Method, apparatus and system for accessing a production facility

DE502022003898D1Active Publication Date: 2025-05-22BKS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502022003898
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-07-09
Filing Date
2022-06-23
Publication Date
2025-05-22
Estimated Expiration
2042-06-23

AI Technical Summary

Technical Problem

Existing access control systems for production facilities lack robust mobile authentication methods, leading to potential unauthorized access.

Method used

A computer-implemented procedure for mobile authentication that involves reading user-specific data from a passive or active transmission device, generating a token with identification and temporal validity information, and encrypting/authenticating this data using cryptographic key pairs to ensure secure access.

Benefits of technology

This solution provides a high-security standard through dynamic encryption and authentication, effectively preventing unauthorized access by ensuring that only valid, time-stamped identification data grants access to production facilities.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to methods, devices and a system for accessing a production facility, in particular in an ordering process for locking systems or parts thereof.

[0002] Such an ordering process can include security cards that enable secure access to the production facility during the ordering process. For example, an ordered locking system or an ordered locking system part will only be released for production by the production facility if authentication is successful during the ordering process.

[0003] The US patent application US2020145212 is further prior art.

[0004] The methods and devices according to the independent claims provide secure mobile authentication of access to the production facility.

[0005] A computer-implemented method for triggering a request for access to a production facility with a user's terminal device provides that the method comprises the following steps: reading out data for identification by the terminal device and from a user-specific passive or active transmitting device on which this data is stored, generating a temporal validity, generating a token by the user's terminal device, wherein the token comprises information based on the data for identification and information on temporal validity, sending the token by the user's terminal device and to a computing device.

[0006] Preferably, the token comprises an encrypted and / or authenticated data set, wherein the data set comprises the identification information and / or the time validity.

[0007] It can be provided that the data comprise a first key of a first key pair, wherein the data comprise a first key of a second key pair, wherein the data comprise a first part of identification data for requesting access, in particular unencrypted, and that the data comprise an encrypted second part of the identification data, wherein the method comprises storing the first key of the first key pair and the first key of the second key pair, in particular in a data memory of the terminal device, sending the encrypted second part of the identification data and the first part of the identification data by the terminal device and to other computing devices, generating a time indication by the user's terminal device that lies within a permissible time range, generating the token by the user's terminal device, wherein the token comprises the data record,which is secured by an operation on the data record with the first key of the second key pair, whereby in the data record the information on temporal validity comprises the time specification and the information on identification comprises the identification data.,

[0008] This method can be implemented as an app for a mobile phone. The user-specific passive or active transmitting device can be a security card, e.g., a hybrid card with near-field communication and a magnetic stripe. The operation can be encryption using a cryptographic encryption method or a cryptographic signature method.

[0009] This method preferably offers a high security standard through dynamic encryption or authentication, whereby the method provides that the operation on the data record with the first key of the second key pair encrypts the data record or that the operation on the data record with the first key of the second key pair signs the data record.

[0010] The method may further comprise receiving data at the terminal device and from the other computing device, wherein the data is secured by an operation on the second part of the identification data with the second key of the first key pair, and checking and / or determining the second part of the identification data by an operation on the data with the first key of the first key pair.

[0011] To increase the security standard, it can be provided that the operation on the data with the first key of the first key pair decrypts the data or that the operation on the data with the first key of the first key pair verifies the data.

[0012] A computer-implemented method for controlling access to a production facility comprises receiving a token by a first computing device and from a second computing device, the token comprising information for identification and time validity, checking whether a data record matching the information for identification exists in a database and whether the token is within its time validity or not, allowing access to the production facility to be granted by the second computing device if the data record matching the information for identification exists in the database and the token is within its time validity, and otherwise refusing to grant access by the second computing device.

[0013] Preferably, the token comprises an encrypted and / or authenticated data set, wherein the data set comprises the identification information and / or the temporal validity.

[0014] It can be provided that the data record is secured by an operation on the data record with a first key of a second key pair, wherein in the data record the information on temporal validity comprises a time specification and the information on identification comprises identification data, wherein the method comprises: checking and / or determining the data record from the token by an operation on the data record with a second key of the second key pair, checking whether a data record matching the data record in the identification data exists in a database and whether the time specification lies within a permissible time range or not, allowing access to the production device to be granted by the second computing device if a data record matching the identification data exists in the database and the time specification lies within the permissible time range,and otherwise refuse to grant access by the second computing device.

