소지한 사용자가 출입 장치(170)로부터 소정의 영역 이내로 진입하여 사용자 단말(110)이 출입 장치(170)의 영역에 있는 것으로 가정한다. 출입 장치(170) 주변의 AP 장치(130)는 통신 커버리지 영역 내의 사용자 단말(110)들을 상대로 주기적으로 와이파이 또는 비콘 프레임의 무선 신호를 송출한다. 상기 통신 커버리지 영역은 출입 장치(170)가 위치하는 영역에 해당된다. 사용자 단말(110)은 송출된 무선 신호를 수신하고, 단말 정보를 AP 장치(130)로 응답한다. AP 장치(130)는 단말 정보 수집부(251)로 응답된 단말 정보를 전송한다. 그러면, 단말 정보 수집부(251)는 AP 장치(130)를 통해 단말 정보를 수집한다.
상기 카드 정보 수신부(253)는 출입 장치(170)를 통해 입장 및 퇴장하는 사용자가 태깅한 출입 카드(111)의 카드 정보를 포함하는 출입 인증의 요청을 콘트롤러(173)로부터 수신한다. 출입 인증의 요청에 의해 수신된 카드 정보는 카드 아이디(예 : RFID), 입장 또는 퇴장의 구분, 출입 게이트의 정보 등을 포함할 수 있다.
상기 판단부(255)는 DB(259)를 조회하여 카드 인증 및 단말 인증을 포함하는 상기 MFA 인증을 처리한다. 상기 DB(259)에는 출입 등록이 완료된 각 사용자의 출입 카드(111)의 카드 아이디(예 : RFID) 및 그 카드 아이디에 매칭된 사용자 단말(110)의 단말 식별 정보(예 : MAC 주소, USIM 정보 등)를 저장한다. 상기 DB(259)는 저장되는 정보에 따라 복수개의 DB(259)로 구성된다.
먼저, 판단부(255)는 상기 인증이 요청된 카드 아이디를 키로 하여 일치되는 카드 아이디 및 매칭된 단말 식별 정보를 DB(259)로부터 조회한다. 일치된 카드 아이디가 DB(259)에서 조회되면, 판단부(255)는 유효한 출입 카드(111)로 인증이 요청된 것으로 판단하여 카드 인증을 성공으로 처리한다.
다음으로, 카드 인증이 성공되면, 판단부(255)는 DB(259)에서 조회된 단말 식별 정보가 단말 정보 수집부(251)에 의해 최근 수신된 단말 정보와 일치하는지를 비교한다. 일치되는 단말 정보가 수신된 것이 판단되면, 판단부(255)는 사용자 단말(110)을 소지한 사용자가 출입 장치(170)의 영역에서 출입 인증을 요청한 것으로 판단하고 단말 인증을 성공으로 처리한다. 카드 인증 및 단말 인증이 모두 성공되면, 상기 MFA 기반의 인증을 성공으로 처리한다.
상기 제어부(257)는 MFA 기반의 인증 결과에 따른 제어 정보를 제어 정보를 출입 장치(170)로 전송하여 사용자의 출입을 제어한다. MFA 인증이 성공이면 사용자의 출입이 허가되는 제어 정보가 출입 장치(170)로 전송된다. 물론, MFA 인증이 실패이면 사용자의 출입이 불허되는 제어 정보가 출입 장치(170)로 전송된다.
도 3은 본 발명의 일 실시예에 따른 MFA 인증 처리의 신호 흐름도이다.
먼저, 제어 서버(150)는 출입 장치(170)를 통해 출입하는 사용자의 사용자 단말(110)의 정보를 등록받고 DB(259)에 등록한다. 상기 등록에 의해, 사용자 단말(110)은 제어 서버(150)에 접속하고 단말 정보를 전송하여 단말 등록의 인증을 요청한다(S301). 여기서, 제어 서버(150)는 사용자 단말(110)로부터 수신된 아이디 및 패스워드의 로그인 인증을 수반하고, 인증이 성공되면 수신된 단말 정보를 DB(259)에 등록할 수 있다. 유효한 등록이 완료되면, 제어 서버(150)는 등록 인증 결과를 사용자 단말(110)로 응답한다(S303).
