Computer-aided door locking system for at least one object and method for operating such a door locking system

The system allows users to transmit current virtual cylinders for authorization verification, addressing inefficiencies in existing systems by enabling on-demand updates offline, ensuring efficient and secure authorization revocation.

DE102024133379A1Pending Publication Date: 2026-05-21DOORFID
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
DOORFID
Filing Date
2024-11-14
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

Existing door locking systems require either a permanent internet connection for immediate revocation of user authorization or involve time-consuming on-site updates, leading to inefficiencies and additional costs.

Method used

A computer-aided door locking system that allows users to transmit current virtual cylinders to a computer system for authorization verification, enabling on-demand updates without a permanent internet connection, using a mandatory cylinder update function to ensure compatibility and security.

Benefits of technology

Enables efficient, secure, and cost-effective revocation of user authorization without the need for continuous internet access, reducing operational effort and costs while maintaining high adaptability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000014_0000
    Figure 00000014_0000
  • Figure 00000014_0001
    Figure 00000014_0001
  • Figure 00000015_0000
    Figure 00000015_0000
Patent Text Reader

Abstract

The invention relates to a computer-controlled door locking system with at least one door associated with an object, at least one door opener associated with the door, and at least one computer system functionally connected to the door opener or the door, comprising a computer program product and a processor. The computer program product includes an executable code which, when executed in the processor, is configured to check, when a virtual key (1g, 4d, 5e) is used on a door opener of a specific door, whether the virtual key (1g, 4d, 5e) is associated with the authorization to open this door and, if so, to trigger the opening of a physical door lock associated with the door by activating the door opener or to open the door.The code of the computer program product includes a mandatory cylinder update function, which can be activated at least on demand, whereby in the activated state of the cylinder update function, the virtual key (1g, 4d, 5e) of at least one user of a door opener is only considered by the computer program product to verify the authorization to open this door if the user has previously transmitted a current virtual cylinder (5g, 5h) to the computer system which is compatible in content with the virtual key (1g, 4d, 5e).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a computer-aided door locking system for at least one object and a method for operating such a door locking system.

[0002] For the purposes of this invention, an object is understood to be, in particular, a building, but also rooms, apartments, containers, and any objects that have at least one door as defined by the invention. A door as defined by the invention can be opened as needed using a virtual key. Opening the door is made possible, in particular, by the provision of a door opener that, upon verification of authorization, allows the door to be opened using a virtual key. A door opener as defined by the invention is understood to be, in particular, a smart lock or a similar device.

[0003] Alternatively or additionally, the door can be opened and closed by an active door opener with a suitable door operating device, for example, a motorized drive that can move the door between an open and a closed position. Such a drive can also provide a sufficiently large closing force so that, in this case – provided that adequate security against forced entry is ensured – an additional physical door lock can be dispensed with.

[0004] For the purposes of this invention, a door is understood to be any movable closing element that can be moved into a position that allows access to an object, in particular to an enclosed space or area. The term "door" is to be interpreted broadly. It encompasses any type of closing element by which an opening is released as needed by moving the closing element. This also includes access control systems such as turnstiles, revolving doors, safes, smart locks, padlocks, doorbells, barriers, roller doors, etc., which, under this broad interpretation of the term "door," are also to be considered doors within the meaning of this invention. It is not essential that a door within the meaning of this invention completely closes the opening of an object when closed.

[0005] The term "users" of the door locking system as used in the invention refers to both administrators and users assigned to a lower level than an administrator. In particular, two or more levels can be provided, specifically a higher-level administrator level and one or more user levels to which individual users or user groups can be assigned. Users at the same level typically have the same permissions, whereas users at different levels have different rights. Alternatively, each user can be assigned individual rights or virtual keys.The term "user" is understood to mean both those persons who do not necessarily use the door locking system near doors, but are primarily involved in its administration (administrators), and those persons who directly at a door initiate a door opening and / or updates to door locks (standard users).

[0006] Using a building as an example, access rights for a specific user or user level can be limited to a specific period (in particular, one or more months, weeks, or hours) and / or to specific times and / or days of the week. Alternatively or additionally, access rights can be restricted to one or more selected doors of a building or buildings. They can also be extended to an unlimited number of doors or users.

[0007] For example, users in the form of cleaning staff may only be granted access on Mondays between 9 a.m. and 10 a.m. so that they can access areas of a building that need to be cleaned.

[0008] Alternatively or additionally, users in the form of tradespeople can be granted access to certain areas of a building during a specific period of time in order to carry out maintenance or repair work.

