Provide access to the lock for a service provider using an authorization token and credentials
By accessing the coordination server to generate authorization tokens and credentials, the management problem of lock owners facing too many access requests is solved, and secure and flexible lock access management and audit tracking is achieved, reducing the risk of service consumers being interfered with.
Patent Information
- Application Number
- CN202080066644.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-10-01
- Filing Date
- 2020-09-29
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2040-09-29
AI Technical Summary
In the prior art, the owner or user of the lock is difficult to effectively manage and control access rights to the lock when facing too many access requests, resulting in excessive interference from the service consumers.
By accessing the mechanism of coordinating the server to generate authorization tokens and credentials, the service consumer first confirms the authorization, generates authorization tokens and limits its validity time, and the lock manager generates credentials to ensure that the service provider accesses during the authorization period and avoids centrally storing sensitive data to reduce the risk of hackers.
It realizes secure and flexible access management for locks, and the service consumers do not need to confirm frequently during the validity period, reducing the risk of lock owners being interfered with by excessive access requests and improving access management and audit tracking capabilities.
Smart Images

Figure CN114467103B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method, an access coordination server, a computer program, and a computer program product for providing access to a lock for a service provider using an authorization token and a subsequent credential. Background Art
[0002] Locks and keys have evolved from traditional purely mechanical locks. Nowadays, electronic locks are becoming increasingly common. For an electronic lock, the authentication of a user does not require a mechanical key profile. An electronic lock can be opened, for example, using a personal identification number (PIN) or an electronic key. The electronic key and the electronic lock can communicate, for example, via a wireless interface. Such electronic locks offer many benefits, including increased flexibility in access rights management, audit trails, key management, etc.
[0003] When the owner or user of such an electronic lock consumes a service, this person is hereinafter referred to as a service consumer. The service can be any service for which the person performing the service needs the electronic lock to be opened. For example, the service can be the delivery of a product, a cleaning service, a builder / plumber / electrician, etc. In order to be able to consume the service, the service consumer therefore needs to provide access to the service provider using the electronic lock. In addition, there is a delicate balance in querying service consumer access. On the one hand, the service consumer needs to approve the service provider to allow access. On the other hand, the service consumer should not be overwhelmed with too many access requests. Summary of the Invention
[0004] The aim is to provide a solution for providing access to a lock that is applicable to all types of services and in which the lock owner is not overwhelmed with too many access requests.
[0005] According to a first aspect, there is provided a method for providing access to a lock to provide a service, the lock being associated with a service consumer. The method is performed in an access coordination server and includes the steps of: receiving a request to access the lock, the request being based on the service consumer ordering a service that requires access to a physical space protected by the lock; sending a consumer request to the service consumer device asking whether to grant access to the lock to the service provider for which the service is to be provided; receiving an affirmative consumer response from the service consumer device, the affirmative consumer response indicating that the service consumer allows the service provider to access the physical space protected by the lock; determining the valid time of an authorization token; obtaining an authorization token for the service provider, the authorization token having a determined valid time; providing the authorization token to the service provider; deleting the authorization token in the access coordination server; receiving a proxy request from a specific service provider proxy device to access the lock, the proxy request including the authorization token; obtaining a credential for the service provider proxy device on condition that the authorization token is valid; and providing the credential to the service provider proxy device.
[0006] The validity period of the credential can expire before the validity period of the authorization token.
[0007] The authorization token may not be usable as a credential for the lock.
[0008] The authorization token can be limited in terms of the number of credentials it can be used for. In this case, the step of obtaining a credential is performed subject to not exceeding the number of credentials of the authorization token.
[0009] The step of obtaining an authorization token can include receiving the authorization token from a lock manager.
[0010] The step of determining the validity period of the authorization token can include determining the validity period as the validity period approved in a positive consumer response.
