Method and apparatus for granting access to storage compartments of a storage compartment facility
By using a key to encrypt access information and indicators in the storage bin facility, security and efficiency issues when confirming recipient rights are solved, achieving higher security and lower data processing volume.
Patent Information
- Application Number
- CN202210404235.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-04-22
- Filing Date
- 2022-04-18
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-04-18
AI Technical Summary
Existing storage bin facilities have security and efficiency issues when confirming that the recipient has the right to access the storage bin, especially to prevent unauthorized access and reduce data processing.
By obtaining the key, access information is generated, and access information is encrypted with the key, the indicator is associated with the encrypted access information, and the output data contains indicators and encrypted access information. Then, based on the indicator and password in the third data, it is confirmed whether access to the storage compartment facility or storage compartment is authorized.
Improves the security and efficiency of storage compartment facilities, ensures that only authorized personnel can access storage compartments, reduces the risk of unauthorized access, and reduces the amount of data processing.
Smart Images

Figure CN115240331B_ABST
Abstract
Description
Technical Field
[0001] Exemplary embodiments of the present invention relate to methods, devices, systems and computer programs for granting access to a storage compartment facility or one or more storage compartments of a storage compartment facility, wherein a necessary condition for granting access is that it has been confirmed that the recipient is entitled to gain access to one or more storage compartments of the storage compartment facility, wherein the storage compartment facility is in particular a storage compartment facility for retrieving and / or storing consignments for a delivery service or a delivery service. Background Art
[0002] Storage compartment facilities are used in various forms, for example, in the form of locker storage compartment facilities or parcel storage compartment facilities. An example of a parcel storage compartment facility is a parcel station of the applicant, to which the consignee can deliver the mail. The mail is placed in a storage compartment of the parcel station near the consignee and / or confirmed in advance by the consignee by the deliveryman, the storage compartment is closed and the consignee is notified accordingly. In order for the notified consignee to extract the mail provided for him from the storage compartment of the storage compartment facility, the storage compartment facility must confirm that the consignee has the right to obtain access to one or more storage compartments of the storage compartment facility.
[0003] In the implementation of the parcel station of the applicant mentioned above, the recipient must enter the user identification code (also called postal code) permanently assigned to the recipient as a customer number and a temporarily valid pickup code into the input device (e.g., numeric keypad) of the parcel station when confirming the right to access one or more storage compartments. The temporarily valid pickup code known as mTAN (mobile Transaktionsnummer, mobile transaction number) from the implementation of the applicant mentioned above has been electronically transmitted to the person in advance together with the notification that one or more mails are ready for the person in the parcel station involved. Here, as long as one or more mails are ready for the user to take out, only one pickup code for all mails is assigned to the user's postal code. As long as at least one mail is still not taken out, the validity of the pickup code is always retained.
[0004] The corresponding access rights information (i.e. user identification code and pickup code or postal code and mTAN) of users registered to use the parcel station is managed and stored by a system (e.g. a backend system or server). The parcel station used as a storage facility is coupled to the system via a remote data communication connection, such as a LAN (Local Area Network) interface, for exchanging data required for access rights checking. Summary of the invention
[0005] In principle, it is desirable with regard to the storage compartment facility that it can reliably, efficiently and securely confirm that the recipient is entitled to access one or more storage compartments of the storage compartment facility in order to subsequently grant access to the corresponding storage compartment.
[0006] With regard to security, it is particularly important here to prevent unauthorized access to the storage compartments of the storage compartment facility.
[0007] With regard to efficiency, it is particularly important that as little data as possible must be acquired and / or processed.
[0008] With regard to reliability, it is expected that, for example, the storage compartment facility functions properly regardless of whether or not there is a permanent connection to a system comprising, for example, one or more servers, and whether or not a user is able to obtain information from the system and / or is able to exchange information with the system when he or she wants to verify his or her authority to access a storage compartment or multiple storage compartments.
[0009] In the parcel station concept described at the outset by the applicant, the storage compartment facility determines whether a user can be granted access to one or more storage compartments based on a user identification code and a pickup code. Here, the user identification code is a six to twelve digit number permanently assigned to the user and is therefore difficult to keep secret, while the pickup code is a code consisting of only a few digits, which is electronically transmitted to the user when one or more consignments destined for the user are placed in the parcel station.
[0010] As mentioned at the outset, the user identification code is stored together with the pickup code on the system, for example on the backend system. As a result, an attacker who has unauthorized access to the system has access to all the information required to access one or more storage compartments of one or more storage compartment facilities. Thus, for example, the attacker also has access to the mail items stored there.
[0011] Furthermore, although it is advantageous that the pickup code only comprises a few digits, the storage compartment facility then only has to acquire and process a few digits when acquiring the pickup code. Likewise, it is also advantageous to assign only one pickup code to the user identification code for retrieving all mailed items, because the storage compartment facility does not have to acquire and process a pickup code for each mailed item.
[0012] On the other hand, however, it is disadvantageous that the pickup code consists of only a few digits, because the pickup code may be more easily known to an attacker, for example, by a brute force attack. Here, the allocation of only one pickup code to a user identification code for the purpose of picking up all the mailed items disadvantageously increases the risk of a successful brute force attack, since the attacker only needs to find out one pickup code to gain access to multiple storage compartments and thus multiple mailed items. In particular, the attacker has time to do this until all the mailed items of the user are picked up.
[0013] The object of the present invention is to overcome one or more of the above-mentioned disadvantages and / or to achieve one or more of the above-mentioned advantages and / or to implement one or more of the above-mentioned improvements.
[0014] According to a first exemplary aspect of the present invention, a method is disclosed, which is implemented, for example, by a storage compartment facility or a system including the storage compartment facility, and the method includes: obtaining a key; generating access information; encrypting the access information with the key; associating an indicator with the access information; outputting first data, wherein the first data includes at least an indicator and the access information encrypted with the key; obtaining or acquiring third data from a device having a key for decrypting the encrypted access information, wherein the third data includes a password and an indicator; determining the access information based at least on the indicator contained in the third data; confirming whether the password authorizes access to the storage compartment facility or one or more storage compartments of the storage compartment facility based at least on the determined access information; and granting access to the storage compartment facility or one or more storage compartments of the storage compartment facility, wherein a necessary condition for granting access is that it has been confirmed that the password authorizes access to the storage compartment facility or one or more storage compartments of the storage compartment facility.
[0015] According to a second exemplary aspect of the present invention, a method is disclosed, which is implemented, for example, by a mobile device, and the method includes: generating or obtaining at least one key; transmitting the key to a device or system, which is configured to transmit the key to a storage compartment facility; obtaining second data, wherein the second data includes at least an indicator and access information encrypted with the key; decrypting the access information encrypted with the key; generating a password based on at least the access information; and transmitting third data to the storage compartment facility or providing third data to the storage compartment facility so as to obtain access to the storage compartment facility or one or more storage compartments of the storage compartment facility, wherein the third data includes at least the password and the indicator.
[0016] According to a third exemplary aspect of the present invention, a method is disclosed, which is implemented, for example, by a device or a system, and the method includes: obtaining or generating a key, for example, from a mobile device; transmitting the key to a storage compartment facility; obtaining first data from the storage compartment facility, wherein the first data includes at least an indicator and access information encrypted with the key; and outputting second data, for example, outputting the second data to the mobile device, wherein the second data includes at least an indicator and access information encrypted with the key.
[0017] According to each of these aspects of the present invention, there is also disclosed:
[0018] -A computer program, the computer program includes program instructions, when the computer program is run on a processor, these program instructions prompt the processor to implement and / or control the method of the corresponding aspects of the present invention. Among others, in this specification, "processor" should be understood as a control unit, a microprocessor, a microcontroller (such as a microcontroller), a digital signal processor (DSP), an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Here, either all steps of the method can be controlled or all steps of the method can be implemented, or one or more steps can be controlled and one or more steps can be implemented. The computer program can be distributed, for example, via a network such as the Internet, a telephone network or a mobile communication network (Mobilfunknetz) and / or a local area network. The computer program can be at least partially the software and / or firmware of the processor. The computer program can also be implemented as hardware at least in part. The computer program can be stored, for example, on a computer-readable storage medium, such as a magnetic, electrical, optical and / or other form of storage medium. The storage medium can be, for example, a part of a processor, for example, a (non-volatile or volatile) program memory of a processor or a part thereof. The storage medium can be, for example, a specific and / or physical storage medium.
[0019] -A device or a system consisting of at least two devices, which is configured to implement and / or control the method according to the corresponding aspect of the present invention, or the device or the system includes corresponding devices for implementing and / or controlling the steps of the method according to the corresponding aspect of the present invention. Here, either all steps of the method can be controlled or all steps of the method can be implemented, or one or more steps can be controlled and one or more steps can be implemented. One or more of these devices can also be implemented and / or controlled by the same unit. For example, one or more of these devices can be composed of one or more processors. The device according to the first aspect of the present invention can be, for example, a storage compartment facility. The device according to the second aspect of the present invention can be, for example, a mobile device, such as a smart phone or device of a courier. The system according to the third aspect of the present invention can, for example, include at least one or two servers.
[0020] - A device comprising at least one processor and at least one memory containing program code, wherein the memory and the program code are configured to cause the device having at least one processor to at least implement and / or control the method according to the corresponding aspect of the present invention. In this case, either all steps of the method can be controlled or all steps of the method can be implemented, or one or more steps can be controlled and one or more steps can be implemented.
[0021] These exemplary aspects of the invention may have, among other things, the characteristics described below.
[0022] The storage compartment facility includes a plurality of storage compartments (i.e., more than one storage compartment or more than two storage compartments, for example). These storage compartments are configured, for example, to accommodate mail (e.g., letters, parcels, small parcels), goods (e.g., washed or to be washed clothes, meals for delivery services (e.g., pizza or sushi services), etc.), or articles (e.g., valuables, luggage, etc.). These storage compartments can be closed separately, for example, by means of respective doors or covers. These storage compartments are, for example, substantially square holding containers, which are provided with doors or covers at one or more sides. For example, a plurality of storage compartments are arranged in a stacked manner and / or side by side in a storage compartment facility. For example, the storage compartment facility can be composed of one or more modules arranged side by side, wherein one or more storage compartments are arranged in a stacked manner in each module. The respective doors of these storage compartments are, for example, hinged laterally and can, for example, be opened forward. The storage compartments of the storage compartment facility can all have the same size. Alternatively, at least some of the storage compartments of the storage compartment facility can have different sizes. The storage compartment facility can, for example, have storage compartments for letters (letter storage compartments) and / or storage compartments for parcels (parcel storage compartments). The letter storage compartments can, for example, each have the same size within the storage compartment facility, but two or more different sizes are also possible. Parcel storage compartments can be present in the storage compartment facility only in the same size or in different sizes. The storage compartment facility can, for example, be designed as a parcel storage compartment facility or as a combined letter and parcel storage compartment facility.
[0023] Each of these storage compartments is, for example, provided with a respective lock so that user access to the individual storage compartments of the storage compartment facility can be controlled. The lock of the storage compartment can, for example, be arranged in or on the storage compartment, for example, on the door (also in the form of a cover plate) of the storage compartment. If the lock is not arranged on the door (i.e., for example, arranged on the side wall of the storage compartment), the lock cooperates with the door, for example, by, for example, introducing a latch into the opening of the door or pulling it out again from the opening of the door. The lock of the storage compartment can, for example, be returned to the locked position according to the standard and then, for example, can only be controlled to unlock. After completing the unlocking of the lock, the door of the storage compartment can be opened, for example. Since the lock automatically returns to the locked position, the locking of the storage compartment can be achieved by closing the door, for example, wherein the locking function is fully utilized when the door is closed.
[0024] The storage compartments of the storage compartment facility can be either open or closed. In the open state of the storage compartment, the lock of the storage compartment is unlocked. Thus, the door of the storage compartment can be opened or opened by a person, for example, without using violence. In the closed state of the storage compartment, the lock of the storage compartment is locked. Thus, the door of the storage compartment cannot be opened by a person who is not authorized to open it, for example, without using violence.
[0025] The lock of each storage compartment is for example controllable, especially electronically. In particular, at least the process of locking and / or unlocking the lock can be controlled. For example, the control of the lock of the storage compartment can be carried out by a lock control unit, wherein each lock is either assigned its own lock control unit, or a (for example, central) lock control unit controls some locks (for example, those of the modules of the storage compartment facility) or all locks of the storage compartment facility. In the first case, a plurality of lock control units, for example, those lock control units of all lock control units or one or more modules of the storage compartment facility are for example controlled by a higher-level control unit, and in the latter case, for example, there is a respective wiring between the lock control unit and each lock in the lock controlled by the lock control unit, wherein the signal transmitted via the respective wiring or the voltage applied is only respectively assigned to the lock to which the wiring leads, and not to other locks. Alternatively, it is also conceivable to use a bus, and the lock control unit and a plurality of locks are electrically connected to the bus. However, then a unit for evaluating the control signal obtained via the bus is required in each lock, which makes the lock more complicated and therefore more expensive to design than in the case of direct wiring.
[0026] For example, a lock control unit (especially a central lock control unit) can be responsible not only for controlling one or more locks, but also for confirming whether the data obtained or acquired authorizes access to one or more storage compartments of a storage compartment facility, and accordingly allowing access to one or more storage compartments (for example, by unlocking the door of the storage compartment or the doors of the storage compartment) or denying access to one or more storage compartments (for example, by not unlocking the door of the storage compartment or the doors of the storage compartment).
[0027] In order to enable a storage compartment facility and / or a unit assigned to the storage compartment facility (e.g. a lock control unit) and / or a system including the storage compartment facility to confirm whether a password authorizes access to a storage compartment or multiple storage compartments of the storage compartment facility and if so, access can be granted, for example, the storage compartment facility or the system including the storage compartment facility implements the steps of the method according to the first exemplary aspect of the present invention. Here, the storage compartment facility implements one or more steps of the method according to the first aspect of the present invention, which are described multiple times below. Although one embodiment of the method according to the first aspect of the present invention is that the storage compartment facility implements all steps of the method according to the first aspect of the present invention. However, the description of these steps should also be clearly understood that the corresponding steps or parts thereof can also be implemented by other devices, which are, for example, part of the system including the storage compartment facility.
[0028] The method according to the second exemplary aspect of the present invention is implemented, for example, by a mobile device, such as a smartphone and / or a device of a courier. The method according to the third aspect of the present invention is implemented, for example, by a device, such as a server or a system, for example, comprising two servers that can, for example, communicate with each other. Here, the device or system implementing the method according to the third aspect of the present invention can be, for example, a backend system or a backend server. However, it can also be the device of the courier or a system comprising the device of the courier.
[0029] The method according to the second exemplary aspect of the present invention comprises: generating or obtaining at least one key. The key may be, for example, a key for symmetric encryption / decryption. Alternatively, the key may be, for example, a public key or a private key of an asymmetric key pair. When the key is, for example, a public key of an asymmetric key pair, generating or obtaining, for example, may also involve a public key and a private key of the asymmetric key pair. The key may have a predetermined length, for example, shorter than 128 bits, 128 bits, 160 bits, 256 bits, 512 bits, 1024 bits, 2048 bits, 4096 bits, or longer than 4096 bits, or any length between the values or lower or higher than the values described. The key may, for example, contain a random value and / or a user identification code and / or a timestamp and / or a version number and / or a checksum of an authentication method. The key may, for example, be generated by a device implementing the method according to the second exemplary aspect of the present invention. Thus, the key may, for example, be initially unknown and / or inaccessible to other devices. Alternatively, the key can also be obtained from another device that has generated a key, or, for example, by obtaining the key through a user input on an input unit (e.g., a touch-sensitive screen) suitable for this purpose of the device implementing the method according to the second exemplary aspect of the present invention. Thus, the device implementing the method according to the second exemplary aspect of the present invention does not need to generate a key in a complex manner, for example.
