ACCESS CONTROL PROCEDURE AND SYSTEM

DE602022021156T2Active Publication Date: 2025-09-10GROUPE LA POSTE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602022021156
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-01-12
Filing Date
2022-01-11
Publication Date
2025-09-10
Estimated Expiration
2042-01-11

AI Technical Summary

Technical Problem

Existing access control systems face vulnerabilities due to the sharing of secret keys between media and reader-central units, leading to risks of cloning and unauthorized access, and lack flexibility in managing access permissions for multiple locations and service providers.

Method used

An access control method utilizing a unique identifier signed and authenticatable medium, with a data management system generating and signing access request data based on specific parameters, ensuring double authentication and verification without sharing secret data, and allowing dynamic management of access permissions through signed access request data.

Benefits of technology

Enhances security by preventing unauthorized access even with cloning or theft, and provides flexible, dynamic control over access based on user, time, geographical area, and activity, without relying on shared secrets.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to a method and system for physical access control. More particularly, the invention relates to the field of physical access control to a protected space, for example to a building or any kind of place or equipment whose access or use must be controlled, for service providers who have to intervene in the protected space.

[0002] The arrival of digital technologies, and particularly so-called contactless technologies which use at least one medium, has enabled the deployment and widespread use of physical access control systems comprising electronic means and a locking device, connected to a reading device, to secure physical access to a protected area.

[0003] By support, within the meaning of the present invention, is meant a support configured to contain at least one electronic data and having a processing unit.

[0004] For example, as a medium, one can have a badge using the radio-identification process (commonly designated by the acronym RFID) or a mobile device such as mobile phones or any other processing unit capable of supporting one or more electronic data transmittable via contact or contactless technology.

[0005] The most well-known method of locking building access consists of placing a reading device, which may be an electronic reader and which is connected to a locking device, at the entrance of a building and distributing an individual badge to resident users as a medium. This individual badge shares a secret with said electronic reader which is associated with a central unit so as to form a central reader assembly. Thus, during an electronic transaction between the badge and the reader-central unit assembly, the latter verifies the authenticity of the badge, and by extension of its bearer, by sharing the secret which is common to the badge and the reader-central unit assembly. In this mode, the reader-central unit assembly and the badge must both store and protect a common secret. In this case, we speak of a secret key security scheme.

[0006] The authentication mechanism can use three types of keys: A single symmetric key, the same secret key, is used by all badges and by all reader-central unit assemblies. This large-scale distribution represents a risk for this key, which could be compromised by a hardware attack on a badge, or one of the reader-central unit assemblies; Symmetric keys derived from a master key, each badge contains a different key, which is derived by an encryption or cryptographic mechanism from a master key and a unique identifier (hereinafter referred to by the acronym UID) specific to each badge. The UID is also contained in the badge.

[0007] During the check, the reader-control unit requests the unique UID identifier of the badge, then, from the master key and the badge's UID (unique number), regenerates the same derived key, which allows the badge to be authenticated. The advantage of this approach is that a hardware attack on a badge only allows it to be cloned. It does not allow a different one to be forged, because the master key is not present within the badge. However, the master key must be used by the reader-control unit during each authentication or verification.

[0008] To do this, the reading device, itself connected to the central unit, can for example be placed near an entrance to a protected space, for example near a door leading to a building to which access is to be controlled. In this case, a medium capable of transmitting at least one access request data item is distributed to potential users, for example to users who are residents of the building, and which is capable of being received by the reading device so as to authorize or not physical access to said building. To authorize or not access to said building, when the medium is located near the reading device, an electronic transmission or exchange takes place between the individual medium which, at least, transmits its access request data item to the reader-central unit assembly.In this situation, said supported access request data transmitted by the medium is verified by an authentication mechanism, with at least one key stored in the central unit so as to identify said medium, and in certain cases to identify its user by extension. In this configuration, the reader-central unit assembly and the medium must therefore both store and protect at least one key.

[0009] The authentication mechanism can be implemented using three distinct methods. A first method implements a unique symmetric key (single symmetric authentication mechanism) which makes it possible to encrypt and / or decrypt the access request data exchanged between at least the medium, which may be individual and belong to a particular user, and the central unit connected to the reading device. Here, the unique symmetric key issued by each of the users' individual media is the same as that stored by the central unit. According to this first method, the fact that all users have the same unique symmetric key represents a risk insofar as a hardware attack on a single individual medium, or on the central unit, would compromise the protection engaged. A second method implements several symmetric keys derived from a master key (derived symmetric authentication mechanism). Here, each individual medium then contains a derived symmetric key which is different from each other.This different derived symmetric key is assigned to each of the individual media after applying an encryption mechanism from at least the master key and the unique identifier UID associated with each of the individual media. The unique identifier UID of the media is part of the data contained in each of the individual media.

[0010] According to this second method, during the electronic exchange between the individual medium and the reader-central unit, the reader-central unit requests the UID of the individual medium, then, from the master key and the UID of the individual medium, regenerates the derived symmetric key assigned to the controlled individual medium, which makes it possible to identify (verify or even authenticate) the controlled individual medium and subsequently, allows the reading device to read the exchanged access request data. The advantage of this second method is linked to the fact that a hardware attack on an individual medium only makes it possible to duplicate media configured to access the protected space. In particular, following such an attack, it is not possible to manufacture more media configured to access the protected space, because the master key is not contained in any of the individual media.On the other hand, the master key must be used by the reader-central unit during each media check.