[0011] According to a second aspect, there is provided an access coordination server for providing access to a lock to provide a service, the lock being associated with a service consumer, the method being performed in the access coordination server. The access coordination server includes: a processor; and a memory storing instructions that, when executed by the processor, cause the access coordination server to perform the following operations: receive a request to access the lock, the request being based on a service consumer subscribing to a service that requires access to a physical space protected by the lock; send a consumer request to the service consumer device asking whether to grant access to the lock to a service provider for providing the service; receive a positive consumer response from the service consumer device, the positive consumer response indicating that the service consumer allows the service provider to access the physical space protected by the lock; determine the validity period of the authorization token; obtain an authorization token for the service provider, the authorization token having the determined validity period; provide the authorization token to the service provider; delete the authorization token in the access coordination server; receive a proxy request for a specific service provider proxy device to access the lock, the proxy request including the authorization token; obtain a credential for the service provider proxy device on condition that the authorization token is valid; and provide the credential to the service provider proxy device.
[0012] The validity period of the credential can expire before the validity period of the authorization token.
[0013] The authorization token may not be usable as a credential for the lock.
[0014] The authorization token can be limited in terms of the number of credentials it can be used for. In this case, the instructions for obtaining a credential include instructions that, when executed by the processor, cause the access coordination server to obtain a credential subject to not exceeding the number of credentials of the authorization token.
[0015] The instructions for obtaining an authorization token can include instructions that, when executed by the processor, cause the access coordination server to receive the authorization token from a lock manager.
[0016] The instruction for determining the validity period of the authorization token may include the following instruction: when executed by a processor, the instruction causes the access coordination server to determine the validity period as the validity period approved in the affirmative consumer response.
[0017] According to a third aspect, there is provided a computer program for providing access to a lock to provide a service, the lock being associated with a service consumer, the method being executed in an access coordination server. The computer program includes computer program code which, when run on the access coordination server, causes the access coordination server to perform the following operations: receiving a request to access the lock, the request being based on a service consumer subscribing to a service that requires access to a physical space protected by the lock; sending a consumer request to the service consumer device asking whether to grant access to the lock to the service provider that is to provide the service; receiving an affirmative consumer response from the service consumer device, the affirmative consumer response indicating that the service consumer allows the service provider to access the physical space protected by the lock; determining the validity period of the authorization token; obtaining an authorization token for the service provider, the authorization token having the determined validity period; providing the authorization token to the service provider; deleting the authorization token in the access coordination server; receiving a proxy request from a specific service provider proxy device to access the lock, the proxy request including the authorization token; obtaining a credential for the service provider proxy device on condition that the authorization token is valid; and providing the credential to the service provider proxy device.
[0018] According to a fourth aspect, there is provided a computer program product which includes the computer program according to the third aspect and a computer-readable device storing the computer program.
[0019] In general, unless otherwise clearly defined herein, all terms used in the claims should be interpreted according to their ordinary meaning in the technical field to which this disclosure pertains. All references to "an / the element, device, component, apparatus, step, etc." will be construed openly to refer to at least one instance of the element, device, component, apparatus, step, etc., unless otherwise clearly stated. Unless explicitly stated, the steps of any method disclosed herein need not be performed in the exact order disclosed. Description of the Drawings
[0020] Aspects and embodiments will now be described by way of example with reference to the accompanying drawings, in which:
[0021] Figure 1 is a schematic diagram showing an environment in which the embodiments proposed herein can be applied;
[0022] Figure 2 is showing in Figure 1 the environment of an example of communication in providing a service;
[0023] Figure 3 is a flowchart showing an embodiment of a method for providing access to a lock to provide a service;
[0024] Figure 4 shows Figure 1 a schematic diagram of components of an access coordination server; and
[0025] Figure 5 shows an example of a computer program product including a computer-readable device. DETAILED DESCRIPTION
[0026] Aspects of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the invention are shown. However, these aspects may be implemented in many different forms and should not be construed as limiting; rather, these embodiments are provided as examples so that the present disclosure will be thorough and complete and will fully convey the scope of all aspects of the invention to those skilled in the art. Throughout the specification, the same reference numerals refer to the same elements.