[0030] The method according to the second exemplary aspect of the present invention also includes: transmitting the key to a device or system, which is configured to transmit the key to a storage compartment facility. For example, the device or system to which the key is transmitted can implement the method according to the second exemplary aspect and / or the third exemplary aspect of the present invention. It can be, for example, a server, a system of servers, a system including a storage compartment facility, a storage compartment facility, a deliveryman's smart phone or equipment.
[0031] Here, the transmission and associated acquisition of the key can be carried out, for example, via a wireless and / or wired communication interface of the device implementing the method according to the second exemplary aspect and / or the third exemplary aspect of the present invention, for example, via the Internet and / or via a local radio connection, such as Bluetooth or NFC. For example, the key can be transmitted by means of one or more messages and / or by means of one or more data packets, such as Internet Protocol (IP) v4 data packets or IPv6 data packets or Bluetooth data packets. Here, for example, other data and / or information can also be transmitted together with the key.
[0032] The method according to the third exemplary aspect of the present invention comprises: obtaining or generating a key. If a key is to be obtained, the key can be obtained, for example, from a mobile device. In particular, the key can be obtained from a mobile device that implements the method according to the second aspect of the present invention. However, additionally or alternatively, the key can also be obtained from other devices, such as from a server. For example, the key can be a key from the method according to the second exemplary aspect of the present invention, or at least have the characteristics described for the key from the method according to the second exemplary aspect of the present invention. The key is transmitted and / or obtained, for example, via one of the transmission types described for transmitting the key in the method according to the second exemplary aspect of the present invention.
[0033] The method according to the third exemplary aspect of the invention further comprises: transmitting the key to a storage compartment facility. For example, the storage compartment facility is a storage compartment facility implementing the method according to the first exemplary aspect of the invention, or is included in a system implementing the method according to the first exemplary aspect of the invention. For example, the transmission is carried out via one of the transmission types already described for transmitting the key in the method according to the second exemplary aspect of the invention. Here, the transmission may also be carried out indirectly, i.e., for example, via a device configured to forward data, such as a courier's device, which, for example, forwards the key and may temporarily store the key in advance.
[0034] The method according to the first exemplary aspect of the present invention comprises: obtaining a key. The key may be, for example, a key from the method according to the second exemplary aspect and / or the third exemplary aspect of the present invention, or at least have the characteristics described for the key from the method according to the second exemplary aspect and / or the third exemplary aspect of the present invention. For example, the acquisition is implemented via a communication interface with the Internet. For example, the key may be obtained from a system or device implementing the method according to the third aspect of the present invention. However, in some embodiments, the key may also be obtained in other ways. For example, the key may be obtained from a device configured to forward data. Such a device may be, for example, a courier's device. To this end, the courier's device may, for example, have stored the key in the following manner, that is, for example, the courier's device synchronizes data with a device (e.g., a server) having a key every day, obtains the key in the process and then stores the key. In other embodiments, the courier's device may, for example, establish a connection with a system or device having a key when the device is near a storage compartment facility, so as to obtain the key from the system or the device and forward the key to the storage compartment facility. Then, the storage compartment facility may, for example, obtain the key from the device via a radio connection, such as Bluetooth, near field communication (NFC), or wireless local area network (WLAN). Alternatively, the key can also be obtained from another device, for example from a device of a user of the locker facility, for example via a radio connection. The device of the user of the locker facility can also be used only for forwarding, or the user's device can have generated the key.
[0035] The method according to the first exemplary aspect of the present invention also includes: generating access information. The access information can be suitable for: at least based on the access information, a password can be generated, and the password authorizes access to a storage compartment facility or one or more storage compartments of the storage compartment facility. For example, the access information can be a random value, and can have a specific length, such as 8 bits, 16 bits, 128 bits, 256 bits, 1024 bits, 4096 bits or more than 4096 bits, or any length between, below or above the above values. Alternatively or additionally, the access information or a part of the access information can be a pattern or follow a predetermined rule. The generation of the access information can follow the predetermined rules in whole or in part, and is pseudo-random and / or random. After generation, the access information can be difficult and / or expensive, especially by personnel or other equipment or devices, to guess, regenerate or otherwise determine.
[0036] The method according to the first exemplary aspect of the present invention also includes: encrypting the access information with a key. Which method is used to encrypt the access information with a key can depend on the time, date, settings of the device performing the encryption, the access information and / or the key. Alternatively, the same method can be used all the time. For example, a symmetric encryption method can be used to encrypt the access information or a part of the access information. Then the key is, for example, a symmetric key. Examples of symmetric encryption methods are data encryption standard (DES), triple DES, advanced encryption standard (AES), international data encryption algorithm (IDEA), Blowfish or Twofish. Alternatively or additionally, an asymmetric encryption method can also be used to encrypt the access information or a part of the access information. Then the key is, for example, a key of an asymmetric key pair. Such an asymmetric encryption method can be, for example, Rivest, Shamir, Adleman (RSA) method, Elgamal method or elliptic curve method (Elliptische-Kurve-verfahren). The advantage of symmetric encryption methods over asymmetric encryption methods is that they are faster. However, in the asymmetric encryption method, the encrypted data cannot be decrypted again with the used key, but the second key of the asymmetric key pair is required.
[0037] The method according to the first exemplary aspect of the present invention further comprises: associating an indicator with the access information. The indicator may for example comprise a numerical value, a time value, a word, and / or a combination of numbers and letters, and may for example be represented as bits or bytes. The indicator may for example be randomly generated or selected from a predefined set of possible values. The selection may then for example be random. Alternatively, the indicator may for example be generated according to a predetermined rule, or selected from a predefined set of possible values according to a predetermined rule.
[0038] The indicator can be associated with the access information by means of a data structure, for example, by means of a table of access information associated respectively including one or more indicators in one column and in another column. Alternatively or additionally, the access information can be present in a list and / or an array, and the indicator can display or can know the position of the access information associated therewith in the list and / or the array, for example. The association can also be indirect, i.e., especially more than one allocation, for example, the allocation carried out through a plurality of allocation levels. Therefore, the access information can be associated with at least one storage compartment of the storage compartment facility, for example, by the following manner, that is, the access information is assigned to a storage compartment of the storage compartment facility or an allocation relationship is established by the storage compartment facility. For example, each storage compartment of the storage compartment facility in which the mailing exists is assigned with access information. So for example, these storage compartments are just assigned one access information respectively. Then, for example, the indicator can be associated with the storage compartment, for example, by means of a table or by means of a list or an array. When the storage compartment has been associated with the access information, for example, when being assigned to the access information, the association of the indicator with the access information can be, for example, only the association of the indicator with the storage compartment. Conversely, the association of the indicator may, for example, only involve the association of the access information with the storage compartment, since in one of the two cases the indicator has already been associated with the access information.
[0039] The method according to the first exemplary aspect of the present invention also includes: outputting first data, wherein the first data at least includes an indicator and access information encrypted with a key. The data can be, for example, bits or bytes or represented as bits or bytes, and the indicator and the access information encrypted with a key can, for example, exist or be represented as bits or bytes, respectively, and / or be included in the first data in this way. For example, the indicator can be included in the first data without being encrypted with a key. Alternatively or additionally, the indicator can be included in the first data at least partially encrypted with a key. The access information and / or indicator and / or a part of the first data can also be encrypted and / or converted, for example, in other ways.
[0040] In principle, data can be output as, for example, letters and / or numbers and / or optical patterns, such as barcodes or QR codes, on a screen and / or printed on paper. However, in principle, data can also be output as a part of one or more messages alternatively or additionally, such as a part of one or more data packets of a communication protocol such as 3G, 4G, Bluetooth, Ethernet or NFC. Therefore, data can be output to other devices, for example, via the Internet and / or other networks. Here, access information and indicators, for example, can also be output, transmitted, received, obtained and / or acquired or otherwise processed in the same message and / or the same data packet or in different messages and / or data packets, respectively, partially or completely. For example, the first data can be output to a device or system, which, for example, controls and / or implements the method according to the second aspect and / or the third aspect of the present invention or is configured to implement a corresponding method. By encrypting the access information contained in the first data with a key at least, the access information is protected, for example, from being peeped out by an unauthorized person who cannot or at least cannot actually decrypt the access information encrypted with a key.
[0041] The method according to the third exemplary aspect of the present invention comprises: obtaining first data from a storage compartment facility, wherein the first data comprises at least an indicator and access information encrypted with a key. In particular, the first data may be the first data output in the method according to the first exemplary aspect of the present invention. Therefore, the first data may be obtained using one of the communication types described for outputting the first data according to the method according to the first exemplary aspect of the present invention.
[0042] In the case of obtaining the first data, i.e., for example at this time, but also before and / or after this, for example, the device or system implementing the method according to the third exemplary aspect of the present invention cannot decrypt the access information encrypted with the key. For example, this is because the device or system does not store or no longer stores the key by which the access information encrypted with the key can be decrypted. The device or system implementing the method according to the third exemplary aspect of the present invention may not be able to decrypt the access information encrypted with the key (for example, because the key used for decryption is not known to the device or is no longer known to the device), thereby, for example, improving the security of the method, device and / or system according to the present invention. As a result, the key used for decryption cannot be snooped out by the device and / or system implementing the method according to the third aspect of the present invention. This is particularly advantageous when the device or the system is, for example, a server or includes a server and, for example, manages multiple storage facilities implementing the method according to the first exemplary aspect of the present invention and / or a mobile device implementing the method according to the second exemplary aspect of the present invention. Otherwise, in this case, when an attacker gains access to the device or system, the attacker may, for example, snoop out multiple keys and / or access information of each storage compartment and / or storage facility from the device or system implementing the method according to the third exemplary aspect of the present invention.
[0043] The method according to the third exemplary aspect of the present invention also includes: outputting second data, for example, outputting the second data to a mobile device, wherein the second data includes at least an indicator and access information encrypted with a key. The device or system implementing the method according to the third exemplary aspect of the present invention can, for example, confirm which part of the first data and / or the second data represents the access information and / or indicator encrypted with a key. Alternatively, this may not be known to the device or system and / or may not be found. The mobile device to which the second data can be output (or transmitted) can, for example, implement the method according to the second exemplary aspect of the present invention. The mobile device can, for example, be a user's smartphone or a courier's device, and the device or system that outputs the second data to the mobile device can, for example, identify the mobile device for outputting the second data, for example, based on user and / or courier data, such as a mobile phone number, an email address and / or a device-media access control (MAC) address.
[0044] For example, the second data may be the same as the first data. Alternatively, the second data may be different from the first data, but nevertheless include an indicator and access information encrypted with a key. For example, in addition to the indicator and access information encrypted with a key, the second data may also include additional information, such as an identification code of a storage compartment facility or other identification codes of a device or system from which the first data was obtained. For example, such an identification code may also be at least partially contained in the first data or first contained in the second data. Outputting the second data (which output may be transmitting the second data) may be performed in one of the ways and methods previously described for data transmission, i.e., for example, transmitting as part of one or more data packets or messages, for example, via an Internet connection and / or a mobile communication network.
[0045] The method according to the second exemplary aspect of the present invention comprises: obtaining second data, wherein the second data comprises at least an indicator and access information encrypted with a key. The data can be obtained, for example, from a device or system implementing the method according to the third aspect of the present invention. The obtaining can be achieved by the generally described feasible scheme for obtaining data.
[0046] The method according to the second exemplary aspect of the present invention also includes decrypting the access information encrypted with a key. Advantageously, the device that has generated the key for encrypting the access information also performs decryption. When encryption is, for example, symmetric encryption, the stored key is sufficient to be able to use the key for decryption. When encryption is, for example, asymmetric encryption, the device, when generating a key representing, for example, a public key, for example, also generates a private key belonging to it and stores the private key, for example. Then the private key can be used for decryption. In the sense of security, it is advantageous to decrypt by the same device that has generated the key for decryption, because as few devices as possible need to obtain, process and / or store the key. In addition, asymmetric encryption is particularly advantageous because the private key required for decryption does not need to leave the device that generates it. In particular, the private key does not need to be transmitted via a potentially unsafe connection so that it may be stored in a potentially unsafe and / or frequently attacked device, such as a server, for example, via the Internet. Therefore, when the private key is only known to the device that implements key generation and decryption, a potential attacker must, for example, fully control the device in order to obtain the private key. If the device is, for example, a smartphone of another person, this is usually very complex and especially for an attacker. In particular, if, for example, only one (private) key is stored on each device, an attacker who wants to obtain multiple keys and / or access information must, for example, obtain access to multiple devices, such as smartphones of multiple users.
[0047] The method according to the second exemplary aspect of the present invention also includes: generating a password based on at least the access information. For example, the password is generated in the following manner, that is, performing a one-way function with at least a portion of the access information as input data. The feature of the one-way function can be, for example, that the calculation of the function itself is simple compared to the calculation of its inverse function. In particular, in fact, for example, it is impossible to find the inverse function of the one-way function, so the reverse operation can only be found by means of a table or by experiment. The example of the one-way function is a hash function, such as a secure hash algorithm (SHA), SHA-2, especially SHA-256, or a message digest algorithm 5 (MD5). However, the generation of the password can be additionally based on other information, such as a part of the second data and / or an indicator contained in the second data.
[0048] For example, the generation of password can be triggered by an event and / or can be automatically performed after the access information is decrypted and / or after a predetermined duration and / or at a predetermined time. Such an event can be, for example, a user input performed on a device that generates a password. This can be, for example, performed in the following manner, that is, the user calls a specific application on his smart phone and / or operates in a certain way, for example, by opening a specific cursor in the application. Alternatively or additionally, such an event can be, for example, a device that has generated or will generate a password approaches another device (for example, a storage compartment facility). Advantageously, the event only exists in or at least exists in or includes user input, so as to prevent unintentional triggering, for example, although the user approaches the device (for example, a storage compartment facility), this approach is not intentional and / or intentional, but random and / or unintentional, for example, when the user drives a vehicle past the device (for example, a storage compartment facility), for example, there are other destinations, such as underground parking lots. However, if such an event, for example, includes or only includes that a device that has generated or will generate a password is close to another device (for example, a storage compartment facility), then the password is generated, for example, in response to or only in response to the following conditions, that is, the device that generates the password confirms that it is within a predetermined proximity, for example, within a spacing of less than 1km, 100m, 50m, 20m, 10m, 5m, or 1m from the storage compartment facility. Here, the storage compartment facility can be, for example, a storage compartment facility, in which the password is authorized and / or should be authorized for one or more storage compartments in the storage compartment facility or its storage compartments. The device can, for example, detect, confirm, determine, or estimate proximity to the storage compartment facility by means of position data, for example, GPS data, and / or by means of receiving other data (for example, Bluetooth beacons, etc.). Proximity can, for example, also be detected, confirmed, estimated, and / or determined based on other received radio data, for example, based on a cell indicator of a mobile communication network and / or a basic service set identifier (BSSID) of a WLAN access point.
[0049] The method according to the second exemplary aspect of the present invention also includes: the third data is transmitted to the storage compartment facility or the third data is provided for the storage compartment facility, so as to obtain access to the storage compartment facility or one or more storage compartments of the storage compartment facility, wherein the third data at least includes a password and an indicator. The third data can also include other information and / or data in addition to the password and the indicator. Here, data, especially the third data and its components (such as passwords and indicators) can be transmitted and / or provided jointly or separately in principle. Transmission can be carried out, for example, via an Internet connection or a radio connection, such as Bluetooth, NFC, WLAN, 4G or 5G. Data can then be sent, for example, in one or more data packets. However, providing, for example, can also be realized by at least one optical pattern, such as a bar code or a QR code, which is displayed, for example, by the screen of the device performing the method steps. Alternatively or additionally, providing can also occur, for example, by displaying letters and / or numbers representing the third data or at least a part thereof. The third data is transmitted to the storage compartment facility or provided to the storage compartment facility, for example, can be triggered by a combination of one or more events, which are, for example, one or more events described in the previous paragraph for triggering the generation of a password. It is also advantageous that the event only exists in or at least exists in or includes the user input, for example, described in the previous paragraph, to prevent unintentional triggering.
