Locking device element for use in an access method
By incorporating a real-time clock and a microcontroller into the locking device element, accurate verification and tamper-proofing of access time are achieved, solving the access control security and tamper-proofing problems of existing locking device elements and ensuring the security and reliability of access authorization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- DORMAKABA SCHWEIZ AG
- Filing Date
- 2024-08-28
- Publication Date
- 2026-04-17
AI Technical Summary
In the prior art, locking device components are difficult to achieve high security and tamper-proof access authorization time management in access control, especially in the combination of electronic keys and electromechanical lock cylinders, where time information is easily tampered with, resulting in insecurity in access control.
The locking device uses a combination of a first time element and a second time element. A real-time clock (RTC) and a microcontroller are respectively installed in the key handle and the key bar. The first time signal is output by the real-time clock and compared with the second time signal in the microcontroller to achieve accurate verification and tamper-proofing of the access time.
It achieves precise verification and anti-tampering of access time, ensuring the security and reliability of access authorization, preventing unauthorized access, and improving the anti-tampering capability of locking device components.
Smart Images

Figure CN121889840A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a locking device element, particularly configured as a key, accessory, or lock cylinder. The locking device element is configured for use in an access method, in which access to a physical area is permitted or denied. Furthermore, this invention illustrates an access method using the locking device element. Background Technology
[0002] EP 1 889 924 B1 shows a previously known key for an electromechanical lock cylinder. The previously known key includes a key handle with electronic devices disposed therebetween two housings. Summary of the Invention
[0003] The object of this invention is to provide a locking device element and an associated access system that allows or denies particularly secure access to a physical area.
[0004] The objective is achieved through the features of the independent claim. The subject matter of the dependent claims is the preferred embodiment of the invention. Similarly, the objective is achieved through the method according to claim 17. Here, the method can be performed by means of a locking device element according to the invention, especially a locking device element according to any one of claims 1 to 16. Furthermore, the locking device element is configured to perform the method according to the invention, especially the method according to claim 16.
[0005] This invention discloses a locking device element, which is particularly configured as a key, electromechanical component, or lock cylinder. The locking device element is configured for use in an access method. In this access method, access to a physical area is permitted or denied. "Permit or deny" specifically means that access can be permitted and denied simultaneously, without both states occurring at the same time. Access is permitted if authorization exists. Conversely, access is denied if no authorization exists. To verify the existence of authorization, at least one access condition is verified, particularly in an access decision step. Preferably, multiple access conditions are verified in multiple access decision steps. If all access decision steps are determined to be affirmative, access is authorized. In particular, if at least one access condition is denied during the access method of verifying at least one access condition, preferably multiple access conditions, then the entire access is denied. The denial of an access condition can particularly mean that the access decision in the access decision step of the access method is determined to be negative.
[0006] It is possible that at least one access decision step is performed by a locking device element.
[0007] "Accessing a physical area" specifically describes an access method that makes a physical area accessible to a person by means of an access device element therein, thereby allowing the person to enter the physical area and / or at least open the physical area. Thus, the physical area can also be, for example, the interior space of a safe or cabinet, which the person does not enter but accesses by opening the corresponding door. Similarly, accessing a physical area can include, for example, opening a door leading to a room or building, or opening a cabinet, revolving door, or anti-rotation device.
[0008] In particular, the locking device element is used to perform at least one access decision step for allowing or denying access to a physical area. It is conceivable that the locking device element makes the access decision completely or only partially. Alternatively or additionally, the locking device element is capable of providing data for at least one access decision step.
[0009] In particular, the locking device element is designed to be carried by the user or placed outside the physical area where access should be permitted or denied. Therefore, attempts to tamper with the locking device element are possible. This invention counteracts tampering attempts.
[0010] As will be described in detail later, the locking device element is preferably configured as a key, which includes a key handle that is inserted into the lock cylinder. Here, an electronic device is contained within the key. This electronic device enables the execution of an access decision step and / or the forwarding of data for the access decision step to the lock cylinder. In the presence of authorized access, rotation of the lock cylinder's actuator is possible. Therefore, the locking device element is configured as an "electromechanical" key because, in addition to the electronic device within the key, the lock cylinder is also mechanically operated—that is, by turning the key.
[0011] Alternatively, the locking device may be configured as an "electronic" key. The electronic device, using the key, can perform access decision steps and / or send data for these steps to the lock, lock cylinder, reader, or accessory, thereby enabling the release of the corresponding access.
[0012] In designs where the locking device element is used as an accessory, particularly an electromechanical accessory, or as a lock cylinder, particularly an electromechanical lock cylinder, the electronic device is located within the accessory or lock cylinder. The electronic device can preferably perform at least one access decision step. The mechanical mechanism within the accessory or lock cylinder can allow or deny access in a manner controlled by the electronic device; this can be done, for example, by releasing or blocking the door handle of the accessory, by coupling or disengaging it, or by unlocking or locking the lock cylinder body within the lock cylinder, by coupling or disengaging the actuating element.
[0013] The locking device element includes a first timing element. Therefore, the first timing element is located within the locking device element, i.e., within a key. The first timing element outputs a first timing signal. The first timing signal displays a first time. The first timing signal is output continuously or at regular intervals by the first timing element. In a simple design, the first timing element outputs an arbitrary signal with a defined frequency. This signal or frequency has a preset clock period, which is counted in another element of the locking device to produce a final count value. This frequency can preferably be allocated before counting. Thus, the timing signal can "display the first time" solely through oscillations at a defined frequency.
[0014] However, in a preferred embodiment, the first time element serves as a time signal, thereby outputting a count value or a value based on the count value (e.g., clock time) as a "first time". Therefore, counting clock cycles, and preferably prior frequency allocation, is performed in the first time element. Particularly preferably, the count value is interpreted in conjunction with a starting value in the first time element or in another element of the locking device element, such that the actual clock time is ultimately derived. Thus, this clock time corresponds to the first time.
[0015] The locking device element also includes an electronic processing device. This electronic processing device is configured to execute inspection steps based on information from a first-time element, particularly based on the first-time element. Particularly preferably, the processing device is located within the controller, particularly a microcontroller, of the locking device element. As will also be shown in detail, the processing device is also capable of executing multiple inspection steps within the inspection process.