단말 정보의 등록이 완료된 이후로, 제어 서버(150)는 출입 인증 서비스를 제공할 수 있다. 출입 장치(170)의 각 AP 장치(130)들은 무선 통신의 커버리지 내에 위치한 사용자 단말(110)들을 상대로 무선 신호를 송출한다. 그러면, 사용자 단말(110)은 송출되는 무선 신호를 수신하여 AP 장치(130)들을 스캐닝한다(S311).
송출된 무선 신호의 수신에 의해, 사용자 단말(110)이 주변의 적어도 하나 이상의 AP 장치(130)를 스캐닝하면, 프라이머리 장치로 선정된 AP 장치(130)로 사용자 단말(110)의 단말 정보를 응답한다(S313). 그러면, AP 장치(130)는 제어 서버(150)로 응답된 단말 정보를 전송하고, 제어 서버(150)는 AP 장치(130)를 통해 상기 단말 정보를 수집한다(S315).
이후, 사용자가 출입 장치(170)를 통해 입장하기 위해, 출입 카드(111)를 태깅하면, 출입 장치(170)는 태킹된 출입 카드(111)의 카드 정보를 읽어들인다(S321). 또한, 제어 서버(150)는 출입 장치(170)로부터 상기 카드 정보를 수신하여 출입 인증을 요청받는다(S323). 출입 인증이 요청되면, 제어 서버(150)는 인증이 요청된 카드 정보에 대해 카드 인증을 처리하고, 카드 정보에 대응된 단말 정보에 대해 단말 인증을 처리하여 MFA 인증을 수행한다(S325). MFA 인증이 완료되면, 제어 서버(150)는 인증 결과에 따른 제어 정보를 출입 장치(170)로 전송한다(S327).
도 4는 본 발명의 다른 실시예에 따른 RSSI(Received Signal Strength Identification)기반의 위치 정보의 예시도이다.
본 발명의 다른 실시예에서는 출입 장치(470) 주변의 각 AP 장치(430)들이 사용자 단말(110)의 위치 정보를 더 포함하는 단말 정보를 수신하고, 수신된 단말 정보를 제어 서버(150)로 전송한다.
여기서, 출입 장치(470)가 위치하는 인근 영역은 복수개의 그리드 영역으로 분할되어 각각의 단위 영역(401)으로 구분된다. 구분된 각 단위 영역(401)은 복수개 AP 장치(430)로부터 무선 신호를 수신할 수 있도록 AP 장치(430)가 설치된다.
예를 들면, 도 4의 총 5*4= 20개의 각 단위 영역(401)에서는 최소한 3개 이상의 AP 무선 신호가 수신된다. 그러면, 각 단위 영역(401)이 주변의 복수개 AP 장치(430)로부터 수신한 각각의 무선 신호의 세기(예 : RSSI)는 고유하므로 위치 정보로서 식별될 수 있다. 각 단위 영역(401)에서는 주변의 복수개 AP 장치(430)로부터 수신되는 신호의 RSS(Received Signal Strength)가 여러번 측정된다. 측정된 RSS 값은 평균화되어 DB(259)에 단위 영역(401)을 식별하는 고유한 위치 정보로서 저장된다. DB(259)에 저장된 각 단위 영역(401)의 위치 정보는 RSS 값의 스코어 맵에 해당된다.
제어 서버(150)가 AP 장치(430)를 통해 사용자 단말(110)의 위치 정보가 포함된 단말 정보를 수신하고, 수신된 위치 정보를 키로 하여 DB(259)에 저장된 위치 정보를 조회하고, 가장 일치하는 것으로 조회된 위치 정보의 단위 영역은 사용자 단말(110)이 위치하는 단위 영역으로 사용자의 위치가 식별된다.
여기서, 출입 장치(470)를 기준으로, 사용자가 외부 영역인 5 또는 8 단위 영역에서 사무실 영역인 4 또는 7 단위 영역으로 이동하는 것은 사무실로 입장한 것이다. 또한, 사용자가 사무실 영역인 4 또는 7 단위 영역에서 외부 영역인 5 또는 8 단위 영역으로 이동하는 것은 사무실로부터 퇴장한 것이다.
