Codeschloss
A decentralized locking system with encrypted authorization codes and transponder readers addresses the need for self-check-in by providing secure, time-bound access control without central data connections, enhancing operational flexibility and security.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2015-10-30
- Publication Date
- 2026-04-02
AI Technical Summary
Existing locking systems, particularly in hotels and hostels, require central data connections for access authorization verification, limiting their functionality and efficiency in self-check-in processes, especially when reception is unstaffed.
A decentralized locking system with independently functioning keypads that utilize encrypted authorization codes containing time and lock-specific information, allowing self-synchronization and verification without central data connections, using a unique identity and transponder readers for enhanced security and flexibility.
Enables self-check-in capabilities with secure, decentralized access control, reducing reliance on central units and enhancing operational flexibility and security by ensuring time-bound and lock-specific authorization.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
field of technology
[0001] The invention relates to a method for operating a combination lock, comprising a code input device for entering a first authorization code consisting of a first number of characters, wherein the first authorization code includes encrypted authorization data which is decrypted by the combination lock and checked for locking authorization, wherein the combination lock performs an opening action upon confirmation of locking authorization, according to the preamble of claim 1.
[0002] The invention also relates to a code lock or a system of several code locks and an administration device, wherein the code lock has a code input device for entering a first authorization code consisting of a first number of characters and a program-controlled code evaluation device for checking the locking authorization of encrypted authorization data contained in the first authorization code, according to the preamble of claim 6. State of the art
[0003] A locking system of the aforementioned type is used, for example, in hotels, but also in youth hostels or other accommodations. Upon check-in, a user is given an authorization code that grants access to at least one lock. However, the authorization code can also grant access to multiple locks, such as a room door lock and a front door lock. This authorization code is intended to be valid only for the duration of the user's stay at the hotel. Access authorization is verified either at the lock itself or at a central processing unit to which the code lock is connected.
[0004] Furthermore, locking systems are known that use transponders as code carriers. A transponder has a unique identifier. This unique identifier can be used to identify a transponder. For this purpose, the code lock has a transponder reader that can read the transponder's unique identifier. The authorization to access the lock is verified by a code evaluation unit located in the lock or by a central code evaluation unit to which the lock is connected.
[0005] If access authorization is verified, either via transponder recognition or an authorization code entered via a keypad, the keypad lock executes an opening action. This opening action can involve retracting the bolt or enabling manual opening, for example, by pressing down a door handle. The opening action can therefore energize a motor or activate a clutch.
[0006] There are hotels that operate without a permanently staffed reception. The reception is only staffed for certain hours during the day, for example. Booking such a hotel is done in the conventional way via an automated booking system. Upon booking, the user receives an authorization code which they can use to open at least one combination lock. This allows for self-check-in.
[0007] German patent DE 10 2006 034 292 A1 discloses a keypad code lock comprising a locking and unlocking device and an actuator for its release or blocking, as well as a control device for controlling the actuator and a keypad for data input.
[0008] DE 10 346 289 A1 discloses a method for managing user rights for a code-secured object, in which a code with an object identifier is generated by a user rights management system, which is transmitted to an authorized user for access to the object and which the authorized user communicates to a control device, wherein the control device checks the code on the basis of the object identifier given to it and, if a valid code is present, enables the authorized user to access the object.
[0009] From DE 10 2006 015 320 A1 a keypad code lock is shown, comprising a locking and unlocking device and an actuator for its release or blocking, a control device for controlling the actuator and a keypad for data input. Summary of the invention
[0010] The invention is based on the objective of further developing a code lock, a method for its operation and a locking system of the type described above in a way that is advantageous for use.
[0011] The problem is solved by a method having the features of claim 1 and by a code lock having the features of claim 6, wherein the dependent claims represent not only advantageous further developments of the subordinate claims, but also independent solutions to the problem.
