Access control system
Patent Information
- Application Number
- DE102014020200
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2013-12-05
- Filing Date
- 2014-04-11
- Publication Date
- 2025-11-06
- Estimated Expiration
- 2034-04-11
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Area
[0001] Exemplary embodiments of the invention relate to an access control system, its components, and methods performed by these components. Exemplary embodiments of the invention relate in particular to a system for controlling access by different persons to parcel or goods delivery containers. background
[0002] Access control systems are used in many ways, for example to control access to rooms of a building, as is the case with hotels, office complexes or laboratories, to events or in an abstract form to functions, resources or services, such as computer functions or resources or server services.
[0003] A specific application of access control systems is the control of people's access to the openings of containers, such as lockers or delivery boxes, especially parcel boxes. Parcel boxes offer a new form of parcel delivery / collection for people who want to receive or send parcels at or near their residence, even when they are not home. Parcel boxes are typically installed in front of the user's residence—similar to a mailbox, but with a larger capacity—and the delivery person then delivers parcels by placing them in the box or collects them by removing them from the box. To prevent misuse and theft, the parcel box must be locked. Both the delivery person and the parcel box user must then be equipped with physical or logical keys to use the parcel box. Summary of some exemplary embodiments of the invention
[0004] To date, there is no satisfactory access control system for the installation of a large number of parcel boxes that allows the boxes to operate without a network connection – i.e., offline – while still ensuring secure and flexible allocation of parcel box access rights to both delivery personnel and parcel box users.
[0005] The present invention therefore aims to overcome this problem.
[0006] According to a first aspect of the invention, a method for access control carried out by an access control device is disclosed, comprising the following: - Receiving access authorization information communicated to the access control device, which includes at least one or more access authorization parameters and initial verification information, - first check, using at least the communicated access authorization parameters, the communicated first check information and a second key of a symmetric or asymmetric key pair stored in the access control device, whether the communicated first check information was generated by performing cryptographic operations on the communicated access authorization parameters using at least one first key of the key pair, - Decide whether access may be granted, whereby necessary conditions for granting access are that the first check yields a positive result and it is determined that at least a predefined set of the communicated access authorization parameters, with respect to the respective reference information present in the access control device at least at the time of the first check, authorize access.
[0007] According to the first aspect of the invention, the use of an access authorization verification device for communicating access authorization information to the access control device according to the first aspect of the invention is further disclosed.
[0008] According to a second aspect of the invention, a method for generating access authorization information is disclosed, in particular carried out by an access authorization generation device, comprising the following: - Generating initial verification information by performing cryptographic operations on one or more access authorization parameters using at least one first key of a symmetric or asymmetric key pair, - Generating access authorization information that includes at least one or more access authorization parameters and the first verification information, and - Outputting the access authorization information for storage on an access authorization verification device, which is configured to communicate the access authorization information to at least one access control device in order to enable the latter to decide whether access may be granted based on the communicated access authorization information, wherein necessary conditions for granting access are that an initial check, using at least the communicated access authorization parameters, the communicated first check information and a second key of the key pair stored in the access control device, is performed to verify whether the communicated first check information was generated by performing cryptographic operations on the communicated access authorization parameters using at least the first key of the key pair.a positive result is obtained and it is determined that at least a predefined set of the communicated access authorization parameters, with regard to the respective reference information present in the access control device at least at the time of the first check, authorize access.
[0009] According to a third aspect of the invention, a method for proving access authorization, carried out by an access authorization verification device, is disclosed, comprising the following: - Communicating access authorization information, which includes at least one or more access authorization parameters and initial verification information, to an access control device in order to enable it to decide whether access may be granted based on the communicated access authorization information, The necessary conditions for granting access are that an initial check, using at least the communicated access authorization parameters, the communicated initial check information, and a second key of a symmetric or asymmetric key pair stored in the access control device, to determine whether the communicated initial check information was generated by performing cryptographic operations on the communicated access authorization parameters using at least one initial key of the key pair, yields a positive result and that it is determined that at least a predefined set of the communicated access authorization parameters, with respect to the respective reference information present in the access control device at least at the time of the initial check, authorize access.
[0010] According to each of these aspects of the invention, the following are further disclosed: - A computer program comprising program instructions that cause a processor to execute and / or control the method according to the respective aspect of the invention when the computer program is running on the processor. For the purposes of this specification, a processor shall include, but is not limited to, control units, microprocessors, microcontrol units such as microcontrollers, digital signal processors (DSPs), application-specific integrated circuits (ASICs), or field-programmable gate arrays (FPGAs). The process may either control all steps, execute all steps, or control and execute one or more steps. The computer program may, for example, be distributed via a network such as the Internet, a telephone or mobile network, and / or a local area network. The computer program may be at least partially software and / or firmware of a processor.It can also be implemented, at least partially, as hardware. For example, the computer program can be stored on a computer-readable storage medium, such as a magnetic, electrical, electromagnetic, optical, and / or other type of storage medium. The storage medium can be part of the processor, for example, a (non-volatile or volatile) program memory of the processor or a part thereof. - A device configured for carrying out and / or controlling the method according to the respective aspect of the invention, or comprising respective means for carrying out the steps of the method according to the respective aspect of the invention. This device may either control all steps of the method, or carry out all steps of the method, or control one or more steps and carry out one or more steps. One or more of the means may also be carried out and / or controlled by the same unit. For example, one or more of the means may be formed by one or more processors. - A device comprising at least one processor and at least one memory containing program code, wherein the memory and the program code are configured to cause the device with the at least one processor to execute and / or control at least the method according to the respective aspect of the invention. It is possible to either control all steps of the method, or execute all steps of the method, or control one or more steps and execute one or more steps.
[0011] According to a fourth aspect of the invention, a system is disclosed which comprises the following: - an access control device according to the first aspect of the invention, - an access authorization generation device, in particular according to the second aspect of the invention, and - an access authorization verification device, in particular according to the third aspect of the invention, wherein the access authorization information is generated by the access authorization generation device and communicated by the access authorization verification device to the access control device.
[0012] These four aspects of the present invention exhibit, among other things, the following – partly exemplary – properties.
[0013] An access control device is used to control access to certain areas of buildings (e.g., hotels, office complexes, laboratories), to events (e.g., concerts, sporting events), to functions (e.g., a computer, via a login), to resources, or to services (e.g., a service provided by a server, e.g., online banking, social networks, email accounts). Examples of access to areas of devices include access to receiving areas of devices such as lockers, cabinets, refrigerators, delivery containers, mailboxes, parcel boxes, or combined mailboxes and parcel boxes, which are, for example, each closed with doors and secured by locking mechanisms.
[0014] The access control device can consist of one or more processors that control one or more locking devices, such as an electronically controlled lock, and thus, for example, cause the lock to open and / or close. The lock can be equipped with a latch function, so that the access control device only needs to control the opening of the lock (for example, by temporarily moving the latch to an open position, perhaps by an electric motor), while closing the lock is done manually by a user who uses the latch function. For example, by pushing a door shut, the latch is forced from the closed position to the open position, and after the door is no longer pushed shut, the latch automatically returns to the closed position, for example, by spring tension.
[0015] The access control device may also include locking mechanisms and other components. The access control device may be part of a device to which it controls access, such as a receiving device. The access control device may, for example, be battery-operated and not have a permanent power supply. The access control device may, for example, be configured to communicate exclusively with access authorization devices during operation and not with the access authorization generation device. The access control device may, for example, not have a connection to a mobile network, a local area network (LAN), a wireless local area network (WLAN), or the internet; it is therefore, for example, an "offline" access control device.The wireless communication of the access control device can, for example, be configured for communication with devices in the immediate vicinity of the access control device (e.g., less than 100 m). The wireless communication of the access control device can, for example, be limited to communication via Radio Frequency Identification (RFID) and / or Near Field Communication (NFC) and / or Bluetooth (e.g., Bluetooth version 2.1 and / or 4.0). RFID and NFC are specified, for example, according to ISO standards 18000, 11784 / 11785 and ISO / IEC standards 14443-A and 15693. The Bluetooth specifications are available at www.bluetooth.org. The access control device may, however, also have, for example, a Universal Serial Bus (USB) interface, which allows for maintenance of the access control device.
[0016] Access control can, for example, consist of deciding, based on presented access authorization information, whether access is granted. Access may be granted. If it is decided that access may be granted, access is granted, for example, by sending a control signal, such as to a lock, to unlock and / or open a door to one or more rooms (e.g., recording rooms of a recording device) to allow access to those rooms. Access can be granted to varying degrees; for example, if there are multiple recording rooms, access may be granted only to specific recording rooms or groups of recording rooms. The degree of access can be defined, for example, in an access authorization parameter of the access authorization information.
[0017] The access control device receives access authorization information that has been communicated to it, in particular from an access authorization verification device on which the access authorization information is stored, at least temporarily. The access authorization information can be communicated to the access control device, for example, via wireless communication, such as RFID, NFC or Bluetooth.
[0018] The access authorization device can be, for example, a portable electronic device. This device is assigned to a user (e.g., a user registered with the access control device) who wishes to gain access to the access control device using their access authorization information and is therefore referred to below as the "user device." The user device has, for example, a graphical user interface and / or its own power supply. Examples of user devices include a mobile phone, a personal digital assistant (PDA), a media player (e.g., an iPod), or a navigation device.If the access control device is assigned to a parcel box, the user device can belong to a parcel box user (e.g., the owner of the parcel box or a person authorized to receive parcels via the parcel box or to deposit them for delivery by a courier). A courier is not considered a user in this context. The user device is configured for wireless communication with the access control device, for example, via Bluetooth and / or RFID and / or NFC. The device has the capability, for example, to communicate via a cellular mobile network (e.g., a mobile network based on the Global System for Mobile Communication (GSM), the Universal Mobile Telecommunications System (UMTS), and / or the Long Term Evolution (LTE) system).
[0019] Alternatively, the access authorization device could be, for example, a portable electronic device used by a delivery person, particularly if the access control device is assigned to a parcel locker. This device is hereinafter referred to as the "delivery device." The delivery device may, for example, have a graphical user interface and functionality for wirelessly capturing information from parcels, such as by optically scanning parcel labels and / or capturing information from parcels via radio waves (e.g., RFID) or magnetic fields (e.g., NFC), for example, if the parcel has an RFID or NFC tag. The delivery device may, for example, have the capability to communicate via a cellular network, but it may not.The delivery device may, for example, be capable of communicating via Wi-Fi and / or a cellular mobile network (especially GPRS). It may also be capable of communicating via Bluetooth and / or NFC, perhaps through a retrofit. An example of a delivery device is a handheld scanner, such as the Honeywell LXE Tecton MX7.
[0020] When the access authorization device (in particular the user device and / or the delivery device) communicates access authorization information to the access control device via Bluetooth, it is advantageous for the access authorization device to know the access control device's MAC address. This allows Bluetooth communication to be initiated without the need for time-consuming Bluetooth pairing. The MAC address of the access control device is communicated to the access authorization device, for example, along with the access authorization information.
[0021] Alternatively, the access authorization device could be, for example, a portable electronic unit for wireless communication with the access control device. This portable electronic unit is referred to below as a "tag." The tag may, for example, lack the capability to communicate via cellular network, and / or Wi-Fi, and / or Bluetooth. The tag may, for example, lack a graphical user interface and / or its own power supply. The tag may, for example, only communicate when a reader's field of view (e.g., electromagnetic or magnetic) is detected. The tag may, for example, be an RFID or NFC tag (e.g., a MiFARE tag from NXP). The tag may, for example, have different form factors. It may, for example, be a key fob or a card (e.g., a key card).The tag can be designed with a form factor similar to that of a credit card. It can be small (e.g., less than 9 cm or 5 cm in height / length / width) and lightweight (e.g., less than 50 g). The information stored on the tag (e.g., access authorization information) can be communicated to a corresponding reader, for example, only after successful authentication of the reader to the tag. The reader can be part of the access control device or operationally connected to it. The tags can operate at frequencies such as 120–135 kHz, 13.56 MHz, or 865–869 MHz, but other, particularly higher, frequencies are also possible. Information transmission can be based on capacitive coupling, inductive coupling, or electromagnetic waves (e.g., backscatter technology).The tag can, for example, include an antenna, an analog circuit for transmitting and receiving (also called a transceiver), a digital circuit (e.g., a microcontroller), and a memory component (e.g., an EEPROM - Electrically Erasable Programmable Read-Only Memory). The access authorization information can be modulated onto a high-frequency signal generated by a reading unit, for example, in the form of load modulation. The reading unit can then obtain the authorization information from the tag.
[0022] The access authorization information is generated on the access authorization generation device, which can be, for example, one or more servers. It is then output for storage on an access authorization verification device. This can be done, for example, by transmitting the access authorization information to the verification device via a communication link between the access authorization generation device and the verification device, particularly if the verification device is a user device (e.g., a mobile phone, as described above). For example, the verification device may contain functionality, such as an application ("app"), which can be downloaded from an online marketplace, for instance, and which serves, among other things, to retrieve access authorization information.Access authorization information can be transferred from the access authorization generation device to the access authorization verification device whenever the validity of the access authorization information has expired, for example, on an annual or semi-annual basis. The access authorization information can be actively pushed from the access authorization generation device to the access authorization verification device (i.e., transferred without a request from the access authorization verification device), or it can be transferred to the access authorization verification device only upon request by the access authorization verification device (or another entity) (and, for example, only generated upon such a request).The communication link between the access authorization generation device and the access authorization verification device can be based on one or more communication networks, at least one of which may be a mobile network or a WLAN network. If the access authorization verification device is, for example, a user device (e.g., a mobile phone), the access authorization information can be obtained from the access authorization generation device via a Hypertext Transfer Protocol (HTTP) or Hypertext Transport Protocol Secure (HTTPS) connection, which may be based on a General Packet Radio (GPRS) connection.
[0023] If the access authorization device is, for example, a delivery device (e.g., a delivery person's handheld scanner), the access authorization information can be transmitted via the internet to a computer (e.g., a computer in a delivery base with which the delivery device is at least temporarily associated) and then, under the computer's control, transferred to the delivery device either via a wired connection (e.g., using a docking station) or wirelessly (e.g., via Wi-Fi). This process can be repeated daily.
[0024] If the access authorization device is, for example, a tag (such as an RFID or NFC tag, as described above), the access authorization generation device outputs the access authorization information to the tag for storage, for example, by transmitting the access authorization information to a writing unit (for example, via the internet), which then writes the access authorization information to the tag. For example, the access authorization information is transmitted to a computer belonging to a tag supplier or manufacturer, which then writes the access authorization information to the tags. This occurs, for example, before the tags are issued to the individuals who are to use the access authorization information for access verification (e.g., users and / or delivery personnel).The validity of the access authorization information stored on tags may be longer than the validity of the access authorization information stored on the user devices and / or delivery devices due to the greater effort required to replace the access authorization information in the tags compared to the user devices and / or delivery devices.
[0025] The access authorization information contains one or more access authorization parameters. These can include, for example, a (particularly unique) identifier for the access control device, a (particularly unique) identifier for the access authorization information itself, time-based validity information (e.g., in the form of a "no-before date", a "no-after date", a "start time of day", and an "end time of day" that specify the days and times of day during which access may be granted, for example, from March 27, 2014, 00:00:00 to March 28, 2014, 23:59:59), an upper limit on the permitted uses of the access authorization information to gain access, and information on the extent to which access may be granted (e.g., whether all doors of a parcel box may be opened, or only one, or a specific group).The one or more access authorization parameters are collectively referred to as access authorization in this specification.
[0026] At least a predefined set (e.g., all or only some) of the access authorization parameters are checked against their respective reference information to determine whether they authorize access. For example, the access control device identifier can be checked against an access control device identifier stored within the device. If there is a match, it can be determined that this access authorization parameter authorizes access. Similarly, the time-based validity information, also used as an access authorization parameter, can be checked against a time-based information (e.g., date and time) received from the access control device's clock. For example, access might be granted if a period defined by the validity information includes the current time according to the access control device's clock.A predefined time tolerance may be permitted to compensate for any time differences between the clock of the access control device and a clock in the access authorization generation device. A communicated upper limit of permitted uses can be checked against a counter stored in the access control device, which is incremented by one each time this access authorization information is used to grant access at the access control device. Comparing the communicated upper limit with the counter as a reference shows that access may be granted if the counter is less than the communicated upper limit.
[0027] While, for example, the access control device identifier and the time information received from the clock are constantly present in the access control device, there may be one or more access authorization parameters that must be checked with regard to reference information that is not constantly present in the access control device, but only, for example, during the first check or shortly before the first check. This can be the case, for example, for the identifier of the access authorization information or the access authorization verification device as an access authorization parameter if this identifier, for example, in encrypted form (or alternatively in combination with a fourth key), is only received by the access control device together with the access authorization information or before or after the access authorization information (for example, but in the same communication session).Here too, granting access requires that the access authorization information identifier communicated as an access control parameter matches the identifier obtained by decrypting the encrypted access authorization information. Similarly, the access authorization information identifier or the access authorization verification device identifier can also be checked against a rejection list as an example of reference information. This rejection list might not be stored on the access control device initially, but only after a certain period of operation.For example, it may happen that the rejection list is received by the access control device in the same communication session in which the access authorization information is also transmitted to the access control device, for example, before the access authorization information.
[0028] An access authorization parameter that is not checked against reference information is, for example, the information regarding the extent of access to be granted. This information is considered when granting access, but not when determining whether access should be granted. For instance, the information regarding the extent of access to be granted might specify which door or group of doors among a building or device should be opened once access has been granted. If the device is a parcel box with one door for a parcel compartment and one for a letterbox, the information might specify whether only the parcel compartment (for example, for a delivery person) or both the parcel compartment and the letterbox (for example, for a user of the parcel box) should be opened.
[0029] Before the individual access authorization parameters are checked against their respective reference information in the access control device, the initial check must yield a positive result. This initial check analyzes the first verification information contained in the access authorization information to determine its integrity (unaltered state or freedom from tampering) and authenticity (genuineness or origin from the presumed source), as will be explained in more detail below.The authenticity of the access authorization information is primarily established by the fact that the issuing entity, i.e., the access authorization generation device, used the first key of a key pair, kept secret between the access control device and the access authorization generation device, during cryptographic operations. This can be verified by the access control device using the second key of this key pair, the first verification information, and the communicated access authorization parameters. This verification also confirms the integrity of the communicated access authorization parameters. None of the keys of the key pair are known outside of the access control device and the access authorization generation device; in particular, neither the access authorization verification device nor its users know these keys.The key pair can be, for example, a symmetric key pair, meaning that the first and second keys are identical. Encryption and decryption with such symmetric keys can be performed using methods such as Advanced Encryption Standard (AES), DES (Data Encryption Standard), Data Encryption Algorithm (DEA), Triple-DES, IDEA (International Data Encryption Algorithm), or Blowfish, to name just a few. Symmetric keys can, for example, be chosen pseudo-randomly. In contrast, with an asymmetric key pair, both keys are different, for example, in an asymmetric key pair using the RSA (Rivest, Shamir, Adleman) algorithm or the McEliece, Rabin, Chor-Rivest, or ElGamal algorithm.Methods for generating symmetric and asymmetric keys for creating digital signatures, Message Authentication Codes (MACs), and for encryption and decryption are described in the publication “Special Publication 800-133 Recommendation for Cryptographic Key Generation” by the National Institute of Standards and Technology (NIST) of the US Department of Commerce.
[0030] Access is granted if the initial check is successful, specifically if the integrity and authenticity of the access authorization information are confirmed, and if it is also established that at least a certain set of access authorization parameters, with respect to their respective reference information in the access control device, authorize access. If it is decided that access may be granted, a corresponding control signal is issued, for example, to a lock. Otherwise, an alarm or warning, such as a visual or audible one, is issued.
[0031] The access control system embodied according to the first to fourth aspects of the invention offers several advantages. Because the access control device and the access authorization generation device treat the key pair as a secret, the access authorization generation device is enabled to create access authorization information for the access control device exclusively on its own. The access control device, in turn, can trust the access authorization information generated by the access authorization generation device. Therefore, the access authorization parameters can, in principle, be communicated to the access control device unencrypted: Using the second key of the key pair, their integrity and the authenticity of the access authorization information can be sufficiently verified.Since the access control device uses either long-term, unchanging reference information, such as the device's identifier, or self-manageable reference information, such as the time information derived from the device's local clock or the counter for accesses already granted with specific access credentials, to verify the communicated access parameters, the device is essentially self-sufficient and does not require a network connection. This also reduces power consumption, which is significant for a battery-powered device. Furthermore, the cryptographic operations in the access control device are performed using the communicated access parameters, and not locally stored ones. This allows, in particular, the integrity check of the received information to be separated from the verification of its content.For example, if the "expected" first verification information were calculated in the access control device and then compared with the communicated first verification information, the expected first verification information would have to be generated for a large number of time points, depending on the granularity of the time validity used as an access authorization parameter (e.g., 1 minute, 10 minutes, 1 hour), and compared with the communicated first verification information in order to precisely "match" the communicated verification information with at least one of the expected first verification values. Instead, the present access control system determines the integrity of the communicated time validity and compares this time validity with the time information in the access control device to determine much more easily and quickly whether the difference is still within a predefined tolerance.
