Authority management method of hotel off-line access control, hotel off-line electronic door lock and hotel off-line access control system
By setting independent version control tracks for different roles in the hotel offline electronic door lock, the problem of replacing the child card has been solved, the permission continuity and security of the permissions are achieved, and the user experience and management efficiency are improved.
Patent Information
- Application Number
- CN202510840831.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-23
AI Technical Summary
In the offline environment of the hotel, the problem of accidentally interrupting the main card permissions when reissue the associated child card will affect the user experience and security of the guests.
In the hotel offline electronic door lock, multiple identifiers are stored for the same permission group, including the primary substitution number, the first type secondary substitution number and the second type secondary substitution number. Select the corresponding secondary substitution number according to the role type of the key card for version verification, and only the corresponding secondary substitution number is updated when the key card is lost or reissue, to ensure that the main card permissions are not affected.
It realizes the reliability of missing cards in an offline environment, ensures the continuity and stability of associated permissions, and improves user experience and system security.
Smart Images

Figure CN120356279A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of hotel offline electronic door locks, and more specifically, to an access control permission management method, a hotel offline electronic door lock, and a hotel offline access control system in a pure offline environment for hotels. Background Art
[0002] In modern hotel management, in order to facilitate family or group guests, it is often necessary to configure access control permissions for the main guest room (main room) and associated guest rooms for relatives and friends, so that the guest room card of the main room (main room card) can not only open its own door, but also open the doors of the guest rooms for relatives and friends. In an offline door lock system that needs to ensure security and cannot rely on the network, a replacement number mechanism (such as a serial number or a timestamp) is usually used to manage the validity of key cards, that is, newly issued cards have a higher replacement number, which can invalidate cards with old replacement numbers.
[0003] However, when this conventional replacement mechanism is applied to the above-mentioned associated scenario of the main room - guest rooms for relatives and friends, serious technical conflicts will occur. The existing method usually sets the same replacement number for the main room card and the guest room cards for relatives and friends, and the door lock only recognizes the latest replacement number. This results in that when a guest room card for relatives and friends is lost and reissued, the new card will use a higher replacement number to update the record of the door lock of the guest room for relatives and friends. Thereafter, the originally valid main room card, because it still holds the old replacement number, will be rejected by the door lock as "too low version" when trying to open the door of the guest room for relatives and friends, and its key associated permission will be unexpectedly interrupted, bringing great inconvenience and trouble to the guests.
[0004] Therefore, how to provide a method and a hotel offline electronic door lock that can not only ensure the continuity of the associated permissions after reissuing a card, but also reliably invalidate a truly lost card in an offline environment without affecting the permissions of other valid cards has become a technical problem that urgently needs to be solved in this field. Summary of the Invention
[0005] The purpose of the present invention is to provide an access control permission management method, a hotel offline electronic door lock, and a hotel offline access control system for hotels, aiming to solve the technical problem that the main card permission is unexpectedly interrupted due to reissuing an associated sub - card in the background art.
[0006] The first aspect of the present invention provides an access control permission management method for hotel offline access control, including the following steps: In the memory of a hotel offline electronic door lock serving as a permission verification end, store at least three identifiers for the same permission group, and the identifiers include: a main replacement number for identifying the permission group, a first - type secondary replacement number for verifying the version of the first - type key cards in the permission group, and a second - type secondary replacement number for verifying the version of the second - type key cards in the permission group; When the hotel offline electronic door lock receives an unlocking request from a key card to be verified, it reads the primary alternative number and secondary alternative number contained in the key card to be verified; Determine whether the primary alternative number of the key card to be verified matches the primary alternative number stored in the hotel offline electronic door lock; When they match, according to the preset role type of the key card to be verified, select the corresponding secondary alternative number for version verification: If the key card to be verified is a first-class key card, compare its secondary alternative number with the first-class secondary alternative number stored in the hotel offline electronic door lock. When the secondary alternative number of the key card to be verified is greater than or equal to the first-class secondary alternative number, authorize unlocking, and update only the first-class secondary alternative number of the hotel offline electronic door lock with the secondary alternative number of the key card to be verified; If the key card to be verified is a second-class key card, compare its secondary alternative number with the second-class secondary alternative number stored in the hotel offline electronic door lock. When the secondary alternative number of the key card to be verified is greater than or equal to the second-class secondary alternative number, authorize unlocking, and update only the second-class secondary alternative number of the hotel offline electronic door lock with the secondary alternative number of the key card to be verified.
