METHOD, DEVICES AND SYSTEM FOR ACCESSING A PRODUCTION FACILITY
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- BKS
- Filing Date
- 2022-06-23
- Publication Date
- 2026-06-03
AI Technical Summary
Existing methods for securing access to production facilities lack robust authentication mechanisms, leading to potential unauthorized access and compromised security.
A cryptographic authentication system using a first and second key pair for encrypting, decrypting, signing, and verifying data, combined with time-stamped tokens, ensures secure access through a mobile app and backup card, enhancing security by dynamically encrypting and authenticating user identity.
The system effectively prevents unauthorized access by ensuring secure data transmission and user authentication, thereby increasing the security standard for accessing production facilities.
Description
[0001] The invention relates to methods, devices and a system for accessing a production facility, in particular in an ordering process for locking systems or parts thereof.
[0002] In such an ordering process, security cards may be used to enable secure access to the production facility. For example, only after successful authentication during the ordering process will an ordered locking system or a component thereof be released for production by the manufacturing facility.
[0003] The methods and devices according to the independent claims provide secure mobile authentication of access to the production facility.
[0004] The invention is defined in claim 1.
[0005] This process can be implemented as a mobile phone app. The user-specific passive or active transmitting device can be a backup card, zB It could be a hybrid card with near-field communication and a magnetic stripe. The operation could be encryption according to a cryptographic encryption method or according to a cryptographic signature method.
[0006] This method preferably offers a high security standard through dynamic encryption or authentication, wherein the method provides that the operation on the data record with the first key of the second key pair encrypts the data record or that the operation on the data record with the first key of the second key pair signs the data record.
[0007] The procedure may also include receiving data at the terminal device and from the other computing facility, whereby the data is secured by an operation on the second part of the identification data with the second key of the first key pair, and checking and / or determining the second part of the identification data by an operation on the data with the first key of the first key pair.
[0008] To increase the security standard, it may be provided that the operation on the data with the first key of the first key pair decrypts the data or that the operation on the data with the first key of the first key pair verifies the data.
[0009] Unauthorized access is effectively prevented.
[0010] To increase security, the procedure may provide that the operation on the data set with the first key of the second key pair encrypts the data set, and the operation on the data set with the second key of the second key pair decrypts the data set, or that the operation on the data set with the first key of the second key pair signs the data set, and the operation on the data set with the second key of the second key pair authenticates the data set.
[0011] The security of the process is further increased.
[0012] It can be provided that the data record is secured by an operation on the data record with a first key from a second key pair, where the data record contains information on the time validity period (a time stamp) and identification information (identification data). This effectively implements the decision of whether access is permitted or not.
[0013] Security is increased if the operation is also carried out using encrypted data transmission.
[0014] An end device, in particular a mobile end device, for a user is designed to execute steps in the process of triggering a request for access to a production facility with an end device.
[0015] A first computing device, in particular a server, is designed to perform steps in the procedure for controlling access to a production facility.
[0016] A second computing unit, in particular an order server, is designed to execute the procedure for accessing a production facility.
[0017] A system that includes the first computing unit and the second computing unit makes it possible to selectively grant or deny access to a production facility in an ordering process.
[0018] Access to the ordering process is enabled for a user or company through a computer program that includes computer-readable instructions, the execution of which by a computer involves steps in a procedure.
[0019] Further advantageous embodiments will become apparent from the following description and the drawing. The drawing shows: Fig. 1 a schematic representation of a system, Fig. 2 steps in a procedure for accessing a production facility.
[0020] The following description describes operations performed on data using a first key pair, SP1, and a second key pair, SP2. In this example, SP1 and SP2 represent key pairs of a cryptographic method. Various cryptographic methods can be used. These operations secure the data. In this context, "secured" means that unauthorized use or access to data secured by the operation is made more difficult.
[0021] The first key pair SP1 comprises a first key S11 and a second key S12.
[0022] The second key pair SP2 comprises a first key S21 and a second key S22.
[0023] The operations can include encryption or decryption on the one hand. On the other hand, the operations can include signing or authentication.
[0024] Encryption or decryption: For example, data encrypted with the second key S12 of the first key pair SP1 can be decrypted using the first key S11 of the first key pair SP1.
[0025] For example, data encrypted with the first key S21 of the second key pair SP2 can be decrypted using the second key S22 of the second key pair SP2.
[0026] Signing or authentication: For example, data signed with the second key S12 of the first key pair SP1 can be verified using the first key S11 of the first key pair SP1.
[0027] For example, data signed with the first key S21 of the second key pair SP2 can be verified using the second key S21 of the second key pair SP2.