[0032] Further advantages of the disclosed access control system are described below using exemplary embodiments, the disclosure of which is intended to apply equally to all four aspects of the invention and all respective categories (method, device / system, computer program).
[0033] In an exemplary embodiment of all aspects of the invention, the key pair is an asymmetric key pair, and the first verification comprises verifying the communicated first verification information as a digital signature via the access authorization parameters using at least the second key of the key pair and the communicated access authorization parameters. The first and second keys of the asymmetric key pair are then different. For example, the first key is a private key and the second key is a public key, or vice versa. The key pair may, for example, have been generated using the RSA algorithm.The digital signature is created, for example, by generating a hash value of the access authorization parameters (particularly within the access authorization generation device), using an algorithm from the Secure Hash Algorithm (SHA) family as specified by the National Institute of Standards and Technology (NIST), such as SHA-1, SHA-224, or SHA-256, to name just a few. This hash value is then encrypted, for example, with the first key to obtain the initial verification information. Alternatively, the access authorization parameters can be encrypted without generating a hash value. To verify the signature, the initial verification information is decrypted with the second key, and the resulting hash value is compared to a hash value generated locally using the same algorithm for the communicated access authorization parameters.If the hash values match, the authenticity of the access authorization information and the integrity of the access authorization parameters can be assumed. If no hash value is generated, the access authorization parameters obtained through decryption are directly compared with the communicated access authorization parameters.
[0034] In an exemplary embodiment of all aspects of the invention, the key pair is a symmetric key pair, and the first verification comprises performing cryptographic operations on the communicated access authorization parameters using at least the second key of the key pair to obtain locally generated first verification information and comparing the communicated first verification information with the locally generated first verification information. The symmetric key pair then comprises two identical keys, for example, an AES key, e.g., an AES-128 key. The first verification information can be generated, as in the case of an asymmetric key pair, by encrypting the access authorization parameters or a hash value thereof using the first key (particularly in the access authorization generation device).The verification is then performed by decrypting the communicated first verification information using the second (identical to the first) key and comparing the result with either the access authorization parameters or a locally generated hash value of the access authorization parameters using the same algorithm. If there is a match, the authenticity of the access authorization information and the integrity of the access authorization parameters are assumed. For encryption / decryption, a block cipher can be used, for example, with an Electronic Code Book (ECB), Cipher Block Chaining (CBC), Cipher Feedback (CFB), Output Feedback, or a counter operating mode, as known to those skilled in the art, to enable the encryption / decryption of information longer than the block of the block cipher. Depending on the operating mode (e.g.,In CBC or CFM operating mode, an initialization vector (IV) may be required in addition to the keys for encryption / decryption. This can either be predefined (and then, for example, stored in the access control device) or communicated to the access control device for each access authorization piece of information. Instead of encrypting / decrypting the access authorization parameters or their hash value to obtain the initial verification information, a message authentication code (MAC) can also be used to generate the initial verification information. This MAC is derived from the access authorization parameters and also incorporates the initial key. Examples of MACs include the Message Authentication Algorithm (MAA), the Keyed-Hash Message Authentication Code (HMAC), and the Cipher-Based Message Authentication Code (CMAC) specified by NIST.In a MAC (Access Authorization Key), for example, a combined process generates a hash value of the access authorization parameters, taking the first key into account. The result forms the first verification information. To verify this first verification information, the access control device uses the second (identical to the first) key to generate the MAC according to the same procedure, based on the communicated access authorization parameters. The result, the locally generated first verification information, is then compared with the communicated first verification information. If they match, the authenticity of the access authorization information and the integrity of the access authorization parameters are proven.
[0035] In an exemplary embodiment of all aspects of the invention, the access control device is one of a plurality of access control devices, wherein a second key of a symmetric or asymmetric individual key pair is stored in the access control device, which is stored only on the access control device and not on any of the other access control devices of the plurality of access control devices, and wherein the second key of the key pair used in the first check is the second key of the individual key pair. Accordingly, the first key of the individual key pair is also used when generating the first check information (in particular at the access authorization generation device).The access authorization information generated for a specific access control device is therefore unique and usable only for that one access control device, but not for any other access control device. If an access authorization device containing such stored access authorization information is lost, misuse is only possible with that one access control device, and not with multiple access control devices.
[0036] In an exemplary embodiment of all aspects of the invention, the access control device represents an access control device from a plurality of access control devices, wherein a second key of a symmetric or asymmetric individual key pair is stored in the access control device, which is stored only on the access control device but not on any of the other access control devices of the plurality of access control devices, wherein the access control device additionally stores a second key of a symmetric or asymmetric group key pair, different from the second key of the individual key pair, which is stored in all access control devices of a group of access control devices of the plurality of access control devices comprising the access control device.and wherein the second key of the key pair used in the first check is either the second key of the individual key pair or the second key of the group key pair. Accordingly, the first key of the individual key pair or the first key of the group key pair is also used when generating the first verification information (especially at the access authorization generation device). The access authorization information generated for a specific access control device with the first key of the individual key pair is unique and usable only for that access control device, but not for any other access control device. Therefore, if an access authorization verification device with such stored access authorization information is lost, misuse is only possible with that access control device.and not possible with multiple access control devices. However, the group key pair also allows the generation of access authorization information that can be used to prove authorization at multiple access control devices. This is advantageous, for example, if service staff in a hotel have access to several rooms, each equipped with its own access control device, or if delivery drivers have access to several parcel boxes, each equipped with its own access control device, e.g., in a delivery area.such access authorization information, generated with a first key of the group key pair, can be stored, for example, on a tag (e.g., an RFID or NFC tag). Since such tags may have a relatively long validity period (e.g., several months) and could be used to gain unauthorized access to numerous access control devices if lost, it is advantageous for such tags or the access authorization information they contain to be provided with a unique identifier that can be blocked, for example, by a rejection list stored in the access control device, as will be explained in more detail below.
[0037] The access control device may, for example, additionally store at least one second key of a symmetrical or asymmetrical further group key pair, different from the second key of the individual key pair and the second key of the group key pair, which is stored in all access control devices of a further group of access control devices of the plurality of access control devices that includes the access control device but, compared to the group of access control devices, includes at least one or more other access control devices, and wherein the second key of the key pair used in the first check is either the second key of the individual key pair, the second key of the group key pair or the second key of the further group key pair.The access control device then has, for example, the second keys of the individual key pair and two group key pairs. This is particularly advantageous if the access control device is logically assigned to two at least partially different groups of access control devices. For example, if the access control device is assigned to a parcel box, it can happen, with dynamically defined delivery areas, that the same parcel box is assigned to a first delivery area on one day and to a second delivery area on another day. Additionally or alternatively, delivery areas can overlap on the same day, for example, because the first delivery area is assigned to a parcel carrier and the second delivery area to a combined carrier (who delivers parcels and letters) or a letter carrier.To ensure that the parcel box can be opened by both the delivery driver in the first delivery area and the delivery driver in the second delivery area, it is advantageous to store the respective second keys of two group key pairs on the access control device. The access authorization information of the delivery driver in the first delivery area (especially their initial verification information) is then based on the first key of the first group key pair, and the access authorization information of the delivery driver in the second delivery area (especially their initial verification information) is then based on the first key of the second group key pair. This access authorization information can then be stored, for example, on respective tags for the individual delivery areas (one tag for the first delivery area and one tag for the second delivery area).
[0038] For example, it may not be possible to change, delete, or replace the second key of the individual key pair in the access control device, but it may be possible to change, delete, or replace the second key of the group key pair. The second key of the individual key pair can therefore be a fixed key that is not changed during the service life of the access control device.In particular, the second key of the individual key pair can be used to verify the authenticity and integrity of information other than access authorization information, especially information generated by the access authorization generation device using the first key of the individual key pair (for example, group key information or rejection information), as will be explained in more detail below. The second keys of the group key pairs, on the other hand, can be changed, deleted, or replaced, which is relevant, for example, if a parcel box needs to be moved to a different delivery area due to its owner's relocation. How this is done will be explained below.
[0039] In an exemplary embodiment of all aspects of the invention, group key information communicated to the access control device, comprising at least one second key of a new symmetric or asymmetric group key pair encrypted with the first key of the individual key pair for the same or at least partially different group of access control devices of the plurality of access control devices, the communicated encrypted second key of the new group key pair is decrypted with the second key of the individual key pair, and the second key of the new group key pair obtained by decryption is stored in the access control device.so that the second key of the key pair used in the first check is at least either the second key of the individual key pair or the second key of the new group key pair. The group key information can be generated in particular at the access authorization generation device and communicated to the access control device by means of the access authorization verification device, for example within the same communication session in which the access authorization information is also communicated to the access control device, but temporally before the access authorization information.so that the second key of the new group key pair can already be considered when verifying the access authorization information, if necessary. The second key of the existing group key pair can either be deleted or retained. For example, the group key information can contain a list of one or more encrypted second keys from each of the one or more new group key pairs, replacing all second keys from the respective group key pairs already present in the access control device. The individual key pair again serves as a basis of trust between the access control device and the access authorization generation device, but does not allow verification of authenticity or integrity.This is because the second keys of each group key pair are not transmitted unencrypted. However, encryption ensures that no one except the access authorization generation device and the access control device can read the second keys of each new group key pair in plaintext, especially not the access authorization verification device. If the individual key pair is a symmetric key pair, for example, symmetric AES encryption in CBC mode is used. An initialization vector for CBC mode can be communicated to the access control device, for example, along with the group key information, e.g., as part of it, for use in decryption.
[0040] To enable verification of the authenticity and integrity of the communicated group key information, the following can be carried out, for example: The second verification information communicated to the access control device is received, and the second key of the new group key pair obtained through decryption is stored in the access control device only if a test based at least on the communicated second verification information, the second key of the individual key pair, and the communicated group key information confirms that the communicated second verification information was generated by performing cryptographic operations on the group key information corresponding to the communicated group key information, using at least the first key of the individual key pair.The calculation and verification of the second verification piece of information can be performed analogously to the process described above for the first verification piece, except that the cryptographic operations are carried out using the group key information instead of the access authorization parameters. For example, digital signatures or MACs can again be used as the second verification piece of information. This second verification piece of information is generated at the access authorization generation device and then communicated from the access authorization verification device to the access control device.
[0041] The group key information can additionally include a counter (update_counter) that is incremented with each new group key pair, wherein the second key of the new group key pair obtained by decryption is stored in the access control device only under the additional condition that a value of a counter (update_counter) included in the group key information is greater than a value of a counter provided in the access control device, and wherein, at or after the storage of the second key of the new group key pair in the access control device, the value of the counter in the access control device is updated to the value of the counter (update_counter) included in the group key information.The counter included in the group key information is, for example, a copy of a counter that is incremented in the access authorization generation device each time new group key information is generated (i.e., each time one or more second keys from one or more new group keys are to be brought to the access control device).
[0042] The group key information can, for example, additionally include an individual identifier of the access control device, and the second key of the new group key pair obtained through decryption in the access control device can, for example, only be stored under the additional condition that an individual identifier of the access control device stored in the access control device matches the individual identifier included in the group key information. This ensures that the group key information is uniquely assigned to only one access control device. Since the second verification information is generated via the group key information, the integrity of the individual identifier in the group key information is also guaranteed.
[0043] The group key information can, for example, additionally include a group identifier associated with the new group key pair, which is common to all access control devices in the group of access control devices for which the new group key pair is intended, and the group identifier obtained through decryption is stored, for example, in the access control device. Storing the group identifier obtained through decryption can only occur, for example, if the prerequisites required for storing the second key of the new group key pair obtained through decryption (described above) are also met.The group identifier can serve as reference information for checking an identifier communicated as an access authorization parameter of the access control device for which the access authorization information is intended, and can facilitate the selection of the second key of the key pair used in the first check, as will be explained in more detail below.
[0044] In an exemplary embodiment of all aspects of the invention, one of the communicated access authorization parameters is an identifier for a single access control device or a group of access control devices, whereby it is determined that the identifier authorizes access if the identifier matches an individual identifier of the access control device stored in the access control device and / or a group identifier for a group of access control devices to which the access control device belongs. An identifier contained in the access authorization information is thus used to assign the access authorization information to an access control device, either based on its individual identifier or based on its group identifier.
[0045] In an exemplary embodiment of all aspects of the invention, one of the communicated access authorization parameters is an identifier for only one access control device or for a group of access control devices, wherein it is determined that the identifier authorizes access if the identifier matches an individual identifier of the access control device stored in the access control device and / or a group identifier for a group of access control devices to which the access control device belongs, wherein the first verification information of communicated access authorization information, which has an identifier for only one access control device, is generated by performing cryptographic operations on the access authorization parameters using at least one first key of the individual key pair, and wherein the first verification information of communicated access authorization information,The access authorization information, which contains an identifier for a group of access control devices, is generated by performing cryptographic operations on the access authorization parameters using at least one key from the group key pair. An identifier contained in the access authorization information is thus used to assign the access authorization information to an access control device, either based on its individual identifier or its group identifier. An additional assignment of the access authorization information occurs via the choice of the group key pair: If the access authorization information contains an identifier for only one access control device,The first verification information is generated using the first key of the individual key pair (and verified accordingly using the second key of the individual key pair in the access control device). However, if the access authorization information contains an identifier for a group of access control devices, the first verification information is generated using the first key of the group key pair (and verified accordingly using the second key of the group key pair in the access control device).
[0046] For example, the identifier, particularly a predefined identifier format, can be used in the access control device to determine whether it is an identifier for a single access control device or for a group of access control devices. This allows the appropriate second key of the individual key pair or the second key of the group key pair to be selected for the initial check in the access control device. For instance, a predefined assignment of one or more predefined bit positions in the identifier can indicate whether it is an identifier for a single access control device (e.g., last bit position = "0") or for a group of access control devices (e.g., last bit position = "1").
[0047] In an exemplary embodiment of all aspects of the invention, one of the communicated access authorization parameters is an identifier for the access authorization information or for an access authorization verification device that communicates the access authorization information to the access control device. It is determined that the identifier authorizes access if the identifier is not included in a rejection list stored in the access control device. This is particularly advantageous because it allows the affected access authorization information to be blocked if the access authorization verification device containing the stored access authorization information is lost.The rejection list on the access control device can be updated, for example, by other access credential devices on the access control device and may then also include recently lost access credential devices / access information, as will be described in more detail below.
[0048] In an exemplary embodiment of all aspects of the invention, it is further provided that information communicated to the access control device is obtained, comprising at least one fourth key encrypted using at least the first key of the key pair. This fourth key can be used for authenticating the access control device to an access authorization verification device that communicates the access authorization information to the access control device, or for verifying the authenticity and / or integrity of information communicated to the access control device. The encrypted fourth key is then decrypted using at least the second key of the key pair to obtain the fourth key. In contrast to the second key of the key pair, the encrypted fourth key is not used for authentication purposes.The fourth key of the access authorization verification device is assigned to the key pair itself, which represents a secret between the access authorization generation device and the access control device.
[0049] The fourth key can, for example, form a symmetrical or asymmetrical key pair with a third key.The fourth key is provided to the access authorization device by the access authorization generation device, for example in encrypted form (using the first key of the key pair) as described above, for communication with the access control device, and additionally, for example, the third key can be provided to the access authorization device in unencrypted form, for example so that the access authorization device can perform cryptographic operations, such as those related to authenticating the access control device to the access authorization device or enabling the access control device to verify the authenticity and / or integrity of information communicated to the access control device.The access control device can then, for example, use the decrypted fourth key, the second key of the key pair, and the communicated access authorization information (containing the first verification information) to determine that the access authorization information is intended for the access control device (using the first verification information and the second key of the key pair as described in detail above) and was communicated by an access authorization verification device authorized by the access authorization generation device (verified by authentication to the access authorization verification device using H or by verifying the authenticity and / or integrity of information communicated to the access control device by the access authorization verification device using H).The information containing the encrypted fourth key can be communicated to the access control device by the access authorization device, for example, in the same session in which the access authorization information is also communicated from the access authorization device to the access control device.
[0050] In an exemplary embodiment of all aspects of the invention, it is further provided that information communicated to the access control device is received, which comprises at least one combination of a fourth key and an identifier for the access authorization information or for an access authorization verification device, encrypted using at least the first key of the key pair, to which the access authorization information is communicated to the access control device, wherein the fourth key can be used for authenticating the access control device against an access authorization verification device that communicates the access authorization information to the access control device, or for verifying the authenticity and / or integrity of information communicated to the access control device.and that the encrypted combination is decrypted using at least the second key of the key pair to obtain the fourth key and the identifier, wherein the identifier additionally represents one of the communicated access authorization parameters, and wherein it is determined that the identifier contained in the communicated access authorization information authorizes access if the identifier contained in the communicated access authorization information matches the identifier obtained by decrypting the encrypted information. The explanations relating to the previous embodiment apply accordingly to the present embodiment. In contrast to the previous embodiment, however, in the present embodiment the fourth key is additionally transmitted by encryption together with the identifier to the identifier,and thus also bound to the access authorization information or access authorization verification device identified by the identifier. The initial advantage here is that a way is provided to supply the access control device with reference information for verifying the identifier of the access authorization information or access authorization verification device contained in the access authorization information as an access authorization parameter, which (unlike other reference information such as the identifier of the access control device or the time information) is not present in the access control device itself. Furthermore, the access control device can then use the decrypted fourth key, the decrypted identifier,of the second key of the key pair and the communicated access authorization information (with the identifier contained therein as access authorization parameters and the first verification information) determine that the access authorization information is intended for the access control device (based on the first verification information and the second key of the key pair as described in detail above),that the access authorization information was communicated by an access authorization device authorized by the access authorization generation device (verified by authentication to the access authorization device using H or by verifying the authenticity and / or integrity of information communicated to the access control device by the access authorization device using H), and that the access authorization device was specifically authorized by the access authorization generation device for this access authorization information. The information with the encrypted combination of the fourth key and the identifier can be communicated to the access control device by the access authorization device, for example, in the same session in which the access authorization information is also communicated from the access authorization device to the access control device.
[0051] In an exemplary embodiment of all aspects of the invention, it is further provided that information communicated to the access control device is received, which comprises at least one combination of a fourth key and an identifier for the access authorization information or for an access authorization verification device that communicates the access authorization information to the access control device, encrypted using at least the first key of the key pair, wherein the fourth key can be used for authenticating the access control device against an access authorization verification device that communicates the access authorization information to the access control device, or for verifying the authenticity and / or integrity of information communicated to the access control device.that the encrypted combination is decrypted using at least the second key of the key pair to obtain the fourth key and the identifier, the identifier additionally representing one of the communicated access authorization parameters, and it is determined that the identifier contained in the communicated access authorization information authorizes access,if the identifier contained in the communicated access authorization information matches the identifier obtained by decrypting the encrypted information and the identifier is not included in a rejection list stored in the access control device. The explanations for the two previous embodiments apply accordingly to the present embodiment. In the present embodiment, however, the identifier of the access authorization information or access authorization verification device contained in the encrypted combination or in the access authorization information fulfills a dual function: firstly, it serves to ensure,that the communicated access authorization information originates from an access authorization verification device authorized by the access authorization generation device (determined by comparing the identifier contained in the encrypted combination with the identifier contained in the access authorization information), and secondly, it is used for comparison with a rejection list stored in the access control device, which thus provides reference information for checking the access authorization parameter represented by the identifier.
[0052] For example, the access authorization information communicated to the access control device can be stored in identical form on at least two access authorization credential devices, wherein these identical access authorization information stored on the at least two access authorization credential devices each have the same identifier for the access authorization information and these access authorization information are each associated with the same fourth key (i.e., the respective identifier for the access authorization information is each encrypted as a combination with the same fourth key using the first key of the key pair, for example, to bind the respective identifier to the fourth key).For example, several or all of the access credentials contained on the access credential device that communicates the access credential information to the access control device can be associated with this fourth key, with the identifiers of this access credential information, which is specifically intended for different access control devices, differing. For example, all access credentials contained on multiple access credential devices can also be associated with this fourth key. In that case, there is (at least at one point in time) only a single fourth key for the access credential devices and their access credentials.The identifier of the access authorization information is then, for example, only specific to the access control device for which the access authorization information is intended, but not specific to the access authorization verification device on which the access authorization information is stored.