[0016] Furthermore, the locking device elements, particularly the electronic processing device, are configured to perform at least one additional step based on the output, i.e., the result, of the inspection step. If multiple inspection steps are performed, this additional step can be related to the outputs of the multiple inspection steps. Alternatively, it is also possible to perform different additional steps corresponding to the multiple inspection steps.
[0017] The actual time, such as clock time or a specific workday, can be decisive in whether or not access to a physical area should be permitted or denied to a particular person or group. For example, a specific person might be allowed entry into a building during the daytime on a weekday, while another group might be released for the same reason on weekends or at night. Therefore, access authorization may exist only for at least one specific access authorization time window. Access authorization time windows are particularly repetitive, comprising specific time periods between the effective start and end of an access authorization, such as several days or hours within a week. To design the functionality as tamper-proof as possible, the locking device element includes at least a first time element such that the verification of access authorization is not related to, or at least not solely related to, time provided in other ways. By providing the first time element within the locking device element, time can be determined within the locking device element.
[0018] Preferably, at least one access decision step performed by the locking device element is executed by means of a first time signal, particularly a first (clock) time obtained from the time signal. Alternatively or additionally, the data sent by the locking device element to cause another device to perform the access decision step may include the first time signal, particularly the first time. For example, the access decision step may include comparing an access authorization time window with the first time. If the first time is within the access authorization time window, the access decision step ends with a positive result. If the first time is outside the access authorization time window, the access decision step ends with a negative result.
[0019] Alternatively or concurrently, it may be proposed to compare the first time with the effective start and / or effective end of access authorization. If the first time is before the effective start of access authorization, the access decision step ends with a negative result. If the first time is after the effective start of access authorization, the access decision step ends with a positive result. If the first time is before the effective end of access authorization, the corresponding access decision step ends with a positive result. If the first time is after the effective end of access authorization, the corresponding access decision step ends with a negative result. Therefore, it is conceivable to utilize multiple different access decision steps executed by means of the first time.
[0020] Preferably, the processing device includes an internal second timing element. The internal second timing element preferably has an internal RC element.
[0021] The internal second timing element is preferably configured to generate a second timing signal within the processing device. Therefore, it is particularly proposed that the second timing signal be generated in the processing device, preferably in a microcontroller.
[0022] The second time signal displays a second time. The second time signal is generated continuously or at regular intervals by a second time element.
[0023] In particular, the second time element generates an arbitrary signal with a defined frequency. This signal or frequency has a preset clock period, which is counted in the second time element, i.e., in the processing device, to generate a final count value. Preferably, the frequency can be allocated before counting. Particularly preferably, the count value is interpreted in conjunction with a starting value in the second time element or in another area of the processing device to ultimately derive the actual clock time. Therefore, the second time can correspond to a second clock time.
[0024] Preferably, the first timing element is configured and disposed separately from the processing device; that is, preferably outside the microcontroller. Preferably, a circuit board is present in the locking device element, and the first timing element is disposed separately from the microcontroller of the processing device on the circuit board. Preferably, the first timing element is electrically connected to the processing device to transmit a first timing signal, especially a first time.
[0025] Particularly preferably, the first timing element is a real-time clock (RTC) with an oscillating crystal. Particularly preferably, the real-time clock also includes a frequency distributor and a frequency counter in addition to the oscillating crystal.
[0026] To minimize the risk of tampering with the time information, first and second time elements are preferably used within the locking device element. Comparing the times of the two time elements allows verification that one of them has been tampered with. For this purpose, it is particularly preferred that the first and second time elements are located in different locations and / or designed differently within the locking device element. The first time element is preferably located outside the processing device, i.e., particularly outside the microcontroller. The second time element is preferably located inside the processing device, i.e., particularly inside the microcontroller. Furthermore, the first time element is preferably a real-time clock, which is significantly more difficult to tamper with in terms of software than the second time element integrated into the processing device. On the other hand, the second time element located inside the processing device is significantly more difficult to physically tamper with than the first time element located outside the processing device. Tampering is particularly difficult because the processing device not only includes the second time element but also performs the verification step.
[0027] Preferably, at least one access decision step performed by the locking device element is executed by a processing device. Thus, the same controller used to obtain the second time is also used to perform the access decision step, particularly the time-related access decision step. This improves tamper resistance. Here, instead of the first time, the second time can be used additionally or alternatively. Therefore, the locking device element can verify whether the second time is within the access authorization time window, and / or compare the second time with the effective start and / or effective end of access authorization.
[0028] Preferably, the processing device is configured to compare a first time with a second time as a verification step. Particularly preferably, the processing device is configured to compare a first time signal, or a value based thereon, with a second time signal, or a value based thereon. The verification step can be performed periodically. Alternatively or additionally, the verification step can be performed within an access method.
[0029] The statement "comparing a first time with a second time" describes a comparison where it is determined whether the two times deviate from each other. For example, a first clock time is calculated based on the first time and a second clock time is calculated based on the second time, where the deviation between these two clock times can be determined. However, this comparison can also be performed without tracing back to the actual clock times. For example, the two times can be counts of clock cycles, where comparing these two times while considering the starting time and clock frequency is feasible.
[0030] As described below in different contexts, locking device elements can be configured to deny access to a physical area. This denial is here prompted by the locking device element, preferably executed by it itself.
[0031] The locking device element is, in principle, capable of causing access to be denied. "Causing" includes the locking device element itself denying access. If access is denied, the locking device element can abort the access method or end the access method with a negative result, or send a message about the denial to another element, causing the access method to end or abort with a negative result. If the locking device element is configured, for example, as an electromechanical key, then the actuator of the lock cylinder cannot rotate when access is denied.
[0032] However, it is also feasible to perform the access method steps, particularly verifying at least one access condition, in another component (e.g., a server, cloud, connected smartphone, lock cylinder, etc.). In this case, the locking device component can induce access denial by not transmitting the corresponding data, particularly the first and / or second time, to the other component; the other component requires the data, particularly the first and / or second time, for the access decision step. Therefore, the locking device component does not forcibly deny access itself.