[0028] In Figure 1System 101 is shown schematically. System 101 comprises a first computing unit 102. The first computing unit 102 is a server.
[0029] The first computing unit 102 includes a database 103 or is connected to it via a data line. The database 103 contains a large number of data records, which include different identification data.
[0030] The first computing unit 102 is configured to provide identification data, particularly from database 103. The identification data comprises a first part I1 and a second part I2.
[0031] In this example, the identification data includes an object ID. The object ID uniquely identifies an entire system consisting of N keys and N lock cylinders.
[0032] System 101 includes a user-specific passive or active transmitting device 104. In this example, the transmitting device 104 is a backup card. The backup card is assigned to a specific object ID.
[0033] Data K1, K2, K3, K4 are stored on the transmitter 104.
[0034] The data K1 includes the first key S11 of the first key pair SP1.
[0035] The data K2 includes an encrypted second part I2 of the identification data for the object ID.
[0036] The data K3 includes the first key S21 of the second key pair SP2.
[0037] The data K4 includes the first part I1 of the identification data for the object ID, in particular unencrypted.
[0038] The second key S12 of the first key pair SP1 and the second key S22 of the second key pair SP2 are provided as authentication data for computer facility 101.
[0039] System 101 is designed to communicate with a user's terminal device 105. In this example, terminal device 105 is a mobile phone. An application, i.e., a computer program, can run on the mobile phone, allowing the user to perform a verification process for an order for a locking system or a component of the locking system, such as a key and / or a lock. In this context, verification process means verifying whether the user is authorized to place an order or not.
[0040] The terminal device 105 includes a data storage device 106. The terminal device 105 is configured to perform steps in a procedure described below.
[0041] System 101 includes a second computing unit 108. In this example, the second computing unit 108 is an order server that provides a service for a retailer during the ordering process. This service allows the user to complete the order verification process via their mobile phone. In this example, the service provides a selection of the locking system or a part thereof. The service allows the user to enter data for this, i.e., order information, via their mobile phone and to complete the order verification process. In this example, the service allows the user to receive and process identification data and tokens. The service includes a user interface for an online retailer portal and an interface to the mobile phone. In this example, the service is a computer program or comprises several computer programs.
[0042] In this example, the payment process and / or order processing between the user and a specialist retailer takes place within the retailer's system. The retailer's order is processed via an order portal.
[0043] During the verification process, the user proves to the ordering portal and the specialist retailer's system that they are authorized to place an order.
[0044] System 101 is configured to communicate with a production unit 109. The production unit 109 and / or the terminal device 105 can also be part of System 101.
[0045] The first computing unit 102 is trained to perform steps in the procedure described below.
[0046] The second computing unit 108 is configured to provide order data B for a production process for the manufacture of the locking system or part thereof, e.g., a key and / or a lock, according to the order data B. In this example, the order data B includes identification data from the ordering process.
[0047] Production facility 109 is configured to execute the production process based on order data B. In this example, production facility 109 is configured to manufacture part of the locking system, in particular a key and / or a lock, according to order data B.
[0048] To access the production facility 109 with the user's terminal device 105, the following steps are provided in the system 101 in particular: Reading data by the terminal device 105 and from the user-specific passive or active transmitting device 104 on which this data is stored.
[0049] The user's terminal device 105 generates a time value that falls within a permissible time range. In this example, the permissible time range defines an expiration date after which the order data B becomes invalid.
[0050] The user's terminal device 105 generates a token FS, where the token FS comprises the data record F, which includes the time stamp and identification data I1, I2. In this example, the token FS is an access request and is intended for the first computing device 102 so that it can check whether access is granted or denied.
[0051] Receiving the token FS for the first computing facility 102 by the second computing facility 108 and by the user's terminal device 105. In this example, the token FS is not sent directly to the first computing facility 102, but via the second computing facility 108. Terminal device 105 does not require a connection to the first computing facility 101 for this. Terminal device 105 does require a connection to the second computing facility 108.
[0052] Sending the token FS through the second computing facility 108 and to the first computing facility 102 to verify the access request.
[0053] Check whether the first computing facility 102 allows access to the production facility 109 or not.
[0054] Sending production data to production facility 109 occurs when the first computing facility 102 allows the second computing facility 108 to access production facility 109, and otherwise denies access to production facility 109. In this example, the second computing facility 108 either grants or denies the terminal access to production facility 109. This means that, in this example, the second computing facility 108 is controlled by the first computing facility 101.