[0027] The embodiments presented herein are based on an authorization token generated when a service consumer receives a service provider to obtain access to a physical space protected by a lock controlled by the service consumer. The authorization token provides blanket access to the service provider during the valid time of the authorization token. In this way, credentials can be generated for different service provider agents of the service provider when needed during the validity period of the authorization token. In addition, the authorization token is not stored centrally, but is stored with the service provider to reduce the risk of hackers stealing valuable access data from a central location.
[0028] Figure 1 is a schematic diagram showing an environment in which the embodiments presented herein can be applied. Access to the physical space 16 is restricted by a selectively unlockable physical barrier 15. The barrier 15 can be a door, gate, hatch, cabinet door, drawer, window, etc. The physical barrier 15 is disposed in the surrounding physical structure (walls, fences, ceilings, floors, etc.) and is located between the restricted physical space 16 and the accessible physical space 14. Note that the accessible physical space 14 itself can be a restricted physical space, but relative to the physical barrier 15, the accessible physical space 14 is accessible. To control the locked or unlocked state of the barrier 15, a lock 10 is provided.
[0029] The owner or user of the lock 10 is herein represented as the service consumer 2. The service consumer carries a service consumer device 4, which is a portable electronic device such as a smartphone, mobile phone, tablet computer, laptop computer, etc.
[0030] Lock 10 is an electronic lock that can communicate with a lock manager 1. The lock manager can in turn (but not necessarily) be connected to multiple similar locks. The lock manager 1 can configure the lock 10, for example, by adding and / or removing credentials that will be allowed access. Lock 10 is an electronic lock and can be opened using non-mechanical credentials. For example, the credential can be a PIN (Personal Identification Number) entered on a keyboard connected to the lock 10. Alternatively or additionally, the lock 10 can be opened using credentials on an electronic key and can be implemented as part of a mobile phone, smartphone, key card, wearable device, smartphone case, access card, electronic physical key, etc. The electronic key can communicate with the lock 10 through a wired interface or a wireless interface such as using Bluetooth, Bluetooth Low Energy (BLE), any IEEE 802.15 standard, Radio Frequency Identification (RFID), Near Field Communication (NFC), any IEEE 802.11 standard, Wireless Universal Serial Bus (USB), USB, Ethernet, serial connection (such as RS-485), etc. The lock 10 can communicate with the lock manager 1 through a wired interface or a wireless interface such as using Bluetooth, BLE, any IEEE 802.11 standard, Wireless USB, USB, Ethernet, serial connection (such as RS-485), etc.
[0031] There is also a service provider server 3 controlled by a service provider. The service provider can be, for example, a delivery company, a cleaning company, a construction company, a plumber, an electrician, etc. The service provider server 3 can also be provided by a third party on behalf of the service provider. This is particularly useful for small businesses that may not want to establish their own service provider server.
[0032] For ease of understanding, whenever any communication or electronic processing performed by the service provider is mentioned herein, that any communication or electronic processing is performed in the service provider server 3 (of the service provider). As described in more detail below, the service consumer 2 orders a service from the service provider that controls the service provider server 3.
[0033] The service provider utilizes a service provider agent 6 to perform the service. The service provider agent 6 can be an employee or subcontractor of the service provider. The service provider agent 6 carries a service provider agent device 7, which is a portable electronic device such as a smartphone, mobile phone, tablet computer, laptop computer, etc. The functions described herein performed by the service provider agent device 7 can be performed, for example, in a software application (also referred to as an app) executed on the service provider agent device. The service provider agent device 7 can be used to request unlocking of the lock 10.
[0034] The access coordination server 5 is a server that coordinates communication between different parties involved in a scenario where a service that requires access to a restricted physical space 16 is provided.