[0033] Preferably, the statement "the locking device element is configured to cause, preferably, itself to refuse access to the physical area" applies to all, i.e., future and, if necessary, current access methods, at least until cancellation occurs. That is, the locking device element is refused use in all access methods—at least until cancellation. Alternatively, as long as the verification step is performed during the access method, the statement "the locking device element is configured to cause, preferably, itself to refuse access to the physical area" is limited to the current access method. In summary, the statement "the locking device element is configured to cause refusal of access to the physical area" means that the locking device element is refused use in all access methods that allow access to the physical area, or that current access to the physical area is refused.
[0034] Preferably, the locking device components are configured to, based on the output of the inspection step, prompt, preferably, itself to refuse access to the physical area.
[0035] In particular, the verification steps that trigger rejection include checking whether the difference between the first time and the second time is greater than the stored first time difference. Therefore, if the deviation between the first time and the second time is too large, the locking device element prompts the execution of additional steps, specifically denying access to the physical area. Alternatively or additionally, as an additional step, the locking device element can output a warning. The verification steps can be performed periodically, regardless of whether the locking device element is currently in the access method. Alternatively or additionally, the verification steps can be performed separately within the access method.
[0036] In particular, if the difference between the first time and the second time is greater than the stored first time difference, access can be disallowed for the access method by means of the locking device element—at least until cancellation. If it is determined in the periodic check that the first time difference has been exceeded, access can be disallowed for all subsequent access methods—at least until cancellation. If it is determined in the access method that the first time difference has been exceeded, access can no longer be allowed in the current and all other access methods—at least until cancellation. The state of the locking device element is preferably set to "tampered with". The locking device element is thus "locked".
[0037] If the locking device element corresponds to a key, then by means of that key, the access method can no longer be definitively terminated to allow access to different physical areas, at least until cancellation occurs. In the case of an electromechanical key as the locking device element, it is no longer possible to execute an access method with a definitive output at different lock cylinders.
[0038] Particularly preferred is to temporarily deny access. Specifically, the locking device element is configured to, preferably, cancel the denial itself upon receiving a positive approval message. This positive approval message can be sent to the locking device element from a backend system.
[0039] In the "tampered" state, the locking device element is specifically able to send an unlock request to the backend system. If the backend generates an affirmative approval message, meaning the locking device element receives the approval message, the locking device element can cancel the "tampered" state. Thus, the locking device element can participate in access methods that end with access granted.
[0040] In the backend system, for example, it can be prompted by corresponding algorithms and / or user input that: despite a large time difference between the first and second times, the locking of the device element should still be released or current access should be allowed.
[0041] The back-end system preferably includes software, and more particularly, hardware on which the software runs. The back-end system can run on a single computing unit or be distributed across multiple computing units, and is at least partially cloud-based. Correspondingly, the back-end system preferably includes at least one server and / or building control unit.
[0042] The data connection between the back-end system and the locking device element can be made in any manner, especially at least partially wirelessly. Particularly preferred is that the data connection between the back-end system and the locking device element is made via an electronic "device." This device should be understood, for example, as a portable computing unit, such as a smartphone, tablet, or laptop.
[0043] Preferably, the device is capable of establishing a connection with the backend system via the Internet and / or via a telecommunications network. Preferably, the device is capable of communicating with the locking device components via wireless near-field communication, such as NFC, Bluetooth Low Energy, or Ultra Wide Band.
[0044] Furthermore, it is preferably proposed that the locking device elements are configured to perform at least one of the two "additional steps" described below, based on the output of the verification step. In particular, the verification step verifies whether the difference between the first time and the second time is less than a stored second time difference. The second time difference is preferably equal to or less than the first time difference. In particular, the verification step verifies that the difference between the first time and the second time is not very large, i.e., less than the stored second time difference. If this is the case, it can be assumed that the time, i.e., particularly the first or second time element, has not been tampered with.
[0045] (i) As a possible additional step, the locking device element is configured to perform the access decision step. In particular, this relates to an access decision step that compares clock time, especially a first or second time, with an access authorization time window and / or with the effective start or end of an access authorization. The access authorization time window, for example, defines daytime hours from 8:00 to 18:00 and / or, for example, specific weekdays on which access should be permitted. The effective start of an access authorization is described, for example, as a start date from which access authorization is in principle granted. The effective end of an access authorization is described, for example, as an end date from which access authorization typically expires, for example, access authorization can be granted for each day, month, or week and expires at a specific time.
[0046] (ii) Alternatively or as a further step, it may be possible to correct the second time based on the first time. This in particular means adjusting the second time element according to the first time. Here, it is particularly considered that the first time element, especially the first time element configured as a real-time clock, operates more accurately than the second time element. Therefore, if it is assumed that there has been no tampering, the second time element or the second time is corrected based on the first time element or the first time.
[0047] Furthermore, it is preferably proposed that during the verification step, the processing device receives and evaluates the error message from the first time element. Therefore, the verification step can be based not only on the first time but also on the error message. The information of the first time element can thus correspond to the error message. Based on the error message, the locking device element can—as a further step—cause, preferably itself, to perform at least a temporary denial of access to the physical area. The first time element, especially one configured as a real-time clock, can, for example, detect that the crystal is no longer oscillating or is no longer functionally oscillating. Subsequently, the first time element can generate a corresponding error message and transmit the error message to the processing device. Based on this error message, tampering or malfunction of the first time element can be inferred as a verification step, which can then cause a denial of access to the physical area. In particular, the status is changed to "tampered with". Furthermore, the error message can also notify of other tampering with the first time element, which can then lead to a denial of access. This corresponds to another step.
[0048] Furthermore, it is preferably proposed that the back-end system described above sends an update time signal to the locking device element. The update time signal can display the update time, especially the update clock time. The update time signal can correspond to the update (clock) time. As already described, the data connection between the back-end system and the locking device element is preferably made via the described device.
[0049] Particularly preferably, the locking device element is configured to encryptly receive an update time signal from the backend system and decrypt it using encrypted information. This encryption information, particularly the key, is specifically individualized for the locking device element. That is, only this locking device element can decrypt the update time signal. Particularly preferably, the backend system knows the public key of the locking device element and stores the corresponding private key of the locking device element. This individualized information enables encryption of communication between the backend system and the locking device element, particularly the transmission of the update time signal.