[0011] This second method, which is very widespread, is particularly suitable for a solution that concerns the resident users of the buildings. Indeed, this strong relationship existing between the reader-central unit and each of the individual supports requires the reader-central unit to be known, managed and to share a master key with one or more individuals authorized to select the individual supports authorized to access the building whose access is controlled by the reader-central unit. Furthermore, with the implementation of this second method, an individual support will only allow access to the single building for which its access has actually been authorized in advance. In other words, to access several buildings, it is necessary to have as many authorized individual supports as there are buildings.Thus, according to this second method, the security constraints imposed on individual supports remain fairly limited due to the fact that each individual support only provides access to a single building. A third method uses several asymmetric keys (asymmetric authentication mechanism). Here, each reader-central unit and each individual medium is assigned a pair of keys that are different from each other, one called public and the other called private. Thus, with such a configuration, electronic exchanges containing the access request data between the medium and the reading device located nearby can be authenticated by the public keys exchanged from the signatures generated using these non-exchanged private keys. More flexible, this third method makes it possible to further protect the private keys associated with each individual medium and reader-central unit by using only one public key and one or more encrypted electronic exchanges.

[0012] The creation and management of all keys implemented in individual media and in reader-central units are appropriate operations to effectively secure access controlled by their uses. During these operations, it is therefore appropriate to ensure the protection of secret keys to the extent that the security of controlled access depends on their uses.

[0013] In certain situations, access to different buildings, access to which is controlled by as many reader-central units as there are buildings, is not only authorized to each of the users residing in one of the buildings and holding an individual card. Indeed, access to these different buildings can also be authorized to several third parties, for example to several people belonging to a service provider. In this situation, it is advantageous to authorize access to each of the people belonging to the service provider to each of the buildings within which the service is to be applied.

[0014] To do this, there is currently a system, that described in international application WO9602899, which allows both to protect a space and also for certain individual media to allow access to this space for a limited and renewable period. To do this, the access request data to be exchanged included in certain of said media is encrypted and can only be encrypted following suitable electronic exchanges between the reader-central unit and the medium. In particular, decryption is only done after receipt by the medium of a suitable key transmitted by the reader-central unit. Said suitable key can be renewed at will.In this case, it is no longer necessary to have to create a blacklist of lost, stolen or duplicated media, nor to have to manage such lists because a stolen, lost or duplicated media will not allow access to the protected space outside the limited authorized period if this is not renewed via the generation of a new suitable key.

[0015] In this system, the encrypted access request data to be exchanged and included in some of said media allows access to the protected space after its decryption following the reception, by the reader-central unit, of said adapted key and the intervention of an electronic signature of data relating to a predetermined period of access use limiting the validity of use of the medium in which the encrypted access request data to be exchanged is stored. The electronic signature of data can also be stored in the medium. Thus, the security of the protected space is based in part on the limited period of validity of said encrypted access request data to be exchanged and stored in the medium.

[0016] However, there are still several drawbacks to this system: the cloning of the media gives access for the entire period of validity of the media to any media holder without restriction of activity or service, on all buildings located throughout the territory having access control and authorizations in accordance with the mechanism used; a sharing relationship of at least one secret and / or encrypted data is necessary between the reader-central units and the media. It is thus necessary for the devices configured to transfer access data to the medium, to also share the secret and / or encrypted data with the reader-central units of a building stock on which the media will be presented. the following documents also constitute relevant documents on the state of the art: WO 97 / 40474 A1, US 2005 / 033962 A1.

[0017] One of the aims of the invention is to remedy the shortcomings of the access control systems and methods of the state of the art. According to a first aspect, the invention relates to an access control method in an access control system comprising: a medium at least defined by a unique identifier previously signed and authenticatable, said medium being configured to support at least one signed access request data; a data management system comprising several records, each record representing a specific data item, and each specific data item being a function of one of the following parameters: ∘ an identifier of an authorized user; ∘ information of an authorized period; ∘ information of an authorized time slot; ∘ information of an authorized geographical area; ∘ information of an activity of said authorized user;a device for generating an access request data item to be signed from several of said specific data and the unique identifier of the medium, means for reading the unique identifier of said medium receiving the signed access request data item, said reading means being connected to said generation device, means for signing said access request data item to be signed to obtain a signed access request data item comprising a first data item representative of several of said specific data items, a second data item relating to said unique identifier of the medium, and a signature data item, a transfer device configured to transfer said signed access request data item to said medium, said transfer device being connected to said signing means and to said management system;a reading device configured to read said signed access request data from said medium and to transmit an access authorization signal to a locking device; first authentication means connected to said reading device and configured to authenticate said signed access request data; second authentication means connected to said reading device and configured to authenticate the medium; verification means connected to said reading device and configured to verify the signature data of said signed access request data; first comparison means connected to said reading device and configured to compare the unique identifier of the medium with said second data of said signed access request data;second comparison means connected to said reading device and to a database in which one or more specific subsets of data are recorded, each subset being representative of a predefined access authorization which is a function of several of said parameters, said second comparison means being configured to compare the first data item of said signed access request data item with said subsets of data; ; said access control method being executed by said access control system and comprising: a step of recording said specific data in said data management system; a step of providing the medium defined by a unique identifier previously signed and authenticatable, a step, via said reading means, of reading the unique identifier of said medium, a step, via said generation device, of generating said access request data to be signed, said step of generating said access request data to be signed being carried out after said step of reading the unique identifier previously signed of said medium; a step, via said signing means, of signing said access request data to be signed and the unique identifier of the medium to obtain said signed access request data; a step of transferring said signed access request data from said transfer device to said medium defined by the unique identifier of the second data of said signed access request data;a step of registering in the database reference base said one or more specific subsets of data, a step, via said reading device, of reading said signed access request data supported by said medium;a step of authenticating, via said second authentication means, the medium, a step of authenticating, via said first authentication means, said signed access request data and a step of verifying, via said verification means, the signature data of said signed access request data, and a step, via said first comparison means, of comparing the unique identifier defining the medium with that of the second data of said signed access request data, a step, via said second comparison means, of comparing the first data of said signed access request data with said subsets recorded in the database reference; a step of transmitting said access authorization signal from said reading device to said locking device. ;

[0018] For the purposes of the present invention, by connected is meant directly or indirectly connected by physical means or means of communication.

[0019] For the purposes of the present invention, a user is understood to mean a legal or natural person. For example, as a user, one may have a service provider to which several individuals are attached.

[0020] For the purposes of the present invention, a period is understood to mean an arbitrarily defined time period representing a relatively short period of validity.