[0015] This effectively prevents unauthorized access.

[0016] To increase security, the method may provide that the operation on the data record with the first key of the second key pair encrypts the data record, wherein the operation on the data record with the second key of the second key pair decrypts the data record, or that the operation on the data record with the first key of the second key pair signs the data record, wherein the operation on the data record with the second key of the second key pair authenticates the data record.

[0017] The method may include receiving a first part of the identification data, in particular unencrypted, and an encrypted second part of the identification data by the first computing device and the terminal device; identifying a data record in the server that matches the identification data by comparing the first part of the identification data and the second part of the identification data with the data records stored in the first computing device, in particular in the database; generating data by encrypting the second part of the identification data with the second key of the second key pair; and sending the data by the first computing device and to the terminal device. This further increases the security of the method.

[0018] A computer-implemented method for accessing a production facility, comprising receiving a token for a first computing device by a second computing device and from a user's terminal, the token comprising information for identification and time validity, sending the token by the second computing device and to the first computing device for verification of an access request, checking whether the first computing device allows access to the production facility or not, sending production data to the production facility if the first computing device allows access to the production facility (109) to be granted by the second computing device, and otherwise refusing to grant access by the second computing device.

[0019] Preferably, the token comprises an encrypted and / or authenticated data set, wherein the data set comprises the identification information and / or the temporal validity.

[0020] It can be provided that the data set is secured by an operation on the data set with a first key of a second key pair, wherein the information regarding temporal validity in the data set comprises a time specification and the information regarding identification comprises identification data. This effectively implements the decision as to whether access is permitted or not.

[0021] Security is increased if the operation is planned in addition to encrypted data transmission.

[0022] A terminal device, in particular a mobile terminal device, for a user is designed to carry out steps in the method for triggering a request for access to a production facility with a terminal device.

[0023] A first computing device, in particular a server, is designed to carry out steps in the method for controlling access to a production facility.

[0024] A second computing device, in particular an order server, is designed to carry out the method for accessing a production facility.

[0025] A system comprising the first computing device and the second computing device makes it possible to grant or deny targeted access to a production facility in an ordering process.

[0026] Access to the ordering process is provided to a user or company by a computer program containing computer-readable instructions, which, when executed by a computer, execute steps in a method. Further advantageous embodiments are evident from the following description and the drawing. The drawing shows: Fig. 1 a schematic representation of a system, Fig. 2 Steps in a procedure for accessing a manufacturing facility.

[0027] In the following description, operations are performed on data using a first key pair SP1 and a second key pair SP2. In this example, the first key pair SP1 and the second key pair SP2 are key pairs of a cryptographic procedure. Various cryptographic procedures can be used. The operations secure the data. In this context, "secure" means that unauthorized use of data secured with the operation or unauthorized access to it is made more difficult.

[0028] The first key pair SP1 comprises a first key S11 and a second key S12.

[0029] The second key pair SP2 comprises a first key S21 and a second key S22.

[0030] The operations can include encryption or decryption on the one hand. The operations can include signing or authentication on the other.

[0031] Encryption or decryption: For example, the first key S11 of the first key pair SP1 can be used to decrypt data that was encrypted with the second key S12 of the first key pair SP1.

[0032] For example, the second key S22 of the second key pair SP2 can be used to decrypt data that was encrypted with the first key S21 of the second key pair SP2.

[0033] Signing or authenticating: For example, the first key S11 of the first key pair SP1 can be used to verify data that was signed with the second key S12 of the first key pair SP1.

[0034] For example, the second key S21 of the second key pair SP2 can be used to verify data that was signed with the first key S21 of the second key pair SP2.

[0035] In Figure 1 A system 101 is shown schematically. The system 101 comprises a first computing device 102. In the example, the first computing device 102 is a server.

[0036] The first computing device 102 comprises a database 103 or is connected to it via a data line. The database 103 comprises a plurality of data records containing different identification data.

[0037] The first computing device 102 is configured to provide identification data, in particular from the database 103. The identification data comprises a first part I1 and a second part I2.

[0038] In this example, the identification data includes an object ID. The object ID uniquely identifies an entire system consisting of N keys and N locking cylinders.

[0039] The system 101 includes a user-specific passive or active transmitting device 104. In the example, the transmitting device 104 is a security card. In the example, the security card is assigned to a specific object ID.