[0035] Figure 1 Communication between different nodes in can use local communication such as using Bluetooth, Bluetooth Low Energy (BLE), any IEEE 802.15 standard, any IEEE 802.11 standard, Wireless USB (Universal Serial Bus), USB, Ethernet, serial connection (such as RS-485), etc. and / or occur via wide area communication such as cellular networks and the Internet. At a higher layer, the Internet Protocol (IP) can be used for communication.
[0036] Figure 2 is a sequence diagram showing the communication in an example of providing a service in the Figure 1 environment.
[0037] First, the service consumer 2 sends an order 20 for the service to the service provider server 3. The order 20 can be an order sent via an electronic service such as the Internet, by phone, in person, etc. In the case where the order 20 is not electronic, the personnel of the service provider enter the data of the order into the service provider server 3. It should be noted that the order 20 can be an indirect order from the service consumer 2 via a third party, without the need to go directly from the service consumer 2 to the service provider server 3. For example, in an online shopping example, the service consumer 2 orders a physical product to be delivered from a supplier ( Figure 2 a third party not shown in). The supplier in turn uses a delivery company to deliver the physical product to the service consumer 2. The choice of the delivery company can be made by the service consumer or the supplier. In this case, the service consumer 2 indirectly orders the delivery service from the delivery company, and in this case, the delivery company is the service provider.
[0038] The service provider server 3 sends an access request 21a to the access coordination server 5. The request 21a indicates that the service provider wants to perform an access to unlock the service consumer 2. The request 21a includes an identifier of the service consumer 2 (or his / her lock 10) (such as an email address or a phone number, or an identifier associated with the email address or the phone number) and the requested valid time of the service provided by the service provider. The requested valid time can be relatively short, for example, 24 hours, or can be longer, for example, in sequence, or weeks, months or even years. The request 21a is not for a specific service provider agent, but for the service provider as a whole. As described below, the access to a specific service provider agent is requested later.
[0039] The access coordination server sends a corresponding access request 21b to the service consumer device 4. The service consumer device 4 then asks the user in the access request 21c whether the service provider should be allowed to use the lock 10 for access within the proposed time window. This can be provided, for example, as an inquiry in a software application (also known as an app) of the service consumer device 4.
[0040] The service consumer 2 accepts the request with an affirmative consumer response 22a (otherwise the sequence ends). The service consumer device 4 sends a corresponding affirmative consumer response ("ok") 22b to the access coordination server 5.
[0041] The access coordination server 5 now obtains 23 an authorization token. The authorization token can be obtained from the lock manager 1 or can be generated in the service consumer device 4. As described in more detail below, the authorization token has a relatively long validity time (compared to the credentials mentioned below), thus allowing credentials (possibly with a shorter validity time) to be generated within the validity time of the authorization token.
[0042] The access coordination server 5 sends the authorization token 24 to the service provider server 3. In this way, the service provider knows that the service consumer is ready to accept the delivery of the service, and the service provider server 3 stores the authorization token for use when a service provider agent has been selected. The access coordination server 5 deletes the authorization token from its memory, thereby reducing the risk of a hacker obtaining access to any sensitive credential data (such as the authorization token) by attacking the access coordination server 5. The selection of a service provider agent (i.e., a natural person) may take a shorter or longer time, but once a service provider agent has been selected, it is sent 25 in the agent request to the access coordination server 5. The agent request 25 also contains the authorization token previously provided by the access coordination server 5 to the service provider server 3.
[0043] The access coordination server 5 sends a request credentials message 29 to the lock manager 1. The request credentials message 29 includes the authorization token. The lock manager 1 checks the authorization token to verify its validity (matching a specific lock and checking its validity time), and only generates 25 (and optionally encrypts) credentials if successful. The lock manager 1 then responds to the access coordination server 5 with the generated credentials 26a, and the access coordination server 5 sends the generated credentials 26b to the service provider agent device 7 (optionally via the service provider). In addition, the access coordination server 5 sends a credentials confirmation 27 to the service provider server 3 to notify that the credentials have been provided to the service provider agent device 7.