[0012] The first and most important proposal is that the initial authorization code should contain at least time information about an authorization period. As a result of this design, a locking system consisting of multiple keypads can operate with independently functioning keypads. The keypads do not need a data connection to a central unit. The keypads generally do not require administration. Each keypad has a unique identity. This identity could be, for example, an 8, 16, or 32-bit number. The keypad has a clock that can remotely synchronize itself with the current civil time, for example, in the familiar manner. The keypad has a code evaluation unit capable of decrypting the authorization code entered by the user, for example, via a keypad.The code evaluation unit thus receives information about the content of the authorization data encoded in the first authorization code. This authorization data includes time information. The code evaluation unit is able to check whether the current time provided by the clock of the code lock falls within the authorization period represented by the time information. If so, the opening action described in the introduction is carried out. The authorization data, which is transmitted in encrypted form via the first authorization code to the code evaluation unit, can also include lock identification information, for example, in the form of an 8-, 16-, or 32-bit value. During code evaluation, the code evaluation unit checks whether this lock identification is the same one possessed by the corresponding lock.The code evaluation unit is thus able to verify whether the first authorization code has been entered into the correct lock. The authorization data can include a check-in date. This is a natural number within a range of values between, for example, 1 and 1024. However, any larger or smaller range of values is possible. This number corresponds to a date that is a certain number of days after a reference date known to both the code evaluation unit and an administration unit. The reference date can be automatically updated if a number of days corresponding to the value range has passed since a reference date. The authorization data can also include a value representing a check-in time. For example, check-in times can be 12:00 PM, 2:00 PM, 4:00 PM, etc.The authorization period is limited to a maximum of 00:00 and, together with the check-in date, to a specific end date. The authorization data can also include a booking duration in the form of a natural number corresponding to the number of booking days. Furthermore, it can include check-out time information, such as 10:00, 11:00, or 12:00. The booking duration and check-out time thus allow for an upper limit on the authorization period. The authorization data also contains information about at least one second authorization code. While the first authorization code has a large number of characters, for example, 10, 12, or more, the second authorization code has a smaller number of characters, for example, only 4 characters.This second authorization code, at least, is sent to the user by the administration unit after booking, along with the first authorization code. This can be done via SMS, email, directly during the booking process online, or by telephone. It is considered advantageous that no communication with the keypad lock is required during booking, the generation of authorization data, or the encryption of that data. This allows for the use of standalone keypad locks located in a completely different, and especially distant, location than the administration unit.The first authorization code preferably contains all the information that the code evaluation unit of the combination lock needs to determine whether the entered first authorization code applies to the lock, for example, by including lock identification information in the encrypted authorization code that contains the lock identification of the respective lock. Furthermore, the combination lock receives information about the authorization period from the encrypted authorization data. Preferably, the authorization data contains information about at least one second authorization code, which is accepted by the code evaluation unit if the locking authorization of the first authorization code is confirmed.The user only needs to enter the first authorization code, which has a large number of digits, the first time they use the lock, and subsequently only the shorter second authorization code to trigger the opening action. The keypad lock stores the access authorization granted to it for the authorization period via the encrypted authorization data of at least one second authorization code. Preferably, only one authorization code is transmitted. However, two or three second authorization codes can also be transmitted. The keypad lock is designed to also include a transponder reader. This transponder reader can read the unique identifier of a transponder. The code evaluation unit is able to verify the access authorization of the unique identifier of a transponder.It is possible for the transponder to carry authorization data in its individually writable memory. This authorization data can be encrypted. The code evaluation unit is capable of decrypting the encrypted authorization data. If the authorization data contains time information, it can be specified that the transponder is only authorized to lock for a certain authorization period. It is provided that one or more transponder identifiers are stored in a memory of the code evaluation unit, so that this transponder has permanent locking authorization. The use of a transponder is particularly advantageous for service, but also for long booking periods. In a variant of the invention, it is proposed that the authorization data be transmitted to the code lock via a transponder.However, it is preferred that the authorization data be entered into the code lock via a keyboard in the form of an initial authorization code, which contains the authorization data in encrypted form. Brief description of the drawings
[0013] An embodiment of the invention is explained below with reference to the accompanying drawings. These show: Fig. 1 schematically the structure of a first authorization code 11 from authorization data 10 encrypted with a crypto key 18; Fig. 2 schematically a code lock 1 with associated transponder 2 and code input keypad 3; Fig. 3 the procedure for generating a first authorization code 11 and a second authorization code 12 from booking data and Fig. 4 the procedure of checking the access authorization and activating a second authorization code 12. Description of the embodiments
[0014] A locking system according to the invention has a decentralized administration unit 9, which may be a computer, in particular one that is connected to the internet and that can provide a web interface. The locking system includes a plurality of combination locks, such as those used, for example, in the Fig. 2 are schematically represented and designated by the reference digit 1. A code lock 1 has a numeric keypad 3 with which an authorization code 11, 12 can be entered. The code lock 1 also has a code evaluation unit 6, which may be a microcontroller connected to storage peripherals. A transponder reader 5 is provided to read the individual identifier of a transponder 2, as well as the data stored in a data memory of the transponder 2. Optical indicators, for example LEDs 4, may be provided to show the user that a used transponder 2 or an entered authorization code has access rights. In addition, the code lock 1 may have electromechanical means to perform an opening action that opens a door lock. For example, an electric motor may be provided that retracts a bolt.A coupling may be provided that couples a door handle with a latch or bolt retraction mechanism, so that after the door handle is operated a latch or bolt can be retracted.