[0050] The method according to the first exemplary aspect of the present invention comprises: obtaining or acquiring third data from a device having a key for decrypting the encrypted access information, wherein the third data comprises a password and an indicator. The device having a key for decrypting the encrypted access information may be, for example, a mobile device, such as a smart phone. The device may be, for example, a device of a recipient of the consignment and / or a courier and / or other person or organization, which in some cases should have the possibility of accessing a storage compartment facility or at least one storage compartment of the storage compartment facility.
[0051] The third data can be obtained or acquired from the device, for example, via an Internet connection, a radio connection (such as Bluetooth, NFC, WLAN, 4G, 5G) and / or, for example, by acquiring an optical pattern (such as a barcode or QR code) displayed on the screen of the device providing the third data. However, obtaining or acquiring the third data from the device can also be achieved in an indirect manner, that is, for example, by causing the device from which the third data is obtained to send the third data to a forwarding device and obtain the third data from the forwarding device. Additionally or alternatively, the third data can also be obtained, for example, in the following manner, that is, causing the device from which the third data is obtained to output the third data, for example as letters and / or numbers. Then, for example, the third data can be read out by a person. Subsequently, the third data can be entered by the person, for example, via a keyboard or another acquisition unit of the device that obtains or acquires the third data, so that the device obtains the third data in this way from a device having a key for decrypting the encrypted access information.
[0052] The transmission and / or provision of the third data and the acquisition or acquisition of the corresponding third data can only be performed in the following manner, that is, the device and / or the user who wishes to transmit and / or provide the third data must be located near the device for acquisition or acquisition (i.e., for example, less than an arm's length, 1m, 5m, 10m, 50m, 1km, in the same radio cell, within the effective range of a short-range radio connection, such as NFC or WLAN or Bluetooth connection or within line of sight) and / or can only be transmitted and / or provided and / or obtained and / or acquired at a predetermined, for example, maximum speed. An example for this is, for example, Bluetooth or NFC transmission from a smart phone to a storage compartment facility. Another example is to provide one or more optical patterns by a mobile device, and, for example, to acquire the one or more patterns by a storage compartment facility. Another example is to perform user input on a storage compartment facility, wherein the input data, for example, corresponds to the third data provided by the mobile device and read by the user.
[0053] The exemplary restriction of the maximum and / or actual achievable speed of transmitting / providing / obtaining / obtaining the 3rd data can be advantageous from a security perspective.This is because an attacker, for example, may attempt to, for example, send a plurality of 3rd data with different passwords and / or indicators to a storage compartment facility during a brute force attack, so as to test whether one or more of these 3rd data are authorized to access a storage compartment facility or one or more storage compartments of a storage compartment facility (i.e., an attacker attempts to guess the 3rd data of authorized access).For example, by limiting the maximum and / or actual achievable speed of transmitting / providing / obtaining / obtaining the 3rd data, the time required for transmitting each 3rd data is improved. Compared with the 3rd data that may be transmitted faster, the attack based on transmitting as much 3rd data as possible (i.e., the attacker wishes to guess and try as much as possible) then lasts longer. However, passwords, for example, are only valid within a limited time. The slower the transmission of the 3rd data, the fewer the 3rd data that the attacker can try within this limited time. Therefore, the probability (i.e., guessing right by chance) that the attacker accidentally transmits the 3rd data to the storage compartment facility of actual authorized access is reduced. For example, brute force attacks therefore become difficult. For example, then in return, the length of the password and / or the length of other data transmitted to the storage compartment facility in order to obtain access to one or more storage compartments of the storage compartment facility can be reduced. This is because the time required for a brute force attack, for example, still does not decrease or does not significantly decrease compared to a password that may be longer but transmitted faster. This reduction in length is, for example, advantageous because, for example, the overall data that must be transmitted and / or processed on the storage compartment facility and / or on the device to which data is transmitted or for which data is provided is less. The exemplary requirement that the device and / or the user must be physically located near the storage compartment facility for transmitting the third data to the storage compartment facility can, for example, also improve the security of the storage compartment facility in the following manner, that is, the storage compartment facility cannot be attacked from a remote location (e.g., via the Internet).
[0054] In addition, the advantage of the transmission of the third data that does not use the Internet connection is that the device that obtains or obtains the third data and / or transmits or provides the third data does not need an Internet connection when transmitting the third data. For example, when the storage compartment facility is to obtain the third data from a smart phone, for example, in a place without a stable Internet connection, this is particularly advantageous. For example, underground parking lots or rural areas where the mobile communication network coverage is not enough as the basis for Internet connection are exactly this case. Although the transmission of the first data and the second data between different devices may still require an Internet connection. However, as long as the Internet is connected at a certain time point, for example, after the mail is stored in the storage compartment of the storage compartment facility and before the user wishes to take out the mail that is stored in the storage compartment facility for it, at least a short-term existence, then what time just exists The Internet connection is not critical for example. In particular, in this way and method, the function of the storage compartment facility at such a location is more reliable than the need to confirm with the Internet connection of the server whether the user who wishes to perform self-authentication on the storage compartment facility is entitled to obtain the access of one or more storage compartments.
[0055] The method according to the first exemplary aspect of the present invention also includes: determining (e.g., selecting) access information based at least on an indicator contained in the third data. For example, the determination is implemented based on the association between the indicator and the access information. For example, when the device performing the determination accesses a data structure, such as a table including an allocation relationship between an indicator and corresponding associated access information, then when determining, for example, the access information can be determined based on the indicator contained in the third data when the data structure is used. Alternatively or additionally, when determining, for example, the storage compartment associated with the indicator can be first determined, and then the access information associated with the same storage compartment, i.e., for example, assigned to the storage compartment, can be determined. This can be advantageous. This is because the method according to the first exemplary aspect of the present invention can be implemented, for example, by a storage compartment facility, which is implemented via multiple storage compartments, some or all of which are associated with corresponding access information. For example, the indicator can more effectively confirm whether the password authorizes access to one or more storage compartments of the storage compartment facility. This occurs, for example, in the following manner, that is, the access information required for confirmation can be determined at least based on the indicator, and for example, it is not necessary to confirm whether the password authorizes access based on multiple or all known access information.
[0056] The method according to the first exemplary aspect of the present invention also includes: confirming whether the password authorizes access to the storage facility or one or more storage compartments of the storage facility based on at least the determined access information. For example, if the device implementing the confirmation generates at least one password corresponding to the password contained in the third data from the determined access information according to a predetermined rule, it can be confirmed that the password authorizes access. For example, the device can generate more than one password from the determined access information according to a predetermined rule, and if only one of the generated passwords is consistent with the password contained in the third data, it is confirmed that the password contained in the third data authorizes access. In particular, if the device generates one or more passwords from the determined access information according to a predetermined rule, but none of the passwords corresponds to the password contained in the third data, the device can also confirm that the password contained in the third data does not authorize access. The predetermined rule that causes the device or system implementing the confirmation to generate at least one password from the determined access information according to a predetermined rule is, for example, also a rule that causes the device that has generated the password contained in the third data to generate the password.
[0057] Alternatively, the device (e.g., storage compartment facility) implementing confirmation can, for example, perform operations and / or conversions on the password contained in the third data when confirming, and compare the results of the operations and / or conversions with the determined access information. If the result of the operations and / or conversions is consistent with the determined access information, then, for example, it can be confirmed that the password authorizes access to the storage compartment facility or one or more storage compartments of the storage compartment facility. If the result is inconsistent with the determined access information, then, for example, it can also be confirmed that the password does not authorize access to the storage compartment facility or one or more storage compartments of the storage compartment facility. Here, operations and / or conversions are, for example, the reversal of the rule that the device that has generated the password contained in the third data is used to generate the password.
[0058] When confirming whether the password authorizes access to the storage compartment facility or one or more storage compartments of the storage compartment facility, for example, confirm which storage compartment and / or which storage compartments the password authorizes access to. Additionally or alternatively, for example, confirm whether the password authorizes access to the storage compartment facility, i.e., for example, whether authorization is given to access all storage compartments and / or any storage compartment of the storage compartment facility and / or the special storage compartment of the storage compartment facility and / or the control system of the storage compartment facility and / or the (special) function of the storage compartment facility. The special storage compartment of the storage compartment facility may, for example, include the technical components of the storage compartment facility, such as a modem, a control module and / or a power switch. A technician may need to access such a special storage compartment, for example, for maintaining the storage compartment facility. For example, a technician may also need to access the control system of the storage compartment facility. Therefore, a technician may, for example, install updates and / or set them. Such settings may include, for example, which storage compartments can be used for ordinary mailings, which storage compartments are unavailable, for example due to technical failures, and / or which storage compartments may be used for unusual purposes (e.g. valuables) and therefore, for example, should have improved or different requirements for user authentication of the storage compartment facility. A password may also, for example, authorize access to a (special) function. A (special) function may, for example, be just this special authentication for taking out valuables from a particularly secure storage compartment. However, other functions, for example, may also be for the user to put in returned items. Other functions may also be provided, for example, for the police and / or customs. This function may, for example, allow police or customs officials to access any storage compartment selected by the police or customs officials.
[0059] In an exemplary embodiment, at least based on the determined access information, the password is confirmed (if the password authorizes access) to only authorize access to the storage compartment associated with the determined access information. For example, if the storage compartment facility generates one or more passwords from the determined access information according to a predetermined rule, and if the password contained in the third data is confirmed to authorize access (this is because one of the generated passwords is consistent with the password contained in the third data), the storage compartment facility also confirms that the password, for example, only authorizes access to the storage compartment associated with the determined access information. Alternatively or additionally, at least based on the determined access information, for example, the password is confirmed (if the password authorizes access) to only authorize access to the storage compartment containing the respective mails, which are associated with the mails in the storage compartment associated with the determined access information. For example, when each mail in each storage compartment is associated with the same user identification code, that is, for example, all mails are determined to the same recipient, this may be the case. Alternatively or additionally, when determining, it is possible to authorize access to the storage compartment facility, i.e., for example, to access all storage compartments and / or any storage compartment and / or a special storage compartment of the storage compartment facility and / or a control system of the storage compartment facility and / or a (special) function of the storage compartment facility, at least based on the determined access information, for example to confirm a password (if the password authorizes access). Such access to the storage compartment facility can, for example, be reserved only for user groups with predetermined functions, such as technicians, police officers and / or couriers.
[0060] The method according to the first exemplary aspect of the present invention also includes: allowing access to a storage compartment facility or one or more storage compartments of a storage compartment facility, wherein the necessary condition for allowing access is to confirm that the password contained in the third data authorizes access to the storage compartment facility or one or more storage compartments of the storage compartment facility. When allowing access to a storage compartment facility or one or more storage compartments of a storage compartment facility, for example, a storage compartment or multiple storage compartments of the storage compartment facility can be opened and / or each door of multiple storage compartments can be unlocked. However, a necessary condition for this is that the password contained in the third data authorizes access to the storage compartment facility or one or more storage compartments that should be opened or unlocked. In particular, if there is no or cannot be confirmed that the password contained in the third data authorizes access to one or more storage compartments of the storage compartment facility, then for example, access to any storage compartment is not allowed. When allowing access to a storage compartment facility or one or more storage compartments of a storage compartment facility, in principle, for example, the following storage compartments of the storage compartment facility can also be denied access, and these storage compartments are not the storage compartments that the password contained in the third data authorizes access to. The storage compartments are then, for example, not opened and / or their respective doors are not unlocked.
[0061] Permitting access to a storage compartment facility or one or more storage compartments of a storage compartment facility may for example also depend on other conditions. Permitting access to a storage compartment may for example be that it has been confirmed that a user (for example, the recipient of a mailing) wishes to access the storage compartment. For example, although the password contained in the third data may authorize access to multiple storage compartments of a storage compartment facility, the recipient of a mailing located in the storage compartment may for example only wish to access those storage compartments that the password that has been obtained or acquired authorizes access to. It is desirable to access which storage compartments may for example be obtained by user input, for example, via an acquisition unit, such as a keyboard or a touch-sensitive screen. Alternatively or additionally, it is desirable to access which storage compartments may for example be determined based on the data obtained from the user's mobile device. Thus, for example, only access to password-authorized and / or user-selected storage compartments from a password-authorized storage compartment set may be permitted. Then, the user may for example, later utilize another indicator and password to obtain access to a storage compartment that has not been opened by the user.
[0062] The necessary condition for granting access, i.e., confirming that the password contained in the third data authorizes access to the storage compartment facility or one or more storage compartments of the storage compartment facility, can also be combined with other conditions. In particular, these conditions can be combined arbitrarily, for example, with UND (and) or ODER (or) or other logical combinations. In the case of three exemplary conditions A, B and C, the combination of (A and B) or (A and C) can be, for example, a necessary condition for granting access, so that when A and B are satisfied, or A and C are satisfied, or A and B and C are all satisfied, access is granted.
[0063] Exemplary embodiments and further advantages of exemplary aspects of the invention are described below, wherein the disclosure thereof shall apply with equal validity to all three aspects of the invention, respectively.
[0064] According to an exemplary embodiment of the first aspect of the present invention, the first data is output to a device or system, and the device or the system is configured to transmit data to a device having a key for decrypting encrypted access information. Therefore, for example, a storage compartment facility outputs the first data to a device or system for implementing, for example, a method according to the third aspect of the present invention. The device having a key for decrypting encrypted access information can be, for example, a mobile device of a user or a courier. An exemplary mobile device can, for example, be generated and stored with a key at an earlier time. Instead of or in addition to the output of the aforementioned first data in this paragraph, the first data can also be directly output to a device having a key for decrypting encrypted access information. For example, the storage compartment facility can therefore output the first data directly to a mobile device having a key for decrypting encrypted access information, for example, via Bluetooth or NFC. So the mobile device can obtain the first data.
[0065] According to an exemplary embodiment of the first aspect of the present invention, the password only authorizes access to the storage compartments of the storage compartment facility in which there are mails associated with the same user identification code. Here, the method according to the first aspect of the present invention, for example, includes one or more of the following method steps: determining the storage compartment associated with the indicator contained in the third data; determining the user identification code based on the information of the mails located in the determined storage compartment, wherein the user identification code is, for example, the user identification code of the recipient of the mails; determining one or more additional storage compartments in which there are mails associated with the determined user identification code. In this way, for example, it is not necessary to transmit and / or provide data and / or passwords to the storage compartment facility for each storage compartment where the mails of the recipient are located, and it is not necessary to obtain and / or obtain and / or process by the storage compartment facility. On the contrary, for example, transmitting / providing or obtaining / obtaining passwords is sufficient to enable the storage compartment facility to confirm that the user has the right to obtain access to multiple storage compartments.
[0066] The user identification code may be, for example, a number (such as a postal code) that identifies a user and / or a group of users, or other sequences or combinations of numbers and / or letters and / or bits. The user may be, for example, a registered customer who is assigned a user identification code during the registration process or who selects a user identification code during the registration process. The user may also be, for example, a courier who has been assigned a user identification code. The courier may be, for example, a human or machine courier, such as a robot and / or a drone.
[0067] The storage compartment facility can, for example, confirm or be informed during the process of storing the mail which user identification code the corresponding mail is associated with and into which storage compartment the corresponding mail is placed. For example, the storage compartment facility can obtain at least a portion of this information by means of user input and / or by a device. For example, the storage compartment facility can obtain at least a portion of this information from a courier's device, which, for example, scans a label of the mail during delivery and forwards at least a portion of the information thus obtained to the storage compartment facility. Alternatively or additionally, the storage compartment facility can also obtain information about the corresponding mail, such as a user identification code associated with the mail, by means of a scanner and / or other sensors.