따라서, 제어 서버(150)는 입장의 유효한 인증을 위해 5 및 8 단위 영역을 출입 장치(470)의 위치 정보로서 DB(259)에 저장하고, 퇴장의 유효한 인증을 위해 4 및 7 단위 영역을 DB(259)에 저장한다. 제어 서버(150)는 사무실 입장을 위한 인증 요청을 출입 장치(470)로부터 수신하고, 대응되는 사용자 단말(110)이 5 또는 8 단위 영역에 위치하는 것으로 DB(259)를 통해 확인할 경우, 사용자의 입장을 허가한다. 또한, 제어 서버(150)는 사무실로부터 퇴장을 위한 인증 요청을 출입 장치(470)로부터 수신하고, 대응되는 사용자 단말(110)이 4 또는 7 단위 영역에 위치하는 것으로 확인할 경우, 사용자의 퇴장을 허가한다. 즉, 제어 서버(150)는 카드 인증이 성공된 사용자의 사용자 단말(110)로부터 수집된 단말 정보로부터 사용자 단말(110)이 위치하는 단위 영역을 확인하고, 사용자 단말(110)이 위치한 단위 영역이 출입 장치(470)가 설치된 단위 영역으로 확인하면, 사용자가 유효한 단위 영역에서 출입 인증을 요청한 것으로 판단하여 MFA 인증을 성공으로 처리한다.
만약, 사용자의 이동을 고려하는 것이라 가정하면, 제어 서버(150)는 출입 장치(470)가 위치한 단위 영역 4, 5, 7, 8에 대해 유효한 이동 경로를 DB(259)에 저장한다. 예를 들어, 단위 영역 5에 위치하기 위한 유효한 이동 경로는 2->5, 3->5, 6->5, 9->5 및 8->5의 5개이다. 제어 서버(150)는 사용자 단말(110)이 현재 위치한 5 단위 영역에 대해, DB(259)에 저장된 5개 이동 경로 중 어느 한 경로가 AP 장치(430)를 통해 수집된 단말 정보의 이동 경로로 확인되면, 성공된 MFA 인증으로 처리하여 사용자의 입장을 허가한다.
도 5는 도 4의 단위 영역(401)의 위치 정보가 저장되는 예시도이다.
위치 정보는 단위 영역(401)의 위치 좌표(501)에 대해 a, b, c 및 d의 4개 AP 장치(430)들로부터 각각 수신된 RSSI의 벡터 값(503) 및 각 벡터 값의 오차 범위(505)가 테이블 정보로서 DB(259)에 저장된다.
한편, 각 단위 영역(401)별 위치 정보는 반드시 상기 벡터 값 및 오차 범위로 제한되는 것은 아니다. RSSI 신호를 기반으로 하는 각종 신호 패턴 정보는 단위 영역(401)의 위치 정보가 될 수 있다. 예를 들면, 각 AP 장치(430)로부터 수신된 신호 세기는 설정된 변환 방식에 의해 단위 영역(401)의 핑거프린트 정보로 변환되어 DB(259)에 저장되어도 무방하다.
도 6은 도 4의 RSSI 기반의 위치 정보를 수집하는 제어 서버(450)의 예시도이다.
각 단위 영역(401)들을 포함하는 출입 영역에 설치된 각 AP 장치(430)는 AP의 동작 정보 및 커버리지를 알리기 위해 무선 신호(예 : 비콘 프레임)을 주기적으로 송출한다. 사용자 단말(410)이 출입 영역에 진입하면, 송출 간격(예 : 100ms)마다 비콘 프레임을 각 AP 장치(430)로부터 수신하고, 수신된 신호의 세기에 따른 RSSI 기반의 위치 정보 및 단말 식별 정보의 단말 정보를 AP 장치(430)로 전송한다.
여기서, 사용자 단말(410)은 RSSI 기반의 위치 정보를 생성하여 AP 장치(430)로 전송하기 위해 어플리케이션(610)이 설치될 수 있다. 물론, 어플리케이션(610)의 기능이 OS를 통해 지원될 경우, 어플리케이션(610)의 설치는 생략되어도 무방하다. 사용자 단말(410)에서 실행된 어플리케이션(610)은 단말 식별 정보 및 RSSI 정보를 포함하는 단말 정보를 AP 장치(430)로 전송한다.