[0050] The update time signal can be temporarily stored in the described device. Correspondingly, the backend system first transmits the update time signal to the device. There, the update time signal is temporarily stored and forwarded to the locking device element. For this purpose, it is preferably proposed that the locking device element is configured to receive the storage duration, with which the update time signal is temporarily stored between the backend system and the locking device element, particularly on the device. The storage duration is determined by the device.
[0051] Furthermore, the locking device element is preferably configured to compare the update time corrected by the temporary duration with the first time and / or the second time in the processing device as a verification step.
[0052] Furthermore, the locking device element is preferably configured to, as an additional step, adjust the first time element and / or the second time element based on the update time corrected for the temporary duration, when the difference between the update time corrected for the temporary duration and the first time and / or the second time is smaller than a value determined among the stored limit values. That is, the first time element and / or the second time element are adjusted based on the update time; however, this is only done when the difference between the update time corrected for the temporary duration and the first and / or second times is not too large. This ensures that the update time, especially in the device, has not been tampered with, because in the event of tampering, an excessively large deviation would result.
[0053] However, if the updated time, corrected for the temporary duration, differs too much from the time of the first and / or second clock, i.e., exceeds the stored limit, the updated time is not used to adjust the first or second time element. More precisely, in this case, the updated time is discarded.
[0054] It is possible that if the storage time is too long, the update time will be discarded. To do this, the storage time can be compared with the storage limit value stored in the locking device element.
[0055] Regardless of whether temporary storage is considered, it is preferably proposed that the locking device elements are configured to adjust the first and / or second time elements by means of the received update time. This adjustment can also be referred to as an update. The adjustment is specifically described herein as adjusting the first and / or second time elements according to the update time. Preferably, an update time corrected for the temporary storage duration can be used here.
[0056] Preferably, the verification step includes: determining the time interval since the last adjustment, i.e., since the last update, using a first time and / or a second time. The time interval is compared with at least one stored update limit value. From this verification step, the following additional steps can be derived:
[0057] (i) The locking device element is configured to output a warning as an additional step to perform an adjustment when the time interval exceeds a stored first update limit value. The warning may be output, for example, via an acoustic and / or optical signal output from the locking device element. Additionally or alternatively, the output warning may also describe transmitting a corresponding signal to the described device and / or backend system.
[0058] (ii) Preferably, the locking device element is configured to, as an additional step, induce, preferably self-execute, at least temporarily deny access to the physical area when the time interval is greater than a stored second update limit value. The denial is particularly temporary: once the first and / or second times have been adjusted by means of the update time, the denial is lifted again.
[0059] Therefore, if the time update is not performed within a certain time period, only a warning can be output. Preferably, access is not denied. However, if the update is not performed for a longer period, i.e., longer than the second update limit, access is preferably denied until the update is performed. This ensures that the first or second time is always accurate, allowing for a more precise and thus more secure determination of the current access authorization.
[0060] As already described, it is preferably proposed that the locking device element be configured as a key. The key preferably includes a particularly rigid key bar for insertion into a lock cylinder. The processing device and the first-time element are preferably located in the key handle of the key.
[0061] Particularly preferably, the key lever includes a transmission device for transmitting energy and / or electronic data to the lock cylinder. The transmission device particularly includes electrical wires as a connection from the processing device to the key lever.
[0062] The transmission can be contact-based. In the area of the key lever, the transmission device specifically constitutes a corresponding conductive contact within the lock cylinder to transmit energy and / or data to the lock cylinder in the manner described.
[0063] Particularly preferably, at least one lock cylinder ID is electronically stored on the key, wherein the key is configured to serve as an access condition check: whether the lock cylinder ID received by the lock cylinder matches the stored lock cylinder ID. This corresponds to the access decision step.
[0064] Particularly preferably, the key is configured to encryptly receive the stored lock cylinder ID from the backend system and decrypt it using encryption information individualized to the key. In other words, only this one key can decrypt the received lock cylinder ID.
[0065] Preferably, the invention includes a component. The component comprises at least a locking device element, particularly a locking device element configured as a key, and the previously described device. As described, the device is particularly a smartphone, tablet, or laptop. The device is preferably configured to receive electronic data from a back-end system and send it to the locking device element. The data can particularly be an update time and / or a lock cylinder ID. In particular, the data is encrypted such that only the locking device element, particularly only the key, can decrypt the data. Preferably, only a single locking device element, particularly only a single key, i.e., the correct recipient of the data, can decrypt the data. The locking device element is preferably configured to induce, particularly to perform, denial or permission. The locking device element, particularly the processing device, is particularly configured to perform at least one verification step and at least one additional step. This can involve one of the previously described verification steps and / or additional steps.
[0066] The invention also includes a method. This can relate to an access method in which access to a physical area is permitted or denied. The previously described designs of the locking device elements and the corresponding dependent claims are advantageously applied to the access method according to the invention.
[0067] The method uses locking device elements, especially the locking device elements previously described.
[0068] Within the scope of the method, the output displays a time signal of the first time, particularly by means of the described first time element.
[0069] Furthermore, in the method, at least one verification step is performed based on a first-time error message or an error message from a first-time element. In particular, this is performed in the electronic processing device of the locking device element.
[0070] In the third step of the method, additional steps are performed based on the output of the inspection method, particularly by a processing device, as described above within the scope of the locking device elements.
[0071] Preferably, in the method, the processing device includes an internal second time element, which preferably has an internal RC element, wherein the second time element generates a second time signal that displays a second time within the processing device.
[0072] Preferably, in the method, the first timing element is configured and arranged separately from the processing device, preferably configured and arranged on a common circuit board, wherein the first timing element transmits a first timing signal to the processing device; in particular, wherein the first timing element is configured as a real-time clock (RTC) with an oscillating crystal.
[0073] Preferably, in the method, as a verification step, the processing device compares a first time with a second time, and in particular compares a first time signal with a second time signal.
[0074] Preferably, in the method, when the difference between the first time and the second time is greater than the stored first time difference, as an additional step, the locking device element, based on the output of the verification step, prompts, preferably, itself to perform at least a temporary denial of access to the physical area. In particular, the locking device element prompts, preferably, itself to cancel the denial after receiving a positive approval message, particularly from the backend system.