[0044] The lock manager 1 can now configure the lock 10 to accept credentials by sending a configuration 30 for causing the lock to accept the generated credentials. The lock manager 1 also sends a credential valid message 31a to the access coordination server 5, and the access coordination server 5 in turn sends a corresponding credential valid message 31b to the service provider server 3, thereby informing the service provider of the fact that the lock 10 is ready to accept the credentials provided to the service provider agent 6. The access coordination server 5 also sends a credential valid message 31c to the service provider agent device 7.
[0045] Once the service provider agent 6 arrives at the location of the lock 10, the service provider agent 6 provides an unlock input 32a to the service provider agent device 7 (e.g., using a user interface or by placing the service provider agent device 7 in close proximity to the lock 10). Then, the service provider agent device 7 unlocks 32b the lock 10 by either directly using the communication between the service provider agent device 7 and the lock 10 or by decrypting the PIN of the generated credential and displaying the PIN of the generated credential to the service provider agent 6 that manually enters the PIN into the lock 10. In one embodiment, the service provider agent device 7 unlocks 32b the lock 10 by communicating with the lock manager 1 to verify the credentials of the service provider agent device 7, thereby unlocking the lock after verification. The service provider agent device 7, the lock manager 1, or the lock 10 allows unlocking only if the valid time of the credential contains the current time.
[0046] When the lock 10 is unlocked, the lock 10 sends an unlocked message 33a to the lock manager 1. The lock manager 1 sends a corresponding unlocked message 33b to the access coordination server 5, and the access coordination server 5 in turn sends an unlocked message 33c to the service provider server 3. In this way, the service provider is informed of the fact that the service provider agent 6 has unlocked the lock 10.
[0047] Figure 3 is a flowchart showing an embodiment of a method for providing access to a lock to provide a service. As described above, the lock is associated with a service consumer. The method is executed in an access coordination server and corresponds to Figure 2 the actions of the access coordination server shown and described above. Using this method, a service consumer can order a service and conveniently and securely provide access to the physical space protected by the lock. In addition, the service consumer can provide a comprehensive license to the service provider during a specific valid period, so that the service consumer does not need to be troubled by the license inquiries of each individual service provider agent during the valid period.
[0048] In receiving access request step 40, the access coordination server receives a request for an access lock. The request is based on a service consumer subscribing to a service that requires access to a physical space protected by the lock. The access request can be received from a service provider. Optionally, the access request includes a requested valid time during which the service provider will be able to allocate a service provider agent that will have the right to access the physical space protected by the lock.
[0049] In sending consumer request step 42, the access coordination server sends a consumer request to the service consumer device asking whether to grant access to the lock to the service provider agent that is to provide the service. When the access request includes the requested valid time, the valid time is included in the consumer request. Alternatively, the access coordination server determines the valid time for which the service provider requests access.
[0050] In conditional receiving affirmative consumer response step 44, the access coordination server determines whether an affirmative consumer response is received from the service consumer device, where the affirmative consumer response indicates that the service consumer allows the service provider to access the physical space protected by the lock. If an affirmative consumer response is received, the method proceeds to determining the valid time of the token step 45. Otherwise, the method ends.
[0051] Using this confirmation process by the service consumer, the service consumer needs to provide an acceptance for the lock to be opened for the service provider agent that provides the service. Once approved, this acceptance is a comprehensive acceptance such that the service provider can access the lock during the valid time requested by any service provider agent of the service provider.