[0015] Furthermore, code lock 1 has a clock that displays the real time. This could be a radio-controlled clock that synchronizes itself with civil time.
[0016] A locking system according to the invention comprises a plurality of independent code locks 1 and at least one administration unit 9, which does not need to establish a direct data transmission connection with a code lock 1 to transmit access authorization information. It is provided according to the invention that access authorization data 10, on the basis of which the code evaluation unit 6 of the code lock 1 transmits the access authorization of a first access code 11 from the first access code 11 itself to the code evaluation unit 6. For this purpose, the first access code 11 possesses the [information] contained in the Fig. 1. Schematic representation of the structure.
[0017] The authorization data 10 contains several data points required to determine access authorization. A check-in date 13 is provided, which is represented by a natural number. This number indicates the number of days after a reference date, which is known to both the code evaluation unit 6 and the administration unit 9. The check-in date can have a value range from 1 to 999, meaning that it can automatically update itself after 999 days. In addition to the check-in date 13, the authorization data 10 contains a natural number corresponding to the booking duration 14. In this example, the booking duration 14 can have a value from 1 to 99. The authorization data 10 also contains information about a check-in time 15 and a check-out time 16.This information can be summarized in a single digit, calculated, for example, as follows: i * 3 + o, where i can take values from 0 to 2, and 0 represents, for example, a check-in time of 12:00 PM, 1 a check-in time of 2:00 PM, and 2 a check-in time of 4:00 PM. o can take values from 0 to 2, where, for example, 0 represents a check-out time of 10:00 AM, 1 a check-out time of 11:00 AM, and 2 a check-out time of 12:00 PM. The authorization data 10 can include, in this example, a four-digit lock identification information 17. This is a natural number in the range of 1 to 9999.Based on this lock identification information, the code evaluation unit 6 can determine whether the authorization data belongs to its associated code lock 1, since this code lock also bears a unique lock identification, which in this exemplary embodiment is four digits. If the lock identification and lock identification information match, the code evaluation unit recognizes the association of the authorization data 10. The authorization data 10 can also include one or more secondary authorization codes 12. In this exemplary embodiment, this is a four-digit sequence.
[0018] When generating the authorization data 10 from the individual data points 12 to 17, the individual data points 12 to 17 are combined with each other as bit sequences in a suitable manner. In the exemplary embodiment, the digits of the individual data points 12 to 17 are written one after the other, resulting in a fourteen-digit sequence. However, more complex code generation algorithms, as described in the relevant literature, are preferably used.
[0019] To generate the first authorization code 11, the authorization data 10 are encrypted. This can also be done using methods described in the prior art and in the relevant literature. In the exemplary embodiment, a simple method is described in which a fourteen-digit cryptographic key 18 is generated, to which the sequence of digits from the authorization data 10 is added, so that the sum of cryptographic key 18 and sequence of digits from authorization data 10 results in a first authorization code 11.
[0020] However, the crypto key 18 is preferably applied to a more complex and secure encryption algorithm.
[0021] The crypto key 18 can be a locking system specific to crypto keys 18. However, it is also intended that each code lock 1 has an individual crypto key 18, so that lock-specific encryption takes place from the administration unit 9.
[0022] The crypto key(s) 18 are not only known to the administration unit 9. Each code evaluation unit 6 possesses the crypto key 18 required to decrypt its assigned first authorization code 11. In a simple decryption algorithm of the exemplary embodiment, decryption is performed by subtracting the crypto key 18 from the first authorization code 11. After decryption, the code evaluation unit 6 can evaluate the authorization data 10.