[0075] Preferably, in the access method, when the difference between the first time and the second time is less than the stored second time difference, as an additional step, the locking device element performs an access decision step based on the output of the verification step; in particular, the locking device element compares the time, especially the first and / or the second time, with the access authorization time window and / or the effective start and / or the effective end of the access authorization to check the access conditions.
[0076] Preferably, in the method, when the difference between the first time and the second time is less than the stored second time difference, as an additional step, the locking device element corrects the second time based on the output of the verification step based on the first time, and in particular, adjusts the second time element according to the first time.
[0077] Preferably, in the method, the verification step includes receiving and evaluating an error message from a first-time element via a processing device, wherein, as an additional step, the locking device element, based on the error message, prompts, preferably, itself to perform at least a temporary denial of access to the physical area.
[0078] Preferably, in the method, the locking device element receives an update time signal displaying the update time from a back-end system, particularly via wireless near-field communication with the device.
[0079] Preferably, in the method, the locking device element receives the updated time signal encrypted from the back-end system and decrypts it using encrypted information individualized for the locking device element.
[0080] Preferably, in the method, the locking device element: receives a temporary duration, and the update time signal is temporarily stored between the back-end system and the locking device element, particularly on the device, with the temporary duration; as a verification step, the update time corrected by the temporary duration is compared with a first time and / or a second time in the processing device; and as an additional step, when the difference between the update time corrected by the temporary duration and the first time and / or the second time is smaller than a value determined among the stored limit values, the first time element and / or the second time element are adjusted based on the update time corrected by the temporary duration, or when the difference between the update time corrected by the temporary duration and the first and / or second clock time is higher than a value determined among the stored limit values, the update time is discarded.
[0081] Preferably, the method proposes that the locking device elements adjust the first and / or second time by means of the received update time, in particular adjusting the first time element and / or the second time element according to the update time, wherein the verification step includes: obtaining the time interval since the last adjustment by means of the first time and / or the second time and comparing the time interval with at least one stored update limit value.
[0082] Preferably, in the access method, when the time interval is greater than the saved first update limit value, as an additional step, the locking device element outputs a warning to perform an adjustment by means of the update time.
[0083] Preferably, in the access method, when the time interval is greater than the saved second update limit value, as an additional step, the locking device element prompts, preferably itself, to perform at least a temporary denial of access to the physical area, especially until the first and / or second times have been adjusted by means of the update time.
[0084] Preferably, in the access method, the locking device element is configured as a key, wherein the key includes a particularly rigid key bar for insertion into the lock cylinder.
[0085] Preferably, in the access method, the key lever transmits energy and / or electronic data to the lock cylinder.
[0086] Preferably, the access method proposes that at least one lock cylinder ID is electronically stored on the key, wherein, as an access condition, the key verifies whether the lock cylinder ID received by the lock cylinder is consistent with the stored lock cylinder ID; in particular, the key receives the lock cylinder ID to be stored encrypted from the back-end system and decrypts it using encryption information individualized for the key. Attached Figure Description
[0087] The invention will now be described in detail with reference to embodiments. Hereinafter:
[0088] Figure 1 An embodiment of the present invention is shown, comprising a locking device element for performing the method according to the present invention.
[0089] Figure 2 An exploded view of the locking device elements according to the present invention based on the described embodiment is shown, and
[0090] Figure 3 A general schematic diagram of the method according to the invention based on the described embodiment is shown.
[0091] Figure 4 A first embodiment of the method according to the present invention is shown.
[0092] Figure 5 A second embodiment of the method according to the invention is shown, and
[0093] Figure 6 A third embodiment of the method according to the invention is shown, wherein... Figures 4 to 6 The methods can also be combined with each other. Detailed Implementation
[0094] Figure 1 Component 100 is shown. Component 100 includes a locking device element 1, which is configured herein as an electromechanical key. Furthermore, component 100 includes a lock cylinder 101, which can be operated, in particular rotated, by means of the locking device element 1.
[0095] Component 100 also includes a device 103 and a backend system 104, the device being configured as a smartphone, tablet, or laptop. The backend system 104 is, for example, a server.
[0096] The backend system 104 and device 103 are interconnected for data transmission. This data transmission can be at least partially wireless. Furthermore, the locking device element 1 and device 103 are interconnected for data transmission, particularly via wireless near-field communication. Data transmission between the lock cylinder 101 and the locking device element 1 is particularly achieved through direct conductive contact, as will be further described.
[0097] The construction of locking device element 1 is as follows: Figure 1 and belonging to Figure 2 The exploded view shows that, accordingly, the locking device element 1 includes a key handle 2, which is formed by a housing 10. The housing 10 is composed of a first housing component 11 and a second housing component 12. These two housing components 11 and 12 are connected to each other by a frame 30. The frame 30 is composed of a first frame component 31 and a second frame component 32.
[0098] A key bar 50 of the locking device element 1 extends from the first frame member 31. The key bar 50 includes a key bar base 51, which is integrally formed with the first frame member 31.
[0099] An embedded element 54 is inserted into the key shank base 51. At least one electrical wire extends through the embedded element 54 as part of a transmission device for transmitting energy and / or electronic data to the lock cylinder 101. The electrical wire has at least one lock cylinder contact surface 56 at the tip of the key shank 50 as part of the transmission device. When the locking device element 1 is inserted into the lock cylinder 101, conductive contact is made via the lock cylinder contact surface 56 for energy and / or data transmission.
[0100] In addition, the embedded element 54 has at least one circuit board contact surface 57, which is located inside the housing 10.
[0101] especially Figure 2 The electronic device 70 of the locking device element 1 is described. The electronic device 70 includes a circuit board 71. A processing device 72 is provided on the circuit board 71, and the processing device is configured as a microcontroller.
[0102] Electronic device 70 includes a first timing element 76 and a second timing element 77. The first timing element 76 is located on a circuit board 71, but outside the processing device 72, and is preferably configured as a real-time clock. The second timing element 77 is located inside the processing device 72, specifically inside a microcontroller. In this embodiment, the first timing element 76 outputs a first time signal displaying a first time t1. In this embodiment, the second timing element 77 is configured to generate a second time signal displaying a second time t2 within the processing device 72. Therefore, the first time t1 is measured by the first timing element 76. Therefore, the second time t2 is measured by the second timing element 77.