[0009] Numerous computer-aided locking systems for objects of the invention are known in practice, particularly electronic locking systems. These computer-aided locking systems make it possible to open a physical door lock and / or a door of the object using a virtual key. Such a virtual key (digital key) differs from conventional (physical) keys in that it does not require the manual insertion of a physical key into a physical door lock, nor a mechanical opening process using the key. Rather, the physical door lock can be unlocked or opened using the virtual key.A door can be opened by a user possessing a virtual key, transmitting this virtual key in a suitable form to a computer system functionally connected to the door locking system, and subsequently triggering the opening of the physical door lock by activating a door opener and / or by opening the door itself. The use of the virtual key can be achieved, in particular, with the aid of a mobile phone, another mobile communication device, or another suitable means (e.g., a transponder or card). The term "virtual key" is to be interpreted broadly. It also includes information in the form of codes, especially information that was generated or can be generated using a virtual key.

[0010] Computerized door locking systems are known in practice. These systems operate on the principle that each virtual lock knows the virtual keys and their access rights for all users. If a virtual key is lost, for example, due to a lost mobile phone, the virtual key is deleted from the virtual lock. Subsequently, if a new virtual key is to be issued to the user as a replacement, the new virtual key is assigned to the virtual lock. This principle requires that each lock be available online or that it be manually updated whenever an update is needed.

[0011] Furthermore, systems are known from practice that require physical access to the respective virtual key and / or virtual lock for every revocation or granting of authorization. This involves a high degree of organizational and time-related effort, and the term "sneaker programming" has become established for systems of this type.

[0012] Systems from the applicant's experience, previously marketed under the name "KIWI," are also known. These systems store and verify permissions in a backend, specifically a backend hosted on the system's server. While this allows for quick and centralized adjustments of permissions without requiring updates to locks or keys, it necessitates that the locks remain permanently online to receive authenticated and authorized access commands from the backend.

[0013] EP 3 770 867 A1 discloses a computerized door locking system for at least one building with users from at least two different levels. The focus is on providing a computerized door locking system that can be operated with multifunctional devices such as smartphones, tablet PCs, smartwatches, etc. This system allows for the assignment of access rights to authorized users from at least two different levels and simultaneously enables the secure transfer of access rights in the event of a change of ownership or use. The modification of access rights for users at the highest level is not addressed in detail.

[0014] In summary, a common conflict of objectives (dilemma) in the technical field of access control via a door locking system, as outlined above, lies in the fact that a sudden and immediate revocation of a user's authorization is contingent on either a permanent or at least on-demand data and / or internet connection to the door or the respective physical door lock, so that revocation of authorization for one or more door locks takes effect immediately at each lock. Alternatively, door locks not equipped with a permanent data and / or internet connection can be accessed by maintenance personnel to manually transfer an updated version of the access authorizations to the respective door lock, for example, by establishing a data connection on-site and using software specifically designed for that door lock.This second option always involves a certain time lag between the decision to revoke authorization and its implementation at the door lock itself. Another disadvantage of this option is the required personnel and the associated additional costs.

[0015] The invention is based on the objective of providing a computer-aided door locking system for at least one object and a method for operating such a door locking system that, on the one hand, involves only minimal effort in operation, but on the other hand, also has a high degree of adaptability.

[0016] The problem is solved according to the invention by the features of the independent claims. Further practical embodiments and advantages of the invention are described in connection with the dependent claims.

[0017] A computer-aided door locking system according to the invention has at least the following elements: a) at least one door assigned to an object, b) at least one door opener assigned to the door and c) at least one computer system functionally connected to the door opener or the door, comprising a computer program product and a processor, in particular a microprocessor, wherein d) the computer program product comprises executable code which, when executed in the processor, is configured to check, when a virtual key is used at the door opener of a particular door, whether the virtual key is associated with the authorization to open that door and, if so, to cause the opening of a physical door lock associated with the door by activating the door opener or to open the door, wherein e) the code of the computer program product implements a mandatory cylinder update function which can be activated at least on demand, wherein in the activated state of the cylinder update function the virtual key of at least one user of a door opener is only and only taken into account by the computer program product to check the authorization to open this door if the user has previously transmitted a current virtual cylinder to the computer system which is compatible in content with the virtual key.

[0018] A virtual key, as defined in the invention, is information that a user, particularly in encrypted form, uses in conjunction with the computer system at a door. The virtual key can be used by generating (preferably encrypted) information using the virtual key and, optionally, other data. This information either directly contains both keys or contains them insofar as these two keys—possibly in conjunction with other keys or other information—have been further processed in a specific way. This further processing can, for example, be carried out by applying a specific predefined or random algorithm, with the server-side capability to verify whether the predefined or randomly selected algorithm is an authenticated algorithm.The generated information, especially an access token, can then be transferred.