[0052] In determining the valid time of the token step 45, the access coordination server determines the valid time of the authorization token. For example, the valid time can be determined as the valid time approved by the affirmative consumer response. In one embodiment, such a valid time is included in the consumer request and is verified in the affirmative consumer response. In one embodiment, the valid time can be determined as the valid time explicitly included in the affirmative consumer response. In either of these two embodiments, the valid time of the authorization token will reflect the valid time approved by the service consumer. In one embodiment, the valid time is determined as the time defined by the duration after receiving the affirmative consumer response. For example, the system can be set such that the valid time is always a specific number of hours, days, etc. after the affirmative consumer response. Then, the service consumer device will be configured to notify the service consumer of such a valid time when asking for the service consumer's approval.
[0053] In step 46 of obtaining an authorization token, the access coordination server obtains an authorization token for the service provider. The authorization token has a determined valid time. The authorization token can be restricted in terms of the number of credentials it can be used for. The authorization token is defined for a specific lock or a specific group of locks for the service consumer. The authorization token can be obtained from the lock manager or can be obtained from the service consumer device. The authorization token may not be used as a credential for the lock. In other words, the authorization token cannot be directly used to open the lock, but can be provided to the lock manager 1 for generating a credential that can open the lock.
[0054] In step 48 of providing the authorization token, the access coordination server provides the authorization token to the service provider.
[0055] In step 49 of deleting the authorization token, the access coordination server (actively) deletes the authorization token in the access coordination server. In other words, the access coordination server avoids storing the authorization token for longer than the time required to provide it to the service provider. It can be ensured that the deletion occurs within one second after providing the authorization token to the service provider.
[0056] In step 50 of receiving a proxy request, the access coordination server receives a proxy request from a specific service provider proxy device to access the lock. The proxy request includes the authorization token, i.e., the same authorization token that was provided to the service provider in step 48. The proxy request is received from the service provider. This step can occur within minutes, hours, days, or weeks after step 49 of deleting the authorization token.
[0057] In step 52 of obtaining a credential, the access coordination server obtains a credential for the service provider proxy device under the condition that the authorization token is valid. The credential can be obtained from the lock manager, i.e., the lock manager generates the credential according to a command from the access coordination server. It should be noted that the authorization token cannot be used as a credential for obtaining access to the lock; the authorization token is provided to the lock manager for generating (when the authorization token is valid) the credential to be provided to the lock. This provides additional security because even if an attacker holds the authorization token, the lock manager can be configured to only allow credential requests (including the authorization token) from a pre-configured access coordination server (e.g., identified by an IP address range or by an encrypted signature). Additionally, the lock manager can control when to provide the credential.
[0058] The validity period of the credential may expire before the validity period of the authorization token. In this way, the same authorization token can be used for several credentials within the (overall) validity period of the authorization token, e.g., for different service agents of the service provider, and this validity period corresponds to the time when the service consumer receives the service provided by the service provider. In other words, the service consumer provides access to the service provider within the overall validity period, and then the service provider requests credentials for the service provider agent within this overall validity period, which is enforced using the authorization token.
[0059] Optionally, when the number of credentials is defined for the authorization token, the credentials are obtained only if the number of credentials of the authorization token is not exceeded. Optionally, the credentials are obtained only if the service consumer has not revoked the access to the service provider. In this way, the service consumer can revoke the access to any service provider if needed, e.g., if the cleaning contract with a specific service provider is terminated.
[0060] In the providing credentials step 54, the access coordination server provides the credentials to the service provider agent device. This allows the use of the service provider agent device to unlock the lock. Then, the credentials are actively deleted from the access coordination server 5.
[0061] In the optional conditional service completion step 56, the access coordination server determines whether the service associated with the positive consumer response and the authorization token is completed. If this is the case, the method ends. Otherwise, the method returns by going back to the receiving agent request step 50 to wait for a new assignment of the service agent.
[0062] Figure 4 is a schematic diagram of the components of the access coordination server 5 shown. The processor 60 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), application specific integrated circuit, etc. that are capable of executing the software instructions 67 stored in the memory 64, and thus the software instructions 67 can be a computer program product. The processor 60 can be configured to execute the method described above with reference to Figure 1 description. Figure 3 description.