[0023] When a booking is made, the administration unit receives nine booking data points in the form of information about a specific hotel room and a booking period beginning with a check-in time and ending with a check-out time. From this, the administration unit generates nine authorization data points, as described in the Fig. Figure 1 shows the authorization data 10. This data contains information about the lock, information about the authorization period, and information about at least one second authorization code 12. The encryption of the authorization data 10 generates a first authorization code 11. This code, along with at least one second authorization code 12, is transmitted to the user.
[0024] With the first authorization code 11, a "self check-in" is possible. The user enters the first authorization code 11 into keypad 3 of the assigned code lock 1. The code lock 1 accepts the code in the Fig.The authorization check is shown schematically in Figure 4. First, the authorization data sequence 10 is reconstructed by decrypting the first authorization code 11. From this, the code evaluation unit 6 can determine the second authorization code 12, the lock identification information 17, the check-in time 15, the check-out time 16, the booking duration 14, and the check-in date 12. The system first checks whether the lock identification information matches the lock identification of the code lock 1 into which the first authorization code 11 was entered. If this is not the case, the check is aborted and an error is displayed via LED 4. Otherwise, an authorization period is calculated from the time information 13 to 16, and it is checked whether the current time falls within this authorization period. If this is not the case, the process is aborted, and a corresponding signal is sent to the user via LED 4.Otherwise, the opening action will be carried out. Here too, the user can be given a corresponding signal via LED 4.
[0025] Furthermore, the second authorization code 12 is activated, so that for the authorization period an opening action can also be triggered by entering the second authorization code 12.
[0026] Alternatively or in combination, the authorization data 10 can also be entered into the code lock 1 via a transponder 2. The authorization data 10 must first be stored as plain text or encrypted in the memory of the transponder 2. If the transponder 2's locking authorization is verified, the unlocking action is carried out.
[0027] Additionally, the code evaluation unit 6 also stores information about an individual identifier of one or more transponders 2, so that the code lock 1 can be permanently opened with one or more transponders 2. This function is particularly useful for service purposes, for example, for granting access to the chambermaid.
[0028] The foregoing statements serve to explain the inventions covered by the application as a whole, which each independently advance the prior art at least through the following combinations of features, namely:
[0029] A method for operating a code lock 1, characterized in that the authorization data 10 includes at least time information 13 - 16 about an authorization period and the code lock 1 only performs the opening action if the current time of a clock of the code lock 1 is within the authorization period.
[0030] A code lock 1, characterized by a clock to provide a current time, wherein the authorization data 10 includes at least time information 13 - 16 over an authorization period, and the code lock 1 only performs the opening action if the current time of a clock of the code lock 1 is within the authorization period.
[0031] A method or code lock characterized in that the first authorization code 11 is provided by an administration facility 9 by generating authorization data 10 from booking data and encrypting this data using a crypto key 18.
[0032] A locking system consisting of an administration unit 9 and a large number of code locks.
[0033] A method, code lock or locking system characterized in that the encrypted authorization data 10 includes at least a second authorization code 12, which is generated by the administration device 9 during the generation of the authorization data 10 and which only receives a locking authorization itself when the first authorization code 11 is entered into the code input device 3 and after the locking authorization has been established, wherein the second authorization code 11 has a second number of characters which is less than the first number of characters.
[0034] A method, code lock or locking system characterized in that the authorization data 10 include lock identification information 17 which has a unique relationship of the first authorization code 11 to a specific code lock 1, wherein the code lock 1 only establishes the locking authorization if the lock identification information 17 corresponds to a unique lock identification of the code lock 1.
[0035] A method, code lock or locking system characterized in that the time information 13 - 16 includes a check-in date 13 and / or a check-in time 15 and / or a check-out time 16.
[0036] A method, code lock or locking system characterized in that the crypto key 18 used to encrypt or decrypt the authorization data 10 has a lock-specific individuality.
[0037] A method, code lock or locking system characterized in that the code lock 1 additionally has a transponder reading device 5 with which an individual identifier of a transponder 2 can be read and the code evaluation device 6 is able to check this individual identifier for locking authorization.