[0103] The first timing element 76 is electrically connected to the processing device 72 to transmit a first timing signal. The first timing element 76 is particularly configured as a real-time clock (RTC) with an oscillating crystal.
[0104] also, Figure 2As shown, the electronic device 70 includes a button 73 on the circuit board 71. The button 73 can be operated by pressing into the first housing component 11. The locking device element 1 can be connected to the device 103, for example, via the button 73.
[0105] In addition, the electronic device 70 includes a socket 74 for charging the energy storage device 85 of the locking device element 1, the socket being, for example, a USB interface.
[0106] Figure 2 It is also shown that the electronic device 70 includes a light-emitting device 75. The light-emitting device 75 can, for example, output warning messages or display other states of the locking device element 1.
[0107] Figure 2 It is also shown that the electronic device 70 includes a wireless communication module 78, by means of which data transmission, in particular, with device 103, is feasible.
[0108] To allow access to the physical space, an electric actuator (not shown), particularly a motor, must be energized in the lock cylinder 101. This enables a locking element (not shown) in the lock cylinder 101 to release the lock between the rotor 105 and the stator 106 of the lock cylinder 101, allowing the rotor 105 to rotate within the stator 106. This, in turn, allows rotation of the drive member 107 of the lock cylinder 101. The corresponding actuator and locking element are disclosed, for example, in EP 4191004 A1. Alternatively, the rotor 105 can always rotate within the stator 106. When access authorization is available, the rotor and drive member 107 are torsionally connected via the actuator, thereby enabling rotation of the drive member 107.
[0109] In order to power the actuator, access authorization must be determined in advance. This involves performing multiple access decision steps. Here, the processing device 72 compares the access authorization time window electronically stored in the processing device 72 with a first and / or second time. If the time used falls within the access authorization time window, the access decision step ends with a positive result; otherwise, it ends with a negative result. The processing device 72 also checks whether the first and / or second time has started after the valid start of the access authorization electronically stored in the processing device 72. If this is the case, the access decision step ends with a positive result; otherwise, it ends with a negative result. The processing device 72 further checks whether the first and / or second time has ended before the valid end of the access authorization electronically stored in the processing device 72. If this is the case, the access decision step ends with a positive result; otherwise, it ends with a negative result.
[0110] In this embodiment, at least one lock cylinder ID can be electronically stored on the locking device element 1. The locking device element 1 is configured to receive the lock cylinder ID to be stored in advance encrypted from the back-end system 104. The locking device element 1 can decrypt the lock cylinder ID using encryption information individualized to the locking device element 1. The locking device element 1 is configured to perform an access condition check: whether the lock cylinder ID received by the lock cylinder 101 matches the stored lock cylinder ID; this also corresponds to the access decision step. If the stored lock cylinder ID matches the received lock cylinder ID, the access decision step ends with an affirmative result; otherwise, it ends with a negative result.
[0111] If all access decision steps that should be performed in the locking device element 1 have been verified with positive results, then the results, for example in the form of an open command, are transmitted to the lock cylinder 101.
[0112] At least one additional access decision step can be performed via lock cylinder 101. For example, the transmitted result is verified as follows: whether the result originates from an authorized locking device element 1, for example, by corresponding decryption. Additionally or alternatively, a key ID can be transmitted to lock cylinder 101, where the lock cylinder verifies as an access decision step whether the key ID is listed in a whitelist or blacklist stored in lock cylinder 101. If all access decision steps end with a positive result, the actuator is powered on and access is granted by the user being able to rotate the actuator 107.
[0113] As an additional access decision step, it is conceivable to perform biometric verification on the user within the device.
[0114] Because the access decision-making process takes a certain amount of time and is performed in the locking device element 1, it operates in a specially tamper-proof manner. The data stored for comparisons during the access decision-making process, such as the access authorization time window, the start of valid access authorization, the end of valid access authorization, and the lock cylinder ID, is encrypted and sent to the locking device element 1 by the backend system 104 via device 103. Device 103 cannot decrypt the data. The data can be correlated; for example, different lock cylinder IDs can be assigned different access authorization time windows.
[0115] Locking device element 1 is configured such that it is connected from the back-end system 104 (see...) Figure 5 The system receives an update time signal, specifically an update time upt, via wireless near-field communication with device 103. In particular, the update time upt is sent from backend system 104 to locking device element 1 via device 103. Here, the update time upt is encrypted so that device 103 cannot decrypt it. Preferably, the update time upt should be decrypted using encryption information individualized for locking device element 1.
[0116] Pressing button 73 can trigger the locking device element 1 to send a request to the backend system 104 via device 103, for example, to receive an update time upt and / or update the comparison data used in the access decision step.
[0117] Because the access decision-making process, which requires a certain amount of time, is performed in the locking device element 1 with the energy storage device 85, time can be measured continuously. Therefore, it is unnecessary to measure time in the lock cylinder 101 and to provide a corresponding energy storage device within the lock cylinder.
[0118] Figure 3 The steps of the access method 200 defined in the invention description are shown schematically, including an inspection step 201 and an additional step 202 based on the output of the inspection step 201. The processing device 72 is configured to execute the inspection step 201 based on a first moment, and the locking device element 1 is configured to execute at least one additional step 202 based on the output of the inspection step 201.
[0119] Here, the time-related access decision steps described can be considered as an example of step 201. Sending information to lock cylinder 101 can be considered as another step.
[0120] Figures 4 to 6 Other examples of inspection step 201 and additional step 202 that can be performed in locking device element 1 are shown.
[0121] In this embodiment, as in Figure 4 As shown in the figure, it is proposed that the processing device 72 is configured to compare the first time t1 with the second time t2 as a verification step 201, in particular to compare the first time signal with the second time signal, for example by comparing the difference |t1 - t2| with the stored time difference dt1.
[0122] Based on the output of verification step 201, preferably when the difference between the first time and the second time is greater than the stored first time difference dt1 or corresponding to the stored first time difference dt1, as an additional step 202, the processing device 72 causes at least a temporary denial of access to the physical area. Here, the state of the locking device element 1 is set to "tampered with".