[0019] The term "at least on-demand activation" of the cylinder update function means that the cylinder update function is either permanently active or dependent on a specific time period, particularly the recency of the virtual cylinder of the door to be opened. For example, the cylinder update function can be automatically activated whenever a virtual cylinder last replaced the previous one more than 24 hours, 48 ​​hours, or any other predefined time period. Alternatively, or in addition, on-demand activation of the cylinder update function can also depend on a security level. For doors with the highest security level, for instance, the cylinder update function can be permanently active.In contrast, for example, with a front door that is typically opened by multiple residents using door openers and is also opened for mail and parcel deliveries without visual verification of the person ringing the bell, the cylinder update function can only be activated after several days or even weeks, or only upon request by an administrator via a backend connected to the computer system. The backend is preferably a server that is functionally connected—at least temporarily—to the one or more door locking systems. This functional connection can be established via a wired or wireless data connection. It can be purely data-based and / or internet-based and / or mobile network-based.

[0020] Authorization exists in particular when compatibility between a user's virtual key and a virtual cylinder of a door is demonstrated.

[0021] The invention is already feasible and implementable if "at least one user" is able to transmit a current virtual cylinder to the computer system functionally connected to a door, provided that the cylinder is compatible with the virtual key. However, it is preferred if multiple users, particularly each user, are able to transmit a current virtual cylinder to the computer system, so that each user, with the cylinder update function activated, can also invalidate their own virtual key by transmitting a new virtual cylinder, because the latter is no longer compatible with the new virtual cylinder. Accordingly, each user is then able to revoke their own authorization.

[0022] In summary, the door locking system according to the invention solves the problem known in access control systems of offline systems, where updates to authorizations have to be transferred to the door on-site via "sneaker programming." To solve this dilemma, the invention creates the prerequisite for the on-demand verification and transfer of virtual cylinders by at least one user, preferably by every user of the door locking system. This is based on the principle of a unified locking system known from the world of physical keys, where many identical, physical (metal) keys can open a door with an identical profile cylinder for many different users. This model is transferred to a corresponding virtual world, i.e.,Virtual keys are distributed to users and virtual cylinders to doors (= objects), whereby, before a door is opened, the current authorizations, in particular a user's virtual key and a door's or object's virtual cylinder, are transferred and synchronized as needed. It is preferred that each user of the door locking system, with a suitable mobile device, especially one with its own processor, is able to receive virtual cylinders, store them on the device, and—at least as needed—transmit them to the computer system of at least one door in the door locking system.

[0023] A computer system according to the invention comprises, in particular, firmware for at least one door, software, especially an app, for at least one mobile device carried by a user, and a backend. The backend is part of a server side of the computer system itself or of another computer system that is functionally connected to one or more computer systems according to the invention. The backend preferably has a user interface through which backend-side tasks can be performed by authorized persons without programming knowledge. Such a user interface is also referred to as a portal within the scope of this disclosure. This is a user interface intended, in particular or exclusively, for the operator or administrator of a door locking system, through which administrative tasks can be performed, such as...Creating new users, deleting, assigning and modifying user permissions, or adding, removing, naming or renaming doors.

[0024] Preferably, the at least one computer system has a backend or is functionally connected to another computer system with a backend that is functionally connected—at least temporarily—to a plurality of doors as defined in the invention. This functional connection can be established via a wired or wireless connection. Preferably, the computer system, at least partially, and in particular the server-side backend, is connected to the internet and / or to a mobile network and / or a data network. In summary, the foregoing means, in particular, that there can be exactly one backend or a few backends for all computer systems of a provider, so that all doors as defined in the invention can be managed via this one backend or these few backends.An internet connection does not necessarily have to be permanently available, as the cylinder update function works independently of an internet connection to a backend.

[0025] If the door locking system has two or more doors, each door can have its own computer system with the functionality described above. In this case, an internet connection for the computer system is not strictly necessary, as the door locking system can also be updated and operated solely through communication between users.

[0026] Alternatively, a multi-door locking system can be configured so that several doors share a common computer system. In particular, a computer system can be assigned to an object and all the doors within that object. Alternatively, a computer system can be assigned to several doors that must always be opened in combination to access a specific location within an object, for example, two functionally linked fire doors, where granting permission to open only one of these doors would be pointless. Furthermore, a computer system can also consist of several subsystems or be designed as a whole with a single backend for a multitude of objects.

[0027] One advantage of the invention is that a user does not need to be connected to the internet with their mobile device while at a door. To carry a sufficiently up-to-date cylinder, it is enough if the mobile device has a computer program, in particular an app, in which at least one current virtual cylinder and one virtual key can be temporarily stored. The user can then transfer these to the computer program functionally associated with the door, particularly using the computer program or the app.