[0068] The consignment is associated with, for example, only one user identification code, for example, the user identification code of the consignee. Alternatively, the consignment is associated with, for example, two user identification codes, for example, the user identification codes of the consignee and the consignor. Alternatively, the consignment is associated with more user identification codes.
[0069] According to an exemplary embodiment of the first aspect of the present invention, a necessary condition for confirming that a password authorizes access to a storage compartment facility or one or more storage compartments of a storage compartment facility is that the confirmation password is generated based on at least information corresponding to the determined access information. The confirmation can be performed, for example, by generating one or more passwords based on the access information respectively and comparing the generated passwords with the passwords contained in the third data. The password is, for example, authorized to access the storage compartment facility or one or more storage compartments of the storage compartment facility when and only when the confirmation is consistent. This condition can be, for example, a unique necessary condition, but alternatively it can also be one of a plurality of necessary conditions. Another necessary condition can be, for example, generating a password within a time window determined according to a predetermined rule and / or obtaining a password with the aid of the third data within a time window determined according to a predetermined rule.
[0070] According to the exemplary embodiment of the first aspect of the present invention, the other necessary condition that the confirmation password authorizes access to the storage grid facility or one or more storage grids of the storage grid facility is that the confirmation password is also generated based on a time value (i.e., for example, representing clock time and / or date), and the time value corresponds to the current time value of the storage grid facility (e.g., determined in the case of the clock of the storage grid facility or obtained from the server) or has a predefined relationship with the current time value of the storage grid facility. For example, the storage grid facility can obtain the time value by a conversion based on the password, and compare the time value with the time value that the storage grid facility has. For example, the password is only valid when the time value obtained is within a predetermined time interval before or after the current time value, such as within 60 seconds. Additionally or alternatively, the storage grid facility can use the current UNIX time value, such as rounded to 60s, and the time value before or in the future, so as to generate a corresponding password based on the corresponding time value and access information and compare the password with the password contained in the third data. Thus, for example, only when one of the generated passwords is consistent with the password contained in the third data, the password authorizes access. Since the validity of the password is limited in time as described in this paragraph, the security of the locker facility can be increased, since an attacker can only attack within a time predetermined by the time limit before a new password is required. Brute force attacks, for example, can thus be made more difficult.
[0071] According to an exemplary embodiment of the first aspect of the present invention, access information is generated to allow one or more user groups with predetermined functions to access the storage compartment facilities independently of the mail. Here, the indicator is associated with the access information, for example, at least in the following manner, that is, the access information is uniquely assigned to the user group with the predetermined function (for example, by the user group being uniquely assigned to the storage compartment facilities or another device to achieve) and the indicator is associated with the user group with the predetermined function. The predetermined function can be, for example, the role of a technician, a (federal) policeman or a courier. Then, the corresponding user group can, for example, include one or more technicians, one or more policemen or one or more couriers. However, especially in the case of a courier, for example, multiple user groups with predetermined functions can also be defined, for example, respectively for the predetermined functions of a machine courier and a human courier. Here, generating access information to allow one or more user groups with predetermined functions to access the storage compartment facilities independently of the mail does not exclude generating additional access information for other purposes, for example, for ordinary recipients.
[0072] For example, generating access information to allow one or more user groups with predetermined functions to access the storage facilities independently of the mailed items can be performed in response to the following conditions, that is, in the method according to the first aspect of the present invention, not only the key is obtained, but also the role information associated with the key, that is, assigned to the key, is obtained at the same time (or later or before), that is, information about the user group with predetermined functions. In an exemplary embodiment of the first aspect of the present invention, the method therefore includes, for example, obtaining allocation relationship information, based on which the key can be assigned to the user group with predetermined functions. The assigned role information (also referred to as allocation relationship information herein) can be updated regularly or irregularly, that is, for example, re-acquired, for example, every day. So, for example, new access information can be generated at each update. In some embodiments, such access information can also be authorized to access only within a predetermined period or during a predetermined duration by, for example, subsequently marking the access information as "invalid" or deleting it. Therefore, according to an exemplary embodiment of the first aspect of the present invention, access information can be generated to allow a user group with the predetermined function to access the storage compartment facility regardless of the mailed items, wherein the indicator is associated with the access information in at least the following manner, that is, the access information is uniquely assigned to the user group with the predetermined function and the indicator is associated with the user group with the predetermined function.
[0073] In order to trigger the generation of access information for a user group with a predetermined role, for example, on a storage facility, in the method according to the second aspect of the invention, for example, on a mobile device that performs the method according to the second aspect of the invention, a key can be assigned to the determined role information. Additionally or alternatively, such assignment can also be performed, for example, by one or more servers in the method according to the third aspect of the invention. Thus, the key and / or the role information (or information representing the information and / or the assignment relationship; i.e., the assignment relationship information) can be transmitted to a device or system that is configured to transmit the key and / or the assigned role information (i.e., the assignment relationship information) to the storage facility. Subsequently, the transmission to one or more storage facilities can be performed in a manner similar to the transmission of the key in the method according to the third aspect of the invention. In particular, the method of the exemplary embodiment of the second aspect or the third aspect of the invention can therefore include one or more of the following method steps: obtaining or generating assignment relationship information, based on which the key can be assigned to a user group with a predetermined role; and transmitting the assignment relationship information to the storage facility or to a device or system (i.e., for example, a device or system that implements the method according to the third aspect of the invention), which is configured to transmit the assignment relationship information to the storage facility. Here, the access information may be generated by the storage compartment facility, for example, in response to obtaining the allocation relationship information.
[0074] In addition, when the role information is assigned to the key, the distribution of the storage compartment facilities can also be performed exemplarily, for example, on the mobile device. The information about the distribution and / or association with the storage compartment facilities (which is also referred to as association information) can then also be transmitted to a device or system (for example, together with the key and / or the role information or separately) in the method according to the second aspect of the present invention, and the device or the system is configured to transmit the key and / or the role information and / or the storage compartment facility allocation relationship to one or more storage compartment facilities. This can be, for example, those storage compartment facilities that are associated with the key and / or the role information (via association information).
[0075] Alternatively or additionally, the distribution relationship of key and the role information determined as above and / or the storage compartment facility distribution relationship (i.e. association information) can also be performed exemplarily by a server or another device.Such a device can be managed and / or controlled and / or controlled by an organization, for example, the organization also manages and / or controls the mobile device of one or more user groups and / or is used by these personnel.This can be, for example, an organization that does not manage the storage compartment facilities described herein, for example, an "external service provider".So, one or more described distributions can be performed by the organization by means of a device (for example, a server and / or computer controlled by the device).Then, for example, key and / or the role information and / or storage compartment facility distribution relationship (i.e. distribution relationship and / or association information) (for example, in the form of a digitally signed permission notification) can be transmitted to a device or system (for example, a server or server system) from the device (for example, only under the condition that the digital signature of the permission notification is checked as valid), and the device or the system is configured to transmit key and / or the role information and / or the storage compartment facility distribution relationship to the storage compartment facilities so distributed. Subsequently, respective access information can be generated on the storage compartment facility, for example, and these access information can be (can be) output as part of the first data, for example, as described in the method according to the first aspect of the present invention. Therefore, the organization can, for example, influence and / or completely or partially control which mobile devices generate access information at which storage compartment stations by means of a device (such as a server) assigned to it, so that these mobile devices are authorized to access at each storage compartment station. The above-mentioned distribution relationship between the key and the determined role information and / or storage compartment facility can be updated regularly, for example, every day. Therefore, the organization that controls this distribution relationship can, for example, control which mobile devices should be authorized to access which storage compartment facilities every day. In particular, the method according to the exemplary embodiment of the second aspect or the third aspect of the present invention can therefore also include: obtaining or generating association information before the key and / or the distribution relationship information are transmitted to the storage compartment facility, wherein the association information associates the key with the storage compartment facility to which the key and / or the distribution relationship information is transmitted or should be transmitted.
[0076] After, for example, access information has been generated to allow one or more user groups with predetermined functions to access the storage facility independently of the mail, the access information can be processed according to the exemplary embodiment of the first aspect of the present invention. Therefore, this can be, for example, also like the case of access information for general mail recipients (distinguished from user groups here). However, it can also be processed in different ways alternatively. For example, in the method according to the third aspect of the present invention, not only can the output / transmission of the second data be performed to the mobile device (from which the key is obtained), but also, for example, the output / transmission of the second data can be performed to other mobile devices, these other mobile devices, for example, have the same key and / or are assigned to the same role information and / or for these other mobile devices, for example, perform the allocation of the storage facility and the delivery organization as described above. If, for example, multiple mobile devices have the same key, this can have an advantage. This is because the number of mobile devices that can access the device (for example, the storage facility) according to the first aspect of the present invention (in terms of each mobile device should have its own key) is limited due to the following reasons, that is, the device according to the first aspect of the present invention must also provide its own indicator for each such mobile device. However, the total number of possible indicators is limited. Therefore can advantageously, multiple mobile devices have the same key.So, these mobile devices also only need one indicator, so that the number of mobile devices that can access the device (such as storage compartment facility) according to the first aspect of the present invention is no longer limited by the total number of indicators available.
[0077] The above exemplary generation of access information is to allow one or more user groups with predetermined functions to access the storage facilities independently of the mailed object. For example, it can be realized that the determined user group, for example, updates their roles on the mobile device for the determined storage facilities every day, and then they are authorized to access these storage facilities by the described method. Therefore, the courier as a part of the user group "courier" can, for example, trigger the generation of access information there for one or more storage facilities for a period of one day or within one day on the mobile device (and finally also obtain the same access information on the mobile device). For example, the mobile device can not be assigned to the courier individual at this, but to the delivery organization. For example, whether and to what extent the determined courier can control the mobile device and / or can trigger the generation and / or acquisition of the described access information by, for example, the user and authorization management of the delivery organization and the registration on the mobile device itself (for example, based on NFC and proof, such as postal proof) to regulate, control and / or pre-set. Additionally or alternatively, for example, a server or another device of a delivery organization can trigger the generation and / or acquisition of the described access information, for example, in the following manner, that is, the device notifies the device or system which mobile devices should have access to which storage facilities, and the device or the system is configured to transmit keys and / or assigned role information to the storage facilities. For example, such notification can be performed regularly, for example, every day. Then, for example, the output or transmission of the second data in the method according to the third aspect of the present invention can be performed to the notified mobile device.
[0078] In principle, the access required by these user groups or the access that may be needed at some time is distinguished from the access required by the general consignment recipient, for example, who only needs to access one or more storage compartments containing his consignment. The storage compartment facility can be confirmed based on an indicator, for example, (when the password authorization access is confirmed positively) the common storage compartment facility program that allows ordinary users to access should not be run, but should implement for example a special program. The special program can for example implement access to the entire storage compartment facility, for example, all storage compartments and / or any storage compartment. In order to make this access to the storage compartment facility possible for the authorized person and for example impossible for ordinary users, for example, in an exemplary embodiment according to the first aspect of the present invention, the other necessary condition for confirming that the password authorization access storage compartment facility is that the indicator contained in the third data is associated with the user group with a predetermined function. If it has been confirmed that the password authorization access storage compartment facility, for example, a special program can be executed, which is for example personalized for each user group. For this reason, the storage compartment facility then for example confirms which special program should be executed based on the indicator.
[0079] According to an exemplary embodiment of the first aspect of the present invention, it has been confirmed that the password for authorizing access to a storage compartment facility or one or more storage compartments of the storage compartment facility is not re-authorized for access or at least not re-authorized for access during a predetermined time interval after the confirmation. For this reason, for example, each password for authorizing access to a storage compartment facility or one or more storage compartments of the storage compartment facility is stored. If the password is subsequently obtained again, for example by means of third data, the password is not re-authorized for access. Therefore, for example, it can be prevented that an attacker who, for example, eavesdrops on the radio transmission of the third data including the password and / or reads the password input by the user together at the storage compartment facility may subsequently obtain access using the password.
[0080] According to an exemplary embodiment of the first and / or second aspects of the present invention, the third data is transmitted to the storage compartment facility or provided to the storage compartment facility (and the corresponding acquisition or acquisition by the storage compartment facility) by means of one or more of the following feasible solutions a) to d): a) by means of a radio connection, in particular Bluetooth or NFC; b) by means of an optical pattern representing the third data, which is displayed on the screen of a mobile device for acquisition by an acquisition unit of the storage compartment facility; c) by means of displaying the third data on the screen of the mobile device for visual acquisition by a person, who then enters the third data on an input unit of the storage compartment facility, in particular a keyboard or a touch-sensitive screen; or d) by means of sound transmission, for example by having the device or the person read out the third data and the storage compartment facility acquires the third data by means of voice recognition (but other sound transmissions, for example by Morse code or other modulation types of sound are also possible). These transmission types, for example, achieve that the device and / or the user are located near the device for acquisition or acquisition, and / or the third data can only be transmitted and / or acquired or acquired at a predetermined, for example maximum speed, thereby obtaining the advantages resulting therefrom and already described.
[0081] According to an exemplary embodiment of the first aspect and / or the second aspect of the present invention, the indicator contained in the third data is represented by a first group of bits, the password contained in the third data is represented by a second group of bits, and the first group of bits and the second group of bits are mixed in the third data according to a predetermined rule. Therefore, the indicator can be represented by any number of bits, such as 1 bit, 2 bits, 3 bits, 10 bits, 12 bits or more bits. Here, the indicator can also be represented by obvious logically separated elements, such as represented by the first grouping bit and the flag. Similarly, the password can also be represented by any number of bits, such as 10 bits, 50 bits or 100 bits, and can be represented by, for example, obvious logically separated elements.
[0082] The indicator contained in the third data is, for example, not encrypted with a key (with which the access information is encrypted), and is therefore, for example, evaluated by a device that acquires or obtains the third data. The device can, for example, determine the access information based on the indicator so that it can then confirm whether the password authorizes access based on the access information. However, since the indicator may therefore at least indirectly contain information that may help a potential attacker gain access to the storage compartment facility, it is advantageous that a potential attacker, for example, cannot distinguish which bits in the third data are part of the indicator and which bits are part of the password. Therefore, the bit representing the indicator is, for example, hidden and / or concealed between other data, especially in a password represented by a bit. This can be done, for example, according to a predetermined rule, such as the bit representing the indicator is always located at the same position between the password bits. However, the bit representing the indicator can also be positioned at a transformed position, for example, according to the clock time and / or the value of the indicator and / or a part of the indicator. For example, by predetermining the rule, the device for transmitting the third data can, for example, prepare the third data accordingly, and the device for obtaining the third data can allocate the bits contained in the third data to the indicator or password respectively based on the understanding of the predetermined rule. This may make a potential attack more difficult, for example, when the rule is unknown to the attacker, compared to the case where the bits representing the indicator and the bits representing the password can be easily assigned.
[0083] According to an exemplary embodiment of the first aspect and / or the second aspect of the present invention, a password is generated based at least on the access information and the time value. The time value may be, for example, the current time value of the device generating the password. The time value may also, for example, indicate the time from, during or until which the password is valid. In principle, the time value may be, for example, a rounded time value, for example, rounded to 60 seconds. In addition, the password may be generated, for example, based on further information, for example, further time values.
[0084] According to the exemplary embodiment of the first aspect and / or the second aspect of the present invention, the password is generated when using a one-way function, especially a hash function, wherein at least a portion of the access information and at least a portion of the time value are used as input data of the one-way function. For example, the mobile device generates a password when using a one-way function, wherein the password uses at least a portion of the UNIX time value of the current time value, for example rounded (for example rounded to 60 seconds) and the access information. The generation of the password can for example also include other steps, for example, the result of the one-way function is truncated to a predetermined length. For example, a cryptographic hash function (such as SHA, SHA-2 or MD5) can be used as a one-way function.