[0053] Using the same fourth key for multiple different access authorization information sets across multiple access authorization devices, and using identifiers specific only to the access control devices but not to the access authorization device itself, can significantly reduce the effort associated with generating and assigning the fourth key and the access authorization information, especially with a large number of access authorization devices and access control devices, compared to individually selected fourth keys for each access authorization device and individual identifiers for each pair of access control device and access authorization device.This is because only one access authorization information needs to be generated for each access control device, and the number of combinations of the fourth key with the identifier of the access authorization information, which must be encrypted with the first key of the key pair for each access control device, also corresponds only to the number of access control devices. However, this simplification has the disadvantage that each access authorization verification device can now gain access to all access control devices whose access authorization information it contains. The access authorization information is thus only bound to one specific access control device.but not to a specific access authorization device. Therefore, if, for example, a group of M access authorization devices (e.g., delivery devices) is each equipped with access authorization information for N different access control devices (e.g., parcel boxes) (where the access authorization information for a specific access control device is the same on each of the M access authorization devices, and only the access authorization information for different access control devices differs), so that each of these access authorization devices can grant access to each of the N access control devices, then in the event of the loss of an access authorization device, the N access authorization information stored on that device can only be blocked by...that the identifiers for this N access authorization information are entered in the respective rejection lists on all N access control devices. However, then no other M-1 access authorization verification device can grant access to the N access control devices. This disadvantage, resulting from a simplified administration option, can be remedied by a number of measures, as described below.
[0054] For example, it may be stipulated that the access authorization information communicated to the access control device has a limited validity period (e.g., 1 month, 2 weeks, 1 week, 3 days, or 1 day) and / or only allows a limited number of access operations within its validity period (e.g., fewer than 5, 4, or 3 access operations) and / or can only be communicated by the access authorization device to the access control device when the access authorization device determines that there is a need for access to the access control device (e.g., because a parcel or shipment is to be placed in or collected from a parcel box controlled by the access control device).Limiting the validity period and / or the number of permitted access operations reduces the potential for misuse, both in terms of time and the number of possible misuse actions per access control device. Considering the necessity of access restricts the potential for misuse to those access control devices where access operations are actually required, which is typically only a small proportion of the access control devices for which an access authorization device has stored access authorization information. The necessity of access can be determined, for example, based on shipment data stored on the access authorization device, such as a delivery device. For instance, the delivery person can optically scan, wirelessly capture, or read the shipment identification from a package and enter it into the delivery device.The delivery device can then, for example, retrieve the shipment data relevant for identification and, by comparing the shipment's address data (e.g., postal code, street, and house number) with the addressees of the parcel boxes and / or the addresses of the parcel box users also stored in the delivery device, select the parcel box for which the shipment is intended. The delivery driver can then, for example, only communicate the access authorization information to this specific parcel box.These measures may, for example, eliminate the need to block identifiers for access authorization information stored on lost access authorization devices and / or significantly reduce the length of the rejection lists maintained in the access control device (for example, they may only contain identifiers of access authorization information stored on lost tags, but not those of access authorization information stored on lost delivery devices).
[0055] For example, the access authorization information communicated to the access control device can be stored in identical form on at least two access authorization devices, each of which has the same third key. Thus, the same third key is used on the at least two access authorization devices (or, for example, on all access authorization devices in a group of access authorization devices), forming a symmetric or asymmetric key pair with the fourth key. Therefore, authentication of these access authorization devices to the access control device takes place using the same third key.The disadvantage of potentially slightly reduced security associated with using an identical third key for multiple access authorization devices (or, for example, all of a group or the system), which allows for a significant reduction in the effort involved in generating and distributing the third key to the access authorization devices (and also generating and using the fourth key), can, however, be mitigated or eliminated by one or more (e.g., all) of the measures described in the previous section.
[0056] The fourth key can also be used additionally or alternatively for the purposes described below.
[0057] For example, the fourth key forms a symmetric or asymmetric key pair with a third key, the communicated access authorization information further includes third verification information, and a second check is further performed at the access control device, using at least one challenge generated by the access control device, the communicated access authorization parameters, the communicated first verification information, the communicated third verification information and the fourth key, to determine whether the communicated third verification information was generated by performing cryptographic operations on information corresponding to the generated challenge, the communicated access authorization parameters and the communicated first verification information, using at least the third key, wherein a further necessary condition for granting access is that the second check yields a positive result.The challenge can be, for example, random information (e.g., a binary random number sequence) transmitted from the access control device to the access authorization device. Based on the challenge, the access authorization parameters, the first verification information, and the third key, the access authorization device can generate the third verification information by performing cryptographic operations, for example, using one of the methods already described above for generating the first verification information.If the fourth key is part of a symmetric key pair, the cryptographic operations can, for example, generate a MAC as the third verification piece of information, or a digital signature can be generated if the fourth key is part of an asymmetric key pair. The second verification step allows the access control device to verify the authenticity and integrity of the access authorization parameters and first verification piece communicated by the access authorization device, ensuring that they were indeed communicated by the access authorization device and have not been altered. The use of the challenge protects against replay attacks. This use of the fourth key can be employed, for example, when the access authorization information is transmitted from a user device (e.g., a mobile phone) or a delivery device (e.g., a delivery vehicle).a handheld scanner) is transmitted to the access control device, for example via Bluetooth transmission.
[0058] Alternatively, the fourth key can be used for authentication against an access credential device containing the access authorization information, with the access authorization information being communicated from the access credential device to the access control device only upon successful authentication. If the fourth key (and consequently the third key as well) is, for example, a symmetric key, the access control device and the access credential device can mutually verify that they each possess the symmetric key, for example, by encrypting challenges received from the other party and performing local cross-checks.If the access authorization device is, for example, a tag, such as an NFC tag from NXP's Mifare tag, the symmetric key can be stored in the tag, and the access control device can only be granted access (in particular to the access authorization parameters and the initial verification information, which are stored, for example, in an "application" of the tag) if both the tag and the access control device accessing the tag have mutually proven that they possess the symmetric key (for example, via so-called three-step mutual authentication).
[0059] In an exemplary embodiment of all aspects of the invention, it is further provided that rejection information (L) communicated to the access control device, comprising at least a new rejection list with identifiers for access authorization information to be rejected or for access authorization verification devices from which access authorization information is to be rejected at the access control device, and is obtained from fourth verification information at the access control device, and that the communicated new rejection list is stored on the access control device only if a test based at least on the communicated fourth verification information, the second key of the key pair and the communicated rejection information determines thatthat the communicated fourth verification information was generated by performing cryptographic operations on the rejection information corresponding to the communicated rejection information, using at least the first key of the key pair. The fourth verification information allows the access control device to verify the authenticity and integrity of the received rejection information, for example, using one of the procedures already explained above for the first verification information. The rejection information and / or the fourth verification information is generated, for example, by the access authorization generation device and communicated by the access authorization verification device to the access control device. A new rejection list can be communicated to the access control device, for example, as soon as it becomes known thatthat at least one identifier of an access authorization information or access authorization device must be blocked, for example, due to the loss of an access authorization device. As explained above, on the access control device, it may be a prerequisite for granting access that the identifier of the access authorization information used to request access is not on the rejection list.
[0060] The rejection information can, for example, additionally include a counter that is incremented with each new rejection list. The new rejection list is stored in the access control device only if the value of the counter included in the rejection information is greater than the value of a counter provided in the access control device. Furthermore, the value of the access control device's counter is updated to the value of the counter included in the rejection information either when or after the new rejection list is stored in the access control device. This prevents attempts to install an old rejection list (which, for example, does not contain identifiers currently to be blocked) on the access control device.
[0061] The rejection information can, for example, additionally include an identifier for only one access control device or group of access control devices on which the new rejection list is to be stored. The new rejection list is stored in the access control device only if an individual identifier of the access control device stored in the access control device, or a group identifier for a group of access control devices containing the access control device, matches the identifier included in the rejection information. This identifier ensures that the rejection list can only be installed on a specific access control device or group of access control devices.
[0062] The embodiments and exemplary configurations of all aspects of the present invention described above are also to be understood as disclosed in all combinations with one another.
[0063] Further advantageous exemplary embodiments of the invention can be found in the following detailed description of some exemplary embodiments of the present invention, particularly in conjunction with the figures. However, the figures accompanying the application are intended only for illustrative purposes and not to determine the scope of protection of the invention. The accompanying drawings are not necessarily to scale and are intended only to reflect the general concept of the present invention by way of example. In particular, features included in the figures should by no means be considered a necessary component of the present invention.
[0064] They show: Fig. 1: a schematic representation of an exemplary embodiment of a system according to the present invention, Fig. 2: a schematic representation of an exemplary embodiment of a device according to the present invention, Fig. 3: a schematic representation of a further exemplary embodiment of a system according to the present invention; Fig. 4: a flowchart of an exemplary embodiment of communication of access authorization information between a handheld scanner / mobile phone and a parcel box according to the present invention; Fig. 5: a flowchart of an exemplary embodiment of communication of access authorization information between a tag and a parcel box according to the present invention; Fig. 6: a flowchart of an exemplary embodiment of communication of rejection information between a handheld scanner / mobile phone / tag and a parcel box according to the present invention; Fig. 7: a flowchart of an exemplary embodiment of communication of group key information between a handheld scanner / mobile phone / tag and a parcel box according to the present invention; Fig. 8: a flowchart of an exemplary embodiment of communication of keys and access authorization information between the key server and other components of an exemplary system according to the invention; Fig. 9: a schematic representation of the distribution of group keys and access authorization information in an exemplary system according to the invention; Fig. 10: a schematic representation of the allocation of parcel boxes to different delivery areas according to an exemplary embodiment of the invention; and Fig. 11: a flowchart of the possible sequence of operations in an exemplary embodiment of a parcel box according to the present invention.
[0065] An overview of an exemplary embodiment of a system 1 according to the invention is given in Fig. Figure 1 shows that the system comprises an access authorization generation device 2, an access authorization verification device 3, and an access control device 4. In particular, the access authorization verification device 3 and the access control device 4 can be present multiple times, but for the sake of simplicity, they are each shown only once. Components 2, 3, and 4 represent exemplary devices according to the first, third, and second aspects of the invention, respectively, the properties of which have already been described in detail. Fig. Section 1 therefore primarily serves to clarify which keys are stored in the individual components and what information is exchanged between the components. Access authorization generation device 2 stores, in particular, the first individual key S1 and optionally also a first group key S1. T1, which are linked to a second individual key S2 or a second group key S T2 In the access control device 4, there is one individual key pair (S1, S2) or one group key pair (S T1 , S T2 These pairs can each form a symmetric or asymmetric key pair, where in the case of a symmetric key pair both keys are the same, e.g. S1=S2=S and / or S T1 =S T2 =S T applies and in the case of an asymmetric key pair S1≠S2 and / or S T1 ≠S T2 applies.
[0066] The access authorization generation device 2 generates and transmits one or more of the following pieces of information to the access authorization verification device 3: - Access authorization information B and initial verification information V, - the one with S1 or S T1 encrypted fourth key H4, within the context of information A, - a third key H3, - the group key information W and the second check information V W , and / or - the rejection information L and the fourth test information V L ,
[0067] This information can be transmitted, for example, at least partially (or completely) within the same communication session between the access authorization generation device 2 and the access authorization verification device 3 (i.e., between the setup and the initiation of a communication link between the access authorization generation device 2 and the access authorization verification device 3), or in different communication sessions. However, the group key information W, for example, can be transmitted less frequently than the access authorization information B and the rejection information L, as there is less frequent need to change them.
[0068] The transmission of this information from the access authorization generation device 2 to the access authorization verification device 3 can be at least partially wireless (e.g., via cellular network or WLAN), particularly if the access authorization verification device 3 is a portable user device (e.g., a mobile phone) or a portable delivery device (e.g., a handheld scanner). The transmission does not have to be direct but can occur via one or more intermediate stations (e.g., the decentralized units discussed below), as will be explained in more detail below. If the access authorization verification device 3 is a tag (e.g., an RFID or NFC tag), the transmission of the information is logically straightforward and could, for example, mean that the information is transmitted to a server of a production system for the tags and stored there in the tags.
[0069] The third key H3 and the fourth key H4 in turn form a key pair (H3, H4), which can be symmetrical, i.e. H3=H4=H, or asymmetrical, i.e. H3≠H4.
[0070] Of the information transmitted from the access authorization generation device 2 to the access authorization verification device 3, in principle every piece of information, except for the third key H3, can be further communicated from the access authorization verification device 3 to the access control device 4 and then used in the access control device 4 to check whether this information is authentic and in good faith and whether - in the case of the access authorization information - the operator of the access authorization verification device 3 may be granted access.
[0071] The third key H3 is stored in the access authorization device 3 and is used, for example, in the context of mutual authentication between access authorization device 3 and the access control device 4, the latter of which has received the counterpart to the third key H3, namely the fourth key H4, in encrypted form (information A) and stores it at least temporarily after decryption.
[0072] Fig. Figure 2 shows a schematic representation of an exemplary embodiment of a device 5 according to the present invention. Device 5 can, for example, be the access authorization generation device 2, the access authorization verification device 3, or the access control device 4 of the Fig. 1 represent.
[0073] Device 5 comprises a processor 50 with associated main memory 52 and program memory 51. The processor executes, for example, program instructions stored in the program memory 51. The program instructions execute and / or control the method according to the first, second, or third aspect of the invention. Thus, the program memory 51 contains a computer program according to the first, second, or third aspect of the invention and represents a computer program product for its storage.
[0074] The program memory 51 can, for example, be persistent memory, such as read-only memory (ROM). The program memory can be permanently connected to the processor 50, or alternatively, it can be detachably connected to the processor 50, for example, as a memory card, floppy disk, or optical data carrier (e.g., a CD or DVD). Further information can also be stored in the program memory 51, or in separate memory. If device 5 is the access authorization generation device 2, this information can include, for example, the keys S1 and / or S2. T1and / or the keys H3 and / or H4, as well as, for example, information about the access control device for which access authorization information is to be generated (e.g., the access control device identifier) and information about the access authorization information, the group key information, and / or the rejection information, as well as their associated verification information. If device 5 is the access authorization verification device 3, this information may include, for example, the information received from the access authorization generation device 2 (in particular B, V, W, V). W , L, V L , A, H3). If device 5 is the access control device 4, the keys S2 and / or S can be added to this information. T2counting as well as reference information, based on which received access authorization parameters are checked to see if they each authorize the granting of access (e.g. an identifier of the access control device, a rejection list, one or more counters e.g. for group key information or rejection information, etc.).
[0075] The main memory 52, for example, is used to store temporary results during the execution of program instructions; this is, for example, a volatile memory such as a random-access memory (RAM).
[0076] The processor 50 is also operationally connected to a communication unit 53, which enables, for example, the exchange of information with external devices.
[0077] If the device 5 represents the access authorization generation device 2, the communication unit 53 may, for example, be set up to communicate via a network such as the Internet, in order to transmit information to one or more of the following units: - to a server of a manufacturer of access control devices 4 (see Server 72 in Fig. 9) and / or - to a server of a manufacturer of access authorization devices 3 (see server 73 in Fig. 9), and / or - to an interface server of a mobile communications network, via which information is to be wirelessly transmitted to an access authorization device 3 (e.g. a mobile phone or a handheld scanner), and / or - to an administration server (e.g., deployment server 66 in Fig. 3), under whose control the distribution of information to decentralized units (see 71-2 in Fig. 8) for transmission to access authorization devices 3 (e.g. delivery devices), and / or - at least indirectly to a computer (e.g. a decentralized unit 71-2 in Fig. 8), from which or under whose control the information is then to be transmitted to access authorization devices 3 (e.g. delivery devices) (e.g. wirelessly (e.g. via a WLAN) or wired (e.g. via a LAN)).
[0078] If the device 5 represents the access authorization verification device 3 in the form of a user device or delivery device, the communication unit 53 may, for example, comprise the following: - a mobile communication interface for receiving information from the access authorization generation device 2, - an interface for wireless (e.g. via WLAN) or wired reception (e.g. via a docking station) of information from a device (e.g. a decentralized unit) to which the access authorization generation device 2 has transmitted this information for transmission to the access authorization verification device 3) - a radio interface for communication with the access control device 4, in particular a Bluetooth interface and / or an RFID interface and / or NFC interface.
[0079] If the device 5 represents the access authorization verification device 3 in the form of a tag, the communication unit 53 may, for example, comprise the following: - a radio interface for communication with the access control device 4, in particular a Bluetooth interface and / or an RFID interface and / or an NFC interface.
[0080] The device 5 may also include further components, such as a graphical user interface to allow an operator to interact with the device 5, particularly if the device 5 represents an access authorization device 3 in the form of a user device or delivery device. If the device 5 represents a delivery device, it may, for example, include a unit for the optical capture of information (e.g., a scanner) and / or, for example, a user interface for capturing handwritten input such as a signature.
[0081] If device 5 represents an access control device 4, it may also include, for example, an optical and / or acoustic user interface to provide the operator with information about the status of the access control device 4 and / or about the success of an attempt to gain access to the access control device 4 using access authorization information. In the case of an access control device 4, device 5 may also include control means for controlling a locking unit (e.g., for unlocking it) depending on the decision as to whether access can be granted. The locking unit may, for example, include a lock, which may be electronically controlled. In the context of the description of the exemplary embodiments of the Fig. In reference 3-10, a unit comprising at least the processor 50, the memory units 51 and 52, and the locking unit is referred to as a "lock". In the case of an access control device 4, the device 5 may additionally include one or more sensors, for example, for detecting the current locked state of the locking unit. In the case of an access control device 4, the device 5 may, for example, include a battery (e.g., rechargeable or non-rechargeable), particularly as the sole power supply. In the case of an access control device 4, the device 5 may, for example, not have a connection to a wired network, i.e., in particular, not a connection to a LAN, and / or may, for example, not have a connection to a WLAN or a mobile network (in particular, a cellular mobile network).
[0082] In the case of an access authorization device 3 in the form of a tag, for example, the device 5 may not have its own power supply and may obtain its energy for communication from the field of a reading unit of the access control device 4. Such a tag may also not have a user interface.
[0083] Components 50-53 can, for example, be designed together as a module or unit, or can at least partially be designed as individual modules to ensure easy replacement in case of defects.
[0084] The following will be based on the Fig. 3-10 presents a more detailed embodiment of an access control system 6 according to the invention, which is in Fig. Figure 3 shows that in this access control system 6, the access authorization generation device 2 is configured as a key server 60, the access control devices 4 are configured as parcel boxes 69 (or access-controlling units thereof, in particular "locks"), which are assigned to users 63 (e.g., users registered to use the parcel boxes), and the access authorization verification devices 3 are configured as handheld scanners 68 or tags 74 of delivery personnel 70 or as mobile phones 61 or tags 62 of users 63, which are collectively referred to as "tokens". The users 63 are, for example, the owners of parcel boxes or other persons (e.g., from the same household or neighborhood) who have registered to receive shipments in or from a specific parcel box 69. The users 63 are also referred to as parcel box users.The delivery personnel (number 70) can be, for example, parcel delivery drivers, combined delivery drivers (who deliver both letters and parcels), or letter carriers. For parcel delivery drivers and combined delivery drivers, it is important to be able to open the parcel box in order to deliver or collect parcels. For combined delivery drivers and letter carriers, it is important to be able to open the parcel box in order to deliver large-format letters (e.g., maxi letters) that may not fit through a standard letter slot.
[0085] The in the Fig. The specification of components 2, 3, and 4 in Section 3-10 and the associated description serves only for explanatory purposes and should not be understood as essential or limiting. In particular, the interaction of the components 2, 3, and 4 specified in this way should also be understood as disclosed in general terms—that is, independently of the specific embodiment of these components. This also applies to the transmission technologies specified for explanatory purposes, especially Bluetooth and NFC, which should only be understood as examples of a possible form of wireless communication between access authorization devices 3 and access control devices 4. A parcel box 69 is a container with at least one lockable door, designed to receive parcels, for example, at least one parcel with dimensions of 45 x 35 x 20 cm (which is a so-called"Packset L" corresponds to), or at least two or three such packages. The parcel box 69 can also have a letterbox (but may alternatively not have a letterbox), into which letters can be inserted, for example, through a letter slot with or without a covering flap. The letterbox can be lockable with its own door (with a mechanical or electronic lock), or alternatively, it can be locked via a door of the parcel box 69 together with a parcel compartment intended for receiving the packages. If one door is provided for the parcel compartment and one for the letterbox, a common access control device can be provided, which, depending on access authorization, either opens one door (e.g., the door of the parcel compartment, e.g., for the delivery person 70) or opens both doors (e.g., for the user 63).Parcel box 69 can be designed for mounting in or on a wall, such as a house wall, or as a freestanding unit for securing to the ground, for example, in front of a house. User 63 is notified of newly delivered items (parcels and / or letters) via email and / or SMS. User 63 can also place prepaid items in parcel box 69 and request a pickup online or by phone. If no pickup is requested, the item may be collected with a slight delay when a delivery person next opens the parcel box and finds the item there. The delivery person will leave a receipt in the parcel box as proof of pickup.