[0028] Furthermore, it is noted that the door locking system could be designed so that each user is assigned an individual virtual key and each door has its own individual virtual cylinder for each user. In this case, the individual virtual cylinder would only need to be replaced if the specific user's access to the door assigned to that virtual cylinder is to be revoked. However, this requires storing an individual virtual cylinder for each user at every door. This results in a significantly higher programming, storage, and data processing effort at each door. Therefore, it is preferable if shared virtual cylinders are provided, at least in groups, for a number of users within a specific group. Preferably, each door is assigned exactly one virtual cylinder, which is used jointly by all users.

[0029] A group that can be considered to include, in particular, tenants of an apartment or house, tradespeople, caretakers, cleaning staff, property managers, and other people with similar access authorization profiles. In this case, fewer users are affected if authorization is revoked, which can have advantages in terms of data protection.

[0030] In a practical implementation of a computerized door locking system, the mandatory cylinder update function is permanently activated. This means that a user's virtual key is only considered by the computer program for verifying authorization to open the door if and when the user has previously transmitted a current virtual cylinder to the computer system that is compatible with the virtual key. In this case, a virtual cylinder must be transmitted for comparison at least once during each opening process. However, the virtual cylinder only needs to be replaced if the virtual cylinder transmitted by the user is different from the one currently assigned to the door.Preferably, the virtual cylinder assigned to a door is only replaced if the cylinder update function is activated and the virtual cylinder transmitted by the user has a newer timestamp than the virtual cylinder currently assigned to the door.

[0031] Alternatively, a comparison function between the virtual cylinder currently assigned to the door and a virtual cylinder transmitted by the user can be omitted by always assigning a virtual cylinder transmitted by the user to the door as the current virtual cylinder of the door, so that the virtual cylinder is always overwritten with each new user of the door. Preferably, at least one timestamp comparison is provided by means of which a timestamp assigned to the user's virtual cylinder is compared with a timestamp of the virtual cylinder currently assigned to the door, whereby the virtual cylinder assigned to the door is only replaced by the virtual cylinder transmitted by the user if the timestamp of the virtual cylinder transmitted by the user has a more recent date than the virtual cylinder assigned to the door.

[0032] In another practical embodiment of a computer-aided door locking system, the mandatory cylinder update function is permanently activated, at least with a time setting, such that an updated virtual cylinder must be transmitted after a predetermined or predefinable time window in order to activate the door opener or open the door. In this case, the average response time of the doors in the locking system can be reduced by not requiring a virtual cylinder update with every user, but instead considering an update of the virtual cylinder assigned to a door only after one day, two days, three days, seven days, or another period of time as sufficient.In this case, it is sufficient if the virtual cylinder assigned to a door is only updated as needed after the respective specified time has elapsed, i.e., when the virtual cylinder assigned to the door has a timestamp that has reached the specified age (e.g., 24 hours, 2 days, 3 days, 7 days, etc.).

[0033] If a computerized door locking system assigns exactly one virtual cylinder to each door, and virtual keys can be generated as needed to grant access to additional users, this offers the advantage that the virtual cylinder only needs to be replaced when a user's access to one or more doors is revoked. In other words, the virtual cylinder assigned to a door, which is relevant for all authorized users with regard to their respective compatible virtual keys, can remain unchanged until the first user's access to that door is revoked. Only then does the virtual cylinder need to be replaced and compatible virtual keys transferred to the authorized users.

[0034] Preferably, virtual keys are provided in the form of so-called access tokens. In addition to the virtual key itself, these tokens contain optional, further information that primarily serves to enhance security. Details on this will be discussed later in connection with the character descriptions.

[0035] In another practical embodiment of a computerized door locking system, a challenge-response security system is integrated into the computer program. This system requires that any communication between a user's virtual key and the computer program associated with the door be preceded by the solution of a task using the virtual key. Solving this task can, in particular, involve solving a cryptographic puzzle to prove possession of a valid virtual key. This has the advantage that, before any further communication between a user's mobile device and the computer program associated with the door, it can be reliably verified that their virtual key is communicating with an authenticated system.Because the lock and smartphone never directly exchange key material, "man-in-the-middle" attacks can be reliably avoided.

[0036] As mentioned above, a large number of users are preferably part of the door locking system, with at least one user group in which, for each user, the virtual key of the respective user is only considered by the computer program to verify authorization to open the door if and when the cylinder update function is activated. This applies to a door opener only if and when the user has previously transmitted an up-to-date virtual cylinder to the computer system. This could, for example, be a main user group consisting of regular users for whom a high level of security regarding the update status of the door locking system is desired.Preferably, the above applies to every user, so that each user is able to update the cylinder assigned to the respective door by transmitting a current virtual cylinder and actually performs this update when the cylinder update function is activated.

[0037] If a computer-aided door locking system includes a decision module in its software product that compares a virtual cylinder transmitted by a user with a virtual cylinder stored in the software product, and only replaces the virtual cylinder stored in the software product with the transmitted cylinder if the comparison reveals that the virtual cylinder transmitted by the user is a more up-to-date virtual cylinder than the virtual cylinder currently stored in the software product, then the data processing effort and thus the response time of the respective door are minimized while simultaneously ensuring maximum possible application security.