[0038] All disclosed features are essential to the invention (individually, but also in combination with one another). The dependent claims, with their features, characterize independent inventive developments of the prior art, in particular for the purpose of filing divisional applications on the basis of these claims. List of reference symbols 1 combination lock 2 transponders 3 Code entry device 4 LED 5 Transponder reading device 6 Code evaluation unit 9 Administration facility 10 Authorization data 11 Authorization code 12 authorization codes 13 Time information 14 Time information 15 Time information 16 Time information 17 Lock identification information 18 crypto keys
Claims
[1] Method for operating a combination lock (1) comprising a code input device (3) for entering a first authorization code (11) consisting of a first number of characters, wherein the first authorization code (11) includes encrypted authorization data (10) which is decrypted by the combination lock (1) and checked for locking authorization, wherein the combination lock (1) performs an opening action when locking authorization is established, wherein the authorization data (10) includes at least time information (13-16) about an authorization period and the code lock (1) only performs the opening action if the current time of a clock of the code lock (1) is within the authorization period and wherein the encrypted authorization data (10) includes at least a second authorization code (12) which is generated by an administration device (9) when generating the authorization data (10) and which only receives a closing authorization when the first authorization code (11) is entered into the code entry device (3) and after closing authorization has been established, wherein the second authorization code (12) has a second number of characters which is less than the first number of characters, characterized by , that the code lock (1) additionally has a transponder reading device (5) with which an individual identifier of a transponder (2) can be read and a code evaluation device (6) is able to check this individual identifier for access authorization, wherein the identifier of the transponder (2) is stored in a memory of the code evaluation device (6) so that the transponder (2) has permanent access authorization. [2] Method according to claim 1, characterized by , that the first authorization code (11) is provided by the administration facility (9) by generating authorization data (10) from booking data and encrypting it using a crypto key (18). [3] Method according to claim 1 or 2, characterized by, that the authorization data (10) include lock identification information (17) which has a unique relationship of the first authorization code (11) to a specific code lock (1), wherein the code lock (1) only establishes the locking authorization if the lock identification information (17) corresponds to a unique lock identification of the code lock (1). [4] Method according to any of the preceding claims, characterized by , that the time information (13 - 16) includes a check-in date (13) and / or a check-in time (15) and / or a check-out time (16). [5] Method according to any of the preceding claims, characterized by , that the crypto key (18) used to encrypt the authorization data (10) or to decrypt the authorization data (10) has a lock-specific individuality. [6] Code lock (1) with a code input device (9) for entering a first authorization code (11) consisting of a first number of characters, with a program-controlled code evaluation device (6) for checking the locking authorization of encrypted authorization data contained in the first authorization code (11), wherein the code evaluation device performs an opening action if the authorization data (10) possess a locking authorization, wherein a clock is provided to provide a current time, wherein the authorization data (10) includes at least time information (13-16) about an authorization period, and the code lock (1) only performs the opening action if the current time of a clock of the code lock (1) is within the authorization period, and wherein the encrypted authorization data (10) includes at least a second authorization code (12) which is generated by an administration device (9) when generating the authorization data (10) and which only receives a closing authorization when the first authorization code (11) is entered into the code entry device (3) and after closing authorization has been established, wherein the second authorization code (12) has a second number of characters which is less than the first number of characters, characterized by , that the code lock (1) additionally has a transponder reading device (5) with which an individual identifier of a transponder (2) can be read and the code evaluation device (6) is able to check this individual identifier for access authorization, wherein the identifier of the transponder (2) is stored in a memory of the code evaluation device (6), so that the transponder (2) has a permanent access authorization. [7] Combination lock according to claim 6, characterized by , that the first authorization code (11) is provided by the administration facility (9) by generating authorization data (10) from booking data and encrypting it using a crypto key (18). [8] Combination lock according to claim 6 or 7, characterized by, that the authorization data (10) include lock identification information (17) which has a unique relationship of the first authorization code (11) to a specific code lock (1), wherein the code lock (1) only establishes the locking authorization if the lock identification information (17) corresponds to a unique lock identification of the code lock (1). [9] Combination lock according to any one of claims 6 to 8, characterized by , that the time information (13 - 16) includes a check-in date (13) and / or a check-in time (15) and / or a check-out time (16). [10] Combination lock according to any one of claims 6 to 9, characterized by , that the crypto key (18) used to encrypt the authorization data (10) or to decrypt the authorization data (10) has a lock-specific individuality.
Citation Information
Patent Citations
Lock system for use with e.g. automated teller machine, has lock activatable in opening position by lock processor, where lock is locked against opening with opening code by lock processor if given code matches with stored opening code
DE102006015320A1
Electronic lock for e.g. personal hotel room safe incorporates activation time limiting device
DE102006034292A1
Management method for user access rights or access to a protected object, in which a generated access code for a particular user also includes an authorization period in which the user can access the object
DE10346289A1