[0086] Key server 60, for example, is operated in a suitable data center of a delivery company, in particular Deutsche Post DHL. It generates keys and access authorizations and communicates these, in particular, to deployment server 66. As shown below, using the Fig. As described in more detail in section 8, the provisioning server selects the access authorizations required for each delivery district from the access authorizations (and possibly also keys) received from the key server 66, enriches this information with address information of parcel boxes and / or their users (and possibly also the MAC addresses of the locks of the parcel boxes 69, which the handheld scanners 68 can use to initiate a Bluetooth connection without the time-consuming Bluetooth pairing process) received from the parcel box management system 65, and makes this information available directly or indirectly to the handheld scanners 68. The selection is based on the so-calledDistrict allocation, i.e., the assignment of shipments to be delivered or collected to delivery districts, for which the delivery personnel 70 can register with their handheld scanners 68. This district allocation is carried out by the allocation server 67, which has access to the shipment data. Simultaneously, the parcel recipients 63 receive their keys and access authorization information, with which they can open the parcel boxes 69. The purchase of a parcel box 69 by a user 63 and / or registration for a parcel box 69 takes place, for example, via an online portal 64 (e.g., the domain www.Paketde), which exchanges relevant information with the parcel box management server 65. In addition to or as an alternative to the delivery personnel's handheld scanners 70, tags 74 are also provided, with which the delivery personnel 70 (especially mail carriers) can open a large number of parcel boxes 69, for example, all parcel boxes 69 in a delivery district.These tags are also referred to below as Group Lock Access (GLA) tokens. Similarly, for users 63, in addition to or as an alternative to mobile phones 61, tags 62 are also provided, which generally only open the parcel box 69 assigned to each user 63. These are also referred to below as Individual Lock Access (ILA) tokens. The access authorization information and keys contained on tags 62 and 74 are also generated by the key server 60 and then stored on the tags, as indicated by the dashed lines in [reference missing]. Fig. 3 is indicated.
[0087] If user 63 uses a mobile phone to open parcel box 69, this mobile phone can communicate with key server 60, for example, via a software application (hereinafter referred to as the "app"). The app itself and / or its communication with key server 60 can be designed to be particularly secure, for example, through measures such as encrypted communication, version control, hardening, password protection, etc.
[0088] The following section describes the components of the access control system 6. Fig. 3 described in more detail. Locks
[0089] Locks are integrated into the parcel boxes 69, which are used by the delivery company to deliver both parcels and letters to customers 63. Since letters and parcels are to be delivered exclusively to the original recipient 63, the parcel boxes 69 are responsible for the actual access authorizations. The parcel boxes 69 are therefore equipped with locks (especially electronically controlled ones) and a communication interface. Furthermore, they contain the logic to obtain access authorizations and to verify and guarantee access, i.e., opening. Parcel boxes 69 are either owned by individual customers 63 or shared by different customers 63. Access permissions
[0090] Delivery personnel (70) or users (63) are only granted access to parcel boxes (69) if they possess a valid access authorization. Access authorizations comprise one or more of the access authorization parameters already described. Access authorizations are represented electronically and written to a physical token. An access authorization can be restricted both with regard to its duration of use (not before and not after) and with regard to the number of times it can be used to open a lock. Physical tokens
[0091] A physical token contains the access authorization. There are three different types: handheld scanners 68, NFC tags 62, 74, and mobile phones 61, for example, smartphones 61. Handheld scanners 68 are used, for example, exclusively by delivery personnel 70 for delivering and collecting shipments (e.g., parcels). Mobile phones 61 are typically used by customers 63. NFC tags 62, 74 can be used by both delivery personnel 70 and users 63. While delivery personnel 70, who deliver letters that don't fit in the letter slot of the parcel box 69, need access to a group of parcel boxes 69, users 63 and parcel carriers 70 with handheld scanners 68 require individual access to parcel boxes 69. Therefore, the system of Fig. 3 Group Lock Access (GLA) tokens (for group access) and Individual Lock Access (ILA) tokens (for individual access) are distinguished and used. On the mobile phone 61 of a user 63, the NFC tag 62 of a user 63 and the hand scanner 68 of a (parcel) delivery person 70, ILA tokens are therefore used, while on the NFC tags 74 of a (letter) delivery person 70, GLA tokens are used. Key server
[0092] The key server 60 manages all access permissions for system 6. In particular, it maintains information about all users 63, all parcel boxes 69, and their associated access rights. It therefore also generates the actual access permissions that can be used on the physical tokens. Cryptographic keys of the locks
[0093] Each lock of a parcel box 69 has two keys, which are used to distinguish between the types of tokens mentioned above.
[0094] For ILA tokens: A lock has an individual key S2. To open a lock, an ILA requires valid access authorization B. Key S2 is used to verify access authorization B. Furthermore, key S2 is used to validate a rejection list and / or group key information. Key S2 forms a key pair with key S1, which can be symmetric or asymmetric. In the case of a symmetric key S1=S2, for example, AES-128 is used as the symmetric cryptographic primitive, and the encryption method, such as Cipher Block Chaining (CBC), is used together with a random initialization vector (IV). The IV can be individually generated for each encryption by a random number generator (RNG) and transmitted as plaintext.In the case of an asymmetric key pair, for example, a digital signature is provided for integrity verification.
[0095] For GLA tokens: A lock has a group key S T2 To open the lock, a GLA token requires valid access authorization B. The key S T2 This is in turn used to verify access authorization B. The key S T2 forms with a key S T1 a key pair that can be symmetrical or asymmetrical.
[0096] The keys S2 and S T2For example, keys are generated during the lock's production process and stored in the lock. Both keys must be adequately protected against unauthorized access within the lock. Both keys, along with the lock's administrative data and a unique identifier (LockID), are transmitted to and stored on key server 60. Key server 60 then uses the keys S1 and S2. T1 for cryptographic protection of access authorizations - to allow verification of the validity of access authorizations at the lock - and the key S1 additionally for protection of the rejection list and group key information. Cryptographic keys for ILA tokens
[0097] Each ILA token is equipped with a third key H3, which, together with a fourth key H4, forms a symmetric (i.e., H3=H4) or asymmetric (i.e., H3≠H4) key pair (H3, H4). This key H3 is used to authenticate the ILA token at the lock, to which the key H4 is made available, at least temporarily. The key server uses the key pair (H3, H4) to guarantee access to the lock via the ILA token. During the initialization of the ILA token, the key H3 is written and stored on the key server.
[0098] The H3 key can also be issued for a group of ILA tokens. In this case, all ILA tokens in a group are equipped with the same H3 key. Multiple keys can exist on a single ILA token, meaning that one or more group keys can be present alongside one or more individual keys. (Even though we refer to groups of tokens here, these should still be considered individual access authorizations that grant access to individual locks, not groups of locks.)
[0099] A group key can be uploaded to the device during or after the initialization process, but the key must exist on the device before it can be used. Cryptographic keys for GLA tokens
[0100] Each GLA token is equipped with a key H3, which, together with a key H4, forms a symmetric or asymmetric key pair (H3, H4). Key H3 is used to gain access to a group of locks that at least temporarily possess key H4. The key server uses the key pair (H3, H4) to grant access permissions for a group of locks to the GLA token. Key H3 is programmed onto the device during the initialization process and stored on the key server. Structure of access authorizations
[0101] Access permissions are granted by the key server. An access permission can contain one or more of the following access permission parameters: • KeyID: Access authorization ID (assigned by the key server) • LockID: ID of the lock • For ILA tokens: The lock number and MAC address are transmitted from order management to the key server. Part of the LockID can be used, for example, to differentiate or identify different lock manufacturers. ◯ For GLA Token: in this case, the LockID is the ID of the group to which the parcel box with the specific lock belongs. • NotBeforeDate: Date “valid from” with year / month / day • NotAfterDate: Date “valid until” with year / month / day • StartTimeOfDate: Time from which the access authorization is valid (default e.g. 00:00:00) • EndTimeOfDay: Time until which the access authorization is valid (default e.g. 23:59:59) • MaxUses: Number of uses; default 0 means "unlimited" • Permissions: Setting permission for security-critical operations, e.g., whether opening the parcel compartment, and / or opening the parcel compartment and the letter compartment is allowed.
[0102] Access authorization can be identified by a unique KeyID. The "LockID" describes for which lock (or group of locks) the access authorization is valid. For example, a predefined number of bits in the LockID (e.g., four bits) can carry a code indicating whether it is an individual or group identifier. With such a code, the lock can recognize which key to use for decryption: the individual key S2 or one of the group keys S1. T2 . This code, or other bits of the LockID, can also be used to encode which manufacturer the lock comes from.
[0103] It may happen that a lock requires multiple group keys if the parcel box is located in an area where two delivery groups overlap. This is explained in more detail below.
[0104] The two parameters "NotBeforeDate" and "NotAfterDate" define the validity period of the access authorization, with the precision of one day. "NotBeforeDate" specifies the date of first use, and "NotAfterDate" specifies the last day of the validity period. "StartTime-OfDay" further specifies the time at which the validity period begins, and "End-TimeOfDay" specifies the time at which it ends. The precision can be, for example, one second. However, other ways of defining validity intervals are also conceivable, for example, in the form of a pointer or index that refers to individual entries of a multitude of predefined validity periods, which, for example, are stored in the key server and the lock, or can be calculated from the index according to a predefined rule.For example, for access authorizations valid for one day only, the validity date can be used as the authorization parameter. This date is specified as an offset to a predefined reference date (e.g., January 1, 2014), for instance, as "20" if the authorization is to be valid on January 21, 2014. "MaxUses" defines how many times the key can be used to open a lock. A value of "0," for example, means that the key can be used an unlimited number of times within the specified period. "Permissions" encodes, for example, by setting individual bits in a bit string, which security-critical operations a token is allowed to perform, as already mentioned above (a bit set to 1, for example, indicates that the authorization is granted).
[0105] The key server grants access authorization B for a lock. Depending on the token type, the server generates the value V as a result of cryptographic operations on access authorization B using either key S1 or key S2. T1 The cryptographic operations can, for example, refer to the creation of a MAC value over B using a symmetric key S1, or the creation of a digital signature over B using an asymmetric key S1, to name just a few non-restrictive examples. Structure of the rejection list
[0106] KeyIDs for a lock can be blocked by rejection lists from key server 60. This list contains all KeyIDs of access authorizations that have been revoked by the lock for a corresponding authorization period. Access authorizations that are no longer valid due to their expiration date are removed from the list to keep it short and thus ensure minimal storage requirements in the locks. For example, it is not possible to reverse a previously initiated revocation of an access authorization. Once an access authorization has been revoked, it is no longer possible to open the lock with that authorization.
[0107] Key server 60 generates the rejection information L (which contains the rejection list) and a check information V. L, which, for example, is again based on cryptographic operations over L using the key S1.
[0108] The rejection information L can, for example, contain the identifier (e.g., LockID) of the lock to which the rejection list refers and a list of the KeyIDs to be blocked. Furthermore, it can contain a unique counter for the rejection list, indicating which rejection list the current one represents for the lock. A corresponding counter can then be maintained in the lock to check the validity of the current rejection information. Lock opening with a handheld scanner or a mobile phone
[0109] A lock opens after a token authenticates itself by submitting a valid access authorization. This process is shown in flowchart 400 of the Fig. 4 shown.
[0110] The token (hand scanner 68 or mobile phone 61) has, for example, received the following data from the key server: An access authorization B and a first verification information V, a third key H3 and an authentication value A, which includes a combination of at least H4 and the KeyID of the access authorization B encrypted with S1. In the case of symmetric encryption, the initialization vector IV of a CBC mode of encryption may also have been received.
[0111] The process 400, to open a lock, then proceeds as described below (see below). Fig. 4) In step 401, a Bluetooth connection is first established between tokens 61, 68 and the lock (of the parcel box 69), preferably using the MAC address of the lock known to tokens 61, 68, in order to avoid Bluetooth pairing.
[0112] In step 402, the token 61, 68 authenticates itself to the lock based on the key H3. For this purpose, at least the information A is transmitted to the lock, from which the lock can derive the key H4 using its key S2. Based on H3 and H4, the token 61, 68 and the lock can then execute an authentication protocol known to those skilled in the art, for example, a challenge-response procedure, in which the token 61, 68 applies the key H3 to a challenge (and possibly further information) received from the lock and sends it as a response to the lock, which in turn can verify the response using the key H4 to determine the authenticity of the token 61, 68.
[0113] After successful authentication of the token 61, 68, or in a process combined with this authentication, the token 61, 68 further transmits the information B and V to the lock.
[0114] In step 403, the lock can then verify the authenticity and integrity of B and V with respect to key server 60, i.e., determine whether B and V originate from the key server and have not been altered. The lock uses key S2 for this purpose. If the verification is successful, the access authorization parameters of B are checked against reference information stored in the lock to determine whether the lock can be opened based on B.
[0115] In particular, depending on the presence of the respective access authorization parameters in the access authorization information, the following can be checked, whereby the order of the checks can be arbitrary and the process can be aborted or skipped to step 404 if a condition is not met, in order to save time and / or power: - Whether the KeyID (decrypted from A) corresponds to the KeyID of the access authorization. - Whether the access authorization is still valid in terms of time (by comparison with a clock on the castle). - Whether the access authorization is not on the rejection list for the lock. - Whether the LockID of the access authorization matches the LockID of the lock. - The extent of access allowed by the "permissions". - MaxUses is compared against the internal counter of the lock and the counter is incremented accordingly.
[0116] In step 404, feedback is then sent to tokens 61 and 68 (e.g., OK, ERROR, WARNING), and if all tests performed are successful, preparations are made to open the lock.
[0117] Key H3 is assigned to tokens 61 and 68, for example, during an initialization phase (particularly in the case of token 61, such as the initialization of an app on mobile phone 61) or is provided as a group key H3 (particularly in the case of token 68). The corresponding or identical key H4 is transmitted to the lock in encrypted form. This eliminates the need for the lock to store all keys H4 from all devices, allowing for highly flexible and offline use. Furthermore, the access authorization's KeyID is encrypted along with key H4. This binds the token's key to the lock's current access authorization. The challenge-response protocol is used to protect against replay attacks. Lock opening with an NFC tag
[0118] A lock is opened after a token 62, 74 has authenticated itself to the lock (of a parcel box 69) by transmitting a valid access authorization.
[0119] This process is shown in flowchart 500 of the Fig. 5 shown.
[0120] The token 62, 74, for example, has received and stores the information B, V, A, H3, and possibly IV, where, in the case of an ILA token, V is used for cryptographic operations on at least B with the key S1, and in the case of a GLA token, V is used for cryptographic operations on at least B with the key S T1 Similarly, in the case of an ILA token, A is based on an encryption of the combination of at least H4 and the KeyID of B with S1, and in the case of a GLA token, A is based on an encryption of a combination of at least H4 and the KeyID of B with S T1The key H3 (and its partner H4) can be chosen differently for each token in the case of ILA and GLA tokens, for example. In contrast to tokens 61 and 68, the information B, V, A, and H3 for tokens 62 and 74 is more durable, as the effort required to register this information is complex and is preferably performed only once, particularly during the production of tags 62 and 74 or during delivery or commissioning.
[0121] Depending on the architecture of the token 62, 74, the third key H3 (which can also be called the device key) can be stored in an externally inaccessible memory of the token and only accessible internally, for example, to a processor of the token 62, 74, while the authentication information A, for example, is stored in a memory area readable by a reader (e.g., an NFC reader, especially of the lock). B and V can be contained in a memory area that is only made available for reading, for example, after mutual authentication has taken place between the reader / lock and the token 62, 74. The process 500, to open a lock, then proceeds as in Fig. Figure 5 is shown below. In step 501, NFC communication is initialized between tokens 62, 74 and the lock.
[0122] In step 502, mutual authentication takes place between tokens 62 and 74 and the lock based on keys H3 and H4. For example, the lock first reads the information A from token 62 or 74 and then decrypts it with key S2 or key S. T2 Key H4. Which key, S2 or S? T2 The lock can be identified, for example, by the LockID, which is also read from token 62, 74 (e.g., as part of A or separately from it), for example, by predefined bit positions that indicate whether it is an ILA token (-> use of S2 required) or a GLA token (-> use of S T2(required). An initialization vector IV can also be read from the token 62, 74, if required depending on the type of encryption, for example as part of A or separately from it. Based on H3 (token) and H4 (lock), an authentication protocol is then carried out, for example the DESFire authentication protocol or any other authentication protocol, which may be based on a challenge-response procedure. It may also be sufficient, for example, for the lock to authenticate itself against the token 62, 74, for example by converting a challenge provided by the token into a response using its key H4, which is then cross-checked in the token against H3.
[0123] Upon successful authentication, the token 62, 74 can, for example, allow the lock (or its reader) to read the information B and V.
[0124] The verification of the authenticity and integrity of B and V then takes place in step 503 analogously to step 403 of the Fig. 4 described, where V is either based on S2 (in the case of ILA tokens) or S T2 (with GLA tokens) is checked. Which key S2 / S T2 The choice of which to use can be determined based on the structure of the LockID contained in the token, as has already been explained.
[0125] Regarding the verification of the access authorization parameters contained in B, reference can also be made to the description for step 403 of the Fig. 4 is referenced, with the difference that the LockID contained in B is compared either with the LockID of the lock (in the case of ILA tokens) or with the GroupID of the lock (in the case of GLA tokens). The lock is opened if B and V are found to be authentic and integer, the check of the access authorization parameters against their reference values present in the lock is successful, and the permissions indicate that opening at least one door is permitted. Submission of the rejection list
[0126] For example, the token does not need to authenticate when transmitting the rejection list. A replay attack cannot be carried out because of the counter contained in the rejection list. The distribution of the rejection lists to the locks can preferably be carried out by the handheld scanners 68 and the mobile phone 61; however, GLA tokens 74, which are specially reprogrammed for this purpose so that they can contain and transmit rejection lists, can also be used for this purpose.
[0127] The process 600 for transmitting the rejection list using ILA tokens (e.g., handheld scanner 68, mobile phone 61, and tag 74) is described below. The ILA token receives, for example, the following information from the key server: rejection information L (containing the rejection list) and fourth check information V. L, for example by performing cryptographic operations over at least L using S1 (ILA token) or S T1 (GLA token) is generated.
[0128] Process 600 then proceeds as follows: In step 601, after a Bluetooth or NFC connection has been established, the token 61, 68, 74 transmits the rejection information L and the validation feature V. L In step 602, the authenticity of L is verified by the lock using V. L and the key S2 or S T2The system checks the values, which are selected based on the structure of the LockID in L. Then, for example, the contents of L can be checked, such as whether the LockID matches the LockID of the lock, and / or whether the Counter value is greater than the value tracked in the lock for the rejection lists. If this is the case, the new rejection list from L is adopted in the lock (by replacing the old one), and the value for the rejection lists in the lock is set to the Counter value from L. In step 603, a response is then sent to the token (OK, ERROR, WARNING).
[0129] The `Counter` value ensures that the rejection list cannot be overwritten by an older rejection list. Since the rejection list is complete when it is generated, the lock can replace all previous KeyIDs with the current KeyIDs. In particular, KeyIDs of invalid access authorizations are removed from the rejection list to keep it short. Update of group keys
[0130] The key S2, which is responsible for individual access, remains constant throughout the entire life cycle of the lock. However, the key S T2 The key responsible for group access may be replaced one or more times (this can occur, for example, if a parcel box is moved to a different delivery area). For this reason, the modifiable key S T2According to the invention, it is protected by the unalterable - and therefore more secure - key S2
[0131] For example, handheld scanner 68 and mobile phone 61 are supposed to use the key S T2 (or possibly several keys already on the lock S T2 ) can exchange. For this purpose, key server 60 creates group key information, which includes, for example, one or more components of the following: a LockID, i.e., the ID of the lock to which the update refers, an update_counter as a unique counter for the update, and one or more entries, i.e., the group key list with the tuples (GroupID, S T2 ).
[0132] Token 61, 68 then receives, for example, a packaged key value W from key server 60, which contains at least the new group key(s) S. T2and each new GroupIDs are encrypted with the individual key S1 of the lock (or, for example, the entire group key information). This makes the new key S T2 The key information is not stored in plain text on the handheld scanner 68 or mobile phone 61 and can only be decrypted by the respective lock. Furthermore, the key server 60 also generates a validation value V. W , which is generated, for example, by cryptographic operations over at least W using the first key S1. These cryptographic operations can, in turn, represent, for example, a MAC function or a digital signature using S1.
[0133] The in Fig. The transmission process 700, as depicted in step 701, then proceeds as follows: In step 701, a token transmits 68 W and V. W to the lock. In step 702, the test information V is then evaluated. Wto establish the authenticity and integrity of W and V W using the key S2. If the result is positive, the group key list can be decrypted with the key S2 and further checks can be performed to determine whether this group key list may be adopted in the lock, e.g., by checking whether the LockID from the group key information (obtained by decrypting W) matches the LockID of the lock, and / or whether the update_counter value from the group key information is greater than the corresponding update-counter value for the current group key(s) in the lock. If the checks are successful, the current group key(s) S T2and the respective GroupID is replaced with the new values from the group key list and the update_counter in the lock is replaced with the value of the update_counter from the group key information. In step 703, the feedback to the token (OK / NOK) then takes place.