[0038] In a particularly preferred embodiment, the replacement of the virtual cylinder stored in the computer program product, as an additional necessary condition, only occurs after it has been verified that data (in particular an access token) has been encrypted with the PSK of the virtual lock. The advantage of this is that it ensures that the new virtual cylinder is a virtual cylinder originating from an authentic backend.

[0039] If each virtual cylinder is part of a virtual lock to which a pre-shared key (PSK) is assigned, the security of a door locking system according to the invention can be further increased insofar as encrypted communication between users, in particular a user's respective mobile device, and the computer program product assigned to the door can take place using the pre-shared key (PSK). This significantly reduces the risk of the communication between a user, in particular a user's mobile device, and the computer program product assigned to a door being stored and evaluated by third parties for misuse. In particular, background updates can be carried out securely using the pre-shared key, both between users' mobile devices and the computer program product assigned to a door, and between a backend and the computer program products assigned to each door.

[0040] The invention also relates to a method for operating a computer-controlled door locking system with at least one door associated with an object, at least one door opener associated with the door, and a computer system functionally connected to the door opener or the door, comprising a computer program product and a processor. The computer program product includes executable code which, when executed in the processor, is configured to verify, when a user employs a virtual key at the door opener of a specific door, whether the virtual key is associated with the authorization to open that door and, if so, to trigger the opening of a physical door lock associated with the door by activating the door opener or by opening the door itself. To verify the authorization to open a door, the following is required: a) in a first step, a user transmits a virtual cylinder to the computer system functionally connected to the door opener or the door, so that b) in a second step, the computer program product checks whether the virtual cylinder is more up-to-date than a virtual cylinder stored by the door opener or the door, whereby, if positive, the transmitted virtual cylinder in the computer system is replaced by the virtual cylinder transmitted by the user, and c) In a third step, it is checked whether the user's virtual key and the currently stored virtual cylinder are compatible, whereby the computer program product only allows the door to be opened if compatibility has been confirmed.

[0041] If, in the process, the execution of the first step by a virtual lock associated with the virtual cylinder is only permitted if, within the framework of communication between the virtual lock and the user's virtual key, a cryptographic task set by the virtual lock has been successfully solved using the virtual key, authentication is mandatory, as already described above in connection with the door locking system. The associated advantages are hereby reiterated.

[0042] Further practical embodiments and advantages of the invention are described below in connection with the drawings. They show: Fig. 1. A schematic diagram of an exemplary implementation of an access authorization based on four individual pieces of information, as well as the derivation of a virtual key and an access token from the access authorization. Fig. 2 a schematic representation of an embodiment of an infrastructure suitable for a computer-aided door locking system according to the invention, Fig. 3 a schematic representation of an infrastructure known from practice (state of the art), Fig. 4. A flowchart to illustrate the individual process steps involved in opening a door and Fig. 5. A description of the communication process in the event of a withdrawal of authorization.

[0043] In the figures explained below, information and data flows, as well as communication in general, are represented by arrows. A one-way arrow indicates that the information and data flow, or communication, occurs only in the direction indicated by the arrow. Lines marked with arrows on both sides indicate that the information and data flow, or communication, is intended to occur in both directions, particularly through a reciprocal exchange of data and information.

[0044] In the Fig. In the embodiment shown in Figure 1, the access authorization 1e comprises, in particular, four separate pieces of information: Permission Timing Information 1a, Permission Scope Information 1b, User ID Information 1c, and a virtual cylinder 1d. Permission Timing Information 1a contains information about the validity period of the authorization, for example, in the form of an expiration date. Permission Scope Information 1b specifies the level of authorization a user has, for example, the authorization to simply open a door or, if the user is an administrator of an object, to remove the lock from the door. User ID Information 1c is a unique identifier assigned to the user, which allows the computer system to track which user opened which door and at what time.The virtual cylinder 1d is a virtual cylinder assigned to a door, which, when the cylinder update function is activated, can be transferred from the access authorization 1e to the computer system of a door.

[0045] In this example, the information 1a, 1b, 1c and 1d are combined as a so-called Access Permission Information 1e.

[0046] Based on the information 1a, 1b, 1c and / or 1d, a virtual key 1g is generated in accordance with step 1.1 as part of a so-called Key Derivation Function, which is sent to a user's mobile device.

[0047] Based on the information 1a, 1b, 1c and / or 1d, an access token 1f is generated according to step 1.2 as part of an encryption process. This access token is also sent to a user's mobile device and contains the virtual cylinder 1d. The access token can only be decrypted by the lock using the PSK, in order to, for example, extract the virtual cylinder for the cylinder update function according to the invention.