[0085] The password produced in this way is for example transmitted to the storage grid facility or offered to the storage grid facility.This storage grid facility determines access information based on the indicator contained in the 3rd data, and produces for example one or more passwords, for example each one password of the current rounded UNIX time value, the last rounded UNIX time value and the next rounded UNIX time value.In order to produce corresponding password, the storage grid facility for example uses a one-way function, especially a hash function, and also implements the same step as the mobile device.Then for example can confirm, whether one of the passwords produced by the storage grid facility is consistent with the password contained in the 3rd data, and therefore authorized access.For example by additionally using earlier and / or later time value, for example can compensate for the deviation of the current time of the mobile device and the current time of the storage grid facility, for example this is because one of them device or even two devices are not connected with the Internet and / or time server and / or have not been connected for a long time.In addition, therefore can for example compensate for transmitting / providing and / or obtaining / obtaining the 3rd data and spend too long to have reached the next UNIX time value.
[0086] According to an exemplary embodiment of all aspects of the present invention, the storage compartment facility generates access information in the corresponding storage process, for example, in response to the corresponding storage, storage or storage of at least one mail in the storage compartment of the storage compartment facility. For example, each time one or more mails are stored in the storage compartment, the storage compartment facility will generate corresponding access information. If the corresponding storage compartment no longer contains mails and / or has been opened at least once after storage, the corresponding access information of the storage compartment is deleted and / or no longer authorized for access. The storage compartment facility can, for example, detect that the courier is going to store the mail in the storage compartment, for example, because the courier triggers the opening of the storage compartment. The storage compartment facility can, for example, generate access information in response to this. Alternatively, the storage compartment facility can, for example, detect that the mail has been stored in the storage compartment by means of a sensor (such as a weight sensor and / or an infrared sensor) and generate access information in response to this. The storage compartment facility can, for example, also generate access information in response to the input of the courier during the storage process. The access information is generated during the corresponding storage process, for example, in response to the corresponding impending storage, storage in progress or storage of at least one consignment in the storage compartment facility. It is not excluded that additional access information may be generated for other purposes, for example, so that one or more user groups with predetermined functions can access the storage compartment facility or one or more storage compartments of the storage compartment facility.
[0087] According to an exemplary embodiment of all aspects of the present invention, the indicator is associated or associated with the access information at least in the following manner, that is, the access information is uniquely assigned to a storage compartment of a storage compartment facility, and the indicator is associated or associated with the storage compartment of the storage compartment facility, wherein the storage compartment is, for example, a storage compartment in which mail has been stored. For example, the storage compartment facility uniquely assigns the access information to the storage compartment of the storage compartment facility during the generation of the access information. In addition, the storage compartment facility also, for example, associates the indicator with the storage compartment, for example, assigns the indicator to the storage compartment. Therefore, the access information and the indicator are, for example, information specific to the storage compartment. By the storage compartment facility obtaining the indicator with the help of third data in this way, the storage compartment facility can then determine the access information, which is needed to confirm whether the password authorizes access to at least the storage compartment. In addition, the storage compartment facility can, for example, confirm which storage compartment should be allowed to access (as long as the password authorizes access).
[0088] According to an exemplary embodiment of all aspects of the invention, a key is assigned to a user identification code, wherein when encrypting the access information, the storage compartment facility uses the key assigned to the user identification code only when the storage compartment facility has been informed during the process of depositing the mailed items in the storage compartments of the storage compartment facility or the storage compartment facility has confirmed that the mailed items are associated with the user identification code, wherein the mailed items are associated with the user identification code, for example in the following way, that is, the user identification code is the user identification code of the recipient of the mailed items. Thus, for example, it can be achieved that only the recipient has the key for decrypting the access information and can therefore generate a password authorizing access to the storage compartment. For example, if the user's smartphone has generated a key, for example during the process of the user registering at a storage facility or registering as a customer on a server, and the key has been associated with a user identification code, for example, the user's smartphone can decrypt the access information encrypted by the storage facility with the key, generate a password based at least on the access information, transmit the password to the storage facility or provide the password to the storage facility and thereby gain access to at least one storage compartment in which at least one consignment has been stored, the at least one consignment being associated with the user identification code of the user.
[0089] According to an exemplary embodiment of all aspects of the invention, the indicator is an element from a first set, wherein the first set includes more elements than a second set, wherein each element of the second set is uniquely assigned to a corresponding storage compartment of the storage compartment facility, and wherein each element of the second set that has a consignment in its uniquely assigned storage compartment is uniquely assigned to an element of the first set. The first set can be, for example, a set of bit combinations or bit sequences. For example, the indicator can have a predetermined length, for example 10 bits. The first set can, for example, contain all possible values formed with 10 bits, i.e., for example 2 10=1024 different values or elements. Correspondingly, there is also a second set. Each element in the second set is, for example, uniquely assigned to a physical storage compartment, such as a corresponding storage compartment of a storage compartment facility. For example, when there are 30 storage compartments in the storage compartment facility, the second set has 30 elements. These elements are, for example, numbers or names, wherein the corresponding storage compartments can be identified based on the elements, for example. For example, when the mail is stored in a storage compartment, exemplarily a storage compartment that is uniquely assigned with the element "17" from the second set, an element of the first set, such as element 1000110101, is uniquely assigned to element "17". This allocation relationship can be, for example, cancelled again in the process of reopening the storage compartment and / or taking out the mail from the storage compartment. The previously assigned element, exemplarily 1000110101, is then, for example, not assigned to any storage compartment. For example, if the mail item is stored again in a storage compartment to which the element "17" from the second set is uniquely assigned, another element from the first set, for example 0010101101, can be assigned to the element "17". Then, the previously used element 1000110101 from the first set can be uniquely assigned to another element from the second set at a later time, for example.
[0090] The elements of the first set assigned to the elements of the second set can be selected, for example, randomly and / or according to a predetermined rule. For example, there can be another set (referred to as a selection set) that only contains elements of the first set that have not yet been assigned to an element of the second set. Thus, from the selection set, for example, the longest-lived element of the selection set can always be assigned to the elements of the second set as the next element. For example, when the assignment relationship between an element of the first set and an element of the second set is released, the elements of the first set are always added to the selection set. Conversely, when, for example, an element of the first set is assigned to an element of the second set, the elements of the first set are removed from the selection set.
[0091] The selection set can also be in the form of a list, for example, and can select, for example, an element at a predetermined list position, that is to say a list item, to be assigned next. This can be, for example, the first list item or the last list item. Likewise, elements can also always be added at the beginning or end of a list.
[0092] The described allocation principle is advantageous in many aspects.For example, it is known in advance how many bits need to be reserved for the indicator, for example, for storage and / or transmission and / or acquisition and / or acquisition and / or processing. In addition, this is, for example, independent of how many storage compartments there are in the storage compartment facility, as long as the storage compartment of the storage compartment facility is less than the elements of the first set. For example, the length of the indicator can be determined to be such a situation for all storage compartment facilities, for example, the storage compartment facilities of a certain type or a certain operator. In addition, the method improves the security of the attack of the storage compartment facility against unauthorized access, especially the purpose is to access the storage compartment selected especially, and the storage compartment selected especially is, for example, a particularly large storage compartment or a potential attacker has observed which mailed object is stored there. This is because, for example, when the mailed object is stored in the storage compartment, this storage compartment is associated with a new indicator value. Therefore, for example, any equipment and / or personnel outside the storage compartment facility for performing distribution do not know which indicator is associated with which storage compartment. In addition, the method, for example, also contributes to the security of the storage grid facility in the following manner, that is, not all indicator values are assigned to the elements of the second set and then to the storage grid. This, for example, reduces the probability that a potential attacker realizes that the password transmitted by the storage grid facility is checked by him, for example, in a test. This is because, if the storage grid facility cannot determine the access information based on the indicator contained in the third data at least (for example, this is because the indicator selected by the attacker is not associated with any storage grid and therefore is not associated with any access information), the storage grid facility, for example, does not implement the step of confirming whether the password authorizes access to the storage grid facility or one or more storage grids of the storage grid facility at all. It is particularly effective here that the indicator originally has or must have a predetermined length (for example, 10 bits) and these advantages can be realized, because the storage grid facility has a predetermined number of storage grids (exemplary is 513 storage grids). Instead of using only 513 of the 1024 available indicator values and leaving 511 unused, additional security effects are achieved by the allocation method described, without the need to transmit additional bits.
[0093] The described allocation principle can also be understood separately from other features of one or all aspects of the present invention and in this sense can also be understood as an independent disclosure. In particular, the described technical advantages are achieved even if the features of one or all aspects of the present invention are not required for this purpose. In addition, the described allocation principle should also be understood as a disclosure in a more general way, that is, in particular, not only in relation to the storage compartments of the storage compartment facility, but also in relation to any number of objects that may undergo a state change (for example, a storage compartment due to the storage of mail), and these objects should be associated or not associated with indicators depending on their state.
[0094] According to an exemplary embodiment of all aspects of the present invention (which exemplary embodiment includes the features of the last two described embodiments required for this embodiment), the user identification code is derived from a third set, which includes more elements than the first set. In particular, the user identification code is derived from a set of numbers with a length of 6-12 decimal places, for example. However, the storage compartment facility can, for example, determine the user identification code based on an indicator derived from the first set, for example because there is a mailing associated with the user identification code in a storage compartment associated with the indicator of the storage compartment facility. Therefore, it is more efficient to transmit and / or provide and / or obtain and / or obtain the indicator, for example, than to transmit and / or provide and / or obtain and / or obtain the user identification code. In addition, it is safer to transmit and / or provide and / or obtain and / or obtain the indicator, for example, than to transmit and / or provide and / or obtain and / or obtain the user identification code, because the user identification code is, for example, statically assigned to the user and may therefore be spied on and may be used again later. In contrast, the indicator is, for example, regularly and / or often reallocated, so that a potential attacker cannot obtain a lasting advantage from the knowledge of the indicator.
[0095] According to an exemplary embodiment of all aspects of the invention, the key is a public key of an asymmetric key pair. For example, the device implementing the method according to the second aspect of the invention also generates the associated private key of the asymmetric key pair. The device then obtains the access information encrypted with the public key, for example in the second data, and decrypts the access information encrypted with the public key using the private key. For example, only the public key then leaves the device that generates the key. This is, for example, particularly safe.
[0096] The above-described embodiments and exemplary configurations of all aspects of the invention are also to be understood openly in all combinations with one another.
[0097] Other advantageous exemplary designs of the present invention are derived from the following detailed description of some exemplary embodiments of the present invention, in particular in conjunction with the accompanying drawings. However, the drawings of the present application are only used for illustrative purposes, but are not used to determine the scope of protection of the present invention. These drawings are not necessarily true to scale and should only reflect the overall concept of the present invention by way of example. In particular, the features contained in the drawings should not be regarded as necessary components of the present invention in any case. The order of the individual steps in the flow chart does not necessarily specify the actual (temporal) order of these steps, but is only exemplary. Nevertheless, these steps can still appear / execute in the same time order shown in the flow chart. In addition, these steps can, but do not have to, be executed in response to each other. BRIEF DESCRIPTION OF THE DRAWINGS
[0098] In the attached picture:
[0099] Figure 1A schematic diagram showing an exemplary embodiment of a system according to the present invention, the system exemplarily comprising a storage compartment facility, a mobile device and a backend system;
[0100] Figure 2 A flow chart showing an exemplary embodiment of a method according to the first aspect of the present invention, the method being implemented and / or controlled by a storage compartment facility, for example;
[0101] Figure 3 A flow chart showing an exemplary embodiment of a method according to a second aspect of the present invention, the method being implemented and / or controlled by a mobile device, for example;
[0102] Figure 4 A flow chart showing an exemplary implementation of a method according to a third aspect of the present invention, the method being implemented and / or controlled by, for example, a backend system and / or a server;
[0103] Figure 5 A schematic diagram showing an exemplary embodiment of an apparatus according to the first aspect of the invention, such as a storage compartment facility;
[0104] Figure 6 A schematic diagram showing an exemplary embodiment of a device according to the second aspect of the present invention, the device being, for example, a mobile device;
[0105] Figure 7 A schematic diagram showing an exemplary embodiment of an apparatus according to a third aspect of the present invention, the apparatus being, for example, a server;
[0106] Figure 8 A schematic diagram of an exemplary data transmission between devices, in particular between an exemplary mobile device, an exemplary server and an exemplary storage compartment facility, which respectively implement an exemplary implementation of the method according to the corresponding aspect of the present invention;
[0107] Fig. 9 A schematic diagram showing an exemplary allocation of indicators, eg managed by a locker facility, of an exemplary embodiment of a method according to all aspects of the invention is shown. DETAILED DESCRIPTION
[0108] Figure 1 A schematic diagram of an exemplary embodiment of a system according to the invention is shown.
[0109] The system 1 includes a storage compartment facility 120 having a plurality of storage compartments. Figure 1In the figure, three exemplary storage compartments are provided with reference numerals 121, 122, and 123. Each storage compartment in the storage compartment facility 120 is configured to accommodate one or more mailings 140 for the corresponding individual user 111. Multiple storage compartments can also be assigned to individual users 111. Each storage compartment is locked or closed in the basic state, and can be electrically unlocked or opened by a lock control unit, for example, arranged in the storage compartment facility 120, under command control and individually. An example of such a storage compartment facility 120 is a storage compartment facility 120 according to the parcel station concept known to the applicant.
[0110] The storage compartment facility 120 is equipped with one or more communication interfaces, which include, for example, an interface for wireless communication with the mobile device 110. The wireless communication connection 131 is, for example, based on optical transmission and / or communication by means of electrical, magnetic or electromagnetic signals or fields, in particular short-range communication, for example based on Bluetooth, WLAN, ZigBee, NFC and / or RFID.
[0111] However, in other embodiments, the storage compartment facility 120 does not include an interface for wireless communication with the mobile device 110, or includes such an interface, which is, for example, not available in principle or only available in certain circumstances or is not used despite being available in principle. For example, the communication of data present on the mobile device 110 (after the data has been transmitted here, for example, from the system 100, the data is decrypted in advance here) and displayed, for example, can be carried out by means of a user 111, who, for example, inputs and therefore transmits these data or a part of these data via an input unit or user interface (for example, a keyboard or a touch-sensitive screen with an on-screen keyboard or a voice recognition module) on the storage compartment facility 120. The data transmitted in this way is, for example, short information, so that the user, for example, only needs to input or transmit a small amount of information by the mobile device 110, and in this way, for example, a shorter transmission time can be achieved. This can be particularly advantageous, for example, that the transmission must be carried out in a predetermined, for example, short time in order to, for example, achieve a particularly high level of security, for example, because the data used for permission only has a limited timeliness. Of course, the user 111 can also, for example, input data that is not stored on the mobile device 110 and / or is not displayed here. Furthermore, the storage compartment facility 120 may also exemplarily comprise an output unit, for example for displaying information via a screen.
[0112] The storage compartment facility 120 is also configured to communicate with the system 100, i.e., for example, has a communication interface capable of accessing the Internet or other network connected to the system 100. In particular, the storage compartment facility is therefore configured for remote communication, for example, has an interface to a cellular mobile communication system, a DSL interface or a local area network (LAN) interface, by means of which the storage compartment facility can communicate with the system 100 via a communication connection 130. However, in other embodiments, the storage compartment facility 120 is not configured to communicate directly with the system 100, for example. Thus, the storage compartment facility uses, for example, a device configured to forward data in order to communicate with the system 100 and / or the various devices 101, 102 of the system 100. The device configured to forward can, for example, exchange data with the system 100 via a remote communication interface, and exchange data with the storage compartment facility 120 via a short-range communication interface, and thus forward data from the system 100 to the storage compartment facility 120, and vice versa.
[0113] System 100 is illustratively a back-end system including two servers 101, 102. Here, servers 101, 102 can communicate with each other, for example. In particular, each server in servers 101, 102 performs different tasks here. Therefore, server 101 manages one or more storage facilities 120, for example, respective locations and status data, and server 102 manages registered users 111 of storage facilities 120 and, for example, devices 110 of users. However, in other embodiments, system 100 may also include only one server 101, 102 and / or include more than two servers 101, 102, which may, for example, also be different physical units. Here, the task allocation between servers 101, 102 may be merged or divided arbitrarily. System 100 and / or one or more servers 101, 102 of the system may, for example, communicate with the device 110 and / or storage facilities 120 of user 111 via one or respective communication interface 103 via one or respective communication connection 132 (for example, Internet connection) .