[0055] An exemplary procedure is described in Figure 2 The process is illustrated and described using the examples of the server, the backup card, the mobile phone, the order server, and the production facility. In this example, the procedure begins with step 201.
[0056] In step 201, data K1, K2, K3, and K4 from the backup card 104 are read by the mobile phone 105. Near Field Communication (NFC) is used for this reading. Both the mobile phone and the backup card are NFC-enabled. Radio Frequency Identification (RFID) or another, particularly wireless, transmission method could also be used.
[0057] Step 202 is then executed.
[0058] In step 202, the data K1 and K3 are stored. This means that the first key S11 of the first key pair SP1 and the first key S21 of the second key pair SP2 are stored. The data is stored in the data storage 106 of the terminal device 105, in this example, the mobile phone 105.
[0059] Then step 203 is executed.
[0060] In step 203, the mobile phone 105 sends the data K2 and K4 to the server 102.
[0061] Then step 204 is executed.
[0062] Data K2 comprises the first part of the identification data I1 in the example, unencrypted. Data K2 comprises the second part I2 of the identification data and is already encrypted and stored on backup card 104.
[0063] In step 204, the second part I2 of the identification data is determined, for example, by the server decrypting the data K2. A third key pair SP3, for encrypting the second part I2 of the identification data during the production of the security card 104 and for decrypting the second part I2 of the identification data during the ordering process with the security card, is provided in server 102 in this example.
[0064] Then step 205 is executed.
[0065] In step 205, a data record I1 and I2 matching in the identification data I1 and I2 is identified in server 102. This may involve comparing the first part I1 of the identification data received in data K4 and the second part I2 of the identification data received in data K2 with the data records stored in the database in server 102.
[0066] Step 206 is then executed. It may be stipulated that the order process is aborted if no matching record is found in the identification data I1 and I2.
[0067] In step 206, on server 102, data A3 is generated by encrypting the second part I2 of the identification data I2 with the second key S12 of the first key pair SP1.
[0068] Step 207 is then executed.
[0069] In step 207, data A3 is transferred from server 102 to mobile phone 105.
[0070] Then step 208 is executed.
[0071] In step 208, on mobile phone 105, the data A3 is verified and the second part I2 of the identification data I2 is decrypted with the first key S11 of the first key pair SP1.
[0072] Step 209 is then executed.
[0073] In step 209, the expiry date and order information are generated using the computer program, which runs on the mobile phone 105.
[0074] In step 209, a data record F is generated for release by the mobile phone 105, including the expiry date and order information.
[0075] Data set F includes the time and the identification data I1 and I2. The time can specify the expiration date, for example, as an absolute time. The time can also specify a start time for determining the expiration date.
[0076] Step 210 is then executed.
[0077] In step 210, the data set F is encrypted by the mobile phone 105 with the first key S21 of the second key pair SP2 to create a token FS.
[0078] Then, step 211 is executed.
[0079] In step 211, the token FS and the identification data I1 and I2 are transmitted from the mobile phone 105 to the order server 108.
[0080] This means that mobile phone 105 triggers a request for access to production facility 109.
[0081] Then step 212 is executed.
[0082] In step 212, order server 108 sends a request to server 102 for verification of the token FS.
[0083] Then step 213 is executed.
[0084] Server 102 controls access to production facility 109. The control system checks the data record F from the token FS.
[0085] In step 213, for example, the token FS is decrypted by server 102 using the second key S22 of the second key pair SP2.
[0086] Then, on server 102, step 214 is executed.
[0087] In step 214, a check is performed to see if a data record matching the identification data I1 and I2 with data record F exists in database 103 and whether the time specification is within the permissible time range or not.
[0088] In step 214, order data B is determined according to the identification data I1 and I2 and the order information from the token FS.
[0089] It may be possible to cancel the order process, i.e., to refuse access by the second party.
[0090] Computing facility 108 is granted if the decryption of data record F fails or no matching data record exists in database 103.
[0091] Then step 215 is executed.
[0092] In step 215, access to production facility 109 by the second computing facility 108 is granted if a data record matching the identification data I1 and I2 exists in database 103 and the time value is within the permissible time range. Otherwise, access by the second computing facility 108 is denied.
[0093] If access is allowed, in this example order data B is transmitted back from server 102 to order server 108.
[0094] Then step 216 is executed.
[0095] In step 216, the order server 108 assigns the token FS to the order data B.
[0096] Then step 217 is executed.
[0097] In step 217, the order is released and the order data B is transferred by the order server 108 to the production facility 109.
[0098] In this example, the token FS is a software token. The token FS can also be implemented in other ways, e.g., as a release record.