그러면, 제어 서버(450)의 단말 정보 수집부(251)는 AP 장치(430)를 통해 사용자 단말(410)의 위치 정보가 더 포함된 단말 정보를 수집한다. 판단부(255)는 카드 인증을 처리하고, 카드 인증이 성공된 사용자에 대해 단말 인증을 처리한다. 단말 인증의 처리에서, 판단부(255)는 수집된 위치 정보를 이용하여 사용자 단말(410)이 위치한 단위 영역이 출입 장치(470)가 위치한 단위 영역이면 단말 인증을 성공으로 판단한다. 카드 인증 및 단말 인증이 모두 성공되면, MFA 인증은 성공으로 처리된다.
도 7은 본 발명의 다른 실시예에 따른 MFA 인증 처리의 신호 흐름도이다.
먼저, 출입 장치(470)의 주변 영역에서 복수개의 AP 장치(430)가 각 단위 영역(401)마다 복수개 AP 신호가 수신되도록 설치된다. AP 신호는 서비스 방식에 따라 비콘 통신 기반의 비콘 프레임, 와이파이 통신 기반의 SSID 등일 수 있으며 특별한 제한을 두지 않는다. 각 단위 영역(401)마다 주변의 AP 장치(430)들로부터 수신된 RSSI 기반의 신호 세기가 각각 측정되고, 측정된 정보는 DB(259)에 각 단위 영역(401)에 대한 RSSI 기반의 위치 정보로서 미리 저장된다.
이후, 출입 장치(470)의 주변 영역에서 복수의 AP 장치(430)는 주변의 사용자 단말(410)들로 무선 신호를 송출한다(S701). 사용자 단말(410)이 출입 영역에 진입하면, 복수개 AP 장치(430)로부터 비콘 프레임, SSID 등의 무선 신호를 수신한다.
무선 신호가 수신되면, 사용자 단말(410)은 단말 식별 정보 및 RSSI 기반의 위치 정보를 포함하는 단말 정보를 AP 장치(430)로 전송하고(S703), AP 장치(430)는 제어 서버(450)로 상기 단말 정보를 전송한다(S705). 제어 서버(450)는 AP 장치(430)를 통해 사용자 단말(410)의 위치 정보가 더 포함된 상기 단말 정보를 수집한다.
이후, 사용자가 입장 또는 퇴장을 위해 출입 장치(470)에 출입 카드(111)를 태깅하면, 출입 장치(470)는 카드 아이디가 포함된 카드 정보를 읽어들여 제어 서버(450)로 전송한다(S707).
카드 정보가 수신되면, 제어 서버(450)는 카드 인증 및 단말 인증을 포함하는 MFA 인증을 수행한다(S709). 먼저, 제어 서버(450)는 수신된 카드 아이디를 키로하여 DB(259)를 조회하고, 일치된 카드 아이디가 조회되면 출입 사용자는 등록된 사용자로 판단하여 카드 인증을 성공으로 처리한다. 다음으로, 제어 서버(450)는 카드 인증이 성공된 사용자의 단말 식별 정보에 대응되어 수집된 단말 정보의 위치 정보를 DB(259)로부터 조회된 출입 장치(470)의 단위 영역(401)과 비교하여 일치하면, 사용자가 유효한 단위 영역에 위치한 것으로 판단하여 단말 인증을 성공으로 처리한다. 카드 인증 및 단말 인증이 성공이면, 제어 서버(450)는 MFA 인증을 성공으로 처리한다.
MFA 인증의 처리가 완료되면, 제어 서버(450)는 MFA 인증 결과에 따른 제어 정보를 출입 장치(470)로 전송한다(S711). 출입 장치(470)는 전송된 제어 정보에 따라 사용자의 출입을 허가 또는 불허한다.
본 발명은 비록 한정된 실시예와 도면에 의해 설명되었으나, 본 발명은 이것에 의해 한정되지 않으며 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자에 의해 본 발명의 기술사상과 아래에 기재될 특허청구범위의 균등범위 내에서 다양한 수정 및 변형이 가능함은 물론이다.