[0048] The Fig. 2 and Fig. Figure 3 shows, for comparison, an infrastructure of an exemplary embodiment of a computer-aided door closing system according to the invention ( Fig. 2) and a door locking system known from practice ( Fig. 3) to visualize an advantage of the door closing system according to the invention.

[0049] Thus, from a synthesis of the Fig. 2 and Fig. It is clearly evident that some basic elements of the respective infrastructures are the same. For example, the infrastructures consist of Fig. 2 and the infrastructure from Fig. 3 each from a backend 2a, 3a and a virtual castle 2c, 3c.

[0050] Regarding the infrastructure from Fig. 2. The functional connection between the backend 2a and the virtual lock 2c is established as needed via a mobile device 2b, in particular a smartphone, smartwatch, transponder, or other mobile device 2b suitable for the corresponding communication. This mobile device does not require a permanent internet connection or a permanent connection to the virtual lock 2c. The mobile device 2b can even be completely disconnected from the internet if updates are possible via other data transmission methods or by replacing the mobile device 2b itself. The only essential requirement of the mobile device 2b is that it is capable of storing a current virtual key (not shown) and a current virtual cylinder and transmitting them to a virtual lock 2c as needed – preferably in encrypted form.

[0051] The connection 2x established at least as needed between the backend 2a and the mobile device 2b is in particular a mobile network connection, a WiFi connection, a satellite internet connection or another connection functionally suitable for the respective data transmission.

[0052] The connection 2y between the mobile device and the virtual lock 2c, which is established at least as needed, is in particular a Bluetooth connection, an NFC connection (Near Field Communication), a UWB connection (Ultra-Wideband), a WiFi connection (Wireless Fidelity), a Bluetooth connection or another connection suitable for the respective data transmission.

[0053] In contrast to the infrastructure from Fig. 2. This is done with the infrastructure from Fig. 3. The functional connection between the backend 3a and the virtual lock 3c is permanently established via an internet gateway 3b. This connection is a critical element, as a permanent connection to the internet and to the virtual lock 3c is also required. Another difference in Fig. The infrastructure shown in section 3, which is known from practice, consists of a mobile device (3d) that establishes a wireless connection (3x) to the backend (3a) as needed. This connection (3x) requires a mobile network connection, a Wi-Fi connection, a satellite internet connection, or another functionally suitable connection.

[0054] A significant advantage that is in Fig. The infrastructure shown in Figure 2 for computer-aided door locking systems according to the invention consists in that communication between backend 2a and virtual lock 2c is provided via a mobile device 2b, namely through connections 2x and 2y. Connection 2y does not require an internet connection, so that the door locking system can also be operated and updated – via the mobile device 2b – in locations without an internet connection.

[0055] Fig. Figure 4 shows a flowchart illustrating the individual steps involved in opening a door. This involves – at least partially – communication between a virtual lock 4a and a mobile device 4b belonging to a user (not shown). The mobile device, specifically an app installed on it, stores at least one access token 4c, comprising a virtual cylinder, and one virtual key 4d.

[0056] In the first step of the process, according to step 4.1, the access token 4c stored on the mobile device 4b is transmitted to the virtual lock 4a.

[0057] Subsequently, according to step 4.2, an authentication check is optionally performed by the virtual lock 4a itself by verifying the presence of certain data using a specific procedure that is not relevant to this disclosure. Such a check can, in particular, be performed by verifying whether the data has been encrypted with the virtual lock's PSK. Furthermore, according to step 4.2 – preferably mandatory – the cylinder update function is initiated by checking whether the virtual cylinder 4c transmitted by the mobile device 4b has a more recent timestamp than the virtual cylinder stored in the virtual lock 4a (not shown). In other words, it is checked whether the virtual cylinder 4c transmitted by the mobile device 4b, which is part of the access token, is more recent than the virtual cylinder stored in the virtual lock 4a.

[0058] If this is the case, or if the virtual cylinder on the lock is identical to the virtual cylinder transmitted via the access token, a challenge-response security system is optionally started in the computer system functionally connected to the virtual lock 4a, according to step 4.3. For this purpose, a task (challenge), preferably encrypted, is transmitted from the virtual lock 4a to the mobile device 4b.

[0059] If a challenge-response security system is in place, it may be designed in particular to only transmit a task in the following cases A) and B): A) The user transfers a virtual cylinder that is newer than the virtual cylinder stored on the lock. B) The user transfers a cylinder that is identical to the virtual cylinder stored on the virtual lock.

[0060] Otherwise, in particular if the user transmits an older virtual cylinder than the virtual cylinder stored on the virtual lock, the task will not be transmitted.

