ACCESS SYSTEM
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- EUCHNER GMBH & CO KG
- Filing Date
- 2018-07-31
- Publication Date
- 2026-05-07
AI Technical Summary
Existing access control systems face limitations in flexibility, security, and convenience due to mechanical key switches, electronic keys, and password-based systems, with programmable systems requiring significant effort and lacking user-friendly configuration options.
An access control system with an access control unit that reads electronic key data, allowing configurable validity criteria, including checksum checks and logic functions, to determine key validity and send control signals directly to the system's controller, enabling flexible and secure access management.
The system provides a high level of functionality with flexible access permissions, enhanced security against copying, and user-friendly configuration, ensuring secure and fail-safe operation without needing programmable modules in the controller.
Description
[0001] The invention relates to an access system and a method for controlling access to a system controlled by a controller.
[0002] Such access systems are used in particular for access control to facilities, whereby facilities within the meaning of the present invention also include machines, work equipment, and the like. Generally, with such access systems, defined authorizations can be specified in such a way that only certain persons can have access to the facility, and access to specific areas or functions of the facility can be further individually restricted.
[0003] Common access control systems use mechanical key switches. With this type of system, a key switch can be inserted into a key slot of an access control unit in various rotational and detent positions. Depending on the specific rotational and detent position, different access permissions can be assigned to the system. A disadvantage of this system is the limited number of rotational and detent positions, which restricts the number of different access permissions that can be granted.
[0004] Other well-known access control systems use electronic keys, which can be in the form of transponders, USB drives, or magnetic strips. Each electronic key contains an identifier that can be read by an access control unit. If the access control unit recognizes the identifier as valid, it grants access to the system. The electronic keys can also store additional information. In this case, this information can be linked to each other or to the identifier, allowing for the creation of different access codes for the system.
[0005] Password-based access control systems are another common method. Their advantage lies in the ability to create virtually unlimited passwords, thus providing a correspondingly large number of access points to the system. However, a disadvantage is that users cannot remember an unlimited number of passwords, making them inconvenient. Furthermore, users typically do not change their passwords and often share them with others, ultimately rendering them insufficient for secure access protection.
[0006] It is known that access control can be implemented by programming the system's control unit. However, the system's control unit is not designed for such access control. Therefore, significant effort is required for the necessary programming.
[0007] EP 0 699 617 A1 relates to an elevator system with a recognition device. Upon a corresponding request from the recognition device, an information transmitter sends data. This data can directly contain information about the desired destination floor or serve to identify the elevator user, thus enabling access to information about the destination floor stored in a memory. The memory is housed in a processing unit of an elevator control system. Communication between the recognition device and the information transmitter takes place via radio frequencies. Based on the received data, the processing unit evaluates the destination floor and transmits it to the elevator control system. The assigned floor is displayed to the passenger. The call input process is automatic, contactless, and independent of the orientation of the information transmitter; that is, it does not need to be visible to the recognition device.An input device is installed to change the floor proposed by the processing unit.
[0008] GB 2 352 057 A concerns an access platform used to control machine functions. The access method is a smart card containing pre-programmed information based on predetermined criteria related to the machine's functions. The information stored on the smart card is read into a processor. The processor then only enables the machine to operate the functions specified on the smart card.
[0009] US 2007 / 0252675 A1 concerns an access system with an electronic key used to control a unit, such as a machine or similar device. The code contained in the key can be read by a control unit, which is equivalent to an access control unit.
[0010] German patent DE 101 52 349 A1 relates to a security device that enables controlled access to restricted security areas by authorized persons in a simple manner. For this purpose, the security device is equipped with a bus system that connects a central control unit to several actuators, each assigned to at least one of the security areas. Access authorization is verified and controlled using a personal identification device.
[0011] The invention is based on the objective of providing an access system that has a high level of functionality.
[0012] The features of the independent claims are provided to solve this problem. Advantageous embodiments and expedient further developments of the invention are described in the dependent claims.