[0007] Optionally, the step of selecting the corresponding secondary alternative number for version verification according to the preset role type of the key card to be verified includes: reading a role code stored in the key card to be verified, and determining whether it is a first-class key card or a second-class key card according to the role code.
[0008] Optionally, the primary alternative number, the first-class secondary alternative number, and the second-class secondary alternative number are all timestamps generated based on time.
[0009] Optionally, both the first-class secondary alternative number and the second-class secondary alternative number are increasing sequence numbers.
[0010] Optionally, when the hotel offline electronic door lock detects that the primary alternative number of the key card to be verified is greater than the primary alternative number stored in itself, before comparing the secondary alternative numbers for unlocking authorization, reset the first-class secondary alternative number and the second-class secondary alternative number stored in the hotel offline electronic door lock to a preset initial value.
[0011] Optionally, the method further includes a check-out step: when receiving a check-out instruction, update the first-class secondary alternative number and the second-class secondary alternative number stored in the hotel offline electronic door lock to a preset capping value that is greater than the maximum value that the secondary alternative number may reach during normal use.
[0012] Optionally, the first-class key card is the main room key card that has the unlocking permission for multiple door locks within a permission group, and the second-class key card is the relative's room key card that has the unlocking permission for only a single door lock.
[0013] Optionally, the method further includes a door lock initialization security verification step: when the main alternative number of the key card to be verified is newer than the main alternative number stored in the electronic door lock, before performing subsequent steps, first read the signature data stored in the key card and generated by the card-issuing system using the private key; and use the public key pre-stored in the electronic door lock to verify the signature data, and only after the verification passes, recognize the key card as a legal card and perform subsequent alternative number update and version verification.
[0014] A second aspect of the present invention provides a hotel offline electronic door lock, including a processor and a memory, and stored in the memory are: A main alternative number for identifying a permission group; A first type of secondary alternative number for verifying the version of the first type of key card within the permission group; And a second type of secondary alternative number for verifying the version of the second type of key card within the permission group; The processor is configured to execute the method according to any one of the first aspects of the present invention.
[0015] Optionally, the memory includes a non-volatile storage unit for storing the main alternative number, the first type of secondary alternative number, and the second type of secondary alternative number.
[0016] Optionally, the memory also pre-stores a card-issuing public key for verifying the legality of the key card; the processor is further configured to, when initializing the door lock, first perform a signature verification step, which uses the card-issuing public key to verify the signature data attached to the key card to be verified, and only after the signature verification passes, perform subsequent alternative number update and version verification.
[0017] A third aspect of the present invention provides a hotel offline access control system, including the hotel offline electronic door lock according to the second aspect of the present invention, and a first type of key card and a second type of key card associated with the permission group of the hotel offline electronic door lock; wherein, both the first type of key card and the second type of key card store: A main alternative number identical to the main alternative number stored in the hotel offline electronic door lock; A secondary alternative number for version verification; and A role code for distinguishing the card type.
[0018] According to the technical content disclosed in the present invention, the following beneficial effects are achieved: The present invention brings significant beneficial effects by establishing mutually independent version control tracks for cards of different roles at the door lock end. This solution fundamentally realizes the "asymmetric invalidation" mechanism, that is, the action of reissuing a sub-card (relative's room card) only invalidates the old sub-card and will never affect any access rights of the main card (main room card) to the door lock, perfectly ensuring the continuity and stability of the associated permissions and greatly enhancing the usage experience of the guests. At the same time, this mechanism can still reliably invalidate any lost card, ensuring the security of the system, and the entire process is completed in a pure offline environment, with a simple door lock structure and high reliability of the system operation.
[0019] Other features and advantages of the present invention will become clear from the following detailed description of exemplary embodiments of the invention with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The drawings incorporated in and constituting a part of this specification illustrate embodiments of the invention and, together with the description, serve to explain the principles of the invention.
[0021] Figure 1 It is a structural block diagram of the access control system of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0022] Now, various exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. It should be noted that: Unless otherwise specifically stated, the relative arrangements of components and steps, numerical expressions and values set forth in these embodiments do not limit the scope of the present invention.
[0023] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way a limitation on the present invention and its application or use.