[0114] In the embodiment described below, the device 110 is the smart phone 110 of the personnel 111, but in other embodiments, the device can be any other mobile device.Here, the personnel 111 can, for example, use the smart phone 110 to register as the user 111 of other services of the operator of the storage compartment facility 120 or multiple storage compartment facilities and / or one or more storage compartment facilities, especially the recipient 111 of the mail 140.Here, the user can be generally understood as the personnel who use / hope to use the storage compartment facility 120 to receive and / or send mail (such as parcels, letters, meals, food, etc.) and the courier who delivers this mail to the storage compartment facility 120 or takes out / hopes to take out this mail from the storage compartment facility 120.The user 111 can be a person or a machine, such as a vehicle, a robot or a drone, just to name a few examples.In the present embodiment, the registration of the recipient 111 of the user 111, especially the mail 140, is exemplarily carried out by means of an application or an interactive website on the smart phone 110. For example, during the registration process, the person 111 is provided with a user identification code, for example, by assigning a user identification code to the person 111 or the person selecting a user identification code. In the present embodiment, the smartphone 110 also generates a key during the registration process, here exemplarily a public key of an asymmetric key pair and a private key belonging to the asymmetric key pair. However, in other embodiments, this generation can also occur in other relationships and include other types of keys, such as symmetric keys, which can only be obtained and cannot be generated on the smartphone 110, for example.
[0115] Then, the smart phone 110 transmits the key, for example, to the system 100. Here, the generated key (in the present embodiment, a public key) can be associated with the user identification code of the user 111, for example, by the smart phone 110 or the system 100. Then, the system 100 is configured, for example, not only to transmit the key to the storage compartment facility 120, but also to transmit the user identification code associated therewith. For example, the transmission can occur immediately after the system 100 obtains the key. Thus, the key is, for example, immediately transmitted to a plurality of storage compartment facilities 120, for example, to all storage compartment facilities of a certain operator or to all storage compartment facilities in a certain region, for example, the area around the residence of the user 111. However, alternatively, the system 100 can also store the key and, for example, only transmit it to the storage compartment facility 120 where, for example, the mailing 140 of the user 111 is being stored, has been stored, or will be stored there.
[0116] The storage of the mail 140 can be performed, for example, by a courier (e.g., a human courier or a machine courier). To this end, the courier, for example, authenticates himself on the storage compartment facility 120, and uses his courier device (the courier device, for example, can transmit the acquired information to the storage compartment facility 120) to scan the label 141 or other mail information of the mail 140 and / or keep the label 141 of the mail 140 in front of the scanner of the storage compartment facility 120, so that the storage compartment facility can scan the label 141 and thus can obtain the mail information of the mail 140. Then, for example, the storage compartment 123 of the storage compartment facility is opened, and the mail 140 can be stored in the storage compartment. Once the mail 140 is stored, the storage compartment 123 is, for example, closed again. Then, the storage compartment facility 120 generates, for example, access information for the storage compartment 123, for example, based at least on a random or pseudo-random value, and stores the access information. Exemplarily, it is assumed here that access information 0x82C73 is generated for storage compartment 123 .
[0117] For example, during the storage process, for example, by scanning the tag 141, the storage compartment facility 120 obtains information about the mail 140 that has been stored or will be stored. In particular, the storage compartment facility 120 also obtains or acquires a user identification code associated with the mail 140, for example, a user identification code of the recipient 111 of the mail 140. Based on the user identification code, the storage compartment facility can, for example, request to transmit a key associated with the user identification code to itself at the system 100. If the storage compartment facility 120 obtains the key (or the storage compartment facility originally has already obtained the key in advance and does not need to request at all, but only needs to access the internal memory), the storage compartment facility can use the key associated with the user identification code to encrypt the access information of the storage compartment 123 where the mail 140 of the user 111 is located, which is generated in advance. In the present embodiment, it is assumed that only one key is associated with the user identification code. However, in other embodiments, it is entirely possible to assign multiple keys to the same user identification code, for example, one key per device, where the user 111 may own / register multiple devices 110 .
[0118] For example, in the present embodiment, the courier also stores another mail of the same recipient 111 in the storage compartment 121, and stores another mail of another recipient in the storage compartment 122. The method of storage is exemplarily the same as the method described for mail 140 and storage compartment 123, respectively. However, in other embodiments, only one mail 140 of the recipient 111 may be stored, and, for example, no other mail may be stored in the same and / or another storage compartment. In other embodiments, only one or more mails 140 of the recipient 111 may be stored, and, for example, no mail of any other recipient may be stored. The method of storage may also vary between several embodiments or in one embodiment.
[0119] Since the storage compartment facility 120 can have multiple storage compartments 121, 122, 123 and these storage compartments can contain multiple mails of multiple recipients, it is advantageous that the storage compartment facility 120 can confirm, for example, when the user 111 makes an authentication request, which storage compartment 121, 122, 123 or mail 140 the user 111 seeks to access and what the associated access information is, based on which information for authorized access can be created. To this end, the storage compartment facility 120 can, for example, associate an indicator with the access information. For example, the storage compartment facility 120 selects the storage compartment number 123 of the storage compartment 123 in which the mail 140 is stored as an indicator, and stores the indicator, for example, as a data structure or a part of a data structure in a manner that associates the indicator with the access information. Thus, when an authentication request is made later, the storage compartment facility 120 can determine, for example based on the indicator and the data it stores, which storage compartment 123 the request relates to and which access information is decisive for this storage compartment 123. In the present embodiment, the storage compartment number is simply selected as the indicator, but in other embodiments, the selection and association of the indicator can be done completely differently, as long as the storage compartment facility 120 still has the possibility to learn the associated access information at least based on the indicator and possibly further information.
[0120] Subsequently, the storage compartment facility 120 can output the first data to the system 100, for example, via the communication connection 130 or also via the equipment configured to forward data (for example, the equipment of the courier having stored the mail 140 and still having the short-range radio communication connection with the storage compartment facility 120). The first data may include an indicator and access information encrypted with a key and possible other data or information, such as the mail identification code and / or the user identification code of the mail 140, such as the user identification code of the recipient 111. Here, the indicator, for example, can also be encrypted with a key. The system 100, for example, can neither decrypt the access information encrypted with a key nor decrypt the indicator encrypted with a key. On the contrary, the system 100, for example, already has a mail identification code and / or the user identification code in plain text form. Based on the mail identification code and / or the user identification code, the system 100, for example, can then identify the user 111 and / or the user's smart phone 110 and output or transmit the second data to the smart phone 110. Here, the second data includes at least access information encrypted with a key and an indicator that may be encrypted with a key. However, in some embodiments, the second data may also include other information, such as an identification code of the storage compartment facility 120 in which the mailed item 140 is stored. Then, the smart phone 110 may, for example, display to the user 111 in an application that the mailed item 140 is ready for the user to take out in the storage compartment facility 120. Then, the user 111 may, for example, have the opportunity to take out the mailed item 140 from the storage compartment facility 120 within a predetermined time period, for example within 9 days.
[0121] In this embodiment, the smartphone 110 has not only the public key (with which at least the access information contained in the second data is encrypted) but also the associated private key. Therefore, the access information contained in the second data can be decrypted, and if the indicator contained in the second data is also encrypted with the public key, the indicator can also be decrypted with the private key.
[0122] Then the smart phone 110 can generate a password at least based on the access information. This generation can be carried out, for example, in response to user input. Therefore, the user 111 can, for example, approach the storage compartment facility 120 to take out the mailing 140 determined to him. Then, in order to authenticate himself on the storage compartment facility 120, the user can open the application on his smart phone 110 or operate the application so that the application generates a password. However, in other embodiments, the password generation can also be automatically triggered in the following manner, that is, the smart phone 110 recognizes that it is in the vicinity of the storage compartment facility 120, for example, this is because the smart phone obtains the Bluetooth beacon from the storage compartment facility 120. Here, at least the general method of generating a password based on the access information can be known completely, and it is not necessary to keep confidentiality in order to ensure the security of the method. Since only the smart phone 110 has a private key, there is almost no other device that can decrypt the access information encrypted with the first key and generate a corresponding password at least based on this. In the present embodiment, the password is generated when using a one-way function, especially a hash function, wherein at least a portion of the access information and at least a portion of the time value are used as input data of the one-way function. In particular, as a time value, a UNIX time value rounded to 60 seconds representing the current time of the smartphone 110 in Temps universel coordonné (Coordinated Universal Time) (UTC) is used as an example to generate the password. Then, for example, when there is a new rounded time value, the password can be automatically regenerated every 60 seconds. In other embodiments, the exact time can be determined as different from 60 seconds, for example, as 30 seconds or 90 seconds, for example, as a configuration parameter (which can be flexibly adapted based on practical experience). In short, the generation and checking of the password can be performed, for example, according to a standard, for example, according to the Oath standard.
[0123] After generating the password, the smart phone 110 can display the third data as a barcode or QR code on its screen, for example, and thus provide the third data for the storage compartment facility 120, which includes at least the password and the indicator. Then, the user 111 can, for example, keep the smart phone 110 in front of the acquisition unit (e.g., scanner) of the storage compartment facility 120 so that the storage compartment facility can acquire the barcode or QR code. In other embodiments, the smart phone 110 can transmit the third data to the storage compartment facility 120 via a short-range radio communication connection (e.g., Bluetooth) and / or display the third data, for example, as a (hex) decimal value, so that the user 111 can enter the third data on the input unit of the storage compartment facility 120, for example, on a touch-sensitive screen.
[0124] Here, the indicator has exemplarily a decimal value 123, which can be represented as bits 01111011. The hexadecimal representation is, for example, 0x7B. The password can also be shown in bits, for example. Exemplarily, it is assumed here that the input data of the one-way function are the rounded time value and the access information 0x82C73 for the storage compartment 123, and the result of the one-way function is truncated after 4 digits, so that the password 9582 with 4 decimal digits (exemplarily very short) is used here exemplarily. In the case of binary representation, the password is, for example, 0010010101101110, and in hexadecimal representation, for example, 0x256E. Thus, the third data may include, for example, a hexadecimal sequence of 0x2756BE, that is, the first 4 bits (0x2) are password bits, the following 4 bits (0x7) are indicator bits, the following 8 bits (0x56) are password bits, the following 4 bits (0xB) are indicator bits, and the last 4 bits (0xE) are password bits. Password bits and indicator bits are, for example, always mixed in the third data (for example, from smart phones 110 and all other devices that wish to authenticate themselves on the storage grid facility 120) according to this rule. The storage grid facility 120, for example, knows this rule, and can easily divide the value 0x2756BE into the value 0x7B for the indicator and the value 0x256E for the password again. However, this rule may not be known to an attacker who wants to access the storage grid facility without authorization and snoop / eavesdrop on the third data in the form of 0x2756BE, so that the attacker cannot identify which bits are indicator bits and which bits are password bits. In other embodiments, the rule may also be changed according to the clock time, predetermined parameters from the system 100 or other factors (eg, the first bit of the password).
[0125] After obtaining the third data, the storage grid facility 120 can determine the access information based on at least the indicator contained in the third data. Therefore, when the value of the indicator is 123, this is the access information 0x82C73 associated with the indicator. In the present embodiment, the storage grid facility 120 then generates three passwords using the same method steps used by the smart phone 110 to generate passwords. Thus, the storage grid facility 120 generates a password based on the access information 0x82C73 and the current UNIX time value (t0) rounded to 60 seconds, and generates a password based on the access information 0x82C73 and the previous UNIX time value (t0) rounded to 60 seconds. -1 ) generates another password and based on the access information 0x82C73 and the next UNIX time value rounded to 60 seconds (t +1) generates another password. Thus, for example, the generated passwords 0xBA23, 0x256E, and 0x5506 are obtained. Then, the storage grid facility 120 can compare each of the three passwords with the password 0x256E contained in the third data, and confirm that the storage grid facility is based on the access information 0x82C73 and the previous UNIX time value rounded to 60 seconds (t -1 ) The password generated is consistent with the password 0x256E contained in the 3rd data. For example, due to the current time value of the storage grid facility 120 and the current time value of the smart phone 110 may be slightly different and may cause time deviation, for example, this is because the storage grid facility 120 is not connected to the Internet when the user 111 is authenticated. Here, the storage grid facility 120 can then, for example, confirm that the password contained in the 3rd data authorizes access to the storage grid 123, because there is consistency, and the storage grid facility 120 can, for example, unlock the door of the storage grid 123 by the storage grid facility 120 and allow the user 111 to access the storage grid 123. Subsequently, the storage grid facility 120 can store the password that the storage grid facility confirms the authorized access. So, within a predetermined duration, for example, within 3 minutes, 5 minutes or 120 minutes, re-authentication attempts using the same password can be rejected by the storage grid facility 120 without further inspection, so as to prevent unauthorized persons from eavesdropping and reusing passwords. However, in other embodiments, more or fewer time values may also be used, which are also rounded in another way and / or have a different relationship with, for example, the current time value, i.e., for example, not using or using only the current time value (t0), the previous time value (t1), or the previous time value (t2). -1 ) and the future time value (t +1 ), but also use a time value (t N ) or multiple time values (t N ), where N represents an arbitrary number. It is also possible to use a time value (t0) which is not relatively dependent on another time value, such as the current time value, but is, for example, an absolute time value. A ). How many and which time values are used are configuration parameters which can be flexibly adapted, for example based on practical experience.
[0126] In the present embodiment, the storage compartment facility 120 generates a plurality of passwords so that it can be confirmed whether the password contained in the third data authorizes access. However, in other embodiments, a variety of other methods can be performed so that it can be confirmed whether the password contained in the third data authorizes access. For example, the storage compartment facility 120 can generate access information based on the password contained in the third data, and check whether the access information is consistent with the access information of the storage compartment involved (for example, 0x82C73 of storage compartment 123 in this case).
[0127] In this embodiment, instead of only confirming that the password contained in the third data authorizes access to the storage compartment 123, the storage compartment facility 120 can also confirm, in addition or alternatively, whether the password authorizes access to other storage compartments of the storage compartment facility, such as storage compartments 121, 122. For example, based on the information of the mail 140 located in the storage compartment 123, the storage compartment facility 120 can determine the user identification code, in particular the user identification code of the recipient 111 of the mail 140. Based on this, the storage compartment facility 120 can determine one or more other storage compartments 121, 122, in which there are individual mails that are also associated with the user identification code of the recipient 111. In this embodiment, the mail of the recipient 111 is also deposited in the storage compartment 121 by the courier. Therefore, the storage compartment facility 120 can confirm that the password also (at the same time) authorizes access to the storage compartment 121. Then, the same password, for example, when entered once or when obtained once, authorizes access to the storage compartments 121, 123 of the storage compartment facility, in which there are individual mailings associated with the user identification code of the same recipient 111. This is advantageous, for example, because it is not required that the storage compartment facility 120 must additionally obtain a user identification code, which can be, for example, a 6-12 digit postal code, just to confirm that the user has access to multiple storage compartments 121, 123, and which storage compartments 121, 123. The recipient 111 can, for example, select which storage compartment 121, 123 should actually be opened as long as he has access to multiple storage compartments 121, 123 after entering a password once. For example, this selection can be made on an input unit or user interface (e.g., a keyboard or a touch-sensitive screen with an on-screen keyboard) of the storage compartment facility 120 or on a mobile device 110 of the recipient 111, and the mobile device transmits this selection to the storage compartment facility 120 via a wireless communication interface. In this embodiment, a password used in this manner may be stored on the locker facility 120 and / or otherwise disabled, for example, after being used once, so that it does not reauthorize access.