[0040] Data K1, K2, K3, K4 are stored on the transmitting device 104.

[0041] The data K1 includes the first key S11 of the first key pair SP1.

[0042] The data K2 includes an encrypted second part I2 of the identification data for the object ID.

[0043] The data K3 includes the first key S21 of the second key pair SP2.

[0044] The data K4 includes the first part I1 of the identification data for the object ID, in particular unencrypted.

[0045] The second key S12 of the first key pair SP1 and the second key S22 of the second key pair SP2 are provided as authentication data to the computing device 101.

[0046] System 101 is configured to communicate with a user's terminal device 105. In this example, terminal device 105 is a mobile phone. An application, i.e., a computer program, can run on the mobile phone, allowing the user to perform a verification process for an order for a locking system or a part of the locking system, e.g., a key and / or a lock. In this context, a verification process means verifying whether or not the user is authorized to place an order.

[0047] The terminal 105 comprises a data memory 106. The terminal 105 is designed to carry out steps in a method described below.

[0048] The system 101 comprises a second computing device 108. In the example, the second computing device 108 is an order server that provides a service of a retailer during the ordering process. The service enables the user to carry out the verification process for the ordering process via the mobile phone. In the example, the service provides a selection of the locking system or part thereof. The service enables data for it, i.e., order information, to be entered via the mobile phone and the verification process for the ordering process to be carried out. In the example, the service enables identification data and tokens for it to be received and processed. The service comprises a user interface of an online retailer portal and an interface to the mobile phone for it. In the example, the service is one or more computer programs.

[0049] In this example, a payment transaction and / or order processing between a user and a retailer takes place in the retailer's system. A retailer's order is processed via an order portal.

[0050] During the verification process, the user identifies himself as authorized to place an order to the ordering portal and the retailer's system.

[0051] The system 101 is configured to communicate with a production facility 109. The production facility 109 and / or the terminal device 105 can also be part of the system 101.

[0052] The first computing device 102 is designed to carry out steps in the method described below.

[0053] The second computing device 108 is configured to provide order data B for a production process for manufacturing the locking system or the part of the locking system, e.g., a key and / or a lock, according to the order data B. In the example, the order data B comprise identification data from the ordering process.

[0054] The production facility 109 is designed to carry out the production process depending on the order data B. In the example, the production facility 109 is designed to manufacture the part of the locking system, in particular a key and / or a lock, according to the order data B.

[0055] To access the production facility 109 with the user's terminal device 105, the following steps are provided in particular in the system 101: Reading out data by the terminal device 105 and from the user-specific passive or active transmitting device 104 on which this data is stored.

[0056] The user's terminal device 105 generates the time information that lies within a permissible time range. In the example, the permissible time range defines an expiration date at which order data B becomes invalid.

[0057] Generating a token FS by the user's terminal device 105, wherein the token FS comprises the data set F, wherein the data set F comprises the time information and identification data I1, I2. In the example, the token FS is an access request and is intended for the first computing device 102 so that it can check whether access is granted or denied.

[0058] Receiving the token FS for the first computing device 102 by the second computing device 108 and from the user's terminal device 106. In the example, the token FS is not sent directly to the first computing device 102, but rather via the second computing device 108. The terminal device 105 does not require a connection to the first computing device 101 for this purpose. The terminal device 105 requires a connection to the second computing device 108 for this purpose.

[0059] Sending the token FS by the second computing device 108 and to the first computing device 102 to verify the access request.

[0060] Check whether the first computing device 102 allows access to the production device 109 or not.

[0061] Sending production data to the production facility 109 if the first computing device 102 allows access to the production facility 109 to be granted by the second computing device 108, and otherwise denying access to be granted by the second computing device 108. This means, in the example, the second computing device 108 grants or denies the terminal device access to the production facility 109. This means, in the example, the second computing device 108 is controlled by the first computing device 101.

[0062] An exemplary procedure is described in Figure 2 and is described using the server, security card, mobile phone, order server, and production facility as examples. In the example, the process begins with step 201.

[0063] In step 201, the data K1, K2, K3, K4 from the security card 104 is read by the mobile phone 105. In this example, Near Field Communication (NFC) is used for the reading. Both the mobile phone and the security card are configured for NFC. Radio Frequency Identification (RFID) or another transmission method, particularly wireless, can also be used.

[0064] A step 202 is then executed.