Claims (19)

  1. 카드 정보 및 단말 정보를 기반으로 출입을 제어하는 장치에 있어서,
    출입 장치 주변의 AP(Access Point) 장치가 수신한 사용자 단말의 단말 정보를 수집하는 수집부;
    상기 출입 장치가 읽어들인 사용자의 카드 정보를 포함하는 출입 인증의 요청을 수신하는 수신부;
    인증이 요청된 카드 정보가 등록된 카드 정보인지 판단하는 카드 인증 및 수신된 카드 정보의 단말 정보가 상기 수집된 단말 정보인지 판단하는 단말 인증을 포함하는 MFA(Multi Factor Authentification)의 인증 결과를 판단하는 판단부; 및
    판단된 인증 결과가 성공인 제어 정보를 상기 출입 장치로 전송하여 사용자의 출입 허가를 제어하는 제어부
    를 포함하는 장치.
  2. 제 1항에 있어서,
    상기 수집부는,
    상기 AP 장치가 와이파이 통신 또는 비콘 통신을 통해 수신한 단말 식별 정보를 상기 단말 정보로서 수집하는 것을 특징으로 하는 장치.
  3. 제 2항에 있어서,
    상기 수집부는,
    와이파이 수신 기능이 꺼진 상태에서도 상기 AP 장치를 항상 검색하는 기능이 실행된 사용자 단말의 와이파이 실행에 의해, 상기 단말 정보를 수집하는 것을 특징으로 하는 장치.
  4. 제 1항에 있어서,
    상기 수신부는,
    상기 출입 장치의 리더기가 읽어들인 출입 카드의 RFID(Radio Frequency IDentification)를 상기 카드 정보로서 수신하는 것을 특징으로 하는 장치.
  5. 제 1항에 있어서,
    사용자의 출입 카드의 카드 아이디 및 매칭된 사용자 단말의 단말 식별 정보를 저장하는 DB(DataBase)를 더 포함하고,
    상기 판단부는,
    인증이 요청된 카드 정보의 카드 아이디를 키로 하여 DB로부터 상기 저장된 카드 아이디 및 단말 식별 정보를 조회하면, 상기 카드 인증을 성공으로 판단하고, 조회된 단말 식별 정보가 상기 수집된 단말 식별 정보이면 상기 단말 인증을 성공으로 판단하고, 카드 인증 및 단말 인증이 성공이면 상기 MFA의 인증 결과를 성공으로 판단하는 것을 특징으로 하는 장치.
  6. 제 1항에 있어서,
    상기 제어부는,
    상기 출입 장치의 게이트 콘트롤러로 출입 허가의 제어 정보를 전송하고,
    상기 게이트 콘트롤러는 전송된 제어 정보에 의해 사용자가 통과하는 게이트 장치를 출입 허가로 제어하는 것을 특징으로 하는 장치.
  7. 제 1항에 있어서,
    상기 출입 장치의 주변 영역이 복수개의 단위 영역으로 구분되고, 각 단위 영역에서 주변의 AP 장치들로부터 각각 수신되는 무선 신호의 세기가 단위 영역별 위치 정보로서 저장되는 DB를 포함하고,
    상기 수집부는,
    상기 사용자 단말의 단말 식별 정보 및 상기 단위 영역에서 수신된 각각의 무선 신호의 세기를 포함하는 상기 단말 정보를 AP 장치를 통해 수집하는 것을 특징으로 하는 장치.
  8. 제 7항에 있어서,
    상기 판단부는,
    수집된 무선 신호의 세기를 키로 하여 상기 DB로부터 가장 일치하는 위치 정보를 조회하고, 조회된 위치 영역의 단위 영역을 사용자 단말이 위치하는 단위 영역으로 판단하는 것을 특징으로 하는 장치.
  9. 제 7항에 있어서,
    상기 DB는 상기 출입 장치가 위치하는 상기 단위 영역 정보를 더 저장하고,
    상기 판단부는,
    수집된 단말 정보의 단위 영역 정보를 키로 하여 상기 DB로부터 출입 장치의 단위 영역 정보를 조회하면, 상기 단말 인증을 성공으로 판단하는 것을 특징으로 하는 장치.
  10. 카드 정보 및 단말 정보를 기반으로 출입을 제어하는 시스템에 있어서,
    각각의 AP 장치로부터 무선 신호를 수신하고, 단말 정보를 응답 전송하는 사용자 단말;
    출입 장치의 주변에 각각 설치되고, 상기 무선 신호를 수신한 사용자 단말로부터 상기 단말 정보를 전송받아 제어 장치로 전송하는 AP 장치;
    출입 허가를 요청하는 사용자의 카드 정보를 읽어들이고, 상기 카드 정보를 포함하는 출입 인증을 요청하고, 인증 결과의 제어 정보를 수신하여 사용자 출입을 허가 또는 불허로 동작하는 출입 장치; 및