[0134] The `update_counter` prevents replay attacks, where an attacker might attempt to place one or more old group keys in the lock. The `LockID` in the group key information ensures that the update originates from key server 60 and was created for the specific lock. Another important process step, not explicitly mentioned here, is that key server 60 receives feedback (for example, from token 68) indicating whether the new group key(s) has been stored in the lock. This information is necessary so that the key server can generate usable access permissions for GLA tokens in the future. Sequence of operations
[0135] Fig. Figure 11 shows an exemplary flowchart 1100 illustrating the possible sequence of operations in a lock according to the invention. The operations to be performed by the lock can be communicated to the lock by the token, for example, by one or more commands. Thus, it is possible, for instance, to perform several operations in a single communication session, such as a group key update, the installation of a new rejection list, and an access authorization check to open the door. Depending on the desired operation, one or more of the operations described above and in Figure 11 are then executed. Fig. 1. Values shown: B, V, A, W, V W , L, V L , transferred from the token to the lock.
[0136] After starting step 1101, either one or more group keys on the lock can be updated (step 1102), a new rejection list can be installed in the lock (step 1103), token authentication (using key H4) can be performed (step 1104), or a firmware update of the lock software can be performed (step 1110). As described in Fig. As shown in Figure 11, some steps, e.g., steps 1102, 1103, and 1104, can also be performed sequentially. Fig. Paragraph 11 should be understood to mean that each operation is basically optional, so, for example, only step 1102, step 1104 and step 1109 can be performed if desired. Furthermore, processing can therefore also be terminated after each operation, for example after step 1102.
[0137] After successful token authentication 1104, the electronics can either be reset (reset in step 1109), the lock status can be queried (step 1108), or a verification of a received access authorization B can be performed (step 1105). A reset can also be performed optionally after both steps (step 1109). If, for example, access authorization B authorizes the opening of one or more doors of parcel box 69, these door(s) will be opened (step 1106). Even after querying the status (step 1108), the door can optionally be opened – provided authorization is granted (step 1106).
[0138] As from Fig. As can be seen in section 11, the door will not open after the reset (step 1109) or the firmware update (step 1110). Furthermore, the installation of the rejection list (step 1102) and the update of one or more group keys (step 1102) always take place before the access authorization check, as the rejection list or the group key(s) may be required for this check.
[0139] The following describes the exemplary implementation of the access control system. Fig. Section 3 explains how the access authorizations and keys are assigned to the devices of the delivery personnel 70 and users 63 and to the parcel boxes 69. Delivery process via handheld scanner
[0140] The allocation server 67 performs the so-called district division, i.e., dynamically defines delivery districts based on the daily shipment volume and the available delivery personnel. As part of this district division, the parcel boxes 69 belonging to a respective district are identified based on their parcel box address (or the addresses of their users). It is assumed that this allocation is dynamic, i.e., no statement can be made in advance as to which parcel boxes 69 will belong to which district.
[0141] The master data for the parcel boxes, described in more detail below, which includes access authorizations for the respective parcel boxes and the H3 key, as well as, for example, the address data of the parcel box users, is then distributed regionally in several intermediate steps. These intermediate steps are irrelevant for the following considerations. Ultimately, one, or possibly several, districts are assigned to a decentralized unit (e.g., a computer or server), from which the handheld scanners 68 are "populated" with the master data (and the address data of the parcel box users) for a selected district. The shipment data (target data) is also transferred from the decentralized unit to the handheld scanner during this process.
[0142] The assignment of handheld scanners to a district is dynamic and occurs after the district boundaries have been defined.
[0143] The above process can be summarized as follows: 1. Define delivery districts (for example, primarily based on the delivery / collection addresses of shipments, the volume of shipments and the available delivery personnel) 2. Distribute master data of the parcel boxes assigned to the delivery districts (and address data of the parcel box users) to the decentralized units. 3. Delivery driver 70 registers with handheld scanner 68 at the decentralized unit. 4. Delivery driver number 70 picks up packages for his district 5. Delivery driver 70 delivers the parcels for parcel boxes 69 in his district.
[0144] If access authorization is created for a handheld scanner (68), the validity period is set to, for example, 1 day. Furthermore, a parameter is provided, for example, that limits the maximum number of uses of this access authorization. Access permissions for handheld scanners
[0145] The key server 60 generates access authorizations B for each lock (of a parcel box 69) together with the corresponding validation feature V. Each delivery person 70 should receive access authorizations B for those parcel boxes 69 (i.e., their locks) together with the validation features V to which they are to deliver on that day, i.e., those in their delivery district.
[0146] Fig. Section 8 provides an overview of an example of a process 800 for delivery with access permissions. The process is as follows: In step 801, for example, key server 60 generates the access permissions B every day. i (where the index i=1..N denotes the respective lock out of a total of N locks), each with corresponding lock key S 1,i (which in turn is connected to a key S stored in the lock) 2,i (forming a symmetric or asymmetric key pair) are validated. For this purpose, pairs (B i,V i ) calculated, where B i an access authorization and V i The previously described associated first test information is that which uses the key S 1,i is generated. In addition, the key server generates, for example, a device key H4 (which forms a symmetric or asymmetric key pair with another key H3), with which a handheld scanner 68 can authenticate itself to a lock of a parcel box 69, and encrypts this (and, for example, one or more other parameters, e.g., the KeyID) with the respective lock key S. 1,i , to create an authorization feature A i to produce.
[0147] All access authorizations are transferred daily (e.g., according to the generation frequency of key server 60) from key server 60 to provisioning server 66 in step 802. The following master data is transferred for each lock: Access authorization B i , Validation V i , and authorization feature A iOptionally, the LockID can also be included. On the provisioning server, the master data can be enriched with further information, such as the MAC address of the lock, and / or address information for the parcel box, and / or address information for the users of the respective parcel boxes, to name just a few examples. However, such information may already have been added to the master data on key server 60. As already mentioned, the MAC address is the Medium Access Control address of the lock, which allows the lock to be addressed directly, for example, without the need for Bluetooth pairing. Fig. For the sake of clarity, step 802 only involves the transfer of the large number of master data records {B i , V i , A i} and the key H3 to the deployment server. In step 803, the district intersection takes place on the allocation server 67.
[0148] In step 804, each of the L decentralized units 71-1 .. 71-L receives all access rights for the districts assigned to it on that day. This is symbolically represented in step 804 by the notation {B i , V i , A i} l represented, where the index l runs from 1 to L and the notation {B i , V i , A i} l The master data of all parcel boxes in district l is designated (where, for the sake of clarity, the additional master data elements LockID, address information, and MAC address are not shown, and it is assumed that each decentralized unit only receives the master data of the parcel boxes in a respective delivery district, although this is not mandatory). A decentralized unit then "fuels" one (or more) handheld scanners within a delivery district l with the master data {B i , V i , A i} l of the parcel boxes in this delivery district.
[0149] A handheld scanner 68-2 (this is an example of a handheld scanner assigned to the second decentralized unit 71-2 and its delivery district l=2) receives the master data {B} during refueling. i , V i ,A i}2 of the parcel boxes for the district l=2 to which it was assigned (step 805). This can be done, for example, via wired (e.g., via a docking station connected to the decentralized unit 71-2, into which the handheld scanner 68-2 is placed) and / or wireless communication (e.g., via WLAN or GPRS).
[0150] In step 806, the handheld scanner 68-2 - to open an exemplary parcel box 69-k from its district - establishes a Bluetooth connection with the lock using the MAC address of the lock of this parcel box 69-k and transmits the access authorization B. k , the validation information V k , the authorization feature Ak and further validation information such as to Fig. 4 described at the lock (step 806).
[0151] In step 807, the lock validates the authorization using V k and S 2,k (analogous to the description of the Fig. 4) and opens if the correct authorization is granted. In step 808, a corresponding status message and, for example, the battery status are finally sent back to the handheld scanner.
[0152] As explained above, handheld scanner 68-2 is authenticated to the lock of parcel box 69-k using key H3. Handheld scanner 68-2 is not assigned an individual device key H3. Instead, a group key H3 is generated, with all handheld scanners 68 forming the relevant group and using the same key H3. During refueling, the group key H3 is transferred to a handheld scanner. An access authorization for this "group key" H3 is then issued for each lock, effectively valid for all handheld scanners. Key H3 is transmitted, for example, from key server 60 to the deployment server (step 802) and then to all decentralized units (step 804), preferably via secure connections to prevent eavesdropping.For example, the transfer from key server 60 to deployment server 66 and / or to decentralized unit 71-2 is encrypted using SSL / TLS. Likewise, the connection between decentralized unit 71-2 and handheld scanner 68-2 should be secured accordingly during refueling. Blocking handheld scanners
[0153] The access authorizations used by the handheld scanners 68 are reissued, for example, for a single day. If it becomes necessary to block a handheld scanner 68, for instance, after the device has been lost, a rejection list must be created for each lock to which the handheld scanner 68 had access. This rejection list would then have to be transferred to the corresponding locks and activated using some kind of "token," which is a considerable undertaking.
[0154] This problem is adequately solved by issuing access authorizations B for the narrowest possible time window (e.g., validity of only 1 day) and / or for the fewest possible uses (e.g., a maximum of 3 uses per day). Additionally or alternatively, the handheld scanner software can restrict the use of the access authorizations as much as possible, for example, by only offering the option to open the lock of parcel box 69 if a corresponding shipment for that parcel box 69 is present (this can be achieved, for example, by comparing the address data (e.g.,Postal code, street, and house number, contained in coded form in the so-called "route code," are used to match shipments with the address data contained in the master data (which is coded in a similar way to the route code) of parcel boxes 69 and / or the addresses (which are coded in a similar way to the route code) of users 63 of parcel boxes 69 (which then allow for the unambiguous assignment of a parcel box 69). These addresses are transferred to the handheld scanner specifically for this purpose. It should also be ensured that a "locked" handheld scanner, especially after being lost, is not connected to and recharged by a decentralized unit on subsequent days.
[0155] This approach eliminates the need for dedicated blocking of handheld scanners 68 via rejection lists. In particular, the rejection lists used to block other lost ILA and / or GLA tokens (e.g., mobile phones 61, delivery tags 74, and user tags 62) remain smaller, which is advantageous since these must be stored by the lock. The advantages of rejection lists for the use of mobile phones 61 and, where applicable, NFC tags 74 and 62 (where access authorizations have a longer validity period than those on the handheld scanners 68) do not apply to handheld scanners when using the approach described above. Transfer of the rejection lists
[0156] As from Fig. As can be seen in section 11, the handheld scanner 68 does not need to authenticate itself to the lock when transmitting a rejection list (step 1103). Accordingly, the restrictions that arise when using access authorizations (especially regarding authentication) do not apply. The rejection lists can, for example, be enriched as master data for each lock in the provisioning server 66 and transferred to the handheld scanners 68 during the refueling process. This may result in a longer time for opening a lock, since according to Fig. 11. The transmission of the rejection list to the lock (step 1103) takes place before the authorization check (step 1105). Furthermore, since the key server 60 has no information about the successful transmission of a rejection list to a lock, the current rejection list would be distributed and transmitted with every access to the lock.
[0157] The following procedure appears advantageous: Locks are initiated by a primary user, a co-user, or on their behalf. The rejection lists subsequently generated by the key server 60 are then transmitted via the corresponding mobile phone to the lock of the parcel box 69. The handheld scanner 68 reports the successful or unsuccessful transmission of the rejection list to the lock to the key server 60 via the provisioning server 66. Key for delivery personnel with NFC token
[0158] As described in section [number], there is a difference between ILA-type tokens (handheld scanner 68, mobile phone 61, NFC token 62 from parcel box users 63) and GLA-type tokens (NFC token 74 from delivery personnel 70). There are several reasons for this distinction, which are listed below: 1. NFC tokens cannot be equipped with access permissions without some effort. 2. NFC tokens used by delivery personnel should be able to open all locks within a specific, particularly static, area. 3. NFC tokens are not able to store many access permissions.
[0159] Requirement (2) clarifies that delivery personnel 70 should be equipped with an NFC token 74 that is valid within a specific area. For this purpose, a group key S is stored on the NFC token 74. T1 stored, which can open a group of locks (and thus parcel boxes 69). As can be seen from requirement (3), it is not possible to equip delivery personnel 70 with individual access authorizations for all locks in a specific area.
[0160] For this reason, the lock is equipped with two or possibly more (symmetrical or asymmetrical) keys: One key S2 ("individual key", with corresponding symmetrical or asymmetrical key S1) to interact with ILA tokens, and one or more keys S T2 (Group key, with corresponding symmetric or asymmetric key S) T1 ) for operations with the GLA tokens of the delivery forces 70. The main difference between these keys is that the first-named key S2 is unique for each lock and the second key S T2 is divided by several locks.
[0161] While the unique key S2 of the lock is applied during the production process – and is, in particular, unalterable – the group key S T2 can be dynamically changed during the operating time of the lock (e.g. by a handheld scanner 68).
[0162] The interchangeable keys S are listed below. T2 described for GLA tokens.
[0163] Key server 60 generates an access authorization and provides it with validation information according to the corresponding group keys S. T1 of a respective delivery area. The device keys are printed on the NFC tokens of the delivery personnel along with an access authorization.
[0164] This is schematically shown in the Fig. Figure 9 shows how NFC tokens (M pieces) 74-1 ... 74-M are distributed to the respective delivery personnel (e.g., via a server of token production 73) to open locks in N areas (area 1 ... area N). Accordingly, the group keys S are distributed via the server of lock production 72 (or later via the update function for group keys). T2,1 ..S T2,Nstored in the locks of the parcel boxes of the respective areas 1..N, i.e. group key S T2,1 into the locks of the parcel boxes in area 1 etc.
[0165] Suppose an NFC token i requires access to all locks in a delivery area j. In this case, token i needs the following information (data): Access permissions B j ; Validation feature V j of the delivery area j (formed by cryptographic operations over B) j using the group key S T1,j ); Authentication value A j , which in turn contains at least one with S T1,j encrypted combination of at least the key H 4,i and the KeyID j includes, for example, the LockID. jThis includes the group identifier of area j, which is encoded. Now, in a delivery area j (j from 1 to N), every delivery person who has access authorization for area j can open any lock with their NFC token.
[0166] Delivery areas are static in nature. Requirement (1) must be considered here, which states that it is technically and economically cumbersome to change (update) access permissions too frequently. On the other hand, access permissions that are valid indefinitely should not be used, as this poses an increased security risk. Therefore, it is advisable to issue access permissions for an extended but limited period, e.g., a few months or years. After the expiry of the validity period, all tokens must be reprogrammed to issue new access permissions. j to obtain. Group key
[0167] In the system of Fig. 3. For example, it may be intended that mail carriers use the NFC tags 74 to open parcel boxes (e.g., for the delivery of large-format letters), and that the NFC tags 74 are also used by parcel carriers, at least temporarily (e.g., as an alternative to handheld scanners 68). It should be noted that delivery areas for carriers in ZB (regular delivery, delivery bases) and ZSPL (combined delivery, i.e., delivery of letters and parcels) may overlap.
[0168] It is therefore possible that a parcel box will be opened once with a tag that "belongs" to a specific delivery area, and once with a different tag that belongs to a different delivery area.
[0169] This is schematically shown in Fig. Figure 10 shows the following. A first parcel box 110 is assigned only to a first delivery district 11 (ZB), and a second parcel box 120 is assigned to a second delivery district 12 (ZSPL), while a third parcel box 130 is assigned to both the first delivery district 11 and the second delivery district 12.
[0170] This problem can be solved by separating parcel boxes located in an overlapping area (e.g., parcel box 130 in [location]). Fig. 10), receive two group keys and then be able to grant access to both tags (possibly more than two, but for example a maximum of five).
[0171] Each delivery area (group) has a GroupID (group identifier). The group keys S T2 are then stored in the lock along with the corresponding GroupIDs: (GroupID1,ST2,1),(GroupID2,ST2,2), …
[0172] If the delivery base area ZB 11 has a GroupID GroupZB and the ZSPL 12 has a GroupID GroupZSPL, and S T2,ZB and S T2,ZSPL If the corresponding group keys are present, then the lock of parcel box 110 has the tuple (GroupZB, S T2,ZB ) stored, the lock of the parcel box 120 the tuple (GroupZSPL, S T2,ZSPL ) saved and the lock of the parcel box 130 both tuples (GroupZB, S T2,ZB ) and (GroupZSPL, S T2,ZSPL Each of the locks also has its own individual key S. 2,i as described above.
[0173] During the authentication phase, a token transmits the LockID, which is also contained in the access authorization for the lock. The LockID instructs the lock (e.g., through the encoding of predetermined bit positions within the LockID) which key should be used for decryption and validation. The LockID either points to the lock's individual key S2 or to one of potentially several group keys S. T2 this is achieved by encoding the GroupID accordingly into the LockID.
[0174] In the example above, a delivery person from ZB 11 can open the lock of parcel box 130 by transmitting GroupZB as part of the LockID. Similarly, a delivery person from ZSPL 12 can open the lock of parcel box 130 by transmitting GroupZSPL as part of the LockID. The lock has both keys and can respond accordingly.
[0175] If a GLA token, e.g., from area ZB 11, is lost, only the locks of the parcel boxes in area ZB 11, specifically parcel boxes 110 and 130, need to receive a corresponding rejection list update. The locks of the parcel boxes in ZSPL 12, however, do not need to be updated with a new rejection list. Key H and access permissions of the owner's NFC token
[0176] It has already been explained how the key server 60 generates the access authorizations and keys for the handheld scanners 68 and how these access authorizations are transferred to the handheld scanners 68. The key server 60 also generates the keys and access authorizations for the user 63 of the parcel box, in particular its owner. The user 63 of the parcel box, for example, always has one NFC token 62 available. For example, when ordering, the user 63 receives two NFC tokens 62 for their parcel box 69.
[0177] The opening of the lock of parcel box 69 with an NFC token 62 then proceeds as follows: The key server 60 generates the access authorization B for the NFC token 62, each of which is validated with the corresponding (lock-specific) key S1. The key S1 forms a symmetric or asymmetric key pair with a key S2 stored in the lock. A pair (B,V) is calculated as already described several times, where B represents an access authorization and V, for example, a MAC address or a digital signature for the authorization B using the key S1. An authentication feature A is also calculated, which comprises a combination encrypted with S1 of at least the key H4 and the KeyID, and, for example, additionally the LockID, where H4 forms a symmetric or asymmetric key pair with a key H3, and the key H3 is stored in the token.KeyID is an identifier for access authorization, and LockID encodes the individual identifier of the lock. Authorization B, features V and A, and key H3 are transmitted to a programming station. The programming station writes the data B, V, A, and H3 to the NFC token(s) 62 of the user 63. To open the parcel box 69, the NFC token 62 establishes a connection with the lock of the parcel box 69, authenticates itself to the lock, and transmits the access authorization and validation features (see the description for [reference]). Fig. 5) The lock validates the authorization using the validation features and opens if sufficient authorization is granted.