[0021] For the purposes of the present invention, a time slot is understood to mean a duration which is included in the period. This time slot can therefore be considered as being a subset of the period.

[0022] For the purposes of the present invention, activity means a service which must be carried out within the protected space.

[0023] For the purposes of the present invention, by geographical area is meant a geographical coverage within which there is at least one locking device.

[0024] For the purposes of the present invention, a unique identifier previously signed and authenticable is understood to mean an identifier that has been associated with the medium and that is independent of the manufacturer identifier of this medium. This also makes it possible to virtualize the medium, i.e. to establish its own unique identifier via its signature so that it can be authenticated by elements of the control system. This signature can be carried out by signature means external to the control system.

[0025] Thus, it is possible to make the support non-falsifiable because it depends on the signed unique identifier, the unique identifier of which, after reading, is integrated into the access request data in order to allow virtualization of the supports which will no longer necessarily depend on the provision of a manufacturer identifier.

[0026] Thus, it is possible to use a volatile RAM type memory like those present at will in mobile phones for example, since the unique identifier of the support can be regenerated and different with each loading. The data support therefore does not require EEPROM.

[0027] With such a method, when the medium supporting the signed access request is reproduced or cloned after its initial user has lost it or had it stolen, for example, a modification of one of said specific data of a subset representing a predefined access authorization and / or a modification of the signature data and / or a modification of the access request data to be signed initially generated and / or a modification of said unique identifier of the medium supporting the signed access request data and / or a modification of the first data and / or the second data of the signed access request data will not allow the locking device to be unlocked.In particular, if at least one of the above modifications is applied, the signed access request data item cannot be authenticated by the authentication means during the authentication step, and / or the step of comparing the unique identifier defining the medium with that of the second data item of the signed access request data item will not be conclusive, and / or the step of comparing the first data item of the access request data item with said subsets will not be conclusive, so that the step of transmitting the access authorization signal will not take place.Thus, without sharing secret data between the transfer device and the medium, and / or between the medium and the reading device, a robust access control method is obtained, adapted to multiple authorization situations which are at least a function of users, time periods, geographical areas, or even user activities for each locking device protecting a particular space and located in a predefined geographical area.

[0028] Using this method, only the medium has the access request data; users are only able to verify it. No distribution of access request data is necessary, so a medium can be authenticated without ever having a connection or trusted relationship with the user.

[0029] The method according to the invention therefore involves at least double authentication before that of the signed access request data supported and transported by the medium: authentication of the medium by the reading device, and also by the generation or transfer devices, and authentication of the generation or transfer devices and the reading device by the medium.

[0030] The access control system may comprise several media, several of the aforementioned means and several of the aforementioned devices. In this case, the unique identifier of each media is different from each other and specific to a single media.

[0031] The records of the management system are recorded and can be modified at will only by a third party authorized to manage the management system.

[0032] Each record in the data management system may represent either a single specific data item relating to only one of said parameters mentioned, or relating to a set of sub-records representing several of said parameters mentioned.

[0033] The generation device, via the means of reading the unique identifier of the medium, reads the unique identifier of the medium onto which the signed access request data is to be transferred.

[0034] Thus, depending on the access authorizations that one wishes to attribute to the user possessing the medium, the generation device generates, from at least one of the records and the identifier of this medium, the access request data to be signed which will allow or not the performance of the step of transmitting the access authorization signal.

[0035] Preferably, the generation device is configured to generate an access request data to be signed from several specific data relating to all of the aforementioned parameters and the unique identifier of the medium.

[0036] The access request data to be signed can then be logical data comprising: a first data item representing several specific data items, each relating to the identifier of the authorized user, to the information of an authorized period, to the information of an authorized time slot, to the information of an authorized geographical area and to the information of an activity of the authorized user, and a second logical data item relating to the unique identifier of the medium onto which the signed access request data item must be transferred.

[0037] Then, the signing means are used to sign the access request data to be signed so as to obtain the signed access request data including among other things the signature data.

[0038] Also, the signing means can be configured to modify its signature data, for example, each time the information of an authorized period is modified. In this case, the authorization control method will further comprise an additional signing step to modify the signature of the previously signed access request data in order to no longer allow the implementation of the step of transmitting the authorization signal which applied with the previously signed access request data. Thus, it is possible to renew the access authorization as many times as necessary by modifying in particular the signature data.

[0039] For example, the signature data can be obtained using any known cryptographic mechanism, namely encryption, signature mechanisms.

[0040] The signing means may, for example, be capable of producing the signature data in the form, for example, of an electronic signature from a production function fn and a private key Kpr.

[0041] Furthermore, it should be noted that the signed access request data may comprise several signature data. For example, several signature data may be calculated and recorded by the signature means on the medium supporting an access request data to be signed, these several signatures being able to be obtained from a key size (Kn) different from each other and from a production function (fn) such that 1 st < signature = f1 (K1, access request data to be signed), a 2 nd < signature = f1 (K2, access request data to be signed), 3 rd < signature = f2 (K1, access request data to be signed), etc.

[0042] After obtaining the signed access request data, the transfer device transfers it to the medium corresponding to the unique identifier of the medium from which the access request data to be signed is generated.

[0043] It should be noted that the functions of said transfer device and said generation device can be performed by a single assembly or physical element.

[0044] The reading device ensures, without sharing secret data and by an asymmetric authentication mechanism, an electronic access control function via the means of authentication, verification and comparison.

[0045] It should be noted that one or more of the means of authentication, verification or comparison are directly or indirectly connected to the reading device. It is therefore possible that one or more of these means are physically integrated into the reading device or remote from it but communicating with it.