    상기 AP 장치를 통해 단말 정보를 수집하고, 상기 출입 장치로부터 상기 인증 요청을 수신하고, 수신된 카드 정보가 등록된 카드 정보인지 판단하는 카드 인증 및 수신된 카드 정보의 단말 정보가 상기 수집된 단말 정보인지 판단하는 단말 인증을 포함하는 MFA의 인증 결과를 판단하고, 판단된 인증 결과가 성공인 제어 정보를 상기 출입 장치로 전송하는 제어 장치
    를 포함하는 시스템.
  11. 장치가 카드 정보 및 단말 정보를 기반으로 출입을 제어하는 방법에 있어서,
    출입 장치 주변의 AP 장치가 수신한 사용자 단말의 단말 정보를 수집하는 단계;
    상기 출입 장치가 읽어들인 사용자의 카드 정보를 포함하는 출입 인증의 요청을 수신하는 단계;
    인증이 요청된 카드 정보가 등록된 카드 정보인지 판단하는 카드 인증 및 수신된 카드 정보의 단말 정보가 상기 수집된 단말 정보인지 판단하는 단말 인증을 포함하는 MFA의 인증 결과를 판단하는 단계; 및
    판단된 인증 결과가 성공인 제어 정보를 상기 출입 장치로 전송하여 사용자의 출입 허가를 제어하는 단계
    를 포함하는 방법.
  12. 제 11항에 있어서,
    상기 수집하는 단계는,
    상기 AP 장치가 와이파이 통신 또는 비콘 통신을 통해 수신한 단말 식별 정보를 상기 단말 정보로서 수집하는 단계인 것을 특징으로 하는 방법.
  13. 제 11항에 있어서,
    상기 수집하는 단계는,
    와이파이 수신 기능이 꺼진 상태에서도 상기 AP 장치를 항상 검색하는 기능이 실행된 사용자 단말의 와이파이 실행에 의해, 상기 단말 정보를 수집하는 단계인 것을 특징으로 하는 방법.
  14. 제 11항에 있어서,
    상기 수신하는 단계는,
    상기 출입 장치의 리더기가 읽어들인 출입 카드의 RFID를 상기 카드 정보로서 수신하는 단계인 것을 특징으로 하는 방법.
  15. 제 11항에 있어서,
    DB가 사용자의 출입 카드의 카드 아이디 및 매칭된 사용자 단말의 단말 식별 정보를 저장하고,
    상기 판단하는 단계는,
    인증이 요청된 카드 정보의 카드 아이디를 키로 하여 DB로부터 상기 저장된 카드 아이디 및 단말 식별 정보를 조회하면, 상기 카드 인증을 성공으로 판단하고, 조회된 단말 식별 정보가 상기 수집된 단말 식별 정보이면 상기 단말 인증을 성공으로 판단하고, 카드 인증 및 단말 인증이 성공이면 상기 MFA의 인증 결과를 성공으로 판단하는 단계인 것을 특징으로 하는 방법.
  16. 제 11항에 있어서,
    상기 제어하는 단계는,
    상기 출입 장치의 게이트 콘트롤러로 출입 허가의 제어 정보를 전송하고,
    상기 게이트 콘트롤러는 전송된 제어 정보에 의해 사용자가 통과하는 게이트 장치를 출입 허가로 제어하는 단계인 것을 특징으로 하는 방법.
  17. 제 11항에 있어서,
    상기 출입 장치의 주변 영역이 복수개의 단위 영역으로 구분되고, 각 단위 영역에서 주변의 AP 장치들로부터 각각 수신되는 무선 신호의 세기가 단위 영역별 위치 정보로서 저장되는 DB를 포함하고,
    상기 수집하는 단계는,
    상기 사용자 단말의 단말 식별 정보 및 상기 단위 영역에서 수신된 각각의 무선 신호의 세기를 포함하는 상기 단말 정보를 AP 장치를 통해 수집하는 단계인 것을 특징으로 하는 방법.
  18. 제 17항에 있어서,
    상기 판단하는 단계는,
    수집된 무선 신호의 세기를 키로 하여 상기 DB로부터 가장 일치하는 위치 정보를 조회하고, 조회된 위치 영역의 단위 영역을 사용자 단말이 위치하는 단위 영역으로 판단하는 단계인 것을 특징으로 하는 방법.
  19. 제 17항에 있어서,
    상기 DB는 상기 출입 장치가 위치하는 상기 단위 영역 정보를 더 저장하고,
    상기 판단하는 단계는,
    수집된 단말 정보의 단위 영역 정보를 키로 하여 상기 DB로부터 출입 장치의 단위 영역 정보를 조회하면, 상기 단말 인증을 성공으로 판단하는 단계인 것을 특징으로 하는 방법.
PCT/KR2017/005072 2016-05-16 2017-05-16 카드 정보 및 단말 정보를 기반으로 출입을 제어하는 장치, 시스템 및 방법 Ceased WO2017200273A1 (ko)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR20160059832 2016-05-16
KR10-2016-0059832 2016-05-16