[0024] Technologies, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods, and devices should be regarded as part of the specification.
[0025] In all the examples shown and discussed herein, any specific values should be construed as merely exemplary and not as limitations. Therefore, other examples of the exemplary embodiments may have different values.
[0026] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it need not be further discussed in subsequent drawings.
[0027] The general concept of the present invention is to provide a hotel offline access control system that manages key cards with binding relationships and different permission levels. The core innovation lies in the internal data structure and verification logic of the hotel offline electronic door lock. A hotel offline electronic door lock no longer records a single, global version number, but maintains multiple independent version number record tracks associated with card roles for the same "permission group". In this way, when a card of a certain role in the permission group needs to be updated, it will not affect the valid cards of other roles.
[0028] First Embodiment: Alternate Number Scheme Based on Timestamp Please refer to Figure 1 , in this embodiment, the hotel offline access control system 10 includes a hotel offline electronic door lock 100, and a first type of key card 200 and a second type of key card 300 that can interact with the door lock. In this embodiment, the first type of key card 200 is the "main room card", which has the permission to open multiple associated doors (such as the main room and the relative's room). The second type of key card 300 is the "relative's room card", which only has the permission to open its own door.
[0029] The hotel offline electronic door lock 100 internally includes a processor 101 and a memory 102. The memory includes a non-volatile storage unit for storing alternate numbers, such as Flash Memory, to ensure that data is not lost after power-off. In this memory, three key alternate numbers are stored for a permission group. In this embodiment, all three key alternate numbers are timestamps, where: Main Alternate Number A: Used to identify the unique ID of this permission group.
[0030] First Type of Secondary Alternate Number B_master: Specifically used to record and verify the latest version of the associated first type of key card 200.
[0031] Second Type of Secondary Alternate Number B_sub: Specifically used to record and verify the latest version of the second type of key card 300 corresponding to this door lock.
[0032] Both the first type of key card 200 and the second type of key card 300 internally store key information, including: A main alternate number that is the same as the main alternate number A in the door lock.
[0033] A secondary alternate number representing its own version.
[0034] A role code used to identify the card type. In the embodiment, the role code can be a specific data bit or byte. For example, the code "01" represents the first type of key card, and the code "02" represents the second type of key card. The processor of the door lock distinguishes and executes different verification logics by reading this role code.
[0035] Next, through a series of typical scenarios, in a way that combines narrative and data evolution, the working process of the present invention will be elaborated in detail.
[0036] Scenario 1: The guest's first check-in and door lock initialization This scenario describes how the system efficiently and reliably configures permissions and completes the progressive, role-based first initialization of the door lock for a brand-new associated check-in request.
[0037] Initial state of the door lock: A newly installed or checked-out hotel offline electronic door lock 100, whose memory record is the default initial value: (Master: 0, B_master: 0, B_sub: 0).
[0038] Front desk card issuance: To ensure the simplicity and robustness of the logic, the card issuer follows a key rule: All associated cards first issued for the same permission group are forced to be given the same initial secondary substitution number.
[0039] Generate a current timestamp as the permission group ID for this check-in, for example, A_new = 10000.
[0040] Generate an initial version number, for example, B_initial = 50.
[0041] Generate a main room card (instance of the first type of key card 200): Write the information {Master: 10000, Secondary: 50, Role: "01"}.
[0042] Generate a relative's room card (instance of the second type of key card 300): Write the information {Master: 10000, Secondary: 50, Role: "02"}.
[0043] Door lock initialization process: Case 1: The main room card swipes the relative's room door lock first Operation: The guest swipes the main room card (10000, 50, "01") to the relative's room door lock 100 for the first time.
[0044] Processing flow: The door lock detects that the card's main substitution number (10000) > the main substitution number in the lock (0), triggering initialization. The door lock updates its own main substitution number with 10000. According to the card role "01", the processor only updates the first type of secondary substitution number B_master with the card's secondary substitution number 50. The second type of secondary substitution number B_sub remains 0.
[0045] Data state change: The record in the lock changes from (0, 0, 0) to (Master: 10000, B_master: 50, B_sub: 0).
[0046] Subsequent: Subsequently, when the guest swipes the lock with the relative's room card (10000, 50, "02"), the verification will pass because 50 > 0, and the second type of secondary substitution number B_sub will be updated to 50. The final record becomes (main: 10000, B_master: 50, B_sub: 50).