[0046] The reading device associated with the aforementioned means therefore ensures the implementation of the step of transmitting the access authorization signal only in the case where the medium and the signed access request data have been authenticated by the authentication means, the signature data verified, the comparison of the unique identifier defining the medium with that of the second data of the signed access request data has been conclusive (i.e. their similarity has been noted), and / or the comparison of the first data of the access request data with said subsets has been conclusive (i.e. the specific data relating to the first data of the signed access request data correspond to one of the subsets entered in the database reference). The first data of the signed access request data is, for example, relating to all of the parameters below: the authorized period, the authorized user associated with an identifier designating an authorized service provider, the activity information of the service provider, the time slot during which access is authorized, the geographical area within which the signed access request data can be authenticated, the time window within which the reading device is in operation to read the signed access request data.

[0047] Thus, the first and second authentication means are configured to authenticate the signed access request data and the medium. In this configuration, the authentication steps are preferably implemented without additional exchange without sharing of secret data between the medium and the reading device.

[0048] It should be noted that the user, once the authorized period from which the access request data to be signed was generated (then signed) has expired, must again transfer a new signed access request data to his support because the previous one will no longer allow access to the protected space.

[0049] For example, the authentication means may, for example, be an integral part of the reading device without connection with a device other than the reading device during the implementation of the step of authenticating the signed access request data to authorize the unlocking of the locking device. Thus, preferably, the reading device is not further connected to processing means themselves connected for example to a central data system. The reading device can then operate autonomously without being able to be altered by the introduction or extraction of data to which it could have access via the central data system for example.

[0050] Preferably, the method is characterized in that a new signed or to be signed access request data item is signed by the signing means or generated by the generation device at the request of the user of the medium for each new duration of use of said medium. Thus, after expiry of a predefined duration, the access request data item that will have been signed beforehand will no longer allow access to the protected space. In particular, in this embodiment, the signature of the signed access request data item may no longer be verified by the verification means connected to the reading device after expiry of this duration. For example, the duration may be defined by a start date and an end date, by a start date and a duration of time, or by an end date and a duration of time.For example, using this duration of use, access to the protected area can be granted for a very limited period defined by one or more calendar days and also by a time slot contained within said one or more days.

[0051] Preferably, when said medium is configured to further support authentication data and when the reading device is configured to receive the authentication data from said medium and is configured to transmit them to said second authentication means which are configured to receive the authentication data via said reading device, said method further comprises: a step of transmitting authentication data from the medium to said reading device; and a step of processing, by said reading device, said authentication data from said medium. Thus, the step of authenticating the medium is ensured by the presence of authentication data which are added to the unique identifier of the medium. For example, these authentication data may be logical certificates.

[0052] Preferably, when said medium is configured to further support authentication data, when the transfer device is further connected to third authentication means configured to authenticate the medium receiving the signed access request data via the authentication data, when the transfer device is further configured to receive authentication data and transmit them to said third authentication means which are configured to receive the authentication data via said transfer device, said method further comprises; a step of transmitting authentication data from the medium to the transfer device; and a step of processing, by said transfer device, said authentication data from said medium.This embodiment has the advantage of allowing exchanges between the transfer device and the medium only if the transfer device has been able to previously authenticate the recipient medium.

[0053] The media authentication data may be relative to the unique, previously signed identifier supported by the media, be a function of it, or be independent of it.

[0054] It may also be advantageous to allow exchanges between the reading device and the medium only if the medium has previously authenticated the reading device. This is why, preferably, when said reading device is further configured to transmit authentication data, when the medium is configured to receive and process said authentication data from said reading device, said method further comprises: a step of transmitting authentication data from the reading device to said medium; a step of processing, by said medium, said authentication data from said reading device.

[0055] It may also be advantageous to allow exchanges between the transfer device and the medium only if the medium has previously authenticated the transfer device. Therefore, preferably, when said transfer device is further configured to transmit authentication data, when the medium is configured to receive and process authentication data from said transfer device, said method further comprises: a step of transmitting authentication data from the transfer device to said medium, a step of processing, by said medium, said authentication data from said transfer device.

[0056] It should be noted that each of the aforementioned authentication data used in the steps mentioned above may be the same or different.

[0057] Preferably, when said medium is configured to further support additional data, when the reading device and / or the transfer device are configured to process said additional data, the method further comprises: a step of transferring said additional data from the medium to the reading device and / or the transfer device, and a step of processing said additional data by said reading device and / or by said transfer device.

[0058] Thus, the medium can be configured to support more data, including logical data, to be exchanged with the transfer device and / or the reading device without this data to be exchanged necessarily being secret data.

[0059] Also, preferably, when said access control system further comprises means for encrypting said access request data to be signed or said signed access request data, said transfer device is further configured to transfer said encrypted signed access request data to said medium, said reading device is further configured to read and decrypt said encrypted signed access request data, said method further comprises: a step of encrypting said access request data to be signed or said signed access request data, and a step of decrypting by said reading device said encrypted and signed access request data.

[0060] For example, these encryption and / or decryption steps may be performed using an ephemeral encryption and / or decryption key generated for the duration of the transfer and / or playback.

[0061] The transfer device can also decrypt the encrypted access request data, and signed if necessary, when the medium wishes to obtain new access request data following, for example, the modification of a parameter of a record relating to at least one specific piece of data.

[0062] So, preferably, when: said transfer device is further configured to decrypt said encrypted signed access request data supported by said medium, said method further comprises: an additional step of decrypting said encrypted signed access request data supported by said medium, and a step of transferring a new encrypted signed access request data to said medium to replace said encrypted signed access request data supported by said medium.

[0063] The transfer device and the reading device can therefore provide an access control function capable of encrypting and decrypting data exchanges between the medium and the transfer device and / or the reading device, always without prior sharing of secret data.

[0064] More preferably, when said support is further configured to support modification data of said database repository, said method further comprises: a step of transferring said modification data from said medium to said reading device, and a step of modifying said database by modifying or deleting one of said subsets, or by adding an additional subset.

[0065] Modifying one of the subsets may consist of modifying the specific data or signature data

[0066] Thus, it is possible to modify the subsets registered in the reference database and update them using only the medium and further guaranteeing the autonomy of the reading device. These updates may consist in particular of modifying the signature data associated with the verification means so that the signature data of the initially signed access request data can no longer be verified or even of modifying at least one of the subsets registered in the reference database so that the comparison carried out by the second comparison means can no longer be conclusive.