[0061] The mobile device 4b then attempts to solve the challenge according to step 4.4 and subsequently sends the result of the challenge, i.e., the solved challenge, back to the virtual lock 4a according to step 4.5. The challenge can only be solved correctly using a valid virtual key. The return message according to step 4.5 is coupled with a command to be executed by the virtual lock 4a, e.g., opening a door.

[0062] If no challenge-response security system is in place, there was no task to solve, so in this case the command is sent directly from the mobile device 4b to the virtual lock 4a in accordance with step 4.4.

[0063] If a challenge-response security system is in place, the virtual lock 4a checks the solved task according to step 4.6, with solving the task serving as confirmation of possession of a virtual lock compatible with the virtual cylinder. If the task was solved correctly, the command sent from the mobile device 4b to the virtual lock 4a, e.g., opening a door, is executed.

[0064] Unless a challenge-response security system is in place, the command is executed immediately.

[0065] Fig. Figure 5 shows a representation of the communication process between two mobile devices 5b and 5c belonging to two different users, a virtual lock 5a, and a backend 5f. The user of mobile device 5b is referred to as User 1 and the user of mobile device 5c as User 2.

[0066] As in the Fig. As shown on the far left, in the initial situation user 1 and user 2 each have the same virtual cylinder 5d and the same, compatible virtual key 5e on their mobile devices 5b, 5c.

[0067] Now, user 2's authorization for virtual lock 5a is to be revoked. This is achieved by creating a new virtual cylinder 5g (i.e., a more up-to-date virtual cylinder) and a compatible new virtual key 5h for virtual lock 5a via backend 5f. This new virtual cylinder 5g and virtual key 5h are distributed to all users who should retain the corresponding authorization. This is illustrated in step 5.1 using user 1 as an example, who receives the new virtual cylinder 5g and the compatible new virtual key 5h via backend 5f. All other users (not shown) receive the new virtual cylinder 5g and the compatible new virtual key 5h in the same way. Users whose authorization is to be revoked optionally receive only the new virtual cylinder 5g (in Fig. 5 not shown), but not the new virtual key 5h.

[0068] If user 2's mobile device is reachable by the backend 5f, the authorization can be revoked immediately according to optional step 5.2 by the backend 5f sending a command to the mobile device 5c, specifically to an app installed on it, instructing the virtual cylinder 5d and the virtual key 5e to be deleted. Alternatively, only the new virtual cylinder 5g can be transmitted to user 2. The latter option (not shown) has the advantage that user 2 is also able to execute step 5.3, explained below, to revoke their own authorization to open the virtual lock 5a.

[0069] According to step 5.3, user 1 communicates with virtual lock 5a using their mobile device 5b, specifically because they want to send an opening command to virtual lock 5a. The cylinder update function is active, which means that the new virtual cylinder 5g stored on user 1's mobile device is initially transmitted to virtual lock 5a. Because this cylinder has a more recent timestamp, or alternatively because the cylinder update function is permanently active, the virtual cylinder 5d stored in virtual lock 5a is first replaced by the new virtual cylinder 5g. From this point on, user 2, who does not have the new virtual key 5h, can no longer open virtual lock 5a, even if their phone has not been online since the authorization was revoked and the original virtual cylinder and virtual key remain on their phone.

[0070] Was the new virtual cylinder 5g also transmitted to user 2 by the backend (in Fig. (5 not shown), he could himself transfer the new virtual cylinder 5g, analogous to step 5.3, which is in Fig. 5 is carried out by user 1.

[0071] The features of the invention disclosed in this description, in the drawings, and in the claims can be essential for realizing the invention in its various embodiments, both individually and in any combination. The invention is not limited to the described embodiments. It can be varied within the scope of the claims and taking into account the knowledge of the person skilled in the art. Reference symbol list Step 1.1 Step 1.2 Step 1.3 1a Permission Timing Information 1b Permission Scope Information 1c User ID Information 1D virtual cylinder 1e Access Permission Information 1f Access Token 1g virtual key 2a Backend 2b Mobile device 2c virtual castle 2x connection 2y connection 3a Backend 3b Internet Gateway 3c virtual castle 3D mobile device 3x connection 3y connection Step 4.1 Step 4.2 Step 4.3 Step 4.4 Step 4.5 Step 4.6 4a virtual castle 4b Mobile device 4c Access Token (virtual cylinder) 4D virtual key Step 5.1 Step 5.2 Step 5.3 5a virtual castle 5b Mobile device 5c mobile device 5D virtual cylinder 5th virtual key 5f Backend 5g new virtual cylinder / more up-to-date virtual cylinder 5h new virtual key / more up-to-date virtual cylinder QUOTES INCLUDED IN THE DESCRIPTION

[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature

[0000] EP 3 770 867 A1

[0013]