[0128] Figure 2 The process of an exemplary embodiment of the method according to the first aspect of the present invention is shown Figure 2 .process Figure 2 The method is implemented and / or controlled, for example, by a storage compartment facility (e.g., storage compartment facility 120 from system 1) or a system including at least a storage compartment facility (e.g., a system and / or system 100 including storage compartment facility 120 and a courier's equipment).
[0129] In step 200, a key is obtained, such as a symmetric key or an asymmetric key, in particular a public key of an asymmetric key pair. In this embodiment, it is exemplarily assumed that the key is a symmetric key.
[0130] In step 210, access information is generated. The access information can be associated with / in association with a storage compartment in which mail has been stored, is being stored, or will be stored. However, alternatively, access information can also be generated that allows one or more user groups with predetermined functions to access the storage compartment independently of the mail. For example, access information that allows a courier to access the storage compartment facility can be generated. The access information can then be regenerated, for example, regularly, such as every 24 hours, every 7 days, or every month, so as to make brute force attacks difficult. Exemplarily, it is assumed here that access information with a decimal representation of "23140896" is generated here.
[0131] In step 220, the access information is encrypted using a key, for example, to prevent unauthorized persons from gaining access to the access information.
[0132] In step 230, the indicator is associated with the access information. This can be done, for example, in that the storage compartment facility can learn about the user group with the predetermined function at least based on the indicator, i.e., for example, the indicator "150" is associated with or assigned to the user group "delivery personnel". Then, the user of this user group with the function should be able to generate a password at least based on the access information, which password authorizes access to the storage compartment facility, i.e., for example, all storage compartments, any storage compartment, special storage compartments, (special) functions (e.g., special programs suitable for the function) or the control system of the storage compartment facility.
[0133] In step 240 , first data is output, wherein the first data at least includes an indicator and access information encrypted with a key, for example, to the server 101 , 102 or the system 100 .
[0134] In step 250, for example, at a later time and / or for example when a user of the user group "deliveryman" is near the storage compartment facility, third data are obtained or acquired from a device having a key for decrypting the encrypted access information, wherein the third data includes a password and an indicator. Exemplarily, the device can be a mobile device of the deliveryman, which communicates with the storage compartment facility, for example, via Bluetooth. Alternatively, for example, the deliveryman's device can also visually show the third data, and the storage compartment facility can acquire the third data.
[0135] In step 260, the access information is determined based at least on the indicator contained in the third data. Exemplarily, here the user group "deliveryman" and the access information "23140896" assigned to the user group are determined based at least on the indicator "150".
[0136] In step 270, it is confirmed whether the password authorizes access to the storage facility or one or more storage compartments of the storage facility based on at least the determined access information. For example, the storage facility uses the obtained symmetric key to decrypt the password contained in the third data and checks whether the decrypted password contains information corresponding to the access information "23140896". If this is the case, the storage facility, for example, confirms that the password authorizes access to the storage facility, such as all storage compartments of the storage facility or all empty storage compartments, especially because it has been confirmed that the indicator contained in the third data is associated with the user group "delivery personnel".
[0137] If it is confirmed that the password authorizes access to the storage facility or one or more storage compartments of the storage facility, access to the storage facility or one or more storage compartments of the storage facility is granted in step 280. If it is confirmed that the password does not authorize access to the storage facility or one or more storage compartments of the storage facility, access to the storage facility or storage compartments of the storage facility is denied in step 281.
[0138] Figure 3 The process of an exemplary embodiment of the method according to the second aspect of the present invention is shown Figure 3 .process Figure 3 The method is implemented and / or controlled, for example, by a mobile device (such as a smart phone 110 from the system 1 or a courier's device).
[0139] In step 300, at least one key is generated or obtained. This may be achieved, for example, in response to user input and / or notification by, for example, the system 100, and / or by user input and / or notification by, for example, the system.
[0140] In step 310, the key is transmitted to a device or system configured to transmit the key to a storage compartment facility. In particular, for example, the key is transmitted to Figure 1 system 100.
[0141] In step 320, second data are obtained, wherein the second data at least includes an indicator and access information encrypted with a key. The second data are obtained, for example, while the device for obtaining the second data is in principle (excluding accidental) not in the vicinity of the storage compartment facility.
[0142] In step 330, the access information encrypted with the key is decrypted, for example, after or in response to obtaining the second data.
[0143] In step 340, at least one password is generated based on the access information. However, for example, multiple passwords can also be generated based on at least the access information. The generation of the password can be triggered, for example, by a user input on the device generating the password and / or can occur at regular time intervals when the user operates the mobile device in a certain way, for example, the user calls up the application and selects the consignment and / or storage facility represented in the application and / or opens a predetermined view in the application and / or leaves it in the foreground.
[0144] In step 350, third data are transmitted to the storage compartment facility or provided to the storage compartment facility in order to obtain access to the storage compartment facility or one or more storage compartments of the storage compartment facility, wherein the third data at least includes a password and an indicator. For example, this can only be done if it is known that the device or entity for transmitting the third data is near the storage compartment facility, i.e., for example, less than an arm's length away, or within a radius of, for example, 5 m.
[0145] Figure 4 The process of an exemplary embodiment of the method according to the third aspect of the present invention is shown Figure 4 .process Figure 4 The method is implemented and / or controlled, for example, by a system (eg, system 100 from system 1), a single server (eg, servers 101, 102), or other device (eg, a courier's equipment).
[0146] In step 400 , a key is obtained from a mobile device, such as the smartphone 110 of the system 1 .
[0147] Then, for example once a communication connection 130 with the storage compartment facility 120 is provided and / or in response to a request from the storage compartment facility 120 and / or in response to a request from a courier or a courier's device and / or in response to a request from another mobile device of the user (e.g., smart phone 110), in step 410, the key is transmitted to the storage compartment facility, such as the storage compartment facility 120.
[0148] In step 420, first data are obtained from the storage facility, wherein the first data at least includes an indicator and access information encrypted with a key. In particular, the device used for obtaining, for example, cannot decrypt the access information encrypted with a key, for example, because the device cannot obtain the key required for decryption.
[0149] In step 430, second data are output / transmitted to the mobile device, wherein the second data at least comprises the indicator and the access information encrypted with the key. This is then done, for example, once a communication connection 132 with the mobile device 110 is provided and / or in response to a request from the storage compartment facility 120 and / or in response to a request from a courier or a courier's device and / or in response to a request from the mobile device 110 itself.
[0150] Figure 5 1 is a schematic diagram of an exemplary embodiment of the device 5 according to the first aspect of the present invention. The device 5 may, for example, represent a storage compartment facility 120 (see Figure 1 ) or its control unit.
[0151] The device 5 comprises a processor 50, a program memory 51, a working memory 52, a user data memory 53, one or more communication interfaces 54, a control unit 55 or a lock control unit for a lock of a storage compartment of a storage compartment facility, one or more optional sensors 56, an optional acquisition unit 57 and an optional input unit / user interface 58. For example, the processor 50 executes a program according to the first aspect of the invention stored in the program memory 51, for example as firmware. The working memory 52 is used in particular to store temporary data during the operation of this program.
[0152] The user data memory 53 is used to store data required when processing a program. Here, the data can be, for example, a key obtained. Other data, such as access information, indicators and passwords, can also be stored in the user data memory 53, for example, in a data structure that also represents the allocation relationship between the access information and the respective indicators and / or the respective storage cells.
[0153] The communication interface(s) 54 include, for example, interfaces for wireless communication with the devices 6 and / or 7, for example by means of optical transmission and / or by means of communication based on electrical, magnetic or electromagnetic signals or fields, in particular based on Bluetooth, NFC and / or RFID (Radio Frequency Identification). For example, the device 5 (and therefore the storage compartment facility 120) is also configured to communicate directly with the device 7 (and therefore the system 100), and therefore has, for example, a communication interface capable of accessing the Internet or other networks connected to the device 7.
[0154] The control unit 55 can realize that a single storage compartment of the storage compartment facility is opened or unlocked in a targeted manner, so that opening can be realized in particular by controlling the lock of the storage compartment or by the lock control unit of the storage compartment. Additionally or alternatively, the locking of the storage compartment can be realized. For example, the control unit 55 is connected to all locks or lock control units of the storage compartment facility via respective wiring, or is also connected to a bus, to which all locks or lock control units of the storage compartment facility are connected.
[0155] Sensor 56 is optional and is, for example, specific to a storage compartment. The sensor can, for example, detect whether the corresponding mail item is located in the corresponding storage compartment and / or whether the mail item is stored in the storage compartment and / or whether it is taken out of the storage compartment. The same sensor or another sensor can, for example, acquire information about mail item 140 by, for example, optically scanning tag 141 or reading an NFC tag belonging to mail item 140.
[0156] The acquisition unit 57 is optional and is a scanner in an exemplary embodiment, which can acquire information optically, for example, a barcode or QR code of the screen of the mobile device 6. In a further exemplary embodiment, the acquisition unit 57 is configured to read, for example, an NFC tag fastened to or inserted into the corresponding mail 140. The acquisition unit 57 can additionally or alternatively be capable of acquiring and processing sound signals, i.e., for example, by means of voice recognition.
[0157] The input unit / user interface 58 is optional and is configured to communicate with the courier / delivery person and / or the user 111. For example, this may include an output unit for displaying (e.g. via a screen or via a compartment-specific light display (e.g. for showing the corresponding occupied / unoccupied status) or sound output information and / or a unit for obtaining information and / or data from a person (e.g. a keyboard or a touch-sensitive screen with an on-screen keyboard or a voice recognition module).
[0158] Figure 6 A schematic diagram of an exemplary embodiment of an apparatus 6 according to the second aspect of the invention is shown. The apparatus 6 can be, for example, a portable scanning device of a courier / delivery person (so-called handheld scanner), i.e. a device configured to optically acquire consignment or delivery data, in particular in the form of a 2D or 3D barcode. When the apparatus 6 represents the device 110 of the user 111, the apparatus can be, in particular, a smartphone, i.e. a mobile phone, in particular, having the capability to autonomously implement more complex programs, so-called apps.
[0159] The device 6 comprises a processor 60 , a program memory 61 , a working memory 62 , a user data memory 63 , one or more communication interfaces 64 , an optional acquisition unit 65 for acquiring consignment or delivery data, and an optional user interface 66 .
[0160] The processor 60 executes, for example, a program according to the second aspect of the invention stored as an application program or as firmware in a program memory 61. The working memory 62 is used in particular for storing temporary data during the execution of this program.
[0161] The user data memory 63 is used to store data required when processing a program, such as one or more keys, access information, indicators and passwords.
[0162] The communication interface(s) 64 include one or more interfaces for enabling the device to communicate with the system 100 and / or the device 7. The interface may be based on IP, for example, but is used as a physical layer based on the portability of the wireless transmission technology of the device 6, which is based on cellular mobile wireless communication (such as GSM, E-GSM, UMTS, LTE, 5G) or WLAN (Wireless Local Area Network). The communication interface(s) 64 may optionally also include an interface for communicating with the storage compartment facility 120, for example based on optical transmission, Bluetooth or NFC. Here, a transmission technology with a relatively small working range, for example less than 100m or 10m or 5m, may be sufficient to make it difficult for a third party to eavesdrop on the transmission, and may even be desirable if necessary.
[0163] The user interface 66 can be designed as a screen and keyboard or as a touch-sensitive display (touch screen), optionally with an additional sound and / or tactile signaling unit. Figure 5 When the user interface 58 is displayed, the display of the third data via the user interface 66 may not require a separate interface 64 for communicating with the storage compartment facility 120. For example, an acquisition unit 65 (e.g. in the form of an optical scanning unit) for acquiring consignment or delivery data is only available when the device is a courier / delivery person's device, but is particularly unavailable when the device is a smartphone 110 of a recipient 111 of the consignment.
[0164] Figure 7 is a schematic diagram of an exemplary embodiment of the apparatus 7 according to the third aspect of the present invention. The apparatus 7 may, for example, represent the entire system 100 or individual units of the system 100, in particular the storage facility management server 101 and the user data management server 102.
[0165] The device 7 comprises a processor 70, a program memory 71, a working memory 72, an optional user data memory 73 and one or more communication interfaces 74. The processor executes, for example, a program according to the third aspect of the invention stored, for example as firmware, in the program memory 71. The working memory 72 is used in particular to store temporary data during the execution of this program.
[0166] The user data memory 73 is used to store the data required when processing the program. Here, the data can be, for example, the keys obtained and to be transmitted and other information, such as indicators and access information encrypted with keys respectively, but also user identification codes, user contact data, such as e-mail addresses and telephone numbers, storage facility identification codes and consignment data. However, the keys obtained and to be transmitted can also be stored only temporarily in the working memory 72, for example, and deleted again immediately after transmission. The exemplary device 7 that only forwards data does not necessarily need a user data memory 73.
[0167] The communication interface(s) 74 may include at least one interface for communicating with the system 1, other units of the system 100 and / or with the device 110. For example, such communication may be based on the Internet Protocol (IP). For example, at least one of the communication interfaces (multiple) 74 may be implemented as a local area network (LAN) interface for this purpose.
[0168] For example, in Figures 5 to 7 In the embodiment of the present invention, the processor can be a control unit, a microprocessor, a microcontroller (such as a microcontroller), a digital signal processor (DSP), an application specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Figures 5 to 7 In an embodiment of the present invention, the program memory and / or the user data memory may be, for example, a persistent memory, such as a read-only memory (ROM) memory. For example, the program memory may be fixedly connected to the corresponding processor, but alternatively may also be connected to the corresponding processor in a detachable manner, for example as a memory card, a floppy disk or an optical data storage medium (such as a CD or a DVD). Figures 5 to 7 The working memory of the exemplary embodiment of is used, for example, for storing temporary results during the processing of program instructions, which is, for example, a volatile memory, such as a random access memory (RAM) memory.
[0169] Figure 8 A schematic diagram showing an exemplary data transmission 8 between devices implementing an exemplary embodiment of a method according to respective aspects of the present invention is shown.
[0170] The mobile device 810 , for example, executes the method according to the second aspect of the present invention. The mobile device 810 , for example, represents the smart phone 110 and / or the device 6 of the system 1 .
[0171] The server 820, for example, executes the method according to the third aspect of the present invention. The server 820, for example, represents the system 100 of the system 1 and / or the device 7.
[0172] The storage compartment facility 830, for example, performs the method according to the first aspect of the invention. The storage compartment facility 830, for example, represents the storage compartment facility 120 and / or the device 5 of the system 1.
[0173] After the mobile device 810 generates the key S, the key is transmitted to the server 820 in step 801. The server 820 forwards the key S to the storage compartment facility 830 in step 802. In an exemplary embodiment, this occurs when the request 802a of the storage compartment facility 830 is answered, for example, the storage compartment facility 830 sends a request about the key S associated with the user identification code B to the server 820. This request 802a can be triggered by an event 803a, for example, the event is that the consignment of the recipient with the user identification code B is stored in the storage compartment of the storage compartment facility. In other embodiments or in other cases, the request 802a and / or the event 803a can be omitted, and for example, before the consignment of the consignee with the user identification code B is stored in the storage compartment of the storage compartment facility 830 or whether the consignment is stored, the server 820 provides the key S, for example, together with the user identification code B to the storage compartment facility 830 in step 802.
[0174] For example, if at a later time, e.g. Figure 8 The event 803b in the storage facility 830 marks the storage of the mailed item, which can trigger the steps of generating access information Z, encrypting the access information Z, associating the indicator I and outputting 804 the first data D1 (see Figure 2 The first data D1 here at least comprises an indicator I and access information Z encrypted with a key S (in Figure 8 After obtaining the first data D1, the server 820 may output / transmit 805 the second data D2 to the mobile device 810. Here, the second data D2 also includes at least C(Z; S) and the indicator I.