[0067] It is then possible to have, preferably, a method according to which one or more of the authentication steps and / or one or more of the comparison steps and / or the verification step are implemented without the means used in these steps communicating with any element external to said system. In this case, the first and second comparison means may not, for example, be connected to an internet base for example. Thus, all the criteria and data allowing the implementation of at least one of the authentication, comparison or verification steps are here directly available to the first and second authentication and / or comparison means and / or verification means, without communication to the outside.

[0068] Correlatively, according to a second aspect, the invention relates to a transfer device belonging to an access control system comprising: a medium at least defined by a unique identifier previously signed and authenticatable, said medium being configured to support at least one signed access request data; a data management system comprising several records, each record representing a specific data item, and each specific data item being a function of one of the following parameters: ∘ an identifier of an authorized user; ∘ information of an authorized period; ∘ information of an authorized time slot; ∘ information of an authorized geographical area; ∘ information of an activity of said authorized user; a device for generating an access request data item to be signed from several of said specific data items and the unique identifier of the medium, a reading device configured to read a signed access request data item from said medium and to transmit an access authorization signal to a locking device;first authentication means connected to said reading device and configured to authenticate said signed access request data; second authentication means connected to said reading device and configured to authenticate the medium; verification means connected to said reading device and configured to verify the signature data of said signed access request data; first comparison means connected to said reading device and configured to compare the unique identifier of the medium with said second data of said signed access request data;second comparison means connected to said reading device and to a database in which one or more specific subsets of data are recorded, each subset being representative of a predefined access authorization which is a function of several of said parameters, said second comparison means being configured to compare the first data item of said signed access request data item with said subsets of data; ; said transfer device being connected to the management system and comprising: means for reading the unique identifier of said medium, means for receiving the access request data to be signed, means for signing the access request data to be signed to obtain signed access request data comprising a first data item representative of several of said specific data items, a second data item relating to said unique identifier of the medium, and a signature data item, means for transmitting said signed access request data item to the medium.

[0069] Correlatively, according to a third aspect, the invention relates to the support at least defined by a unique identifier previously signed and authenticable and belonging to an access control system comprising: a data management system comprising several records, each record representing a specific piece of data, and each specific piece of data being a function of one of the following parameters: ∘ an identifier of an authorized user; ∘ information of an authorized period; ∘ information of an authorized time slot; ∘ information of an authorized geographic area; ∘ information of an activity of said authorized user;a device for generating an access request data item to be signed from several of said specific data and the unique identifier of the medium, means for reading the unique identifier of said medium receiving the signed access request data item, said reading means being connected to said generation device, means for signing said access request data item to be signed to obtain a signed access request data item comprising a first data item representative of several of said specific data items, a second data item relating to said unique identifier of the medium, and a signature data item, a transfer device configured to transfer said signed access request data item to said medium, said transfer device being connected to said signing means and to said management system;a reading device configured to read said signed access request data from said medium and to transmit an access authorization signal to a locking device; first authentication means connected to said reading device and configured to authenticate said signed access request data; second authentication means connected to said reading device and configured to authenticate the medium; verification means connected to said reading device and configured to verify the signature data of said signed access request data; first comparison means connected to said reading device and configured to compare the unique identifier of the medium with said second data of said signed access request data;second comparison means connected to said reading device and to a database in which one or more specific subsets of data are recorded, each subset being representative of a predefined access authorization which is a function of several of said parameters, said second comparison means being configured to compare the first data item of said signed access request data item with said subsets of data; ; said support comprising: means for receiving at least one signed access request data; means for supporting said signed access request data; means for sending said signed access request data.

[0070] Correlatively, according to a fourth aspect, the invention relates to a reading device belonging to an access control system comprising a medium at least defined by a unique identifier previously signed and authenticatable, said medium being configured to support at least one signed access request data; a data management system comprising several records, each record representing a specific data item, and each specific data item being a function of one of the following parameters: ∘ an identifier of an authorized user; ∘ information of an authorized period; ∘ information of an authorized time slot; ∘ information of an authorized geographical area; ∘ information of an activity of said authorized user;a device for generating an access request data item to be signed from several of said specific data and the unique identifier of the medium, means for reading the unique identifier of said medium receiving the signed access request data item, said reading means being connected to said generation device, means for signing said access request data item to be signed to obtain a signed access request data item comprising a first data item representative of several of said specific data items, a second data item relating to said unique identifier of the medium, and a signature data item, a transfer device configured to transfer said signed access request data item to said medium, said transfer device being connected to said signing means and to said management system; ; said reading device comprising: means for reading said signed access request data, first authentication means configured to authenticate said signed access request data; second authentication means configured to authenticate the medium; verification means configured to verify the signature data of said signed access request data; first comparison means configured to compare the unique identifier of the medium with said second data of said signed access request data;second comparison means connected to a database reference base in which one or more specific subsets of data are recorded, each subset being representative of a predefined access authorization which is a function of several of said parameters, said second comparison means being configured to compare the first data of said signed access request data with said subsets of data; means for transmitting an access authorization signal to a locking device.;

[0071] According to a fifth aspect, the invention relates to an access control system comprising a transfer device as described above, a medium as described above and a reading device as described above.

[0072] Preferably, the control system further comprises means for encrypting said access request data to be signed or said signed access request data.

[0073] Preferably, in the access control system: said transfer device is further configured to transfer said encrypted signed access request data to said medium, and preferably to decrypt said encrypted signed access request data supported by said medium, and said reading device is further configured to read and decrypt said encrypted signed access request data.

[0074] The invention will be better understood by reading the following description, given solely by way of example, and with reference to the appended figures in which: [ Fig 1 ] there figure 1 schematically represents a system according to different embodiments of the invention; [ Fig 2 ] there figure 2 schematically represents an asymmetric key mechanism implemented between a reading device and a support according to different embodiments of the invention; [ Fig 3 ] there figure 3 schematically represents an asymmetric key mechanism implemented between a reading device and a support according to different embodiments of the invention.