[0063] The memory 64 can be any combination of a read-write memory (RAM) and a read-only memory (ROM). The memory 64 also includes a permanent storage device, which can be, for example, any one or combination of a magnetic memory, an optical memory, a solid-state memory, or even a remotely mounted memory.
[0064] A data memory 66 is also provided for reading and / or storing data during the execution of software instructions in the processor 60. The data memory 66 can be any combination of read-write memory (RAM) and read-only memory (ROM).
[0065] The access coordination server 5 also includes an I / O interface 62 for communicating with other external entities such as the lock manager 1, service consumer devices, and service providers. The I / O interface 62 can include components for communicating via any one or more of the following: any IEEE 802.11 standard, wireless USB (Universal Serial Bus), USB, Ethernet, serial connection (e.g., RS-485), Bluetooth, Bluetooth Low Energy (BLE), any IEEE 802.15 standard, radio frequency identification (RFID), near field communication (NFC), etc.
[0066] To avoid obscuring the concepts presented herein, other components of the access coordination server 5 are omitted.
[0067] Figure 5 An example of a computer program product including a computer-readable device is shown. A computer program 91 can be stored on the computer-readable device, and the computer program can cause a processor to execute a method according to the embodiments described herein. In this example, the computer program product is an optical disc such as a CD (Compact Disc) or a DVD (Digital Versatile Disc) or a Blu-ray Disc. As described above, the computer program product can also be implemented in the memory of the device, such as Figure 4 the computer program product 64. Although the computer program 91 is schematically shown herein as a track on the illustrated optical disc, the computer program can be stored in any manner suitable for the computer program product, such as a removable solid-state memory, such as a Universal Serial Bus (USB) drive.
[0068] The various aspects of the present disclosure have been described above mainly with reference to some embodiments. However, as will be readily understood by those skilled in the art, other embodiments in addition to the embodiments disclosed above can also be within the scope of the present invention defined by the appended patent claims. Therefore, although various aspects and embodiments have been disclosed herein, other aspects and embodiments will be apparent to those skilled in the art. The various aspects and embodiments disclosed herein are for illustrative purposes and are not intended to be limiting, and their true scope and spirit are indicated by the appended claims.
Claims
1. A method for providing access to a lock (10) to provide a service, the lock (10) being associated with a service consumer (2), the method being executed in an access coordination server (5) and comprising the following steps: Receiving (40) a request from a service provider to access the lock (10), the request being based on the service consumer (2) subscribing to a service that requires access to a physical space (16) protected by the lock; Sending (42) a consumer request to a service consumer device (4) asking whether to grant the service provider to be served access to the lock (10); Receiving (44) an affirmative consumer response from the service consumer device, the affirmative consumer response indicating that the service consumer (2) allows the service provider to access the physical space (16) protected by the lock; Determining (45) the validity period of an authorization token; Obtaining (46) an authorization token for the service provider, the authorization token having a determined validity period, wherein the authorization token provides full access for the service provider during the validity period of the authorization token; Providing (48) the authorization token to the service provider (3); Deleting (49) the authorization token in the access coordination server (5); After the step of deleting (49) the authorization token, receiving (50) a proxy request from a specific service provider proxy device (7) to access the lock (10), the proxy request including the authorization token; Obtaining (52) a credential for the service provider proxy device (7) on condition that the authorization token is valid; and Providing (54) the credential to the service provider proxy device (7).
2. The method according to claim 1, wherein, The validity period of the credential expires before the validity period of the authorization token.
3. The method according to claim 1 or 2, wherein The authorization token cannot be used as a credential for the lock.
4. The method according to claim 1 or 2, wherein The authorization token is limited in terms of the number of credentials it can be used for, and wherein the step of obtaining (52) the credential is performed on condition that the number of credentials does not exceed that of the authorization token.