[0013] The invention relates to an access control system for controlling access to a system controlled by a controller, comprising an access control unit and at least one electronic key, wherein the access control unit is configured to read key data stored in an electronic key. Various criteria can be specified in the access control unit by inputting commands, according to which the validity of an electronic key is determined based on the key data read from it, one of the specifyable validity criteria being a checksum check. Upon recognition of a valid electronic key, the access control unit sends at least one signal to the controller.The electronic key includes a memory for the key data, which is divided into different areas. One area is a non-writable memory containing an identifier for the electronic key. The other areas are writable memory, each containing user key data. One of these other areas is designated for storing a configurable checksum. The checksum comprises the identifier and some or all of the other key data. The scope of the checksum is configurable. Upon detection of a valid checksum, the electronic key is recognized as valid, and the access control unit generates a signal for the controller.The checksum check is performed by calculating the checksum in the access control unit based on the key data stored in the electronic key and comparing it with a checksum stored in the electronic key.
[0014] The invention further relates to a corresponding method.
[0015] The access system according to the invention allows for flexible configuration of different access methods to the system, adapted to application-specific constraints. The access system, together with the access control unit and its associated electronic keys, forms a secure, and in particular tamper-proof, system for controlling access to the system.
[0016] The basic idea of the invention is that a user can define different criteria in the access control unit to determine the validity of an electronic key. The user can use all or only a portion of the key data stored in the electronic key for a validity check. Furthermore, the operating mode of the system can also be selected based on the key data. As described, for example, in DE 10 2015 114 717 A1, an operating mode selection can include automatic operation of the system and / or operation of the system with or without security monitoring.
[0017] The access control unit is a programmable unit containing a processor or similar component. A suitable configuration system with input options allows a user to easily and quickly define criteria for the validity of an electronic key. By defining different criteria, the user can also define different access permissions, such that an electronic key, whose key data is read by the access control unit and classified as valid, only grants access to specific areas or functions of the system.
[0018] A particular advantage here is that all key data stored on an electronic key can be used individually or in combination to define validity criteria. This allows for a corresponding variety of different access authorizations for the system.
[0019] A key aspect of the invention is that the criteria for the validity of an electronic key are defined solely within the access control unit, with the user entering suitable input commands into the access control unit. This has the advantage that no units, in particular no programmable modules, need to be provided in the controller for access control to the system. Instead, signals are sent from the access control unit to the controller, which can then directly use them as control commands.
[0020] The access control unit can perform a general verification of the validity of an electronic key, in particular by determining the validity of an electronic key based on an identifier stored in a non-writable memory of the electronic key. As is known, the electronic key has a memory with a user-writable and a non-writable part.
[0021] The identifier stored in the electronic key thus forms an unchanging, individual code that can be used to identify the electronic key.
[0022] Furthermore, the validity of an electronic key can also be checked using an expiry date stored in it.
[0023] According to the invention, the validity of an electronic key is determined by means of a checksum for key data stored in the electronic key.
[0024] The size of the checksum can be adjusted.
[0025] Advantageously, the checksum includes the identifier stored in the electronic key in the non-writable part of the memory.
[0026] The checksum check is performed by calculating the checksum in the access control unit based on the key data stored in the electronic key and comparing it with a value stored in the electronic key.
[0027] The checksum verification provides protection against copying the electronic key, because when the key is copied, the identifier is not copied along with it, but only additional key data stored in writable memory. Since the copying is done to an electronic key with a different identifier, the checksum for this new electronic key no longer matches after the copying process, thus detecting the unauthorized copying.
[0028] In addition to the general recognition of the validity of an electronic key, the invention also enables a specific recognition of the validity of an electronic key. For this purpose, various key data stored on the electronic key are linked to an adjustable logic function as a criterion for the validity of the electronic key.
[0029] This method exploits the fact that different types of key data are stored in different areas of a writable memory of an electronic key.
[0030] The access control unit can thus read the various key data from the electronic key in the different areas of the writable memory and link them with logic functions to define validity criteria.
[0031] Various types of data can be stored in the electronic key, including information about the system, such as the plant where it is installed, possibly supplemented by area or department, or specific parts of the system.
[0032] Since user-specific data of the electronic key is also stored, validity criteria can be defined for electronic keys from different manufacturers, meaning that access to the system is possible with electronic keys from different manufacturers, whereby user-specific programming of the access control unit, in particular a specification of logic function, type and scope of access, can be flexibly defined.