[0047] Situation 2: The relative's room card swipes the relative's room door lock first Operation: The guest swipes the relative's room door lock 100 for the first time with the relative's room card (10000, 50, "02").
[0048] Processing flow: The door lock also triggers initialization. According to the role "02", the processor only updates the second type of secondary substitution number B_sub with the card secondary substitution number 50. The first type of secondary substitution number B_master remains 0.
[0049] Data status change: The record in the lock changes from (0, 0, 0) to (main: 10000, B_master: 0, B_sub: 50).
[0050] Subsequent: Subsequently, when the guest swipes the lock with the main room card (10000, 50, "01"), the verification will pass because 50 > 0, and the first type of secondary substitution number B_master will be updated to 50. The final record also becomes (main: 10000, B_master: 50, B_sub: 50).
[0051] Result: This progressive logic that strictly initializes according to the role ensures that the system can reach a unique and correct stable working state regardless of the card swiping order, reflecting the robustness of the solution.
[0052] Scenario 2: Permission verification during daily use After initialization is completed, the record in the lock stabilizes at (main: 10000, B_master: 50, B_sub: 50).
[0053] The main room card opens the main room door: When the main room card swipes the main room door lock, the door lock verifies it as the "own room card", identifies the role "01", and compares its "first type of secondary substitution number". 50 ≥ 50, and the verification passes.
[0054] The main room card opens the relative's room door: When the main room card swipes the relative's room door lock, the door lock identifies the role "01", and compares its secondary substitution number 50 with the "first type of secondary substitution number" (B_master, with a value of 50) stored in the lock. 50 ≥ 50, and the verification passes.
[0055] The relative's room card opens the relative's room door: When the relative's room card swipes the relative's room door lock, the door lock identifies the role "02", and compares its secondary substitution number 50 with the "second type of secondary substitution number" (B_sub, with a value of 50) stored in the lock. 50 ≥ 50, and the verification passes.
[0056] A relative's room card attempts to open the main room door: When the processor of the main room door lock verifies, it checks whether this card (or its role code "02") has been granted the permission to open this door lock. Since it was not granted during card issuance, the unlocking is refused.
[0057] Scenario 3: Key card loss and replacement This scenario fully demonstrates the "asymmetric invalidation" mechanism of the present invention.
[0058] Loss and replacement of a relative's room card (the second type of key card): Current status: The record of the relative's room door lock 100 is (main: 10000, B_master: 50, B_sub: 50).
[0059] Replacement operation: The front desk makes a new relative's room card with the information {main: 10000, secondary: 90, role: "02"}.
[0060] Card swiping and status change: When the new card (10000, 90, "02") is swiped on the relative's room door lock, the lock recognizes its role as "02" and finds that its version number 90 is higher than B_sub (50) recorded in the lock. The lock authorizes the door opening and only updates the secondary replacement number of the second type.
[0061] Data change: The record in the lock changes from (10000, 50, 50) to (10000, 50, 90).
[0062] Result: The lost old relative's room card (secondary: 50) is invalidated. The verification track B_master of the main room card (secondary: 50) is not affected, and its permission to open the relative's room door is perfectly retained.
[0063] Loss and replacement of the main room card (the first type of key card): Current status: The record of the relative's room door lock is (main: 10000, B_master: 50, B_sub: 90).
[0064] Replacement operation: The front desk makes a new main room card with the information {main: 10000, secondary: 80, role: "01"}.
[0065] Card swiping and status change: When the new main room card is swiped on the relative's room door lock, the lock recognizes its role as "01" and finds that its version number 80 is higher than B_master (50) recorded in the lock. After successful verification, the first type of secondary replacement number is updated to 80.
[0066] Data change: The record of the relative's room door lock becomes (10000, 80, 90).
[0067] Result: The lost old main room card (times: 50) is invalidated. The verification track B_sub of the valid relative room card (times: 90) is not affected and the permissions are not disturbed.
[0068] Scenario Four: Other management operations Adding a companion card: If a companion card needs to be added to a relative room, the card issuer only needs to copy all the information of the currently valid relative room card, that is, write the information of {main: 10000, times: 90, role: "02"} of this card into a new card. Since the secondary substitution number is the same, it can be used simultaneously with the original card. Adding a companion card can occur at the time of check-in or at any time after check-in.