[0065] In step 202, the data K1 and K3 are stored. This means that the first key S11 of the first key pair SP1 and the first key S21 of the second key pair SP2 are stored. The data is stored in the data memory 106 of the terminal device 105, in this example, the mobile phone 105.

[0066] Then a step 203 is executed.

[0067] In step 203, the data K2 and K4 are sent by the mobile phone 105 to the server 102.

[0068] Subsequently, a step 204 is executed.

[0069] Data K2 comprises the first part of the identification data I1 in the example, unencrypted. Data K2 comprises the second part I2 of the identification data and is already stored encrypted on the security card 104.

[0070] In step 204, the second part I2 of the identification data is determined, e.g., by decrypting the data K2 by the server. A third key pair SP3 for encrypting the second part I2 of the identification data during the production of the security card 104 and for decrypting the second part I2 of the identification data during the ordering process with the security card is provided in the example in the server 102.

[0071] Then a step 205 is executed.

[0072] In step 205, a data record I1 and I2 matching the identification data I1 and I2 is identified in the server 102. For this purpose, a comparison of the first part I1 of the identification data received in the data K4 and the second part of the identification data I2 received in the data K2 with the data records stored in the database in the server 102 can be provided.

[0073] Subsequently, a step 206 is executed. It may be provided that the ordering process is aborted if no data record matching the identification data I1 and I2 can be found.

[0074] In step 206, data A3 is generated in the server 102 by encrypting the second part I2 of the identification data I2 with the second key S12 of the first key pair SP1.

[0075] Then a step 207 is executed.

[0076] In step 207, the data A3 is transmitted from the server 102 to the mobile phone 105.

[0077] Then a step 208 is executed.

[0078] In step 208, in the mobile phone 105, the data A3 is verified and the second part I2 of the identification data I2 is decrypted using the first key S11 of the first key pair SP1.

[0079] Then a step 209 is executed.

[0080] In step 209, the expiration date and order information are generated using the computer program running on the mobile phone 105.

[0081] In step 209, a data record F is generated for release by the mobile phone 105 and including the expiration date and the order information.

[0082] Data set F includes the time information and the identification data I1 and I2. The time information can, for example, indicate the expiration date as an absolute time value.

[0083] The time specification can also specify a starting point for determining the expiration date.

[0084] A step 210 is then executed.

[0085] In step 210, in the mobile phone 105, the data set F is encrypted with the first key S21 of the second key pair SP2 by the mobile phone to form a token FS.

[0086] Then a step 211 is executed.

[0087] In step 211, the token FS and the identification data I1 and I2 are transmitted from the mobile phone 105 to the order server 108.

[0088] This means that the mobile phone 105 triggers a request for access to the production facility 109.

[0089] A step 212 is then executed.

[0090] In step 212, a request for verification of the token FS is sent by the order server 108 to the server 102.

[0091] A step 213 is then executed.

[0092] The server 102 controls access to the production facility 109. The controller checks the data record F from the token FS.

[0093] In step 213, for example, the token FS is decrypted by the server 102 using the second key S22 of the second key pair SP2.

[0094] Subsequently, a step 214 is executed in the server 102.

[0095] In step 214, a check is made as to whether a data record matching the data record F in the identification data I1 and I2 exists in the database 103 and whether the time specification lies within the permissible time range or not.

[0096] In step 214, order data B is determined according to the identification data I1 and I2 and the order information from the token FS.

[0097] It may be provided to abort the ordering process, ie to refuse to grant access by the second computing device 108, if the decryption of the data record F fails or no matching data record exists in a database 103.

[0098] A step 215 is then executed.

[0099] In step 215, access to the production facility 109 is permitted by the second computing device 108 if a data record matching the identification data I1 and I2 exists in the database 103 and the time specification is within the permissible time range. Otherwise, access is denied by the second computing device 108.

[0100] If access is permitted, in the example, order data B is transmitted back from server 102 to order server 108.

[0101] A step 216 is then executed.

[0102] In step 216, the token FS is assigned to the order data B by the order server 108.

[0103] Subsequently, a step 217 is executed.

[0104] In step 217, the order is released and the order data B is transferred by the order server 108 to the production facility 109.

[0105] In the example, the token FS is a software token. The token FS can also be used in other ways eg be implemented as a release record.

[0106] In the example, communication between the first computing device 101, the second computing device 108 and the terminal device 105 takes place using at least one encryption protocol.