5. The method according to claim 1 or 2, wherein The step of obtaining (46) the authorization token includes receiving the authorization token from a lock manager (1).
6. The method according to claim 1 or 2, wherein The step of determining (45) the validity period of the authorization token includes: determining the validity period as the validity period approved in the affirmative consumer response.
7. An access coordination server (5) for providing access to a lock (10) to provide a service, the lock (10) being associated with a service consumer (2), the access coordination server (5) comprising: A processor (60); And A memory (64) storing instructions (67) that, when executed by the processor, cause the access coordination server (5) to perform the following operations: Receiving a request from a service provider to access the lock (10), the request being based on the service consumer (2) subscribing to a service that requires access to a physical space (16) protected by the lock; Sending a consumer request to a service consumer device (4) asking whether to grant the service provider to be served access to the lock (10); Receive a positive consumer response from the service consumer device, the positive consumer response indicating that the service consumer (2) permits the service provider to access the physical space (16) protected by the lock; Determine the valid time of the authorization token; Obtain an authorization token for the service provider, the authorization token having a determined valid time, wherein the authorization token provides full access for the service provider during the valid time of the authorization token; Provide the authorization token to the service provider (3); Delete the authorization token in the access coordination server (5); After executing the instruction to delete the authorization token, receive a proxy request from a specific service provider proxy device (7) to access the lock (10), the proxy request including the authorization token; Obtain a credential for the service provider proxy device (7) on the condition that the authorization token is valid; and Provide the credential to the service provider proxy device (7).
8. The access coordination server (5) according to claim 7, wherein The valid time of the credential expires before the valid time of the authorization token.
9. The access coordination server (5) according to claim 7 or 8, wherein, The authorization token cannot be used as a credential for the lock.
10. The access coordination server (5) according to claim 7 or 8, wherein, The authorization token is limited in terms of the number of credentials it can be used for, and wherein the instruction to obtain the credential includes an instruction (67) that causes the access coordination server (5) to obtain the credential on the condition that the number of credentials does not exceed that of the authorization token when executed by the processor.
11. The access coordination server (5) according to claim 7 or 8, wherein, The instruction to obtain the authorization token includes an instruction (67) that causes the access coordination server (5) to receive the authorization token from the lock manager (1) when executed by the processor.
12. The access coordination server (5) according to claim 7 or 8, wherein, The instruction to determine the valid time of the authorization token includes an instruction (67) that causes the access coordination server (5) to determine the valid time as the valid time approved in the positive consumer response when executed by the processor.
13. A computer-readable device having stored thereon a computer program (67, 91) for providing access to a lock (10) to provide a service, the lock (10) being associated with a service consumer (2), the computer program including computer program code which, when run on an access coordination server (5), causes the access coordination server (5) to perform the following operations: Receive a request from a service provider to access the lock (10), the request being based on the service consumer (2) subscribing to a service that requires access to the physical space (16) protected by the lock; Send a consumer request to the service consumer device (4) asking whether to permit the service provider for which the service is to be provided to access the lock (10); Receive a positive consumer response from the service consumer device, the positive consumer response indicating that the service consumer (2) permits the service provider to access the physical space (16) protected by the lock; Determine the valid time of the authorization token; Obtain an authorization token for the service provider, the authorization token having a determined valid time, wherein the authorization token provides full access for the service provider during the valid time of the authorization token; Provide the authorization token to the service provider (3); Delete the authorization token in the access coordination server (5); After running the code to delete the authorization token, receive a proxy request from a specific service provider proxy device (7) to access the lock (10), the proxy request including the authorization token; Obtain a credential for the service provider proxy device (7) under the condition that the authorization token is valid; and Provide the credential to the service provider proxy device (7).
14. A computer program product (64, 90) comprising a computer-readable device according to claim 13.
Citation Information
Patent Citations
Login credentials verifying method and apparatus
CN106790183A
Providing access to a lock for a service provider
CN110024004A