[0099] In this example, communication between the first computing unit 101, the second computing unit 108 and the terminal device 105 takes place using at least one encryption protocol.
[0100] In this context, encryption protocols are network protocols that guarantee encrypted data transmission over a computer network. For example, a network protocol is used according to one of the following standards: Transport Layer Security (TLS), Wi-Fi Protected Access 3 (WPA3), Wi-Fi Protected Access 2 (WPA2), Secure Shell (SSH), or Internet Protocol Security (IPsec).
[0101] The described key pairs are used in the example in addition to such an encryption protocol. The resulting additional encryption differs from these encryption protocols and also from other types of encrypted data transmission, e.g., using an encrypted Virtual Private Network.
[0102] In this example, data is used for identification and authentication, where data K1 comprises the first key S11 of the first key pair SP1, data K3 comprises the first key S21 of the second key pair SP2, data K4 comprises the first part I1 of identification data for requesting access, specifically unencrypted, and data K2 comprises the encrypted second part I2 of the identification data. Other data can also be used for identification or authentication.
[0103] In the example, the user's terminal device 105 determines a time validity period that includes the time specification which lies within the permissible time range.
[0104] In this example, a token is used that contains information for identification and validity period. This token comprises the data record F, which is secured by the operation on data record F using the first key S21 of the second key pair SP2. Data record F includes the time stamp and the identification data I1 and I2. Alternatively, a different token could be used that also contains information for authentication, identification, and validity period.
Claims
1. Computer-implemented method for controlling access to a production facility (109) for manufacturing part of a locking system, the method comprising: - receiving (212) a token (FS) by means of a first computing unit (102) and from a second computing unit (108), wherein the first computing unit is a server (102), wherein the token (FS) includes information regarding identification and temporal validity, - checking (214) whether a data set that matches with respect to the information regarding identification exists in a database (103) and whether the token is within its temporal validity or not, - allowing (215) granting of access to the production facility (109) by the second computing unit (108) if the data set that matches with respect to the information regarding identification exists in the database (103) and the token is within its temporal validity, and otherwise refusing the granting of access by the second computing unit (108), wherein the token (FS) comprises an encrypted and / or authenticated data set (F), wherein the data set (F) comprises the information regarding identification and / or the temporal validity, wherein the method comprises checking and / or determining (213) the data set (F) from the token (FS), wherein the data set is secured by an operation on the data set (F) using a first key (S21) of a second key pair (SP2), wherein, in the data set (F), the information regarding temporal validity comprises a time indication and the information regarding identification comprises identification data (I1, I2), wherein the method further comprises: - checking and / or determining (213) the data set (F) from the token (FS) by means of an operation on the data set (F) using a second key (S22) of the second key pair (SP2), - checking (214) whether a data set that matches the data set (F) with respect to the identification data (I1, I2) exists in a database (103) and whether the time indication lies within a permissible time range or not, - allowing (215) the granting of access to the production facility (109) by the second computing unit (108) if a data set that matches with respect to the identification data (I1, I2) exists in the database (103) and the time indication lies within the permissible time range, and otherwise rejecting the granting of access by the second computing unit (108), - receiving (203) a first part (I1) of the identification data (K4), which is in particular unencrypted, and an encrypted second part (I2) of the identification data (K2) by means of the first computing unit (102) and from an end device (105), - identifying (205) a data set (I1, I2) in the server (102) that matches with respect to the identification data (I1, I2) by comparing the first part (11) of the identification data (K4) and the second part (I2) of the identification data (K2) with the data sets (I1 and I2) stored in the first computing unit (102), in particular in the database (103), - generating (206) data (A3) by encrypting the second part (I2) of the identification data using the second key (S22) of the second key pair (SP2), - sending (207) the data (A3) by means of the first computing unit (102) and to the end device (105).
2. Method according to claim 1, characterized in that the operation on the data set (F) using the first key (S21) of the second key pair (SP2) encrypts the data set (F), the operation on the data set (F) using the second key (S22) of the second key pair (SP2) decrypting the data set (F), or in that the operation on the data set (F) using the first key (S21) of the second key pair (S22) signs the data set (F), the operation on the data set (F) using the second key (S22) of the second key pair (SP2) authenticating the data set (F).
3. First computing unit (102), characterized in that the first computing unit (102) is designed to execute the method according to either of claims 1 or 2.
4. System (101) comprising the first computing unit (102) according to claim 3 and a second computing unit (108).
5. Computer program, characterized in that the computer program comprises computer-readable instructions, in the execution of which by a computer, steps are run in a method according to either of claims 1 or 2.