[0069] Guest check-out and re-initialization of the door lock: After the guest checks out, to ensure safety, a staff member (such as a cleaning staff) needs to use a special work card (check-out card) with the "initialization" or "check-out" permission to perform the check-out operation on the physical door lock. This card will send an instruction to the door lock to update the internal main substitution number to a brand new current timestamp (for example, Z = 20000), and the time node of this current timestamp is the time node recorded on the physical door lock rather than the check-out card of the staff member, and clear the two secondary substitution number tracks.
[0070] Data change: The record in the lock changes from (10000, 80, 90) to (main: 20000, B_master: 0, B_sub: 0).
[0071] Result: All cards based on the old main substitution number 10000 become invalid, and the door lock returns to a safe and clean initial state to serve the next new guest.
[0072] Second Embodiment: Substitution Number Scheme Based on Sequence Number To adapt to the electronic door lock hardware with limited storage space and sensitive power consumption, the present invention also provides a preferred implementation. In this embodiment, the secondary substitution number does not use a timestamp, but uses a sequence number that occupies less memory (such as an integer starting from 1), and the management of the door lock state and the re-initialization logic after the guest checks out are optimized.
[0073] The main difference between this embodiment and the first embodiment is as follows: Nature of the secondary substitution number: Both the first type of secondary substitution number B_master and the second type of secondary substitution number B_sub are simple sequence numbers.
[0074] Zero-clearing logic of the secondary substitution number: Each time a new guest checks in, the door lock will automatically clear the two secondary substitution number tracks. The trigger condition for clearing is that the door lock detects that the main substitution number A_new of the key card to be verified is greater than the old main substitution number A_old stored in the lock. This marks the start of a new check-in cycle.
[0075] Next, its working process will be described in combination with specific scenarios.
[0076] Scenario 1: New guest check-in (based on sequence number) Previous state of the door lock: The previous guest has checked out, and the records in the lock may be (main: 10000, B_master: 999, B_sub: 999) (for the cause of this state, see the "Check-out" scenario below).
[0077] Front desk card issuance: Check in a new guest.
[0078] The card issuance system generates a new main replacement number greater than 10000, for example, A_new = 10001 (the main replacement number can still be generated based on a timestamp or other increment algorithms).
[0079] Assign an initial sequence number to the newly issued main room card and relative room card, for example, starting from 1.
[0080] New main room card (Type 1): Write the information {main: 10001, sub: 1, role: "01"}.
[0081] New relative room card (Type 2): Write the information {main: 10001, sub: 1, role: "02"}.
[0082] Card swiping and initialization: The guest swipes the new main room card (10001, 1, "01") at the lock for the first time.
[0083] The door lock processor detects that the card main replacement number (10001) > the main replacement number in the lock (10000), and identifies this as a brand-new check-in request.
[0084] The processor executes "guest change initialization": Update the main replacement number in the lock to 10001.
[0085] Automatically clear or reset both the Type 1 secondary replacement number B_master and the Type 2 secondary replacement number B_sub to their initial values (for example, 0).
[0086] Subsequently, execute the normal verification logic: Since the card secondary replacement number (1) > the B_master in the lock (0), the verification passes, authorize unlocking, and update B_master with 1.
[0087] Data status change: The records in the lock change from (10000, 999, 999) to (main: 10001, B_master: 1, B_sub: 0). Subsequently, when the relative room card is swiped, the records will finally become (main: 10001, B_master: 1, B_sub: 1).
[0088] Scenario 2: Loss and Reissue of Relatives and Friends' Room Cards (Based on Sequence Number) Current Status: The records in the lock are (main: 10001, B_master: 1, B_sub: 1).
[0089] Reissue Operation: The front desk makes a new relatives and friends' room card with the sequence number incremented. The information is {main: 10001, secondary: 2, role: "02"}.
[0090] Card Swiping and Status Change: When the new card (10001, 2, "02") is swiped on the lock, the door lock recognizes the role "02". Since the first type of secondary substitution number B_sub (2) of the card > B_sub (1) in the lock, it authorizes opening the door and only updates the second type of secondary substitution number at the lock end.
[0091] Data Change: The records in the lock change from (10001, 1, 1) to (10001, 1, 2).
[0092] Result: The second type of secondary substitution number with a value of "1" for the lost old relatives and friends' room card is invalidated. The verification track B_master of the first type of secondary substitution number with a value of "1" for the main room card is not affected and the permission is retained. Since the number of card reissues and losses is limited within one occupancy period, the sequence number will not accumulate too large.