Publications (1)

Publication Number Publication Date
WO2017200273A1 true WO2017200273A1 (ko) 2017-11-23

Family

ID=60325188

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2017/005072 Ceased WO2017200273A1 (ko) 2016-05-16 2017-05-16 카드 정보 및 단말 정보를 기반으로 출입을 제어하는 장치, 시스템 및 방법

Country Status (2)

Country Link
KR (1) KR101981604B1 (ko)
WO (1) WO2017200273A1 (ko)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113129810A (zh) * 2020-01-15 2021-07-16 西安诺瓦星云科技股份有限公司 接口匹配检测方法和系统
CN115601864A (zh) * 2022-10-24 2023-01-13 深圳市博铭维系统工程有限公司(Cn) 一种智慧园区一卡通管理系统及方法

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102097868B1 (ko) 2018-06-15 2020-04-06 주식회사 에스원 Mdm 제어 방법, mdm을 이용한 출입 제어 방법 및 그 시스템
KR102672570B1 (ko) * 2023-01-17 2024-06-07 주식회사 고스트패스 본인 인증 요청 방법 및 장치
EP4478223A4 (en) * 2023-01-17 2025-07-09 Ghost Pass Inc IDENTITY AUTHENTICATION REQUEST METHOD, IDENTITY AUTHENTICATION REQUEST DEVICE, AND IDENTITY AUTHENTICATION SYSTEM
KR102612063B1 (ko) * 2023-09-15 2023-12-08 주식회사 스피드정보 실내 위치 측위를 활용한 출입 통제 방법, 장치 및 시스템

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20010007874A (ko) * 2000-10-13 2001-02-05 최형선 지문인식 및 얼굴인식을 이용한 출입통제시스템 및 그 방법
JP2008217598A (ja) * 2007-03-06 2008-09-18 Ntt Docomo Inc 入室管理システム、入室管理サーバ、入室管理方法
JP2011076520A (ja) * 2009-10-01 2011-04-14 Nec Corp 入場管理システム、入場管理方法及び入場管理制御プログラム
KR20150003549A (ko) * 2013-07-01 2015-01-09 포컬쳐주식회사 출입관리를 위한 무인 gate시스템
KR20160014295A (ko) * 2014-07-29 2016-02-11 현대자동차주식회사 차량 출입 관제 시스템 및 그 제어 방법

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101303810B1 (ko) * 2011-11-03 2013-09-04 주식회사 유니온커뮤니티 휴대 전화기를 이용한 출입관리기 제어방법 및 그 출입관리기
KR101329520B1 (ko) 2011-12-08 2013-11-20 포항공과대학교 산학협력단 순차적 무선 인증을 통한 스마트기기의 출입인증 및 위치인증 장치 및 이를 이용한 출입인증 및 위치인증 방법
KR101491706B1 (ko) * 2014-09-15 2015-02-11 박준희 앱 기반 출입 통제 서비스 제공 방법