[0123] The verification step 201 can also include an error message received by the processing device 72 from the first timing element 76, such as because the crystal is no longer oscillating. In this case, the state of the locking device element 1 is also set to "tampered with".
[0124] In the "tampered" state, it is not feasible to use the locking device element 1 for an access method with a positive result. That is, at any lock cylinder 101, it is not possible to achieve the rotatability of the drive member 107 by means of the locking device element 1 in the "tampered" state.
[0125] In the "tampered" state, locking device element 1 sends an unlock request E to backend system 104 via device 103. This corresponds to subsequent step 203. Locking device element 1 is then able to receive an approval message G from backend system 104 in step 204. In order to replace the tampered time with the correct time in step 205 ("reset"), locking device element 1 receives an update time upt in addition to the approval message. With the help of the update time upt, the first time t1 at the first time element 76 and / or the second time t2 at the second time element 77 can be adjusted.
[0126] As already mentioned, the update time upt is encrypted and sent to the locking device element 1 by the backend system 104, preventing the device 103 from tampering with the update time upt. In a first variant, the update time upt is used only when there is a continuous connection between the backend system 104 and the locking device element 1, thereby preventing the update time upt from being temporarily stored in the device 103 for an extended period and becoming inaccurate. For example, the time between sending the unlock request E and receiving the response G+upt can be used as a measure of the connection with the backend system 104. Alternatively or additionally, the device 103 adds a temporary storage duration zt to the approval message, with the update time upt temporarily stored on the device 103 between the backend systems for the temporary storage duration. The first and / or second times t1, t2 are adjusted with the update time upt corrected for the temporary storage duration zt. To prevent tampering, it can be proposed that adjustment is only made if the temporary storage duration zt does not exceed the duration stored in the processing device 72.
[0127] The test 201, which compares the first and second times t1 and t2, is performed as an access decision step at regular time intervals and within the scope of the access method.
[0128] In this embodiment, the locking device element 1 is configured to, as a further step 202, induce, preferably automatically, grant access to the physical area, based on the output of the verification step 201, preferably when the difference between the first time t1 and the second time t2 is less than the stored first time difference dt1, taking into account at least one other access condition; in particular, the locking device element 1 is configured to compare the time, especially the first time and / or the second time, with the access authorization time window and / or the effective start and / or the effective end of the access authorization to check the access condition. This applies when comparing the first and second times t1 and t2 within the access method.
[0129] In this embodiment, the locking device element 1 can be configured to, as another step 202, correct the second time t2 based on the first time t1, especially adjusting the second time element 77 according to the first time t1, based on the output of the verification step 201, preferably when the difference between the first time t1 and the second time t2 is less than the stored first time difference dt1.
[0130] As in Figure 5 As shown, the locking device element 1 is configured to receive a temporary storage duration zt, and an update time upt is temporarily stored on the device 103 between the backend system 104 and the locking device element 1 for the temporary storage duration. As a verification step 201, the update time upt corrected by the temporary storage duration zt is compared with a first time t1 and / or a second time t2 (not shown) in the processing device 72, and as a further step 202, when the difference between the update time upt corrected by the temporary storage duration zt and the first time t1 and / or the second time t2 is less than (i.e., the value is lower than) the stored limit value g, the first time element 76 and / or the second time element 77 are adjusted based on the update time upt corrected by the temporary storage duration zt ("sync"); or, when the difference between the update time upt corrected by the temporary storage duration zt and the first and / or second times t1, t2 is greater than (i.e., the value is higher than) the stored limit value g or corresponding to the limit value g, the update time upt is discarded ("no sync").
[0131] If the first and / or second times t1, t2 are adjusted, the time interval ZS is restarted (ZS=0). The time interval ZS indicates how long ago the first and / or second times t1, t2 were adjusted by the update time upt. If the limit value g is exceeded and the update time upt is discarded, the time interval ZS is not restarted ("no reset ZS"). Alternatively, the time during which the first and / or second times t1, t2 are adjusted according to the update time upt can be stored in the processing device 72.
[0132] exist Figure 6 The diagram illustrates the inspection steps, which ensure that the first and / or second times t1 and t2 are periodically adjusted by updating the time upt. Figure 6 The verification step 201 includes: obtaining the time interval ZS since the last adjustment by means of a first time t1 and / or a second time t2, and comparing the time interval with at least one saved update limit value ZD1, ZD2.
[0133] If the time interval ZS is greater than the saved first update limit value ZD1, then as an additional step 202, a warning ("Warn(warning)") is output to perform the adjustment with the help of the update time upt.
[0134] If the time interval ZS is greater than the stored second update limit value ZD2, then as an additional step 202, the state of the locking device element 1 is set to "inaccurate". In the "inaccurate" state, it is not feasible to perform an access method for the locking device element 1 with a positive output. That is, the rotatability of the actuating member 107 cannot be achieved at any lock cylinder 101 by means of the locking device element 1 in the "inaccurate" state. However, unlike in the "tampered" state, the "inaccurate" state can be canceled again by performing time synchronization with the backend system 104. This is in Figure 6 The following is shown in the downlink. Here, in step 206, a request for update time upt is first sent to backend system 104, and then update time upt is received from backend system 104.
[0135] exist Figure 6 In the example described, the temporary storage duration zt is missing because a connection is ensured between the backend system 104, device 103, and locking device element 1. Alternatively, and in Figure 6 Not shown, it is possible to use the temporary duration zt to perform time synchronization with the backend system 104, as previously combined Figure 5 As described.
[0136] In step 208, time synchronization is performed, thereby canceling the "inaccurate" state.
[0137] Alternatively, and not shown, a lock cylinder 101, particularly when operable by a knob, can correspond to the locking device element 1 and communicate directly with the device 103 via near-field communication. Communication between the device 103 and the back-end system 104 is maintained. In this case, the corresponding access decision step is performed in the lock cylinder 101. Instead of the lock cylinder 101, electromechanical components, padlocks, or smart locks can function as the locking device element 1 and communicate directly with the device 103 to perform the corresponding access decision step.