[0033] The access control unit offers a selection of different logic functions.
[0034] In particular, any combination of logic functions such as an "AND", an "OR", a "NOT" or a "COMPARE" can be provided.
[0035] In the access control unit, several logic functions can be combined into one logic condition, where the logic condition is a criterion for the validity of an electronic key and / or serves to specify functions of the system.
[0036] In particular, logic functions are grouped with parentheses in the logic condition.
[0037] A key aspect of the invention is that the user-specific configuration of the access control for the system is carried out solely in the access control unit, and this unit directly transmits signals, in particular control commands, to the system's control unit, which can be used directly in the control unit.
[0038] According to an advantageous embodiment, the signal output to the control system is an ON signal to enable operation of the system or an OFF signal to shut down the system.
[0039] Alternatively, an operating mode of the system is selected using a signal sent to the control unit.
[0040] This significantly expands the functionality of the access control unit. In particular, it is advantageous that the access control unit can also achieve a safe, i.e., fail-safe, operating mode selection in the sense of machine safety, not access security, which is necessary for the use of the access system in the field of safety engineering. In general, the access system according to the invention exhibits fail-safe functionality in the sense of machine safety.
[0041] The operating mode selection can be initiated by reading an electronic key using the access control unit. For this purpose, an authorization to select an operating mode of the system is stored as key data in an electronic key.
[0042] For operating mode selection, it is advantageous to connect the access control unit to an operator panel, for example, a touchscreen, via a bus system or another suitable communication interface, such as USB. After reading authorization for an operating mode selection in an electronic key, the access control unit sends a request to the operator panel, whereupon the operator panel sends the selected operating mode back to the access control unit, which then forwards the signal to the controller.
[0043] A non-safety-based bus system is provided for the connection between the access control unit and the operator panel. However, safe operating mode selection can be achieved by providing a safe selection procedure for operating mode selection, as described in German patent application DE 10 2015 114 717 A1, using the access control unit and / or the operator panel.
[0044] Another advantage is that the operating mode selection is configurable, meaning the user can specify the type and scope of the operating mode selection.
[0045] The invention will be explained below with reference to the drawings. The drawings show: Figure 1: First embodiment of the access system according to the invention. Figure 2: Schematic representation of the memory of an electronic key for the access system according to the invention. Figure 1 Figure 3: Second embodiment of the access system according to the invention.
[0046] Figure 1 Figure 1 shows a first embodiment of the access system 1 according to the invention for controlling access to a system 3 controlled by a controller 2. The system 3 can generally also be a machine, a piece of equipment, or a mobile system. The controller 2 can be a PLC or the like.
[0047] The access system 1 comprises as essential components an access control unit 4 and the associated electronic key 5, of which in Figure 1 Only one is shown. In this case, the electronic keys 5 consist of a transponder. In principle, the electronic keys 5 could also be made up of chips, magnetic strips, and the like.
[0048] The access control unit 4 has a processor 6, in particular a microprocessor, which controls the functions of the access control unit 4. The access control unit 4 also has an output structure 7 with one or more outputs and / or a communication system, for example a bus, via which the access control unit 4 is connected to the controller 2. Furthermore, the access control unit 4 has a sensor unit 8 with which key data stored in an electronic key 5 can be read. In order to read key data from an electronic key 5, the electronic key 5 must be brought so close to the access control unit 4 that it is within a reading distance of the reading unit. In principle, the electronic key 5 can be inserted through a receptacle (not shown) of the access control unit 4 for this purpose.
[0049] Finally, the access control unit 4 is connected to an input / output unit 9 with a suitable user interface for configuration purposes, allowing a user to input values into the access control unit 4 or its processor 6. In principle, the input / output unit 9 could also be integrated into the access control unit 4.
[0050] The access system 1 generally functions as follows: key data read from an electronic key 5 is checked in the access control unit 4 according to predefined validity criteria to determine whether a valid electronic key 5 is present. If an electronic key 5 is recognized as valid, the access control unit 4 grants controlled access to the system 3. For this purpose, the access control unit 4 sends corresponding signals to the controller 2 via the output structure 7.