[0075] In the figure 1 , the access control system according to a particular mode according to the invention, comprises several supports 101, each being defined by a unique identifier, for example a unique identifier vigik ®< (commonly designated by the acronym VUID), configured to support at least one signed access request data.

[0076] This access control system further comprises a data management system 104 comprising sub-records, each sub-record representing specific data such as particular DPR service provider data defining a service provider (a company for example), for example, DGEO geographical areas in which the service provider is present, and DACT activities defining the activities of the service provider. In addition, the management system also comprises data representative of the following parameters: information on an authorized DP period; and information on an authorized DSLOT time slot.

[0077] In this way, each sub-record can be associated with information on an authorized DP period and information on an authorized DSLOT time slot.

[0078] This access control system further comprises several devices for generating access request data to be signed DAS from one of the sub-records, specific DP and DSLOT data and the VUID of the medium onto which the access request data to be signed DAS is to be transferred.

[0079] The access request data to be signed DAS is therefore generated from one of the subsets, the DP and DSLOT parameters and the unique identifier VUID of one of the media 101 read by reading means to which the management system and each of the generation devices are connected. Each generation device may be located on the premises of an accredited or authorized service provider so as to facilitate generation before the transfer of the access request data.

[0080] This access control system further comprises a transfer device 102 connected to the management system and comprising means for reading the unique identifier of said medium, means for receiving the access request data to be signed and generated by the generation device, means for signing the access request data to be signed to obtain signed access request data comprising a first data item representative of said one or more of said specific data, a second data item relating to said unique identifier of the medium, and a signature data item, and means for transmitting said signed access request data item to the medium. Thus, this transfer device 102 is configured to transfer the signed access request data item to the medium 101 corresponding to the VUID from which the access request data item was generated.

[0081] The means for signing the access request data to be signed make it possible to obtain, once it has been signed, signed access request data comprising a first data item representative of the parameters DP, DPR, DACT, DGEO and DSLOT and comprising a second data item relating to the VUID of the support 101, and DSIGN signature data item so as to certify the access request data item.

[0082] Here, the signature data DSIGN of the access request to be signed DAS by the means of signature, can therefore be written DSIGN = fn(Kpr,VUID,DPR,DP,DSLOTS,DACT,DGEO). In order for the signature data to be verified by each of the verification means capable, among other things, of authorizing access, the means of verification have adequate cryptographic means. These cryptographic means are broken down into a verification algorithm fn and a verification key Kpu which, depending on whether the algorithm of the signature data is a secret key or a public key, is equal to the secret or public key of the means of signature.

[0083] The signing means can be configured to modify, after a predefined period which can be a period of use of the medium 101, its signature data so that the certificate of the access request data initially signed is no longer valid.

[0084] Thus, each support 101 comprises means for receiving the signed access request data, means for supporting the signed access request data, and means for sending the signed access request data.

[0085] This access control system further comprises several reading devices 210 configured to read the signed access request data issued by a medium 101 among said mediums 101 and to transmit an access authorization signal to locking devices once the signed access request data and its medium 101 have been authenticated, verified and compared.

[0086] Each reading device 210 is located in a geographic area covered by at least one DGEO geographic area of ​​at least one of the supports.

[0087] Each reading device 210 is advantageously provided with an internal clock which verifies that the current date / time information of presentation of the medium 101 is indeed within the range of the medium DP and the authorized time range DSLOT of the access control then, authenticates the medium and the access request data using authentication means, verifies the signature using verification means which includes for example a verification key, then compares the VUID of the medium read with the VUID contained in the signed access request data from which the latter was generated and also compares the first data of the signed access request data with subsets registered in a database reference connected to the reading device.If the authentications, verifications and comparisons are satisfied, the reading device 210 generates and transmits an ATA access authorization signal to the locking device (or several locking devices) to which it is connected.

[0088] To do this, the reading device 210 is connected to: first connected authentication means configured to authenticate the signed access request data; to second authentication means configured to authenticate the medium 101; to verification means to verify the signature data of the signed access request data; to first comparison means to compare the unique identifier of the medium 101 with the second data of said signed access request data; and to second comparison means connected to a database reference in which one or more specific subsets of data are recorded, each subset being representative of a predefined access authorization which is a function of several of the parameters, the second comparison means being configured to compare the first data of the signed access request data with the subsets of data.

[0089] It should be noted that the signed access request data may be similar to a certificate (cert(c)) generated by a certification authority (CA) (22) using, among other things, generation and transfer devices 102 as well as signature means.

[0090] Thus, in the system according to the invention, the data medium 101, whether in the form of a card or a mobile telephone, can then have an electronic key function capable of unlocking the locking devices installed in a particular geographical area defined by DGEO, to carry out a DACT activity provided that it is an accredited service provider and / or carrying out an authorized activity DPR registered in the data management system 104 and this within a given time slot DSLOT on a planned date DP.

[0091] To do this, the mechanism involved can be that indicated in the figure 2 [Fig 2 ], which illustrates an asymmetric key mechanism, in which it is not necessary to share secret data, nor to share an identical key between the reading device 210 and the medium 101 supporting the certificate cert(c) generated by a certification authority (CA) (22). The access control system is then configured here so that the medium 101 supports additional information in addition to the certificate cert(c) (or signed access request data). In this case, the reading device 210, alone or associated with other technical means, is furthermore capable of evaluating, analyzing, controlling this additional information.

[0092] In particular, the support 101 can further be configured to support a key pair and the reading device 210, which can be designated by the term terminal, are both configured to further receive a key pair or "keypair" (KP) (21), can also be connected to a means defined by another key pair. Each of these key pairs is composed of a public part (KPU) and a private part (KPR). The private part of the support 101 must never be disclosed under penalty of possible cloning. The reading device 210 may use a static or ephemeral key pair and is further configured to generate a random number called “random” RND(T) 23. In addition, the medium, apart from the certificate cert(c), also supports a processing unit configured to generate a random number “random” RND(C) and an additional signature S from its private key KPR(C) and the two random numbers RND(C) and RND(T).