[0175] The mobile device 810 can then decrypt C(Z;S) (and thus obtain the access information Z) and generate the password K based on at least the access information Z in connection with the event 806, for example in response to the event 806 (see Figure 3Steps 330, 340). In this embodiment, the access information is exemplarily also generated based on the time value T. Event 806 can be, for example, a user input or a confirmation by the mobile device 810 that it is in the vicinity of the storage facility 830. Subsequently, the mobile device 810 performs a transmission 807 of the third data D3 to the storage facility 830 or provides the third data D3, so that the user can enter the third data on the storage facility 830. Here, the third data D3 includes at least a password K(Z,T) generated based on at least the access information Z and the exemplary time value T and an indicator I. After obtaining the third data D3, the storage facility 830 can check whether the third data D3 is authorized for access (see Figure 2 Steps 260, 270, 280, 281 and possible additional steps, which have been described, for example, with Figure 1 described in detail above).
[0176] For all exemplary data transmissions 8, it is applicable here that the transmissions represented by arrows (e.g. 804, but also 801, 802a, 802, 805 or 807) either represent a transmission in one unit, for example in a communication protocol packet, or represent a transmission in multiple units, for example also separated units, for example in packets of one or more corresponding communication protocols. For example, the corresponding transmission can also take place in encrypted form, that is, in particular, for example, in a manner that goes beyond encryption with a key S. In addition, corresponding processing steps are also possible, such as entropy coding or encoding, for example, by means of forward error correction (FEC) coding. This can be, for example, encryption and / or processing according to the encryption and / or processing commonly used for the corresponding communication protocol (e.g. Bluetooth, WLAN, 4G or 5G). However, it is also possible to perform uncommon and / or additional encryption and / or processing on the corresponding transmission.
[0177] Fig. 9 A schematic diagram showing an exemplary allocation 9 of indicators according to an exemplary embodiment of the method according to all aspects of the present invention is shown. Fig. 9 In particular, it shows Figure 1 The alternative scheme of selecting the indicator and associating the indicator described in the embodiment of FIG. Here, the storage compartment number is simply selected as the indicator. However, the following Fig. 9 The described embodiment should also be understood in particular separately from the other features of the above-described embodiments, i.e. in particular not only relating to the storage compartments of a storage compartment facility, but also to any number of objects whose state may change (such as occurs in the storage compartments as an example here by depositing mail), and which should be associated or not associated with indicators depending on their state.
[0178] Exemplary allocation 9 shows a selection set 900 , a first allocation table 910 , and a second allocation table 920 .
[0179] The second allocation table 920 is divided into two halves, wherein the upper half in rows 921 to 926 exemplarily shows the allocation relationship between the elements of the second set and the respective access information, and the lower half in rows 927 , 928 shows the allocation relationship between the functions and the respective access information.
[0180] In the present embodiment, it is assumed that there is a storage compartment facility with 6 storage compartments. Each storage compartment is assigned to the corresponding element of the second set respectively. There are mails in some storage compartments. This is shown in rows 921, 923, 924, 925 as an example. There are no mails in the storage compartments of rows 922 and 926. As can be seen from rows 921 to 926, only when there is at least one mail in the corresponding storage compartment, access information is distributed to the elements of the second set. Therefore, in particular, corresponding access information is not distributed to elements 2 and 6 of the second set.
[0181] Each element of the storage compartments of the second set that are assigned to the storage compartment facilities, in which the mail is respectively contained, is assigned to the elements of the first set, especially to the elements 1, 3, 4 and 5 in rows 921, 923, 924 and 925. Here, the first set exemplarily includes elements 0-9, i.e. 10 elements in total, and therefore more than the elements of the second set. The element 2 of the first set is assigned to the element 4 of the second set, the element 3 of the first set is assigned to the element 3 of the second set, the element 5 of the first set is assigned to the element 1 of the second set, and the element 7 of the first set is assigned to the element 5 of the second set. Therefore, the indicator represented by one of the elements 2, 3, 5 or 7 of the first set is uniquely assigned to the elements of the second set, the storage compartments of the storage compartment facilities and the access information. For example, the storage compartment facilities can therefore determine the access information FB6CC2F37721D based on the indicator with a value of 7. Based on the indicator with a value of 1, the storage compartment facilities can, for example, confirm that the indicator is not assigned, and therefore the access request containing the indicator is unreliable.
[0182] In the present embodiment, it is assumed that two user groups with functions, i.e. special roles, have been defined as being allowed to access the storage compartment facilities. One of the user groups is a courier (see 927), and the other user group is a technician (see 928). Here, only the access that can be realized is stored for these user groups respectively. However, in other embodiments, other information such as how large a range can be realized for access can also be stored. The user group with the function of technician is assigned to the element 0 of the first set, for example, and the user group with the function of courier is assigned to the element 6 of the first set, for example. Therefore, the storage compartment facilities can determine access information 708CEA053ECA based on the indicator with a value of 6, and confirm that the request with the indicator not only relates to the access to take out the mail from the storage compartment, but also, for example, relates to the access to the entire storage compartment facilities and / or to the courier can deposit the corresponding mail into a plurality of storage compartments.
[0183] Since the first set includes more elements than the second set and additional functions are included, the first set, for example, always has some elements (even if there are changes) that are not allocated. Here, illustratively, elements 1, 4, 8, and 9 of the first set are not allocated. Exemplarily, if the mailing is now stored in the storage compartment assigned to element 2 of the second set (see 922), the storage compartment facility, for example, generates the corresponding access information and allocates an element of the first set to element 2 of the second set. For example, it is possible to select which element of the first set to be allocated based on selection set 900. For example, selection set 900 is used to avoid searching for empty elements of the first set when empty elements of the first set are needed. Exemplarily, element 1 of selection set 900 pointed to by start pointer 901 can be selected and allocated to element 2 of the second set. Subsequently, for example, the start pointer is made to point to position 4 of the selection set. If the allocation relationship with the elements of the first set is now released, such as the allocation relationship with element 3, the element is included in selection set 910. In particular, exemplary, the end pointer 902 is raised by one position so that it points to position 7. Then, element 3 can be listed in the selection set at this position. If such a first-in, first-out (FIFO) principle is adopted, the element of the first set that has not been used for the longest time is always automatically selected as the next one. Initially, when all elements of the first set are in the selection set, for example, the Fisher-Yates (shuffle) algorithm can be adopted to the selection set, so that the elements of the first set are used or distributed in a pseudo-random order.
[0184] The allocation relations shown in tables 900, 910 and 920 are only set to the description of possible allocation relations. In different embodiments, these allocation relations can be represented in completely different and different ways, for example, they are present in different data structures and / or in different memories, and in particular, such tables do not necessarily have to be physically present in memories (but they can be). The order of operations described within the scope of this embodiment can also be different. In addition, in some embodiments, only some parts of the exemplary allocation 9 can be present. Therefore, for example, it is not mandatory to have a selection set 900 and to sort the selection set according to which principle or to access the selection set according to which principle. For example, it is not necessary to have a user group with a predetermined function as shown in rows 927 and 928. Finally, the indicator need not be a value from the first set, but can also be a value composed only by the storage grid facility and derived from different input data.
[0185] The exemplary embodiments / embodiments of the present invention described in this specification should also be understood to be disclosed in all combinations with each other. In particular, the description of the features included in the embodiment - as long as it is not explicitly stated in opposition - should not be understood here as the feature being necessary or important for the function of the embodiment. The order of the method steps listed in the present specification and in each flowchart is not mandatory, and alternative orders of these method steps are also conceivable. These method steps can be implemented in different ways and methods, so it is conceivable to implement these method steps in software (through program instructions), hardware or a combination of the two. Terms such as "including", "having", "including", "containing" and the like used in the patent claims do not exclude other elements or steps. The expression "at least partially" falls into both the case of "partially" and the case of "completely". The expression "and / or" should be understood as follows, that is, both alternative solutions and combination solutions should be disclosed, that is, "A and / or B" means "(A) or (B) or (A and B)". Multiple numbers of units, personnel, etc. in the context of this specification mean multiple units, personnel, etc. The use of the indefinite article does not exclude a plurality. A single means may perform the functions of several units or means mentioned in the patent claims. The reference signs given in the patent claims should not be seen as limitations to the means and steps used.
Claims
1. A method implemented by a storage compartment facility or a system including a storage compartment facility, the method comprising: - Get the key; - generate access information; - storing the access information; - encrypting the access information using the key; - associating an indicator with said access information; - storing said indicator in association with access information; - outputting first data, wherein the first data at least comprises the indicator and access information encrypted with the key; - obtaining or acquiring third data from a device having a key for decrypting the encrypted access information, wherein the third data comprises the password and the indicator; - determining stored access information based at least on the indicator contained in said third data; - confirming, at least based on the determined access information, whether the password authorizes access to the storage facility or one or more storage compartments of the storage facility, wherein a necessary condition for confirming that the password authorizes access to the storage facility or one or more storage compartments of the storage facility is to confirm that the password was generated using a one-way function based on at least a part of the determined access information and at least a part of a time value, which time value corresponds to or has a predefined relationship with a current time value of the storage facility; and - granting access to the locker facility or to one or more lockers of the locker facility, wherein granting access is conditional upon confirmation that the password authorizes access to the locker facility or to one or more lockers of the locker facility. 2 . The method according to claim 1 , wherein the first data is output to a device or a system, which is configured to transmit the data to a device having a key for decrypting the encrypted access information.
3. The method according to claim 1, wherein the password authorizes access only to the storage compartments of the storage compartment facility in which there are consignments respectively associated with the same user identification code, wherein the method further comprises one or more of the following method steps: - determining a storage compartment associated with the indicator contained in the third data; - determining the user identification code based on information about the mail items located in the determined storage compartment; - determining one or more further storage compartments in which the consignments associated with the determined user identification code are respectively located.
4. The method of claim 3, wherein the user identification code is a user identification code of a recipient of the consignment.
5. The method according to claim 1, further comprising: - obtaining distribution relationship information, based on which the key can be distributed to a user group with a predetermined role.
6. A method according to claim 5, wherein the access information is generated so as to allow the user group with the predetermined function to access the storage facility independently of the mailed items, and wherein the indicator is associated with the access information at least in the following manner, so that the access information is uniquely assigned to the user group with the predetermined function and so that the indicator is associated with the user group with the predetermined function.
7. A method according to claim 6, wherein a further necessary condition for confirming that the password authorizes access to the locker facility is to confirm that the indicator contained in the third data is associated with a user group with a predetermined function.
8. A method according to claim 1, wherein a password that has been confirmed to authorize access to the storage facility or one or more storage compartments of the storage facility does not reauthorize access or at least does not reauthorize access during a predetermined time interval after the confirmation.
9. A method implemented by a mobile device, the method comprising: - generating or obtaining at least one key; - transmitting the key to a device or system configured to transmit the key to a storage compartment facility; - obtaining second data, wherein said second data comprises at least an indicator and access information encrypted with said key, said indicator forming the basis for the storage compartment facility to determine the access information; - decrypting the access information encrypted with the key; - generating a password based at least on the access information, wherein the password is generated using a one-way function, wherein at least a part of the access information and at least a part of the time value are used as input data of the one-way function; as well as - transmitting third data to the storage compartment facility or providing the storage compartment facility with third data in order to gain access to the storage compartment facility or one or more storage compartments of the storage compartment facility, wherein the third data comprises at least the password and the indicator.
10. The method according to claim 9, wherein the third data are transmitted to the storage compartment facility or provided to the storage compartment facility by means of one or more of the following options a) to d): a) by means of a radio link; b) by means of an optical pattern representing the third data, the optical pattern is displayed on a screen of the mobile device for acquisition by an acquisition unit of the storage compartment facility; c) by means of displaying the third data on the screen of the mobile device for visual acquisition by the person, who then inputs the third data on an input unit of the storage compartment facility; or d) By means of sound transmission. The method according to claim 10 , wherein the radio connection is a Bluetooth connection or an NFC connection.
12. The method of claim 10, wherein the input unit of the storage compartment facility is a keyboard or a touch-sensitive screen.
13. The method according to claim 10, wherein the sound transmission is achieved by having a device or a person read out the third data and the storage compartment facility acquires the third data by means of voice recognition.
14. A method according to any one of the preceding claims, wherein the indicator contained in the third data is represented by a first group of bits, wherein the password contained in the third data is represented by a second group of bits, and wherein the first group of bits and the second group of bits are mixed in the third data according to a predetermined rule.
15. A method implemented by a device or system, the method comprising: - obtaining a key from a mobile device, wherein the key is a public key of an asymmetric key pair generated by the mobile device; - transmitting said key to a storage compartment facility; - obtaining first data from the storage facility, wherein the first data comprises at least an indicator and access information encrypted with the key, the indicator forming the basis for the storage facility to determine the access information; as well as - outputting second data to the mobile device, wherein the second data comprises at least the indicator and the access information encrypted with the key.
16. The method according to claim 9 or 15, further comprising one or more of the following method steps: - obtaining or generating distribution relationship information, based on which the key can be distributed to a user group with a predetermined function; - transmitting the allocation relationship information to the storage grid facility or to a device or system, wherein the device or the system is configured to transmit the allocation relationship information to the storage grid facility.
17. The method according to claim 16, further comprising: - obtaining or generating association information before the key and / or the allocation relationship information is transmitted to the storage compartment facility, wherein the association information associates the key with the storage compartment facility to which the key and / or the allocation relationship information is transmitted or should be transmitted.
18. The method according to claim 1, wherein the storage compartment facility generates the access information during a respective depositing process of at least one mail item in a storage compartment of the storage compartment facility.
19. The method of claim 18, wherein the storage compartment facility generates the access information in response to the at least one consignment being about to be, being, or having been deposited into a storage compartment of the storage compartment facility, respectively.
20. A method according to one of claims 1 to 13 or 15, wherein the indicator (I) is associated or associated with the access information at least in the following manner, namely, so that the access information is uniquely assigned to a storage compartment of the storage compartment facility, and the indicator is associated or associated with the storage compartment of the storage compartment facility.
21. The method according to claim 20, wherein the storage compartment is a storage compartment in which consignments have been stored.
22. A method according to one of claims 1 to 13 or 15, wherein the key is assigned to a user identification code, and wherein when encrypting the access information, the storage compartment facility uses the key assigned to the user identification code only if the storage compartment facility has been informed when the mail items were stored in the storage compartments of the storage compartment facility or the storage compartment facility has confirmed that the mail items are associated with the user identification code.
23. The method of claim 22, wherein the consignment is associated with the user identification code in such a manner that the user identification code is a user identification code of a recipient of the consignment.
24. A method according to one of claims 1 to 13 or 15, wherein the indicator is an element from a first set, wherein the first set has more elements than a second set, wherein each element of the second set is uniquely assigned to a respective storage compartment of the storage compartment facility, and wherein each element of the second set that has a consignment in its uniquely assigned storage compartment is uniquely assigned to an element of the first set.
25. A method according to claim 22, wherein the indicator is an element from a first set, wherein the first set has more elements than a second set, wherein each element of the second set is uniquely assigned to a respective storage compartment of the storage compartment facility, and wherein each element of the second set that has a mail item in its uniquely assigned storage compartment is uniquely assigned to an element of the first set, and wherein the user identification code is from a third set, the third set including more elements than the first set.
26. The method according to any one of claims 1 to 13, wherein the key is a public key of an asymmetric key pair.
27. A device or a system consisting of at least two devices, wherein the device or the system is configured to implement and / or control the method according to one of claims 1 to 13 or 15, or the device or the system includes corresponding devices for implementing and / or controlling the steps of the method according to one of claims 1 to 13 or 15.
28. A computer program, comprising program instructions, which, when the computer program is run on a processor, cause the processor to implement and / or control the method according to one of claims 1 to 13 or 15.
Citation Information
Patent Citations
Locker system access control
CN108986261A
Location tracking for locking device
US20160035163A1
Deposit box unit, logistical system and method for operating the deposit box unit
WO2009018995A1