[0051] According to the invention, user-specific validity criteria for the electronic keys 5 are defined by suitable user input via the input / output unit 9. The assignment of validity criteria and the verification of compliance with these criteria for the individual electronic keys 5 thus take place in the access control unit 4 and not in the controller 2. Upon recognition of a valid electronic key 5, the access control unit 4 sends signals in the form of control commands to the controller 2, which can be determined there or provided for the controller 2 of the system 3.
[0052] In particular, the signal output to control unit 2 can also be an ON signal to enable the operation of system 3 or an OFF signal to shut down system 3. Furthermore, data can be sent to system 3, especially to define its functions.
[0053] Figure 2Figure 1 schematically shows the memory of an electronic key 5, divided into different areas a, b1 ... bN. Area a is a non-writable memory containing an identifier for the electronic key 5. Areas b1 ... bN are writable memory. All electronic keys 5 have a corresponding memory subdivision. User key data is stored in each of the individual areas b1 ... bN. This key data can include data relating to Annex 3. Furthermore, an expiration date for an electronic key 5 can be stored. Finally, an area is provided for storing a checksum, which is preferably configurable. The checksum includes the identifier and preferably some or all of the other key data.
[0054] In the access control unit 4, a validity check of an electronic key 5 is carried out on the basis of the data read from it, whereby the validity criteria in the access control unit 4 can be specified by a user via the input / output unit 9.
[0055] Validity criteria can include, for example, the recognition of the identifier, the checksum and / or the expiry date.
[0056] Upon detection of a valid identifier or checksum, or if the expiration date has not yet expired, the electronic key 5 is recognized as valid and the access control unit 4 generates a signal for the controller 2, for example, an ON signal to enable functions of the system 3. Depending on the result of the validity check, only some of the functions of the system 3 may be enabled.
[0057] Alternatively or additionally, for a validity check, key data from different areas b1 ... bN can be linked using user-defined logic functions. A logic function is an "always TRUE", an "AND", an "OR", a "NOT", or a "COMPARE".
[0058] In particular, several logic functions can be combined into a logic condition, where the logic condition is a criterion for the validity of an electronic key 5.
[0059] Logic functions can be grouped using parentheses in the logic conditions.
[0060] The validity criteria can be linked to different access permissions, so that different accesses to Annex 3 are granted depending on the established validity.
[0061] Figure 3Figure 1 shows a second embodiment of the access system 1. This access system 1 differs from the embodiment shown in Figure 1. Figure 1 This is only possible if the access control unit 4 is connected to an operator panel 11 via a bus system 10 or another communication interface. For this purpose, the access control unit 4 and the operator panel 11 each have a bus connection 12. The bus system 10 is configured as a non-safety-sensitive bus system 10. In principle, the operator panel 11 can also be connected to the controller 2.
[0062] Using this access system 1, an operating mode selection for the system 3 can be performed. An operating mode selection is initiated when the access control unit 4 reads an electronic key 5 in which authorization for an operating mode selection is stored. The access control unit 4 then sends a request to the operator panel 11, which in turn sends a selected operating mode, for example, as described in application DE 10 2015 114 717 A1, and forwards this as a signal from the access system 1 to the controller 2, where the operating mode is activated. The operating mode selection can be performed in a fail-safe manner, even though the bus system 10 is not inherently safe. The required safety is achieved through safe selection procedures in the access control unit 4 and / or in the operator panel 11. The operating mode selection is configurable and can thus be specified by a user. Reference symbol list
[0063] (1) Access system (2) Control unit (3) System (4) Access control unit (5) Electronic key (6) Processor (7) Output structure (8) Sensor unit (9) Input / output unit (10) Bus system (11) Operator device (12) Bus connection aArea b1 - bNAreas
Claims
1. Access system (1) for controlling access to a facility (3) controlled by a control unit (2), with an access control unit (4) and at least one electronic key (5), wherein the access control unit (4) is designed to read key data stored in an electronic key (5), wherein by entering input commands in the access control unit (4) different criteria can be specified, on the basis of which the validity of an electronic key (5) is determined on the basis of the key data read from it, wherein one of the specifiable validity criteria is a checksum check, and wherein, upon recognition of a valid electronic key (5), the access control unit (4) sends at least one signal to the control unit (2), characterised in that the electronic key (5) comprises a memory for the key data, which is divided into different areas (a, b1 ... bN), wherein one area (a) forms a non-writable memory in which an identifier of the electronic key (5) is stored, wherein the other areas (b1... bN) are writable memories in which user key data is stored, one of the other areas being provided for storing an adjustable checksum, the checksum comprising the identifier and some or all of the other key data, and the size of the checksum being adjustable, the access system (1) is designed such that, if the specified validity criterion is the checksum check, the electronic key (5) is recognised as valid when a valid checksum is detected and the access control unit (4) generates a signal for the control unit (2), and that the checksum check is performed in such a way that the checksum is calculated in the access control unit on the basis of the key data stored in the electronic key (5) and compared with a checksum stored in the electronic key (5).