Claims
1. A locking device element (1), particularly a key (1), fitting, or lock cylinder (101), for use in an access method (200), in which access to a physical area is permitted or denied. • The locking device element (1) includes a first timing element (76), wherein the first timing element (76) outputs a first timing signal that displays a first time (t1). • The locking device element (1) includes an electronic processing device (72) configured to perform a verification step (201) based on information from the first time element (76), particularly the first time (t1). • The locking device element (1) is configured to perform at least one additional step (202) based on the output of the inspection step (201).
2. The locking device element (1) according to claim 1, wherein the processing device (72) includes an internal second time element (77), the second time element preferably having an internal RC element, wherein the second time element (77) is configured to generate a second time signal displaying a second time (t2) within the processing device (72).
3. The locking device element (1) according to claim 1 or 2, wherein the first timing element (76) is configured and disposed separately from the processing device (72), preferably configured and disposed on a common circuit board (71), wherein the first timing element (76) is electrically connected to the processing device (72) to transmit the first timing signal; in particular, wherein the first timing element (76) is configured as a real-time clock (RTC) having an oscillating crystal.
4. The locking device element (1) according to any one of claims 2 to 3, wherein the processing device (72) is configured to compare the first time (t1) with the second time (t2) as a verification step (201), in particular comparing the first time signal with the second time signal.
5. The locking device element (1) according to any one of the preceding claims, wherein the locking device element (1) is configured to perform the additional step (202) based on the output of the verification step (201) when the difference between the first time (t1) and the second time (t2) is greater than the stored first time difference (dt1).
6. The locking device according to claim 5, wherein the locking device element (1) is configured, as a further step (202), to induce, preferably by itself, to perform at least a temporary denial of access to the physical area; In particular, the locking device element (1) is configured to, preferably, cancel the rejection itself after receiving a positive approval message, especially from the back-end system (104).
7. The locking device element (1) according to any one of the preceding claims, wherein the locking device element (1) is configured to, based on the output of the inspection step (201), preferably when the difference between the first time (t1) and the second time (t2) is less than the stored second time difference (dt1), • As an additional step (202), the time, especially the first and / or second time (t1, t2), is compared with the access authorization time window and / or the effective start and / or effective end of the access authorization to check the access conditions. • And / or as an additional step (202), the second time (t2) is corrected based on the first time (t1), in particular the second time element (77) is adjusted according to the first time (t1).
8. The locking device element (1) according to any one of the preceding claims, wherein the inspection step (201) includes receiving and evaluating an error message of the first time element (76) by the processing device (72), wherein the locking device element (1) is configured to, as an additional step (202), induce, preferably itself to perform at least a temporary denial of access to the physical area based on the error message.
9. The locking device element (1) according to any one of the preceding claims, wherein the locking device element (1) is configured to receive an update time signal of the display update time (upt) from the back-end system (104) via wireless near-field communication with the device (103).
10. The locking device element (1) according to claim 9, wherein the locking device element (1) is configured to receive the update time signal encrypted from the back-end system (104) and decrypt the update time signal by means of encryption information individualized for the locking device element (1).
11. The locking device element (1) according to any one of claims 9 or 10, wherein the locking device element (1) is configured as follows: • Receive temporary storage duration (zt), the update time signal being temporarily stored on the device (103) between the backend system (104) and the locking device element (1) for the temporary storage duration, and the temporary storage duration being determined by the device. • As a verification step (201), the update time (upt) corrected for the temporary storage duration (zt) is compared with the first time (t1) and / or the second time (t2) in the processing device (72). • As an additional step (202), when the update time (upt) corrected by the temporary storage duration (zt) differs from the first time (t1) and / or the second time (t2) by less than the saved limit value, the first time element (76) and / or the second time element (77) are adjusted based on the update time (upt) corrected by the temporary storage duration (zt), or when the update time (upt) corrected by the temporary storage duration (zt) differs from the first and / or second clock time by more than the saved limit value, the update time (upt) is discarded.
12. The locking device element (1) according to any one of claims 9 to 11. • The locking device element (1) is configured to adjust the first and / or second time (t2) by means of the received update time, and in particular, to adjust the first time element (76) and / or the second time element (77) according to the update time (upt). • The verification step (201) includes: obtaining the time interval (ZS) since the last adjustment by means of the first time (t1) and / or the second time (t2) and comparing the time interval with at least one saved update limit value (ZD1, ZD2).
13. The locking device element (1) according to claim 12, wherein when the time interval (ZS) is greater than the stored first update limit value (ZD1), the locking device element (1) is configured to output a warning as a further step (202) to perform the adjustment by means of the update time (upt).
14. The locking device element (1) according to claim 12 or 13, wherein when the time interval (ZS) is greater than the stored second update limit value (ZD2), the locking device element (1) is configured to, as an additional step (202), induce, preferably itself to perform at least a temporary denial of access to the physical area, especially until the first time (t1) and / or the second time (t2) have been adjusted by means of the update time (upt).
15. The locking device element (1) according to any one of the preceding claims, wherein the locking device element (1) is configured as a key, wherein the key includes a particularly rigid key bar (50) for insertion into a lock cylinder (101).
16. The locking device element (1) according to claim 15, wherein the key bar (50) includes a transmission device (56) for transmitting energy and / or electronic data to the lock cylinder (101).
17. The locking device element (1) according to claim 15 or 16, wherein at least one lock cylinder ID is electronically stored on the locking device element (1), wherein the locking device element (1) is configured to perform an access condition check: whether the lock cylinder ID received by the lock cylinder (101) is consistent with the stored lock cylinder ID; wherein the locking device element (1) is configured to receive the lock cylinder ID to be stored encrypted from the back-end system (104) and decrypt it by means of encryption information individualized for the locking device element (1).
18. A method, particularly an access method (200), wherein access to a physical area is permitted or denied. • Using the locking device element (1) according to any one of the preceding claims, and outputting a time signal displaying a first time (t1), particularly by means of the first time element (76) of the locking device element, • An inspection step (201) is performed in the electronic processing device (72) of the locking device element (1) based on the first time (t1). • Perform another step (202) based on the output of the inspection step (201).
Citation Information
Patent Citations
Method of designing probes for detecting target sequence and method of detecting target sequence using the probes
EP1889924B1
Locking device for a locking element
EP4191004A1