[0107] Encryption protocols in this context are network protocols that guarantee encrypted data transmission over a computer network. For example, a network protocol is used according to one of the following standards: Transport Layer Security (TLS), Wi-Fi Protected Access 3 (WPA3), Wi-Fi Protected Access 2 (WPA2), Secure Shell (SSH), or Internet Protocol Security (IPsec).

[0108] In this example, the key pairs described are used in addition to such an encryption protocol. The additional encryption achieved differs from these encryption protocols and also from other types of encrypted data transmission, e.g., using an encrypted virtual private network.

[0109] In the example, data is used for identification and authentication, with data K1 comprising the first key S11 of the first key pair SP1, data K3 comprising the first key S21 of the second key pair SP2, data K4 comprising the first part I1 of identification data for requesting access, particularly in unencrypted form, and data K2 comprising the encrypted second part I2 of the identification data. Other data can also be used for identification or authentication.

[0110] In the example, the user's terminal device 105 determines a temporal validity that includes the time information that lies within the permissible time range.

[0111] In the example, a token is used that contains information for identification and time validity. The token comprises the data set F, which is secured by the operation on the data set F with the first key S21 of the second key pair SP2. The data set F comprises the time information and the identification data I1, I2. Another token can also be used that contains information for authentication, identification, and time validity.

Claims

1. Computer-implemented method for triggering a request for access to a production facility (109) for manufacturing a part of a locking system, by means of a user terminal (105), characterized in that the method comprises: reading (201) of data (K1; K2; K3; K4) for identification by the terminal (105) and of a user-specific passive or active transmitting device (104) on which these data (K1; K2; K3; K4) are stored, generating (209) a temporal validity period, generating (210) a token (FS) by means of the user terminal (105), the token (FS) comprising identification information and temporal validity information based on the data (K1; K2; K3; K4), sending (211) the token (FS) through the user terminal (105) and to a computing device (108).

2. Method according to claim 1, characterized in that the token (FS) comprises an encrypted and / or authenticated data set (F), the data set (F) comprising the information for identification and / or the temporal validity.

3. Method according to claim 2, characterized in that the data (K1) comprise a first key (S11) of a first key pair (SP1), the data (K3) comprising a first key (S21) of a second key pair (SP2), the data (K4) comprising a first part (I1) of identification data for requesting access, in particular unencrypted, and in that the data (K2) comprise an encrypted second part (I2) of the identification data, the method comprising: storing (202) the first key (S11) of the first key pair (SP1) and the first key (S21) of the second key pair (SP2) in particular in a data memory (106) of the terminal (105), sending (203) the encrypted second part (I2) of the identification data (K2) and the first part (I1) of the identification data (K4) through the terminal (105) and to another computing device (102), generating (209) a time stamp which lies within a permissible time range by means of the user terminal (105), generating (210) the token (FS) by means of the user terminal (105), the token (FS) comprising the data set (F) which is secured by an operation on the data set (F) by the first key (S21) of the second key pair (SP2), in the data set (F) the information which relates to temporal validity comprising the time stamp and the information which relates to identification comprising the identification data (I1, I2).

4. Method according to claim 3, characterized in that the operation on the data set (F) by the first key (S21) of the second key pair (SP2) encrypts the data set (F) or in that the operation on the data set (F) by the first key (S21) of the second key pair (SP2) signs the data set (F).

5. Method according to one of claims 3 or 4, characterized in that the method comprises: receiving (207) further data (A3) at the terminal (105) and from the other computing device (102), the further data (A3) being secured by an operation on the second part (I2) of the identification data by the second key (S12) of the first key pair (SP1), checking and / or determining (208) the second part (I2) of the identification data by an operation on the further data (A3) by the first key (S11) of the first key pair (SP1).

6. Method according to claim 5, characterized in that the operation on the further data (A3) by the first key (S11) of the first key pair (SP1) decrypts the further data (A3) or in that the operation on the further data (A3) by the first key (S11) of the first key pair (SP1) verifies the further data (A3).

7. Method according to any of claims 3 to 6, characterized in that the operation is provided in addition to an encrypted data transfer.

8. Terminal (105), in particular mobile terminal, for a user, characterized in that the terminal (105) is designed to carry out the method according to any of claims 1 to 7.

9. Computer program, characterized in that the computer program comprises computer-readable instructions, in the execution of which by a computer, steps are run in a method according to any of claims 1 to 7.