[0178] The following embodiments of the present invention shall be disclosed: Example 1: Access control procedure carried out by means of an access control device (4), the procedure comprising - Receiving access authorization information (B, V) communicated to the access control device (4), which includes at least one or more access authorization parameters (B) and initial verification information (V), - first check, using at least the communicated access authorization parameters (B), the communicated first check information (V) and a second key (S2, S) stored in the access control device (4). T2 ) of a symmetric or asymmetric key pair, whether the communicated first verification information (V) can be used to perform cryptographic operations on the communicated access authorization parameters (B) corresponding access authorization parameters (B) using at least one first key (S1, S2). T1 ) of the key pair was generated, - Decide whether access may be granted, whereby necessary conditions for granting access are that the first check yields a positive result and it is established that at least a predefined set of the communicated access authorization parameters (B) with respect to the respective reference information present at least at the time of the first check in the access control device (4) authorize access. Example 2: Method according to embodiment 1, wherein the key pair is an asymmetric key pair, and wherein the first check comprises checking the communicated first check information (V) as a digital signature via the access authorization parameters (B) using at least the second key of the key pair and the communicated access authorization parameters (B). Example 3: Method according to embodiment 1, wherein the key pair is a symmetric key pair, and wherein the first check is the execution of the cryptographic operations over the communicated access authorization parameters (B) using at least the second key (S2, S3). T2 ) of the key pair to obtain locally generated first test information and to compare the communicated first test information (V) with the locally generated first test information. Example 4: Method according to embodiment 3, wherein the cryptographic operations for determining a message authentication code (MAC) serve as verification information (V). Example 5: Method according to one of embodiments 1-4, wherein the access control device (4) is an access control device (4) from a plurality of access control devices, wherein a second key (S2) of a symmetric or asymmetric individual key pair is stored in the access control device (4), which is stored only on the access control device but not on any of the other access control devices of the plurality of access control devices, and wherein the second key (S2, S) used in the first check T2 ) of the key pair, the second key (S2) of the individual key pair is Example 6: Method according to one of embodiments 1-4, wherein the access control device (4) is an access control device (4) from a plurality of access control devices, wherein a second key (S2) of a symmetric or asymmetric individual key pair is stored in the access control device (4), which is stored only on the access control device, but not on any of the other access control devices of the plurality of access control devices, wherein the access control device (4) additionally contains a second key (S) different from the second key (S2) of the individual key pair T2 ) of a symmetric or asymmetric group key pair that is stored in all access control devices of a group of access control devices comprising the access control device (4) of the plurality of access control devices, where the second key used in the first check (S2, S) T2 ) of the key pair either the second key (S2) of the individual key pair or the second key (S T2) of the group key pair is Example 7: Method according to embodiment 6, wherein in the access control device (4) at least one of the second key (S2) of the individual key pair and the second key (S T2 ) of the group key pair of different second keys (S T2 ) of a symmetric or asymmetric further group key pair, which is stored in all access control devices of a further group of access control devices comprising the access control device (4), but which, compared to the group of access control devices, includes at least one or more other access control devices of the plurality of access control devices, and wherein the second key used in the first check (S2, S) T2 ) of the key pair either the second key (S2) of the individual key pair, the second key (S T2) of the group key pair or the second key (S T2 ) of the further group key pair. Example 8: Method according to one of embodiments 6-7, wherein it is not provided to change, delete or exchange the second key (S2) of the individual key pair in the access control device (4) for another key, but wherein it is provided that the second key (S T2 ) of the group key pair can be changed, deleted, or replaced with another key. Example 9: Method according to one of embodiments 6-8, further comprising: - Receipt of group key information (W) communicated to the access control device (4), which includes at least one second key (S) encrypted with the first key (S1) of the individual key pair T2) of a new symmetric or asymmetric group key pair for the same or at least partially different group of access control devices of the multitude of access control devices, - Decrypting the communicated encrypted second key (S T2 ) of the new group key pair with the second key (S2) of the individual key pair, and - Storing the second key obtained through decryption (S T2 ) of the new group key pair in the access control device, so that the second key (S2, S) used in the first check T2 ) of the key pair, at least either the second key (S2) of the individual key pair or the second key (S T2 ) of the new group key pair. Example 10: Method according to embodiment 9, further comprising: - Receipt of second test information communicated to the access control device (4) (V W ), and - Storing the second key obtained through decryption (S T2 ) of the new group key pair in the access control device (4) only on the condition that, in the case of at least one communicated second test piece (V W ), based on the second key (S2) of the individual key pair and the communicated group key information (W), it is determined that the communicated second check information (V) W ) by performing cryptographic operations on the group key information corresponding to the communicated group key information (W) using at least the first key (S1) of the individual key pair. Example 11: Method according to embodiment 10, wherein the group key information additionally includes a counter (update_counter) which is incremented with each new group key pair, and wherein the second key obtained by decryption (S T2 ) of the new group key pair in the access control device (4) is stored only under the additional condition that a value of a counter included in the group key information (update_counter) is greater than a value of a counter provided in the access control device (4), and wherein, at or after the storage of the second key (S T2 ) of the new group key pair in the access control device (4) the value of the counter in the access control device (4) is updated to the value of the counter (update_counter) included by the group key information. Example 12: Method according to one of embodiments 10-11, wherein the group key information additionally includes an individual identifier (LockID) of the access control device (4), and wherein the second key obtained by decryption (S T2 ) of the new group key pair in the access control device (4) is stored only under the additional condition that an individual identifier (LockID) of the access control device (4) stored in the access control device (4) matches the individual identifier (LockID) included in the group key information. Example 13: Method according to one of embodiments 9-12, wherein the group key information additionally includes a group identifier (GroupID) associated with the new group key pair, which is common to all access control devices of the group of access control devices for which the new group key pair is intended, and wherein the group identifier (GroupID) obtained by decryption is stored in the access control device (4). Example 14: Method according to one of embodiments 1-13, wherein one of the communicated access authorization parameters is an identifier (LockID) for only one access control device (4) or a group of access control devices, and wherein it is determined that the identifier authorizes access if the identifier (LockID) matches an individual identifier (LockID) of the access control device (4) stored in the access control device (4) and / or a group identifier (GroupID) for a group of access control devices to which the access control device (4) belongs. Example 15: Method according to one of embodiments 6-14, wherein one of the communicated access authorization parameters is an identifier (LockID) for only one access control device (4) or for a group of access control devices, wherein it is determined that the identifier (LockID) authorizes access if the identifier matches an individual identifier (LockID) of the access control device (4) stored in the access control device (4) and / or a group identifier (GroupID) for a group of access control devices to which the access control device (4) belongs, wherein the first verification information (V) of communicated access authorization information, which has an identifier (LockID) for only one access control device (4), is generated by performing cryptographic operations on the access authorization parameters (B) using at least one first key (S) of the individual key pair,and wherein the first verification information (V) of communicated access authorization information, which has an identifier (LockID) for a group of access control devices, is obtained by performing cryptographic operations on the access authorization parameters using at least one first key (S, T ) of the group key pair is generated. Example 16: Method according to embodiment 15, wherein, based on the identifier (LockID), in particular based on a predefined format of the identifier, it can be recognized in the access control device (4) whether it is an identifier for only one access control device (4) or an identifier for a group of access control devices, so that for the first check either the second key (S2) of the individual key pair or the second key (S T2 ) of the group key pair can be selected. Example 17: Method according to one of embodiments 1-16, wherein one of the communicated access authorization parameters (B) is an identifier (KeyID) for the access authorization information (B, V) or for an access authorization verification device (3) that communicates the access authorization information (B, V) to the access control device (4), and wherein it is determined that the identifier (KeyID) authorizes access if the identifier is not included in a rejection list (RL) stored in the access control device (4). Example 18: Method according to one of embodiments 1-16, further comprising: - Receiving information (A) communicated to the access control device (4), which includes at least one key (S1, S2) used by at least the first key (S1, S2). T1) of the key pair includes the encrypted fourth key (H4), which can be used for authentication of the access control device (4) to an access authorization verification device (3) that communicates the access authorization information to the access control device (4), or for checking the authenticity and / or integrity of information communicated to the access control device (4), and - Decrypting the encrypted fourth key using at least the second key (S2, S T2 ) of the key pair to obtain the fourth key (H4). Example 19: Method according to one of embodiments 1-16, further comprising: - Receipt of information (A) communicated to the access control device (4), which includes at least one key (S1, S2) used by at least the first key (S1, S2). T) 1 of the key pair comprises an encrypted combination of a fourth key (H4) and an identifier (KeyID) for the access authorization information (B, V) or for an access authorization credential device (3) that communicates the access authorization information (B, V) to the access control device (4), wherein the fourth key (H4) is usable for authenticating the access control device (4) to an access authorization credential device (3) that communicates the access authorization information (B, V) to the access control device (4), or for verifying the authenticity and / or integrity of information communicated to the access control device (4), and - Decrypting the encrypted combination using at least the second key (S2, S3). T2) of the key pair to obtain the fourth key (H4) and the identifier (KeyID), wherein the identifier (KeyID) additionally represents one of the communicated access authorization parameters (B), and wherein it is determined that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted information Example 20: Method according to one of embodiments 1-16, further comprising: - Receiving information (A) communicated to the access control device (4), which includes at least one key (S1, S2) used with at least the first key (S1, S2). T1) of the key pair comprises an encrypted combination of a fourth key (H4) and an identifier (KeyID) for the access authorization information (B, V) or for an access authorization credential device (3) that communicates the access authorization information (B, V) to the access control device (4), wherein the fourth key (H4) is usable when authenticating the access control device (4) to an access authorization credential device (3) that communicates the access authorization information (B, V) to the access control device (4), or when verifying the authenticity and / or integrity of information communicated to the access control device (4), and - Decrypting the encrypted combination using at least the second key (S2, S3). T2) of the key pair to obtain the fourth key (H4) and the identifier (KeyID), wherein the identifier (KeyID) additionally represents one of the communicated access authorization parameters (B), and wherein it is determined that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted information and the identifier (KeyID) is not included in a rejection list (RL) stored in the access control device (4). Example 21: Method according to one of embodiments 19-20, wherein the access authorization information (B, V) communicated to the access control device (4) is stored in identical form on at least two access authorization verification devices (3), wherein the identical access authorization information (B, V) stored on the at least two access authorization verification devices (3) each have the same identifier (KeyID) for the access authorization information (B, V) and this access authorization information (B, V) is each associated with the same fourth key (H4). Example 22: Method according to embodiment 21, wherein the access authorization information (B, V) communicated to the access control device (4) has a limited validity period and / or only allows a limited number of access operations within its validity period and / or can only be communicated by the access authorization verification device (3) to the access control device (4) if it is determined at the access authorization verification device (3) that there is a need for access to the access control device (4). Example 23: Method according to one of embodiments 18-22, wherein the fourth key (H4) forms a symmetric or asymmetric key pair with a third key (H3), and wherein the communicated access authorization information (B, V, V') further comprises third verification information (V'), the method further comprising: - second check, using at least one challenge (R) generated by the access control device (4), the communicated access authorization parameters (B), the communicated first check information (V), the communicated third check information (V') and the fourth key (H4), to verify whether the communicated third check information (V') was generated by performing cryptographic operations on information corresponding to the generated challenge (R), the communicated access authorization parameters (B) and the communicated first check information (V), using at least the third key (H3), wherein a further necessary condition for granting access is that the second check yields a positive result. Example 24: Method according to one of embodiments 18-22, the method further comprising: - Authentication to an access authorization device (3) containing the access authorization information (B, V) using at least the fourth key (H4), wherein the access authorization information (B, V) is communicated from the access authorization device (3) to the access control device (4) only upon successful authentication. Example 25: Method according to one of embodiments 17 and 20, further comprising: - Receipt of rejection information (L) communicated to the access control device (4), which includes at least one new rejection list (RL) with identifiers (KeyIDs) for access authorization information (B, V) to be rejected or for access authorization verification devices (3) from which access authorization information (B, V) is to be rejected at the access control device (4), and of fourth verification information (V L ), and - Saving the communicated new rejection list (RL) only if at least one fourth check information (V) communicated is present L ), the second key (S2, S T2 ) of the key pair and the communicated rejection information (L) it is determined that the communicated fourth check information (V) L ) by performing cryptographic operations on the rejection information corresponding to the communicated rejection information (L) using at least the first key (S1, S2) T1 ) of the key pair was generated. Example 26: Method according to embodiment 25, wherein the rejection information (L) additionally includes a counter which is incremented with each new rejection list (RL), and wherein the new rejection list (RL) is stored in the access control device (4) only under the additional condition that the value of the counter included in the rejection information (L) is greater than a value of a counter provided in the access control device (4), and wherein the value of the counter of the access control device (4) is updated to the value of the counter included in the rejection information (L) at or after the storage of the new rejection list (RL) in the access control device (4). Example 27: Method according to one of embodiments 25-26, wherein the rejection information (L) additionally includes an identifier (LockID) of only one access control device (4) or a group of access control devices on which the new rejection list (RL) is to be stored, and wherein the new rejection list (RL) is stored in the access control device (4) only under the additional condition that an individual identifier (LockID) of the access control device (4) stored in the access control device (4) or a group identifier (GroupID) for a group of access control devices containing the access control device (4) matches the identifier included in the rejection information. Example 28: Method according to one of embodiments 1-27, wherein one of the communicated access authorization parameters (B) specifies the extent to which, in particular to which openings of the access control device (4) or of a device controlled by the access control device (4), access is to be granted. Example 29: Computer program, comprising program instructions that cause a processor to execute and / or control the method according to one of embodiments 1 to 28 when the computer program is running on the processor. Example 30: Access control device, configured to execute and / or control the method according to one of embodiments 1-28 or comprising respective means for executing and / or controlling the steps of the method according to one of embodiments 1-28. Example 31: Use of an access authorization verification device (3) for communicating access authorization information to an access control device (4) according to embodiment 30. Example 32: - Example 33: - Example 34: Method for generating access authorization information (B, V), the method encompassing - Generating initial verification information (V) by performing cryptographic operations on one or more access authorization parameters (B) using at least one initial key (S1, S2) T1 ) of a symmetric or asymmetric key pair, - Generating access authorization information (B, V) that includes at least one or more access authorization parameters (B) and the first verification information (V), and - Outputting the access authorization information (B, V) for storage on an access authorization verification device (3) which is configured to communicate the access authorization information (B, V) to at least one access control device (4) in order to enable the latter to decide whether access may be granted on the basis of the communicated access authorization information (B, V), wherein necessary conditions for granting access are that a first check, using at least the communicated access authorization parameters (B), the communicated first check information (V) and a second key (S2, ST2) of the key pair stored in the access control device (4), is performed to determine whether the communicated first check information (V) can be used to derive corresponding access authorization parameters (B) by performing cryptographic operations on the communicated access authorization parameters (B) using at least the first key (S1,ST1) of the key pair, yields a positive result and it is determined that at least a predefined set of the communicated access authorization parameters (B) authorize access with respect to the respective reference information present at least at the time of the first check in the access control device (4). Example 35: Method according to embodiment 34, wherein the key pair is an asymmetric key pair, wherein generating the first verification information (V) includes generating a digital signature via the access authorization parameters (B) using at least the first key of the key pair. Example 36: Method according to embodiment 34, wherein the key pair is a symmetric key pair, and wherein the first check involves performing the same cryptographic operations (CRYPT) as are used in generating the first check information (V) over the communicated access authorization parameters (B) using at least the second key (S2, S3). T2 ) of the key pair to obtain locally generated first test information and to compare the communicated first test information (V) with the locally generated first test information. Example 37: Method according to embodiment 36, wherein the cryptographic operations for determining a message authentication code (MAC) serve as verification information (V). Example 38: Method according to one of embodiments 34-37, wherein the access control device (4) is an access control device (4) from a plurality of access control devices, wherein a second key (S2) of a symmetric or asymmetric individual key pair is stored in the access control device (4), which is stored only on the access control device (4) but not on any of the other access control devices of the plurality of access control devices, and wherein the first key (S1, S2) used in generating the first test information T1 ) of the key pair, the first key (S1) of the individual key pair is Example 39: Method according to one of embodiments 34-37, wherein the access control device (4) is an access control device (4) from a plurality of access control devices, wherein a second key (S2) of a symmetric or asymmetric individual key pair is stored in the access control device (4), which is stored only on the access control device (4) but not on any of the other access control devices of the plurality of access control devices, wherein in the access control device (4) an additional second key (S) different from the second key of the individual key pair T2 ) of a symmetric or asymmetric group key pair that is stored in all access control devices of a group of access control devices comprising the access control device (4) of the plurality of access control devices, where the first key used when generating the first test information (S1, S) T1 ) of the key pair either a first key (S1) of the individual key pair or a first key (ST1 ) of the group key pair is Example 40: Method according to embodiment 39, wherein in the access control device (4) at least one of the second key (S2) of the individual key pair and the second key (S T2 ) of the group key pair of different second keys (S T2 ) of a symmetric or asymmetric further group key pair, which is stored in all access control devices of a further group of access control devices comprising the access control device (4), but which, compared to the group of access control devices, includes at least one or more other access control devices of the plurality of access control devices, and wherein the second key used in the first check (S2, S) T2) of the key pair either the second key (S2) of the individual key pair, the second key (S T2 ) of the group key pair or the second key (S T2 ) of the further group key pair. Example 41: Method according to one of embodiments 39-40, wherein it is not provided to change, delete or exchange the second key (S2) of the individual key pair in the access control device (4) for another key, but wherein it is provided that the second key (S T2 ) of the group key pair can be changed, deleted, or replaced with another key. Example 42: Method according to one of embodiments 39-41, further comprising: - Generating group key information (W) that includes at least one second key (S) encrypted with the first key (S1) of the individual key pair T2 ) of a new symmetric or asymmetric group key pair for the same or at least partially different group of access control devices of the multitude of access control devices, - Outputting the group key information (W) for storage on the access authorization device (3), which is configured to communicate the group key information at least to the access control device (4) in order to enable it to use the communicated encrypted second key (S) by decrypting it. T2 ) of the new group key pair obtainable using at least the second key (S2) of the individual key pair T2) of the new group key pair in the access control device (4) so that the second key (S2, S) used in the first check T2 ) of the key pair either the second key (S2) of the individual key pair or the second key (S T2 ) of the new group key pair. Example 43: ▪ Method according to embodiment 42, further comprising: - Generating second test information (V W ), and - Output of the second test information (V W ) for storage on the access authorization verification device (3) which is set up, the second verification information (V W) at least to communicate to the access control device (4), and wherein the second key of the new group key pair obtainable by decryption is stored in the access control device (4) only on the condition that, in the event of a second test information communicated at least on the W ), based on the second key (S2) of the individual key pair and the communicated group key information (W), it is determined that the communicated second check information (V) W ) by performing cryptographic operations on the group key information corresponding to the communicated group key information (W) using at least the first key (S1) of the individual key pair. Example 44: Method according to embodiment 43, wherein the group key information (W) additionally includes a counter (update_counter) which is incremented with each new group key pair, and wherein the second key obtained by decryption (S T2 ) of the new group key pair in the access control device (4) is stored only under the additional condition that a value of a counter included in the group key information (update_counter) is greater than a value of a counter provided in the access control device (4), and wherein, at or after the storage of the second key (S T2 ) of the new group key pair in the access control device (4) the value of the counter in the access control device (4) is updated to the value of the counter (update_counter) included by the group key information. Example 45: Method according to one of embodiments 43-44, wherein the group key information additionally includes an individual identifier (LockID) of the access control device (4), and wherein the second key obtained by decryption (S T2 ) of the new group key pair in the access control device (4) is stored only under the additional condition that an individual identifier (LockID) of the access control device (4) stored in the access control device (4) matches the individual identifier (LockID) included in the group key information. Example 46: Method according to one of embodiments 42-45, wherein the group key information additionally includes a group identifier (GroupID) associated with the new group key pair, which is common to all access control devices of the group of access control devices for which the new group key pair is intended, and wherein the group identifier (GroupID) obtained by decryption is stored in the access control device (4). Example 47: Method according to one of embodiments 34-46, wherein one of the access authorization parameters (B) is an identifier (LockID) for only one access control device (4) or a group of access control devices, and wherein the access control device (4) determines that the identifier authorizes access if the identifier (LockID) matches an individual identifier (LockID) of the access control device (4) stored in the access control device (4) and / or a group identifier (GroupID) for a group of access control devices to which the access control device (4) belongs. Example 48: Method according to one of embodiments 39-46, wherein one of the access authorization parameters is an identifier (LockID) solely for the access control device (4) or for a group of access control devices that includes the access control device (4), wherein the access control device (4) determines that the identifier (LockID) authorizes access if the identifier matches an individual identifier (LockID) of the access control device (4) stored in the access control device (4) and / or a group identifier (GroupID) for a group of access control devices to which the access control device (4) belongs, wherein the first check information (V) of access authorization information, which has an identifier (LockID) solely for the access control device (4),by performing cryptographic operations on the access authorization parameters (B) using at least the first key (S1) of the individual key pair, and wherein the first verification information (V) of access authorization information, which has an identifier (LockID) for the group of access control devices, is generated by performing cryptographic operations on the access authorization parameters using at least the first key (S, T1 ) of the group key pair is generated. Example 49: Method according to embodiment 48, wherein, based on the identifier (LockID), in particular based on a predefined format of the identifier, it can be recognized in the access control device (4) whether it is an identifier for only one access control device (4) or an identifier for a group of access control devices, so that for the first check either the second key (S2) of the individual key pair or the second key (S T2 ) of the group key pair can be selected. Example 50: Method according to one of embodiments 34-49, wherein one of the access authorization parameters (B) is an identifier (KeyID) for the access authorization information (B, V) or for the access authorization verification device (3) which communicates the access authorization information (B, V) to the access control device (4), and wherein it is determined that the identifier (KeyID) authorizes access if the identifier is not included in a rejection list (RL) stored in the access control device (4). Example 51: Method according to one of embodiments 34-50, further comprising: - Encrypting a fourth key (H4) using at least the first key (S1, S2) T1) of the key pair, wherein the fourth key (H4) is usable for authentication of the access control device (4) to the access authorization verification device (3) which communicates the access authorization information to the access control device (4), or for checking the authenticity and / or integrity of information communicated to the access control device (4), - Generating information (A) that includes at least the encrypted fourth key (H4), and - Outputting the information (A) for storage on the access authorization device (3), which is configured to communicate the information (A) at least to the access control device (4) in order to enable it to generate the encrypted fourth key using at least the second key (S2, S3). T2 ) of the key pair to decrypt and use. Example 52: Method according to one of embodiments 34-50, further comprising: - Encrypting a combination of a fourth key (H4) and an identifier (KeyID) for the access authorization information (B, V) or for the access authorization verification device (3) that communicates the access authorization information (B, V) to the access control device (4), using at least the first key (S1, S T1 ) of the key pair, wherein the fourth key (H4) is usable for authentication of the access control device (4) to an access authorization verification device (3) which communicates the access authorization information (B, V) to the access control device, or for checking the authenticity and / or integrity of information communicated at the access control device (4), - Generating information (A) that includes at least the encrypted combination, and - Outputting the information (A) for storage on the access authorization device (3), which is configured to communicate the information (A) at least to the access control device (4) in order to enable it to generate the encrypted combination using at least the second key (S2, S3). T2 ) of the key pair to decrypt in order to obtain the fourth key (H4) and the identifier, wherein the identifier (KeyID) additionally represents one of the access authorization parameters (B), and wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted combination. Example 53: Method according to one of embodiments 34-50, further comprising: - Encrypting a combination of a fourth key (H) and an identifier (KeyID) for the access authorization information (B, V) or for the access authorization verification device (3) that communicates the access authorization information (B, V) to the access control device (4), using at least the first key (S1, S2). T1 ) of the key pair, wherein the fourth key (H4) is usable for authentication of the access control device (4) to an access authorization verification device (3) which communicates the access authorization information (B, V) to the access control device (4), or for checking the authenticity and / or integrity of information communicated to the access control device (4), - Generating information (A) that includes at least the encrypted combination, and - Outputting the information (A) for storage on the access authorization device (3), which is configured to communicate the information (A) at least to the access control device (4) in order to enable it to generate the encrypted combination using at least the second key (S2, S3). T2 ) of the key pair to decrypt in order to obtain the fourth key (H4) and the identifier, wherein the identifier (KeyID) additionally represents one of the access authorization parameters (B), and wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted combination and the identifier (KeyID) is not included in a rejection list (RL) stored in the access control device (4). Example 54: Method according to one of embodiments 52-53, wherein the access authorization information (B, V) communicated to the access control device (4) is stored in identical form on at least two access authorization verification devices (3), wherein the identical access authorization information (B, V) stored on the at least two access authorization verification devices (3) each have the same identifier (KeyID) for the access authorization information (B, V) and this access authorization information (B, V) is each associated with the same fourth key (H4). Example 55: Method according to embodiment 54, wherein the access authorization information (B, V) communicated to the access control device (4) has a limited validity period and / or only a limited permissible number of access operations within its validity period and / or can only be communicated by the access authorization verification device (3) to the access control device (4) if it is determined at the access authorization verification device (3) that there is a need for access to the access control device (4). Example 56: Method according to one of embodiments 51-55, wherein the fourth key (H4) forms a symmetric or asymmetric key pair with a third key (H3), the method further comprising: - Issuing the third key (H3) to the access authorization device (3) to enable the access authorization device (3) to generate a third verification information (V') and communicate it to the access control device (4) by performing cryptographic operations on a challenge (R) generated by the access device, the access authorization parameters (B) and the first verification information (V) using at least the third key (H3), wherein a further necessary condition for granting access is that a second verification, performed at the access control device, using at least the challenge (R), the communicated access authorization parameters (B), the communicated first verification information (V), the communicated third verification information (V') and the fourth key (H4), yieldsthat the communicated third verification information (V') was generated by performing cryptographic operations on information corresponding to the challenge (R), the communicated access authorization parameters (B) and the communicated first verification information (V), using at least the third key (H3). Example 57: Method according to one of embodiments 51-55, wherein the access control device (4) can authenticate itself to the access authorization verification device (3) using at least the fourth key (H4), wherein the access authorization information (B, V) is communicated from the access authorization verification device (3) to the access control device (4) only upon successful authentication. Example 58: Method according to one of embodiments 50 and 53, further comprising: - Generating fourth test information (V L) by performing cryptographic operations on rejection information (L) using at least the first key (S1, S2) T1 ) of the key pair, wherein the rejection information (L) includes at least one new rejection list (RL) with identifiers (KeyIDs) for access authorization information (B, V) to be rejected or for access authorization credential devices (3) of which access authorization information (B, V) is to be rejected at the access control device (4), and - Output of the rejection information (L) and the fourth check information (V) L ) for storage on the access authorization verification device (3) that is set up, the rejection information (L) and the fourth verification information (V) L) at least to communicate to the access control device (4), wherein the communicated new rejection list (RL) is stored in the access control device (4) only if at least the fourth check information communicated (V) L ), the second key (S2, S T2 ) of the key pair and the communicated rejection information (L) it is determined that the communicated fourth check information (V) L ) by performing cryptographic operations on the rejection information corresponding to the communicated rejection information (L) using at least the first key (S1, S2) T1 ) of the key pair was generated. Example 59: Method according to embodiment 58, wherein the rejection information (L) additionally includes a counter which is incremented with each new rejection list (RL), and wherein the new rejection list (RL) is stored in the access control device (4) only under the additional condition that the value of the counter included in the rejection information (L) is greater than a value of a counter provided in the access control device (4), and wherein the value of the counter of the access control device (4) is updated to the value of the counter included in the rejection information (L) at or after the storage of the new rejection list (RL) in the access control device (4). Example 60: Method according to one of embodiments 58-59, wherein the rejection information (L) additionally includes an identifier (LockID) of only one access control device (4) or a group of access control devices on which the new rejection list (RL) is to be stored, and wherein the new rejection list (RL) is stored in the access control device (4) only under the additional condition that an individual identifier (LockID) of the access control device (4) stored in the access control device (4) or a group identifier (GroupID) for a group of access control devices containing the access control device (4) matches the identifier included in the rejection information. Example 61: - Example 62: - Example 63: Method according to one of embodiments 34-60, wherein one of the access authorization parameters (B) specifies the extent to which, in particular to which openings of the access control device (4) or to which openings of a device controlled by the access control device (4), access is to be granted. Example 64: Computer program comprising program instructions that cause a processor to execute and / or control the method according to one of embodiments 34 to 63 when the computer program is running on the processor. Example 65: Access authorization generation device (2), configured to execute and / or control the method according to one of the embodiments 34-63 or comprising respective means for executing and / or controlling the steps of the method according to one of the embodiments 34-63. Example 66: Procedure for verifying access authorization, carried out by means of an access authorization verification device (3), the procedure comprising: - Communicating access authorization information (B, V), which includes at least one or more access authorization parameters (B) and initial verification information (V), to an access control device (4) in order to enable it to decide whether access may be granted on the basis of the communicated access authorization information (B, V), where necessary conditions for granting access are that an initial check, using at least the communicated access authorization parameters (B), the communicated first check information (V) and a second key (S2, S) stored in the access control device (4) T2) of a symmetric or asymmetric key pair, whether the communicated first verification information (V) can be used to perform cryptographic operations on the communicated access authorization parameters (B) corresponding access authorization parameters (B) using at least one first key (S1, S2). T1 ) of the key pair, yields a positive result and it is determined that at least a predefined set of the communicated access authorization parameters (B) with regard to the respective reference information present at least at the time of the first check in the access control device (4) authorize access. Example 67: Method according to embodiment 66, wherein the access authorization information (B, V) is generated by an access authorization generation device (2) and stored in the access authorization verification device (3) before the access authorization verification device (3) is issued to a user of the access authorization verification device (3) for the first time. Example 68: Method according to embodiment 67, wherein the access authorization verification device (3) is a portable RFID or NFC unit, in particular an RFID or NFC tag. Example 69: Method according to embodiment 66, wherein the access authorization information (B, V) is generated by an access authorization generation device (2) and communicated to the access authorization verification device (3) via an at least partially wireless communication link, in particular a cellular mobile network. Example 70: Method according to embodiment 69, wherein the access authorization verification device (3) is a portable terminal device equipped for wireless communication, in particular a mobile phone. Example 71: Method according to embodiment 66, wherein the access authorization information (B, V) is generated by an access authorization generation device (2), transmitted via a communication network to a computer and communicated to the access authorization verification device (2) under its control. Example 72. Method according to embodiment 71, wherein the access authorization verification device (3) is a handheld scanner. Example 73: Method according to one of embodiments 66-72, wherein the communication of information from the access authorization verification device (3) to the access control device (4) is wireless, in particular by means of RFID, NFC or Bluetooth communication. Example 74: Method according to one of embodiments 66-73, wherein the key pair is an asymmetric key pair, wherein the first verification information (V) is generated as a digital signature via the access authorization parameters (B) using at least the first key (S1) of the key pair. Example 75: Method according to one of embodiments 66-73, wherein the key pair is a symmetric key pair, and wherein the first check is the performance of the same cryptographic operations (CRYPT) as are used in generating the first check information (V) over the communicated access authorization parameters (B) using at least the second key (S2, S3). T2 ) of the key pair to obtain locally generated first test information and to compare the communicated first test information (V) with the locally generated first test information. Example 76: Method according to embodiment 75, wherein the cryptographic operations for determining a message authentication code (MAC) serve as verification information (V). Example 77: Method according to one of embodiments 66-76, wherein the access control device (4) is an access control device (4) from a plurality of access control devices, wherein a second key (S2) of a symmetric or asymmetric individual key pair is stored in the access control device (4), which is stored only on the access control device but not on any of the other access control devices of the plurality of access control devices, and wherein the first key (S1, S2) used in generating the first test information T1 ) of the key pair, the first key (S1) of the individual key pair is Example 78: Method according to one of embodiments 66-76, wherein the access control device (4) is an access control device (4) from a plurality of access control devices, wherein a second key (S2) of a symmetric or asymmetric individual key pair is stored in the access control device (4), which is stored only on the access control device, but not on any of the other access control devices of the plurality of access control devices, wherein in the access control device (4) an additional second key (S) different from the second key of the individual key pair T2 ) of a symmetric or asymmetric group key pair that is stored in all access control devices of a group of access control devices comprising the access control device (4) of the plurality of access control devices, where the first key used in generating the first test information (S1, S) T1 ) of the key pair either a first key (S1) of the individual key pair or a first key (ST1 ) of the group key pair is Example 79: Method according to embodiment 78, wherein in the access control device (4) at least one of the second key (S2) of the individual key pair and the second key (S T2 ) of the group key pair of different second keys (S T2 ) of a symmetric or asymmetric further group key pair, which is stored in all access control devices of a further group of access control devices comprising the access control device (4), but which, compared to the group of access control devices, includes at least one or more other access control devices of the plurality of access control devices, and wherein the second key used in the first check (S2, S) T2) of the key pair either the second key (S2) of the individual key pair, the second key (S T2 ) of the group key pair or the second key (S T2 ) of the further group key pair. Example 80: Method according to one of embodiments 78-79, wherein it is not provided to change, delete or exchange the second key (S2) of the individual key pair in the access control device (4), but wherein it is provided that the second key (S T2 ) of the group key pair can be changed, deleted, or replaced with another key. Example 81: Method according to one of embodiments 78-80, further comprising: - Communicating group key information (W), which includes at least one second key (S) encrypted with the first key (S1) of the individual key pair. T2 ) of a new symmetric or asymmetric group key pair for the same or at least partially different group of access control devices of the plurality of access control devices, to the access control device (4) to enable it to use the encrypted second key (S) by decrypting the communicated T2 ) of the new group key pair obtainable using at least the second key (S2) of the individual key pair T2 ) of the new group key pair in the access control device (4) so that the second key (S2, S) used in the first check T2) of the key pair either the second key (S2) of the individual key pair or the second key (S T2 ) of the new group key pair. Example 82: Method according to embodiment 81, further comprising: - Communicating second test information (V W ) to the access control device, wherein the second key of the new group key pair obtainable by decryption is stored in the access control device (4) only on the condition that, in the event of at least one communicated second test information (V W ), based on the second key (S2) of the individual key pair and the communicated group key information (W), it is determined that the communicated second check information (V) W) by performing cryptographic operations on the group key information corresponding to the communicated group key information (W) using at least the first key (S1) of the individual key pair. Example 83: Method according to embodiment 82, wherein the group key information (W) additionally includes a counter (update_counter) which is incremented with each new group key pair, and wherein the second key obtained by decryption (S T2 ) of the new group key pair in the access control device (4) is stored only under the additional condition that a value of a counter included in the group key information (update_counter) is greater than a value of a counter provided in the access control device (4), and wherein, at or after the storage of the second key (S T2) of the new group key pair in the access control device (4) the value of the counter in the access control device (4) is updated to the value of the counter (update_counter) included by the group key information. Example 84: Method according to one of embodiments 82-83, wherein the group key information additionally includes an individual identifier (LockID) of the access control device (4), and wherein the second key obtained by decryption (S T2 ) of the new group key pair in the access control device (4) is stored only under the additional condition that an individual identifier (LockID) of the access control device (4) stored in the access control device (4) matches the individual identifier (LockID) included in the group key information. Example 85: Method according to one of embodiments 81-84, wherein the group key information additionally includes a group identifier (GroupID) associated with the new group key pair, which is common to all access control devices of the group of access control devices for which the new group key pair is intended, and wherein the group identifier (GroupID) obtained by decryption is stored in the access control device (4). Example 86: Method according to one of embodiments 66-85, wherein one of the access authorization parameters (B) is an identifier (LockID) for only one access control device (4) or a group of access control devices, and wherein the access control device (4) determines that the identifier authorizes access if the identifier (LockID) matches an individual identifier (LockID) of the access control device (4) stored in the access control device (4) and / or a group identifier (GroupID) for a group of access control devices to which the access control device (4) belongs. Example 87: Method according to one of embodiments 78-85, wherein one of the access authorization parameters is an identifier (LockID) solely for the access control device (4) or for a group of access control devices that includes the access control device (4), wherein the access control device (4) determines that the identifier (LockID) authorizes access if the identifier matches an individual identifier (LockID) of the access control device (4) stored in the access control device (4) and / or a group identifier (GroupID) for a group of access control devices to which the access control device (4) belongs, wherein the first check information (V) of access authorization information, which has an identifier (LockID) solely for the access control device (4),by performing cryptographic operations on the access authorization parameters (B) using at least the first key (S1) of the individual key pair, and wherein the first verification information (V) of access authorization information, which has an identifier (LockID) for the group of access control devices, is generated by performing cryptographic operations on the access authorization parameters using at least the first key (S, T1 ) of the group key pair is generated. Example 88: Method according to embodiment 87, wherein, based on the identifier (LockID), in particular based on a predefined format of the identifier, it can be recognized in the access control device (4) whether it is an identifier for only one access control device (4) or an identifier for a group of access control devices, so that for the first check either the second key (S2) of the individual key pair or the second key (S T2 ) of the group key pair can be selected. Example 89: Method according to one of embodiments 66-88, wherein one of the access authorization parameters (B) is an identifier (KeyID) for the access authorization information (B, V) or for the access authorization verification device (3), and wherein it is determined that the identifier (KeyID) authorizes access if the identifier is not included in a rejection list (RL) stored in the access control device (4). Example 90: Method according to one of embodiments 66-89, further comprising: - Communicating information (A) that uses at least one key (S1, S2) T1) of the key pair includes the encrypted fourth key (H4), which can be used when authenticating the access control device (4) to the access authorization device (3), or when verifying the authenticity and / or integrity of information communicated to the access control device (4), to enable the access control device (4) to transmit the encrypted fourth key using at least the second key (S2, S3). T2 ) of the key pair to decrypt and use. Example 91: Method according to one of embodiments 66-89, further comprising: - Communicating information (A) that uses at least one key (S1, S2) T1) of the key pair comprises an encrypted combination of a fourth key (H4) and an identifier (KeyID) for the access authorization information (B, V) or for the access authorization authentication device (3), wherein the fourth key (H4) is usable when authenticating the access control device (4) to the access authorization authentication device (3) or when verifying the authenticity and / or integrity of information communicated to the access control device (4), to enable the access control device (4) to process the encrypted combination using at least the second key (S2, S3). T2 ) of the key pair to decrypt in order to obtain the fourth key (H4) and the identifier, wherein the identifier (KeyID) additionally represents one of the access authorization parameters (B), and wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted combination. Example 92: Method according to one of embodiments 66-89, further comprising: - Communicating information (A) that uses at least one key (S1, S2) T1) of the key pair comprises an encrypted combination of a fourth key (H4) and an identifier (KeyID) for the access authorization information (B, V) or for the access authorization authentication device (3), wherein the fourth key (H4) is usable when authenticating the access control device (4) to the access authorization authentication device (3) or when verifying the authenticity and / or integrity of information communicated to the access control device (4), to enable the access control device (4) to process the encrypted combination using at least the second key (S2, S3). T2 ) of the key pair to decrypt in order to obtain the fourth key (H4) and the identifier, wherein the identifier (KeyID) additionally represents one of the access authorization parameters (B), and wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted combination and the identifier (KeyID) is not included in a rejection list (RL) stored in the access control device (4). Example 93: Method according to one of embodiments 91-92, wherein the access authorization information (B, V) communicated to the access control device (4) is stored in identical form on at least two access authorization verification devices (3), wherein the identical access authorization information (B, V) stored on the at least two access authorization verification devices (3) each have the same identifier (KeyID) for the access authorization information (B, V) and these access authorization information (B, V) are each associated with the same fourth key (H4). Example 94: Method according to embodiment 93, wherein the access authorization information (B, V) communicated to the access control device (4) has a limited validity period and / or only a limited permissible number of access operations within its validity period and / or can only be communicated by the access authorization verification device (3) to the access control device (4) if it is determined at the access authorization verification device (3) that there is a need for access to the access control device (4). Example 95: Method according to one of embodiments 90-94, wherein the fourth key (H4) forms a symmetric or asymmetric key pair with a third key (H3), the method further comprising: - Generation of a third verification information (V') by performing cryptographic operations on a challenge (R) generated by the access device, the access authorization parameters (B) and the first verification information (V) using at least the third key (H3), - Communicating the third verification information (V') to the access control device, wherein a further necessary condition for granting access is that a second check, performed on the access control device, using at least the challenge (R), the communicated access authorization parameters (B), the communicated first verification information (V), the communicated third verification information (V') and the fourth key (H4), reveals that the communicated third verification information (V') was generated by performing cryptographic operations on information corresponding to the challenge (R), the communicated access authorization parameters (B) and the communicated first verification information (V), using at least the third key (H3). Example 96: Method according to one of embodiments 90-94, wherein the access control device (4) can authenticate itself to the access authorization verification device (3) using at least the fourth key (H4), and wherein the access authorization information (B, V) is communicated from the access authorization verification device (3) to the access control device (4) only upon successful authentication. Example 97: Method according to one of embodiments 89 and 92, further comprising: - Generating fourth test information (V L ) by performing cryptographic operations on rejection information (L) using at least the first key (S1, S2) T1) of the key pair, wherein the rejection information (L) includes at least one new rejection list (RL) with identifiers (KeyIDs) for access authorization information (B, V) to be rejected or for access authorization credential devices (3), of which access authorization information (B, V) is to be rejected at the access control device (4), and - Communicating rejection information (L), which includes at least one new rejection list (RL) with identifiers (KeyIDs) for access authorization information (B, V) to be rejected or for access authorization credential devices (3), of which access authorization information (B, V) is to be rejected at the access control device (4), and by performing cryptographic operations on the rejection information (L) using at least the first key (S1, S2). T1 ) of the key pair generated fourth test information (V L), to the access control device, wherein the communicated new rejection list (RL) is stored in the access control device (4) only if at least the fourth test information communicated (V) L ), the second key (S2, S T2 ) of the key pair and the communicated rejection information (L) it is determined that the communicated fourth check information (V) L ) by performing cryptographic operations on the rejection information corresponding to the communicated rejection information (L) using at least the first key (S1, S2) T1 ) of the key pair was generated. Example 98: Method according to embodiment 97, wherein the rejection information (L) additionally includes a counter which is incremented with each new rejection list (RL), and wherein the new rejection list (RL) is stored in the access control device (4) only under the additional condition that the value of the counter included in the rejection information (L) is greater than a value of a counter provided in the access control device (4), and wherein the value of the counter of the access control device (4) is updated to the value of the counter included in the rejection information (L) at or after the storage of the new rejection list (RL) in the access control device (4). Example 99: Method according to one of embodiments 97-98, wherein the rejection information (L) additionally includes an identifier (LockID) of only one access control device (4) or a group of access control devices on which the new rejection list (RL) is to be stored, and wherein the new rejection list (RL) is stored in the access control device (4) only under the additional condition that an individual identifier (LockID) of the access control device (4) stored in the access control device (4) or a group identifier (GroupID) for a group of access control devices containing the access control device (4) matches the identifier included in the rejection information. Example 100: Method according to one of embodiments 66-99, wherein one of the access authorization parameters (B) specifies the extent to which access is to be granted, in particular to which openings of the access control device (4) or to which openings of a device controlled by the access control device (4). Example 101: Computer program comprising program instructions that cause a processor to execute and / or control the method according to one of embodiments 66 to 100 when the computer program is running on the processor. Example 102: Access authorization verification device (3), configured to execute and / or control the method according to one of embodiments 66-100 or comprising respective means for executing and / or controlling the steps of the method according to one of embodiments 66-100. Example 103: System, comprehensive: - an access control device (4) according to embodiment 32, - an access authorization generation device (2), in particular according to embodiment 65, and - an access authorization verification device (3), in particular according to embodiment 102, wherein the access authorization information (B, V) is generated by the access authorization generation device (2) and communicated by the access authorization verification device (3) to the access control device (4).