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20010007874A (ko) * 2000-10-13 2001-02-05 최형선 지문인식 및 얼굴인식을 이용한 출입통제시스템 및 그 방법
JP2008217598A (ja) * 2007-03-06 2008-09-18 Ntt Docomo Inc 入室管理システム、入室管理サーバ、入室管理方法
JP2011076520A (ja) * 2009-10-01 2011-04-14 Nec Corp 入場管理システム、入場管理方法及び入場管理制御プログラム
KR20150003549A (ko) * 2013-07-01 2015-01-09 포컬쳐주식회사 출입관리를 위한 무인 gate시스템
KR20160014295A (ko) * 2014-07-29 2016-02-11 현대자동차주식회사 차량 출입 관제 시스템 및 그 제어 방법

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113129810A (zh) * 2020-01-15 2021-07-16 西安诺瓦星云科技股份有限公司 接口匹配检测方法和系统
CN113129810B (zh) * 2020-01-15 2022-06-17 西安诺瓦星云科技股份有限公司 接口匹配检测方法和系统
CN115601864A (zh) * 2022-10-24 2023-01-13 深圳市博铭维系统工程有限公司(Cn) 一种智慧园区一卡通管理系统及方法

Also Published As

Publication number Publication date
KR20170129068A (ko) 2017-11-24
KR101981604B1 (ko) 2019-05-23

Similar Documents

Publication Publication Date Title
WO2017200273A1 (ko) 카드 정보 및 단말 정보를 기반으로 출입을 제어하는 장치, 시스템 및 방법
CN108305360B (zh) 门禁控制方法和相关装置
US12363085B2 (en) Network device proximity-based authentication
WO2010036017A2 (en) Method and apparatus for communicating with external device using contactless interface
US9848363B2 (en) Sending access information from physical access control system to user terminal
CN103220313A (zh) 设备网络共享方法及与其配合的设备操控方法
BR112012005123B1 (pt) Método e sistema para autenticação de um usuário em um dispositivo de acesso e dispositivo de acesso
WO2019039746A1 (ko) 출입문 도어락 제어 방법 및 시스템과, 그 도어락 장치
KR101623432B1 (ko) 블루투스 연결에 의한 실내에서의 출입인증을 차단할 수 있는 블루투스 출입인증장치 및 그 방법
KR101855494B1 (ko) 모바일 장치를 이용한 도어 시스템 및 방법
US20090113027A1 (en) Personal network management method and personal network management apparatus
CN109775484A (zh) 电梯楼层控制方法、装置、系统及计算机设备
KR20150137947A (ko) 근거리 유저 식별을 이용한 차량 도어락 시스템
US20060161770A1 (en) Network apparatus and program
WO2016148483A1 (ko) 홈에너지 관리 시스템에서 비콘을 이용한 홈에너지 관리 장치 및 방법
WO2018155828A1 (ko) 영역별 사용자 인증시스템
KR20160062369A (ko) 출입 인증 시스템 및 그 인증 방법
WO2017164494A1 (ko) 출입관리기에 접속한 사용자 단말기의 사용자 인증방법, 그 방법을 위한 어플리케이션 및 그 어플리케이션이 저장된 어플리케이션 분배 서버
CN113556740B (zh) 身份认证系统及方法
KR20090061550A (ko) 펨토셀에서의 아이디 정보 기반 사용자 관리 방법 및시스템
KR101738056B1 (ko) 근거리 유저 식별을 통한 엘리베이터 관리 시스템
WO2009075467A1 (en) User management method and system based on identification information in femtocell
WO2013100646A1 (ko) 무선 단말장치에서 근거리 통신 연결 제어장치 및 방법
WO2018194302A1 (ko) 휴대용 디바이스를 이용하는 인증 방법
KR20170065709A (ko) 출입통제 관리기와 연결되는 휴대 단말기의 출입 인증방법 및 그 방법을 구현한 소프트웨어를 분배하는 소프트웨어 분배 서버

Legal Events

Date Code Title Description
NENP Non-entry into the national phase

Ref country code: DE

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17799630

Country of ref document: EP

Kind code of ref document: A1

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205 DATED 12/03/2019)

122 Ep: pct application non-entry in european phase

Ref document number: 17799630

Country of ref document: EP

Kind code of ref document: A1