[0093] Scenario 3: Guest Check-out and Re-initialization of Door Locks This method aims to immediately and reliably invalidate all guest cards without changing the main substitution number.
[0094] Current Status: Assume that the guest has reissued cards multiple times during their stay, and the records in the lock are (main: 10001, B_master: 5, B_sub: 8).
[0095] Check-out Operation: The staff (such as the cleaning staff) swipes a work card with special "check-out" permission on the lock. The function of this card is to issue an instruction to the door lock: to cover the values of the two secondary substitution number tracks with a preset capping value (e.g., 999) that is much larger than the normal usage range.
[0096] Card Swiping and Status Change: After the check-out card is swiped on the lock, the door lock executes the instruction.
[0097] Data Change: The records in the lock change from (10001, 5, 8) to (main: 10001, B_master: 999, B_sub: 999).
[0098] Result: At this time, when any previously valid guest card (such as the main card sub-number is 5 and the relative card sub-number is 8) tries to unlock the door again, it will be rejected because its version number is much smaller than the 999 recorded in the lock. This method cleverly utilizes the version comparison mechanism to place the door lock in a safe intermediate state of "checked out but not yet changed guests", effectively preventing the re-entry of checked-out guests. This state will be maintained until the next guest comes with a new card having a higher main replacement number for initialization.
[0099] In this embodiment, by using sequence numbers and optimized check-out / initialization logic, not only the requirements for the door lock hardware resources are reduced, but also through two actions of "automatically clearing when changing guests" and "writing the capping value when checking out", a safe and efficient closed-loop management process is formed.
[0100] Furthermore, in another preferred embodiment, the main replacement number itself can also be a sequence number or a numerical string generated by a specific rule, without necessarily being associated with a time stamp, as long as it can be guaranteed to increase with each new check-in.
[0101] Furthermore, in some embodiments, in order to further enhance the security of the system, especially to prevent any unauthorized illegal cards from deceptively occupying the door lock during the initialization phase, the present invention can also include an "issuing card signature" mechanism based on asymmetric encryption. As a preferred enhancement to the above-described implementation, this mechanism exists independently and does not affect the integrity of the foregoing solution.
[0102] The hotel back-end card issuing system holds a globally unique card issuing private key. All hotel offline electronic door locks 100: At the time of factory, the card issuing public key paired with this card issuing private key is pre-written.
[0103] In the initial card issuing step of Scenario 1, when the card issuing machine writes information such as {main replacement number, secondary replacement number, role code} to the key card, it will additionally perform one step: digitally sign these core information (or their hash values) with the card issuing private key to generate a string of signature data, and write this signature data into the card together.
[0104] In the door lock initialization process of Scenario 1, after the door lock processor detects that the main replacement number of the card is greater than the initial value recorded inside it, it will first perform a mandatory signature verification step: It will use the card issuing public key stored inside itself to verify whether the "signature data" attached to the card is valid for the core information on the card.
[0105] Only when the signature verification is successful and it is confirmed that the card is issued by an official authorized channel, will the door lock continue to perform the subsequent initialization operations. If the signature verification fails, the door lock will directly reject the card.
[0106] This "signature-verification" mechanism establishes a solid trust root for the entire offline access control system. It completely eliminates any attack path where a forged card maliciously initializes a "masterless" door lock, ensuring that only legitimate guests can be the "first opener" of a room's access rights, thereby enhancing the security of the system.
[0107] In summary, the present invention innovatively sets a main alternative number for identifying permission groups, as well as first and second types of secondary alternative numbers for recording key card versions of different roles, respectively, within a hotel offline electronic door lock. Combining with the role code stored in the key card, a complete, closed-loop, and reliable asymmetric permission management and invalidation mechanism is established. The detailed elaboration of the above scenarios specifically shows how the present invention precisely invalidates a specified lost card while ensuring the continuity of associated permissions, thus jointly solving the industry problems of security and convenience.
[0108] It should be understood that the above are only preferred embodiments of the present invention and are not used to limit the protection scope of the present invention. For those skilled in the art, without departing from the core concept of the present invention, several modifications and improvements can be made, such as expanding the two types of roles into more roles, or adjusting the specific coding method of the alternative number, etc. These equivalent replacements and improvements should all be included in the protection scope of the present invention.