[0179] The exemplary embodiments / exemplary embodiments of the present invention described in this specification are to be understood as being disclosed in all combinations with one another. In particular, the description of a feature included in an embodiment—unless explicitly stated otherwise—is not to be understood as meaning that the feature is indispensable or essential for the function of the exemplary embodiment. The sequence of the process steps described in this specification in the individual flowcharts is not mandatory; alternative sequences of the process steps are conceivable. The process steps can be implemented in various ways; for example, implementation in software (by program instructions), hardware, or a combination of both is conceivable.Terms used in the claims, such as "comprise," "have," "include," "contain," and the like, do not exclude further elements or steps. The phrase "at least partially" covers both "partially" and "completely." The phrase "and / or" should be understood to mean that both the alternative and the combination are disclosed; thus, "A and / or B" means "(A) or (B) or (A and B)." A plurality of units, persons, or the like, in the context of this specification, means several units, persons, or the like. The use of the indefinite article does not preclude a plurality. A single device can perform the functions of several units or devices mentioned in the claims. Reference numerals specified in the claims are not to be considered as limitations on the means and steps employed.
Claims
[1] Access control method carried out by an access control device (4) comprising the method - Receiving access authorization information (B, V) communicated to the access control device (4), which includes at least one or more access authorization parameters (B) and initial verification information (V), - first check, using at least the communicated one or more access authorization parameters (B), the communicated first check information (V) and a second key (S2, S) stored in the access control device (4). T2 ) of a symmetric or asymmetric key pair, whether the communicated first verification information (V) can be verified by performing cryptographic operations on the communicated one or more access authorization parameters (B) corresponding to one or more access authorization parameters (B) using at least one first key (S1, S2). T1) of the key pair was generated, - Decide whether access may be granted, whereby necessary conditions for granting access are that the first check yields a positive result and it is established that at least one predefined set of the communicated one or more access authorization parameters (B) with respect to the respective reference information present at least at the time of the first check in the access control device (4) each authorize access, - Receiving information (A) communicated to the access control device (4), which includes at least one key (S1, S2) used by at least the first key (S1, S2). T1) of the key pair, which includes the encrypted fourth key (H4) that can be used for authentication of the access control device (4) to an access authorization device (3) that communicates the access authorization information to the access control device (4), or for authentication of an access authorization device (3) that communicates the access authorization information to the access control device (4) to the access control device (4), or for verifying the authenticity and / or integrity of information communicated to the access control device (4), and - Decrypting the encrypted fourth key using at least the second key (S2, S T2 ) of the key pair to obtain the fourth key (H4). [2] Access control method carried out by an access control device (4) comprising the method - Receiving access authorization information (B, V) communicated to the access control device (4), which includes at least one or more access authorization parameters (B) and initial verification information (V), - first check, using at least the communicated one or more access authorization parameters (B), the communicated first check information (V) and a second key (S2, S) stored in the access control device (4). T2 ) of a symmetric or asymmetric key pair, whether the communicated first verification information (V) can be verified by performing cryptographic operations on the communicated one or more access authorization parameters (B) corresponding to one or more access authorization parameters (B) using at least one first key (S1, S2). T1 ) of the key pair was generated, - Decide whether access may be granted, whereby necessary conditions for granting access are that the first check yields a positive result and it is established that at least one predefined set of the communicated one or more access authorization parameters (B) with respect to the respective reference information present at least at the time of the first check in the access control device (4) each authorize access, - Receipt of information (A) communicated to the access control device (4), which includes at least one key (S1, S2) used by at least the first key (S1, S2). T) of the key pair comprises an encrypted combination of a fourth key (H4) and an identifier (KeyID) for the access authorization information (B, V) or for an access authorization credential device (3) that communicates the access authorization information (B, V) to the access control device (4), wherein the fourth key (H4) is usable when authenticating the access control device (4) to an access authorization credential device (3) that communicates the access authorization information (B, V) to the access control device (4), or when authenticating an access authorization credential device (3) that communicates the access authorization information to the access control device (4) to the access control device (4), or when verifying the authenticity and / or integrity of information communicated to the access control device (4), and - Decrypting the encrypted combination using at least the second key (S2, S3). T2 ) of the key pair to obtain the fourth key (H4) and the identifier (KeyID), where the identifier (KeyID) additionally represents one of the communicated access authorization parameters (B), where it is determined that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted information or where it is established that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted information and the identifier (KeyID) is not included in a rejection list (RL) stored in the access control device (4). [3] Method according to claim 2, wherein it is determined that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted information [4] Method according to claim 2, wherein it is determined that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted information and the identifier (KeyID) is not included in a rejection list (RL) stored in the access control device (4). [5] Method for generating access authorization information (B, V), the method encompassing - Generating initial verification information (V) by performing cryptographic operations on one or more access authorization parameters (B) using at least one initial key (S1, S2) T1 ) of a symmetric or asymmetric key pair, - Generating access authorization information (B, V) that includes at least one or more access authorization parameters (B) and the first verification information (V), and - Outputting the access authorization information (B, V) for storage on an access authorization verification device (3) which is configured to communicate the access authorization information (B, V) to at least one access control device (4) in order to enable the latter to decide whether access may be granted on the basis of the communicated access authorization information (B, V), wherein necessary conditions for granting access are that an initial check, using at least the communicated one or more access authorization parameters (B), the communicated initial check information (V) and a second key (S2, S3) stored in the access control device (4). T2) of the key pair, whether the communicated first verification information (V) can be verified by performing cryptographic operations on the communicated one or more access authorization parameters (B) corresponding to one or more access authorization parameters (B) using at least the first key (S1, S2). T1 ) of the key pair, yields a positive result and it is determined that at least one predefined set of the communicated one or more access authorization parameters (B) with regard to the respective reference information present at least at the time of the first check in the access control device (4) authorizes access, - Encrypting a fourth key (H4) using at least the first key (S1, S2) T1) of the key pair, wherein the fourth key (H4) is usable for authentication of the access control device (4) to the access authorization device (3), or for authentication of the access authorization device (3) to the access control device (4), or for checking the authenticity and / or integrity of information communicated to the access control device (4), - Generating information (A) that includes at least the encrypted fourth key (H4), and - Outputting the information (A) for storage on the access authorization device (3), which is configured to communicate the information (A) at least to the access control device (4) in order to enable it to generate the encrypted fourth key using at least the second key (S2, S3). T2 ) of the key pair to decrypt and use. [6] Method for generating access authorization information (B, V), the method encompassing - Generating initial verification information (V) by performing cryptographic operations on one or more access authorization parameters (B) using at least one initial key (S1, S2) T1 ) of a symmetric or asymmetric key pair, - Generating access authorization information (B, V) that includes at least one or more access authorization parameters (B) and the first verification information (V), and - Outputting the access authorization information (B, V) for storage on an access authorization verification device (3) which is configured to communicate the access authorization information (B, V) to at least one access control device (4) in order to enable the latter to decide whether access may be granted on the basis of the communicated access authorization information (B, V), wherein necessary conditions for granting access are that an initial check, using at least the communicated one or more access authorization parameters (B), the communicated initial check information (V) and a second key (S2, S3) stored in the access control device (4). T2) of the key pair, whether the communicated first verification information (V) can be verified by performing cryptographic operations on the communicated one or more access authorization parameters (B) corresponding to one or more access authorization parameters (B) using at least the first key (S1, S2). T1 ) of the key pair, yields a positive result and it is determined that at least one predefined set of the communicated one or more access authorization parameters (B) with regard to the respective reference information present at least at the time of the first check in the access control device (4) authorizes access, - Encrypting a combination of a fourth key (H4) and an identifier (KeyID) for the access authorization information (B, V) or for the access authorization verification device (3), using at least the first key (S1, S T1) of the key pair, wherein the fourth key (H4) can be used for authentication of the access control device (4) to the access authorization device (3), or for authentication of the access authorization device (3) to the access control device (4), or for checking the authenticity and / or integrity of information communicated at the access control device (4), - Generating information (A) that includes at least the encrypted combination, and - Outputting the information (A) for storage on the access authorization device (3), which is configured to communicate the information (A) at least to the access control device (4) in order to enable it to generate the encrypted combination using at least the second key (S2, S3). T2) of the key pair to obtain the fourth key (H4) and the identifier, wherein the identifier (KeyID) additionally represents one of the access authorization parameters (B), and wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted combination, or wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B,V) contained identifier (KeyID) matches the identifier (KeyID) obtained by decrypting the encrypted combination and the identifier (KeyID) is not contained in a rejection list (RL) stored in the access control device (4). [7] Method according to claim 6, wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted combination [8] Method according to claim 6, wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted combination and the identifier (KeyID) is not contained in a rejection list (RL) stored in the access control device (4). [9] Method for verifying access authorization, carried out by an access authorization verification device (3), the method comprising: - Communicating access authorization information (B, V), which includes at least one or more access authorization parameters (B) and initial verification information (V), to an access control device (4) to enable it to decide whether access may be granted based on the communicated access authorization information (B, V), wherein necessary conditions for granting access are that an initial verification, using at least the communicated one or more access authorization parameters (B), the communicated initial verification information (V) and a second key (S2, S3) stored in the access control device (4) T2) of a symmetric or asymmetric key pair, whether the communicated first verification information (V) can be verified by performing cryptographic operations on the communicated one or more access authorization parameters (B) corresponding to one or more access authorization parameters (B) using at least one first key (S1, S2). T1 ) of the key pair, yields a positive result and it is determined that at least one predefined set of the communicated one or more access authorization parameters (B) authorize access with respect to the respective reference information present at least at the time of the first check in the access control device (4), and - Communicating information (A) that uses at least one key (S1, S2) T1) of the key pair, the encrypted fourth key (H4) is included, which can be used for authentication of the access control device (4) to the access authorization device (3), or for authentication of the access authorization device (3) to the access control device (4), or for verifying the authenticity and / or integrity of information communicated to the access control device (4), to enable the access control device (4) to transmit the encrypted fourth key using at least the second key (S2, S3). T2 ) of the key pair to decrypt and use. [10] Method for verifying access authorization, carried out by an access authorization verification device (3), the method comprising: - Communicating access authorization information (B, V), which includes at least one or more access authorization parameters (B) and initial verification information (V), to an access control device (4) to enable it to decide whether access may be granted based on the communicated access authorization information (B, V), wherein necessary conditions for granting access are that an initial verification, using at least the communicated one or more access authorization parameters (B), the communicated initial verification information (V) and a second key (S2, S3) stored in the access control device (4) T2) of a symmetric or asymmetric key pair, whether the communicated first verification information (V) can be verified by performing cryptographic operations on the communicated one or more access authorization parameters (B) corresponding to one or more access authorization parameters (B) using at least one first key (S1, S2). T1 ) of the key pair, yields a positive result and it is determined that at least one predefined set of the communicated one or more access authorization parameters (B) authorize access with respect to the respective reference information present at least at the time of the first check in the access control device (4), and - Communicating information (A) that uses at least one key (S1, S2) T1) of the key pair comprises an encrypted combination of a fourth key (H4) and an identifier (KeyID) for the access authorization information (B, V) or for the access authorization authentication device (3), wherein the fourth key (H4) is usable when authenticating the access control device (4) to the access authorization authentication device (3), or when authenticating the access authorization authentication device (3) to the access control device (4), or when verifying the authenticity and / or integrity of information communicated to the access control device (4), to enable the access control device (4) to process the encrypted combination using at least the second key (S2, S3). T2) of the key pair to obtain the fourth key (H4) and the identifier, wherein the identifier (KeyID) additionally represents one of the access authorization parameters (B), and wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted combination, or wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B,V) contained identifier (KeyID) matches the identifier (KeyID) obtained by decrypting the encrypted combination and the identifier (KeyID) is not contained in a rejection list (RL) stored in the access control device (4). [11] Method according to claim 10, wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted combination [12] Method according to claim 10, wherein the access control device (4) determines that the identifier (KeyID) contained in the communicated access authorization information (B, V) authorizes access if the identifier (KeyID) contained in the communicated access authorization information (B, V) matches the identifier (KeyID) obtained by decrypting the encrypted combination and the identifier (KeyID) is not included in a rejection list (RL) stored in the access control device (4). [13] Method according to any of the preceding claims, wherein the key pair is a symmetric key pair, and wherein the first check is the execution of the cryptographic operations over the communicated access authorization parameters (B) using at least the second key (S2, S3). T2) of the key pair to obtain locally generated first test information and to compare the communicated first test information (V) with the locally generated first test information includes [14] Method according to claim 13, wherein the cryptographic operations for determining a message authentication code (MAC) serve as verification information (V). [15] Method according to one of the preceding claims, wherein one of the communicated access authorization parameters is an identifier (LockID) for only one access control device (4) or a group of access control devices, and wherein the access control device (4) determines that the identifier authorizes access if the identifier (LockID) matches an individual identifier (LockID) of the access control device (4) stored in the access control device (4) and / or a group identifier (GroupID) for a group of access control devices to which the access control device (4) belongs. [16] Method according to claim 15, wherein the first verification information (V) of communicated access authorization information, which has an identifier (LockID) for only one access control device (4), is generated by performing cryptographic operations on the access authorization parameters (B) using at least one first key (S1) of the individual key pair, and wherein the first verification information (V) of communicated access authorization information, which has an identifier (LockID) for a group of access control devices, is generated by performing cryptographic operations on the access authorization parameters using at least one first key (S T1 ) of the group key pair is generated. [17] Method according to claim 16, wherein, based on the identifier (LockID), in particular based on a predefined format of the identifier, it can be recognized in the access control device (4) whether it is an identifier for only one access control device (4) or an identifier for a group of access control devices, so that for the first check either the second key (S2) of the individual key pair or the second key (S T2 ) of the group key pair can be selected. [18] Method according to one of the preceding claims, wherein one of the communicated access authorization parameters (B) is an identifier (KeyID) for the access authorization information (B, V) or for an access authorization verification device (3) that communicates the access authorization information (B, V) to the access control device (4), and wherein it is determined that the identifier (KeyID) authorizes access if the identifier is not included in a rejection list (RL) stored in the access control device (4). [19] Method according to any of the preceding claims, insofar as it refers back to any of claims 2, 6 or 10, wherein the access authorization information (B, V) communicated to the access control device (4) is stored in identical form on at least two access authorization verification devices (3), wherein the identical access authorization information (B, V) stored on the at least two access authorization verification devices (3) each have the same identifier (KeyID) for the access authorization information (B, V) and each of these access authorization information (B, V) is associated with the same fourth key (H4). [20] Method according to claim 19, wherein the access authorization information (B, V) communicated to the access control device (4) has a limited validity period and / or only allows a limited number of access operations within its validity period and / or can only be communicated by the access authorization verification device (3) to the access control device (4) when it is determined at the access authorization verification device (3) that there is a need for access to the access control device (4). [21] Method according to any of the preceding claims, insofar as it refers back to any of claims 1 or 2, wherein the fourth key (H4) forms a symmetric or asymmetric key pair with a third key (H3), and wherein the communicated access authorization information (B, V, V') further comprises third verification information (V'), the method further comprising: - second check, using at least one challenge (R) generated by the access control device (4), the communicated one or more access authorization parameters (B), the communicated first check information (V), the communicated third check information (V') and the fourth key (H4), to determine whether the communicated third check information (V') was generated by performing cryptographic operations on information corresponding to the generated challenge (R), the communicated one or more access authorization parameters (B) and the communicated first check information (V), using at least the third key (H3), wherein a further necessary condition for granting access is that the second check yields a positive result. [22] A method according to any of the preceding claims, insofar as it refers back to any of claims 1 or 2, the method further comprising: - Authentication to an access authorization device (3) containing the access authorization information (B, V) using at least the fourth key (H4), wherein the access authorization information (B, V) is communicated from the access authorization device (3) to the access control device (4) only upon successful authentication. [23] Method according to any of the preceding claims, insofar as it refers back to claim 4 or to claim 18, insofar as it refers back to claim 1, 2 or 4, further comprising: - Receipt of rejection information (L) communicated to the access control device (4), which includes at least one new rejection list (RL) with identifiers (KeyIDs) for access authorization information (B, V) to be rejected or for access authorization verification devices (3) from which access authorization information (B, V) is to be rejected at the access control device (4), and of fourth verification information (V L ), and - Saving the communicated new rejection list (RL) only if at least one fourth check information (V) communicated is present L ), the second key (S2, S T2 ) of the key pair and the communicated rejection information (L) it is determined that the communicated fourth check information (V) L) by performing cryptographic operations on the rejection information corresponding to the communicated rejection information (L) using at least the first key (S1, S2) T1 ) of the key pair was generated. [24] Method according to claim 23, wherein the rejection information (L) additionally comprises a counter which is incremented with each new rejection list (RL), and wherein the new rejection list (RL) is stored in the access control device (4) only under the additional condition that a value of the counter included by the rejection information (L) is greater than a value of a counter provided in the access control device (4), and wherein the value of the counter of the access control device (4) is updated to the value of the counter included by the rejection information (L) at or after the storage of the new rejection list (RL) in the access control device (4). [25] Method according to one of claims 23-24, wherein the rejection information (L) additionally comprises an identifier (LockID) of only one access control device (4) or a group of access control devices on which the new rejection list (RL) is to be stored, and wherein the new rejection list (RL) is stored in the access control device (4) only under the additional condition that an individual identifier (LockID) of the access control device (4) stored in the access control device (4) or a group identifier (GroupID) for a group of access control devices containing the access control device (4) matches the identifier included in the rejection information. [26] Method according to any of the preceding claims, insofar as referred back to claim 9 or 10, wherein the fourth key (H4) forms a symmetric or asymmetric key pair with a third key (H3), the method further comprising: - Generation of a third verification information (V') by performing cryptographic operations on a challenge (R) generated by the access device, the access authorization parameters (B) and the first verification information (V) using at least the third key (H3), - Communicating the third verification information (V') to the access control device, wherein a further necessary condition for granting access is that a second check, performed on the access control device, using at least the challenge (R), the communicated access authorization parameters (B), the communicated first verification information (V), the communicated third verification information (V') and the fourth key (H4), reveals that the communicated third verification information (V') was generated by performing cryptographic operations on information corresponding to the challenge (R), the communicated access authorization parameters (B) and the communicated first verification information (V), using at least the third key (H3). [27] Method according to any of the preceding claims, insofar as referred back to claim 5 or 6, wherein the fourth key (H4) forms a symmetric or asymmetric key pair with a third key (H3), the method further comprising: - Issuing the third key (H3) to the access authorization device (3) to enable the access authorization device (3) to generate a third verification information (V') and communicate it to the access control device (4) by performing cryptographic operations on a challenge (R) generated by the access device, the access authorization parameters (B) and the first verification information (V) using at least the third key (H3), wherein a further necessary condition for granting access is that a second verification, performed at the access control device, using at least the challenge (R), the communicated access authorization parameters (B), the communicated first verification information (V), the communicated third verification information (V') and the fourth key (H4), yieldsthat the communicated third verification information (V') was generated by performing cryptographic operations on information corresponding to the challenge (R), the communicated access authorization parameters (B) and the communicated first verification information (V), using at least the third key (H3). [28] Method according to any of the preceding claims, insofar as referred back to claim 5, 6, 9 or 10, wherein the access control device (4) can authenticate itself to the access authorization device (3) using at least the fourth key (H4), and wherein the access authorization information (B, V) is communicated from the access authorization device (3) to the access control device (4) only upon successful authentication. [29] Computer program comprising program instructions that cause a processor to execute and / or control the method according to any one of claims 1 to 25, if referred back to any one of claims 1 or 2, when the computer program is running on the processor. [30] Access control device (4), configured to execute and / or control the method according to any one of claims 1-25, if referred back to any one of claims 1 or 2, or comprising respective means for executing and / or controlling the steps of the method according to any one of claims 1-25, if referred back to any one of claims 1 or 2. [31] Use of an access authorization verification device (3) for communicating access authorization information to an access control device (4) according to claim 30. [32] Computer program comprising program instructions that cause a processor to execute and / or control the method according to any one of claims 5 to 28, if related back to claim 5 or 6, when the computer program is running on the processor. [33] Access authorization generation device (2), configured to execute and / or control the method according to any one of claims 5 to 28, if referred back to claim 5 or 6, or comprising respective means for executing and / or controlling the steps of the method according to any one of claims 5 to 28, if referred back to claim 5 or 6. [34] Computer program comprising program instructions that cause a processor to execute and / or control the method according to any one of claims 9 to 28, if referred back to claim 9 or 10, when the computer program is running on the processor. [35] Access authorization verification device (3), configured to execute and / or control the method according to any one of claims 9 to 28, if referred back to claim 9 or 10 or comprising respective means for executing and / or controlling the steps of the method according to any one of claims 9 to 28, if referred back to claim 9 or 10. [36] System (1), comprising: - an access control device (4) according to claim 30, - an access authorization generation device (2), in particular according to claim 33, and - an access authorization verification device (3), in particular according to claim 35, wherein the access authorization information (B, V) is generated by the access authorization generation device (2) and is communicated by the access authorization verification device (3) to the access control device (4).
Citation Information
Patent Citations
Package receiving system and method
US20020180580A1
System for the checking of limited access to authorized time slots renewable by means of a portable storage device
US5768379A