[0093] Thus, the reading device 210 draws the random number called “random” RND(T) 23 and provides it to the support 101 at the same time as its public key KPU(T). The support 101, in turn, draws the random number “random” RND(C) and generates the additional signature S. The support 101 returns to the reading device 210 its VUID identifier, the random number RND(C), the certificate cert(c) and the additional signature S.

[0094] The reading device 210 is then able to verify the validity of the certificate cert(C) and to verify the additional signature S with the public key of the data medium 101 KPU(C) contained in the certificate cert(C). Each entity will then calculate a shared secret, or result, Z with a Diffie-Hellman type algorithm using the two random numbers RAND(C) and RAND(T), the public key of the other entity and its own private key.

[0095] The result Z will then be diversified into session keys SK1 and SK2 from a derivation function f'. These keys will be used to encrypt and sign future exchanges.

[0096] The support 101 has successfully authenticated itself with the reading device 210 by proving its knowledge of the private key KPR(C) associated with the certificate cert(c), itself successfully signed by a certification authority via the signature means.

[0097] The private key KPR(C) must be protected by the support 101 so that it can never be extracted. This may be the condition under which cloning can be avoided. The key pair of the reading device 210 can be generated either at installation, at startup, or at each transaction (ephemeral key pair) depending on the expected performance.

[0098] This mechanism can also take place between the support 101 and the transfer device 102 when, for example, it is desired to transfer new signed access request data into the support 101.

[0099] The verification means of the reading device 210 are preferably configured to also receive the certificates of the certification authorities (CA) as well as the certificate of the root authority (root CA). The certificates must be able to be updated and revocation lists must be managed, as for any system based on a public key solution called PKI.

[0100] Alternatively, the signature data obtained by the signing means may be obtained using a public key production algorithm. For example, an “Elliptic curve digital signature algorithm” known as ECDSA using a key size of at least 192 bits.

[0101] Furthermore, in a variant, the system further comprises means for encrypting said access request data to be signed or said signed access request data and the transfer device 102 is further configured to transfer the encrypted signed access request data to the medium 101, and preferably to decrypt the encrypted signed access request data supported by said medium 101, and the reading device 210 is also further configured to read and decrypt the encrypted signed access request data supported by the medium 101.

[0102] For example, the encryption of the encrypted signed access request data is produced by an AES "Advance Encryption Standard" type algorithm using 256-bit keys.

[0103] Thus, without being obliged to share a secret between the reading or transfer devices 210, and the data support 101, it is possible that the support 101 is configured to authenticate these devices and / or that these devices are configured to authenticate the support 101 using in particular the implementation of a step of transmitting authentication data from the medium to the reading device and / or from the medium to the transfer device and / or from the reading device to the medium and / or from the transfer device to the medium; and of a step of processing, by the reading device and / or by the transfer device and / or by the medium 101, the collected authentication data.

[0104] There figure 3 illustrates this case. Indeed, as indicated in the figure 3 [Fig 3] illustrating an asymmetric key scheme, it is not necessary to share an identical key between a terminal 30 which may be the reading device 30 (or the transfer device 102, and the medium 101. In the following, it is considered that the terminal 30 is the reading device 210. Thus, the medium 101 and the terminal 30 both receive a key pair (KP) 31, composed of a public part (KPU) and a private part (KPR). The private part of the terminal 30 must not be disclosed in order to prevent unauthorized reading devices from communicating with the medium 101. The terminal 30 will receive the unique identifier (VUID) of the medium and the certificate cert(c) supported by the medium 101 and initially generated by a certification authority (CA) (32).

[0105] The medium 101 draws a random number called “random” RND(C) (33) and provides it to the terminal 30 along with its VUID identifier and its public key KPU(C). After verifying the certificate chain, the terminal 30 generates an additional signature S with its private key KPR(T) and the random number using a cryptographic algorithm and then transmits this additional signature to the medium 101.

[0106] The support 101 is then able to verify the validity of the certificate and to verify the additional signature S with the public key of the support 101 of the terminal 30 KPU(T) contained in the certificate previously transferred to the support 101 currently supported by the support 101.

[0107] Terminal 30 has in turn authenticated itself with support 101 by proving its knowledge of the private key KPR(T) associated with the certificate, itself signed by a certification authority.

[0108] The private key KPR(T) must be protected by terminal 30 so that it can never be extracted.

[0109] In particular, the additional signature of the terminal 30 can be obtained by means of a public key production algorithm. For example “RSA” using a key size of at least 1024 bits. After this authentication of the terminal 30, the certificate equivalent to the signed access request data is accessible in read mode from the medium 101 in encrypted form. The encryption of the access request data is produced by an AES “Advance Encryption Standard” type algorithm using 256-bit keys.

[0110] The two authentication phases (that of the medium by the reading device and that of the reading device by the medium) constitute a mutual authentication of the two entities: the medium 101 and the terminal 30.

[0111] This mechanism can also take place between the support 101 and the transfer device 102, which is then considered to be the terminal 30, when it is desired, for example, to transfer new signed access request data into the support 101.

[0112] Thus, the authentication of the reading device 210, or of the transfer device 102 by the medium 101, also uses an authentication principle without being obliged to share a secret.

[0113] In a variant, the support 101 is further configured to support modification data of the database reference connected to the reading device 210. The support 101 is in this case configured to transport update data of the reading device 210, and to transmit it to it during their reading. Thus, the support 101 can support data allowing for example the updating of the authentication, verification or even comparison conditions relating to the reading device 210. This can also be the case for example for any other element intended to be pollinated across the entire access control system.

[0114] It should be noted that when the access request conditions read on the media 101 via the access request data signed by the reading device 210 or by other authorized terminals such as the transfer device 102 are met, new parameters, intended for optional applications other than access control, i.e. other than authentication and the transmission of an access authorization signal, may be evaluated. This additional data, independent of the main access control application, will thus benefit from the authentication system implemented, the security provided by the media 101 and the availability of the database reference base as well as the overall architecture of the system.