2. Access system (1) according to claim 1, characterised in that the validity of an electronic key (5) is determined on the basis of an identifier stored in a non-writable memory of the electronic key (5).
3. Access system (1) according to one of claims 1 or 2, characterised in that, for the purpose of specifying functions of the system and / or as a criterion for the validity of an electronic key (5), different types of key data stored on this electronic key (5) are linked to one or a combination of adjustable logic functions, whereby a logic function, in particular an "AND", is an "OR", a "NOT" or a "COMPARE".
4. Access system (1) according to claim 3, characterised in that different types of key data are stored in different areas of a writable memory of an electronic key (5).
5. Access system (1) according to one of claims 3 or 4, characterised in that several logic functions are combined to form a logic condition, wherein the logic condition is a criterion for the validity of an electronic key (5), and / or functions of the system are specified by the logic condition.
6. Access system (1) according to claim 5, characterised in that logic functions are grouped with brackets in the logic condition.
7. Access system (1) according to one of claims 1 to 6, characterised in that the signal output to the control unit (2) is an ON signal for enabling functions of the system (3).
8. Access system (1) according to one of claims 1 to 7, characterised in that a mode of operation of the system (3) is selected by a signal sent to the control unit (2).
9. Access system (1) according to one of claims 1 to 8, characterised in that it has a fail-safe functionality in terms of machine safety.
10. Access system (1) according to one of claims 1 to 9, characterised in that an authorisation for selecting an operating mode of the system (3) is stored in an electronic key (5) as key data.
11. Access system (1) according to claim 10, characterised in that, for an operating mode selection, the access control unit (4) is connected to an operating device (11) via a bus system (10), in that the access control unit (4) sends a request to the operating device (11) after reading an authorisation for an operating mode selection in an electronic key (5), whereupon the operating device (11) sends a selected operating mode to the access control unit (4), which is forwarded as a signal to the control unit (2).
12. Access system (1) according to claim 11, characterised in that the option for selecting the operating mode is configurable.
13. Method for controlling access to a system (3) controlled by a control unit (2) by means of an access system (1) with an access control unit (4) and at least one electronic key (5), wherein the access control unit (4) is designed to read key data stored in an electronic key (5), wherein different criteria can be specified by entering input commands in the access control unit (4), on the basis of which the validity of an electronic key (5) is determined on the basis of the key data read from it, wherein a checksum check is specified as a validity criterion, and wherein, upon recognition of a valid electronic key (5), the access control unit (4) sends at least one signal to the control unit (2), characterised in that the electronic key (5) comprises a memory for the key data, which is divided into different areas (a, b1 ... bN), wherein one area (a) forms a non-writable memory in which an identifier of the electronic key (5) is stored, wherein the other areas (b1 ... bN) are writable memories in which user key data is stored, one of the other areas being provided for storing an adjustable checksum, the checksum comprising the identifier and some or all of the other key data, and the size of the checksum being adjustable, the electronic key (5) is recognised as valid and the access control unit (4) generates a signal for the control unit (2), and that the checksum check is performed in such a way that the checksum is calculated in the access control unit on the basis of the key data stored in the electronic key (5) and compared with a checksum stored in the electronic key (5).