Claims
1. A method for managing permissions of hotel offline access control, characterized in that, Including the following steps: In the memory of a hotel offline electronic door lock serving as an authorization verification terminal, store at least three identifiers for the same authorization group. The identifiers include: a primary alternative number for identifying the authorization group, a first type of secondary alternative number for verifying the first type of key card version within the authorization group, and a second type of secondary alternative number for verifying the second type of key card version within the authorization group; When the hotel offline electronic door lock receives an unlocking request from a key card to be verified, read the primary alternative number and secondary alternative number contained in the key card to be verified; Judge whether the primary alternative number of the key card to be verified matches the primary alternative number stored in the hotel offline electronic door lock; When they match, according to the preset role type of the key card to be verified, select the corresponding secondary alternative number for version verification: If the key card to be verified is a first type of key card, compare its secondary alternative number with the first type of secondary alternative number stored in the hotel offline electronic door lock. When the secondary alternative number of the key card to be verified is greater than or equal to the first type of secondary alternative number, authorize unlocking and update only the first type of secondary alternative number of the hotel offline electronic door lock with the secondary alternative number of the key card to be verified; If the key card to be verified is a second type of key card, compare its secondary alternative number with the second type of secondary alternative number stored in the hotel offline electronic door lock. When the secondary alternative number of the key card to be verified is greater than or equal to the second type of secondary alternative number, authorize unlocking and update only the second type of secondary alternative number of the hotel offline electronic door lock with the secondary alternative number of the key card to be verified.
2. The method according to claim 1, wherein The step of selecting the corresponding secondary alternative number for version verification according to the preset role type of the key card to be verified includes: reading a role code stored in the key card to be verified and determining whether it is a first type of key card or a second type of key card according to the role code.
3. The method according to claim 1, characterized in that The primary alternative number, the first type of secondary alternative number, and the second type of secondary alternative number are all timestamps generated based on time.
4. The method according to claim 1, wherein Both the first type of secondary alternative number and the second type of secondary alternative number are incremental sequence numbers.
5. The method according to claim 4, wherein When the hotel offline electronic door lock detects that the primary alternative number of the key card to be verified is greater than the primary alternative number it stores itself, before comparing the secondary alternative numbers for unlocking authorization, reset the first type of secondary alternative number and the second type of secondary alternative number stored in the hotel offline electronic door lock to a preset initial value.
6. The method according to claim 1 or 4, characterized in that The method further includes a check-out step: when receiving a check-out instruction, update the first type of secondary alternative number and the second type of secondary alternative number stored in the hotel offline electronic door lock to a preset ceiling value that is greater than the maximum value that the secondary alternative number may reach during normal use.
7. The method according to claim 1, wherein The first type of key card is the main room key card that has the unlocking permission for multiple door locks within the authorization group, and the second type of key card is the guest room key card that has the unlocking permission only for a single door lock.
8. The method according to claim 1, characterized in that The method further includes a door lock initialization security verification step: when the main alternative number of the key card to be verified is newer than the main alternative number stored in the electronic door lock, before performing subsequent steps, first read the signature data stored in the key card and generated by the card-issuing system using a private key; and use the public key pre-stored in the electronic door lock to verify the signature data. Only after the verification passes, the key card is recognized as a legal card and subsequent alternative number updates and version verifications are performed.
9. A hotel offline electronic door lock, comprising a processor and a memory, characterized in that The memory stores: A main alternative number for identifying a permission group; A first secondary alternative number for verifying the version of the first type of key card within the permission group; And a second secondary alternative number for verifying the version of the second type of key card within the permission group; The processor is configured to execute the method according to any one of claims 1 to 8.
10. A hotel offline access control system, characterized in that, Including the hotel offline electronic door lock according to claim 9, and a first type of key card and a second type of key card associated with the permission group of the hotel offline electronic door lock; Wherein, both the first type of key card and the second type of key card store: A main alternative number identical to the main alternative number stored in the hotel offline electronic door lock; A secondary alternative number for version verification; and A role code for distinguishing the card type.
Citation Information
Patent Citations
Hotel management method for obtaining and returning room card through self-service
CN106600477A
Hotel door lock management method based on access network recognition
CN107767512A
User Authentication Using Behavior Patterns
US20240029490A1