Claims

Computerized door locking system comprising a) at least one door associated with an object, b) at least one door opener associated with the door, and c) at least one computer system functionally connected with the door opener or the door, comprising a computer program product and a processor, wherein d) the computer program product comprises an executable code which, when executed in the processor, is configured to check, with the aid of the computer program product, whether the virtual key (1g, 4d, 5e) is associated with the authorization to open this door when a virtual key (1g, 4d, 5e) is used on a door opener of a specific door, and if so, to cause the opening of a physical door lock associated with the door by activating the door opener or to open the door, characterized in that e) a mandatory cylinder update function is implemented in the code of the computer program product, which can be activated at least on demand.where, in the activated state of the cylinder update function, the virtual key (1g, 4d, 5e) of at least one user of a door opener is only considered by the computer program product for verifying the authorization to open this door if the user has previously transmitted a current virtual cylinder (5g, 5h) to the computer system which is compatible in content with the virtual key (1g, 4d, 5e). Computer-aided door locking system according to the preceding claim, characterized in that the mandatory cylinder update function is permanently activated, so that the virtual key (1g, 4d, 5e) of a user is only taken into account by the computer program product for checking the authorization to open this door if the user has previously transmitted a current virtual cylinder (5g, 5h) to the computer system which is compatible in content with the virtual key (1g, 4d, 5e). Computer-aided door locking system according to claim 1, characterized in that the mandatory cylinder update function is permanently activated at least with a time specification such that after the expiry of a specified or specifiable time window, an updated virtual cylinder (5g, 5h) must be transmitted in order to activate the door opener or to open the door. Computer-aided door locking system according to one of the preceding claims, characterized in that exactly one virtual cylinder (1d, 4c, 5d) is assigned to a door of the door locking system, to which virtual keys (1g, 4d, 5e) can be generated as required to grant authorization to additional users. Computer-aided door locking system according to one of the preceding claims, characterized in that a challenge-response security system is stored in the computer program product, with which communication between a virtual key (1g, 4d, 5e) of a user and the computer program product requires the prior solving of a task using the virtual key (1g, 4d, 5e). Computer-aided door locking system according to one of the preceding claims, characterized in that a plurality of users are part of the door locking system, wherein at least one user group exists in which, for each user, the virtual key (1g, 4d, 5e) of the respective user is only considered by the computer program product for checking the authorization to open this door if the user has previously transmitted a current virtual cylinder (5g, 5h) to the computer system when the cylinder update function is activated. Computer-aided door locking system according to one of the preceding claims, characterized in that a decision module is stored in the computer program product, with which a virtual cylinder (1d, 4c, 5d) transmitted by a user is comparable with a virtual cylinder (1d, 4c, 5d) stored in the computer program product and which only causes the virtual cylinder (1d, 4c, 5d) stored in the computer program product to be replaced by the transmitted cylinder if the comparison determines that the virtual cylinder transmitted by the user is a more current virtual cylinder (5g, 5h) than the virtual cylinder (1d, 4c, 5d) currently stored in the computer program product. Computer-aided door locking system according to one of the preceding claims, characterized in that each virtual cylinder (1d, 4c, 5d) is part of a virtual lock (2c, 3c, 4a, 5a) to which a Pre-Shared Key (PSK) is assigned. Method for operating a computer-aided door locking system with at least one door assigned to an object, at least one door opener assigned to the door, and a computer system functionally connected to the door opener or the door, comprising a computer program product and a processor, wherein the computer program product includes an executable code which, when executed in the processor, is configured to check, when a user uses a virtual key (1g, 4d, 5e) at the door opener of a specific door, whether the virtual key (1g, 4d, 5e) is associated with the authorization to open that door, and if so, to cause the opening of a physical door lock assigned to the door by activating the door opener or to open the door, characterized in that, to check the authorization to open a door, a) in a first step, a user uses a virtual cylinder (1d, 4c,5d) must transmit to the computer system functionally connected to the door opener or the door, so that b) in a second step, the computer program product checks whether the virtual cylinder is more current than a virtual cylinder (1d, 4c, 5d) stored by the door opener or the door, whereby, if positive, the transmitted virtual cylinder in the computer system of the door opener or the door is replaced by the virtual cylinder (5g, 5h) transmitted by the user, and c) in a third step, it checks whether the user's virtual key (1g, 4d, 5e) and the currently stored virtual cylinder (5g, 5h) are compatible, whereby the computer program product only allows the door to be opened if compatibility has been confirmed. Method according to the preceding claim, characterized in that the execution of the first step by a virtual lock (2c, 3c, 4a, 5a) associated with the virtual cylinder (1d, 4c, 5d) is only permitted if, within the framework of communication between the virtual lock (2c, 3c, 4a, 5a) and the virtual key (1g, 4d, 5e) of the user, a cryptographic task posed by the virtual lock (2c, 3c, 4a, 5a) could be successfully solved using the virtual key (1g, 4d, 5e).