[0115] In one embodiment of the invention, the devices that constitute the system are completely independent of each other. Also, there is no dependency link between the reading device 210 and the transfer device 102, just as the support 101 also operates on all the reading devices, when the system comprises several, without them having any links or dependencies between them. The system, in this variant, does not need to be connected as a whole to operate during the steps of transferring and transmitting the access authorization signal, for example. It will be able to connect autonomously and independently of these steps. Signed access request data supported by the supports 101 following the transfer step via any transfer device 102 will be able to be accepted on any reading device 210 participating in the system.That is to say that the reading devices, when the system includes several, have no link of dependence with the transfer devices, particularly when the system includes several.

Claims

1. An access control method in an access control system comprising: - a medium at least defined by a previously signed and authenticatable unique identifier, said medium being configured to support at least one signed item of access request data; - a data management system comprising a plurality of records, each record representing a specific item of data, and each specific item of data being a function of one of the following parameters: ▪ an authorized user ID; ▪ an item of information about an authorized period; ▪ an item of information about an authorized time slot; ▪ an item of information about an authorized geographical area; ▪ an item of information about an activity of said authorized user; - a device for generating an item of access request data to be signed, based on a plurality of said specific items of data and on the unique identifier of the medium, - means for reading the unique identifier of said medium receiving the signed item of access request data, said reading means being connected to said generating device, - means for signing said item of access request data to be signed in order to obtain a signed item of access request data comprising a first item of data representative of a plurality of said specific items of data, a second item of data relating to said unique identifier of the medium, and an item of signature data, - a transfer device configured to transfer said signed item of access request data to said medium, said transfer device being connected to said signing means and to said management system; - a reading device configured to read said signed item of access request data from said medium and to transmit an access authorization signal to a locking device; - first authentication means connected to said reading device and configured to authenticate said signed item of access request data; - second authentication means connected to said reading device and configured to authenticate the medium; - verification means connected to said reading device and configured to verify the item of signature data of said signed item of access request data; - first comparison means connected to said reading device and configured to compare the unique identifier of the medium with said second item of data of said signed item of access request data; - second comparison means connected to said reading device and to a reference database in which one or more subsets of specific data are saved, each subset being representative of a predefined access authorization which is a function of a plurality of said parameters, said second comparison means being configured to compare the first item of data of said signed item of access request data with said subsets of data; said access control method being executed by said access control system and comprising: - a step of recording said specific data in said data management system; - a step of supplying the medium defined by a previously signed and authenticatable unique identifier, - a step, via said reading means, of reading the unique identifier of said medium, - a step, via said generating device, of generating said item of access request data to be signed; said step of generating said item of access request data to be signed being performed after said step of reading the previously signed unique identifier of said medium; - a step, via said signing means, of signing said item of access request data to be signed and the unique identifier of the medium in order to obtain said signed item of access request data; - a step of transferring said signed item of access request data from said transfer device to said medium defined by the unique identifier of the second item of data of said signed item of access request data; - a step of saving one or more subsets of specific data in the reference database, - a step, via said reading device, of reading said signed item of access request data supported by said medium; - a step of authenticating the medium, via said second authentication means, - a step of authenticating, via said first authentication means, said signed item of access request data and a step of verifying, via said verification means, the item of signature data of said signed item of access request data, and - a step, via said first comparison means, of comparing the unique identifier defining the medium with that of the second item of data of said signed item of access request data, - a step, via said second comparison means, of comparing the first item of data of said signed item of access request data with said subsets saved in the reference database; - a step of transmitting said access authorization signal from said reading device to said locking device.

2. The access control method according to claim 1, characterized in that a new signed item of access request data or one to be signed is signed by the signing means or generated by the generating device at the request of the user of the medium for each new period of use of said medium.

3. The access control method according to one of claims 1 or 2, in which said medium is configured to furthermore support authentication data and in which the reading device is configured to receive the authentication data from said medium and is configured to transmit said data to said second authentication means which are configured to receive the authentication data via said reading device, said method further comprises: - a step of transmitting authentication data from the medium to said reading device; and - a step of processing said authentication data originating from said medium, by said reading device.

4. The access control method according to one of claims 1 to 3, in which said medium is configured to furthermore support authentication data, in which the transfer device is further connected to third authentication means configured to authenticate the medium receiving the signed item of access request data via the authentication data, in which the transfer device is further configured to receive authentication data and transmit said data to said third authentication means which are configured to receive the authentication data via said transfer device, said method further comprises; - a step of transmitting authentication data from the medium to the transfer device; and - a step of processing said transfer data originating from said medium, by said transfer device.

5. The access control method according to one of claims 1 to 4, in which said reading device is further configured to transmit authentication data, in which the medium is configured to receive and process said authentication data originating from said reading device, said method further comprises: - a step of transmitting authentication data from the reading device to said medium; - a step of processing, by said medium, said authentication data originating from said reading device.

6. The access control method according to one of claims 1 to 5, in which said transfer device is further configured to transmit authentication data, in which the medium is configured to receive and process authentication data originating from said transfer device, said method further comprises: - a step of transmitting authentication data from the transfer device to said medium, - a step of processing, by said medium, said authentication data originating from said transfer device.

7. The access control method according to one of claims 1 to 6, in which said access control system further comprises means for encrypting said item of access request data to be signed or said signed item of access request data, - said transfer device is furthermore configured to transfer said encrypted signed item of access request data to said medium, - said reading device is furthermore configured to read and decrypt said encrypted signed item of access request data, said method further comprises: - a step of encrypting said item of access request data to be signed or said signed item of access request data, and - a step of decrypting said encrypted signed item of access request data by said reading device.

8. The access control method according to claim 7, in which: - said transfer device is furthermore configured to decrypt said encrypted signed item of access request data supported by said medium, said method further comprises: - a further step of decrypting said encrypted signed item of access request data supported by said medium, and - a step of transferring a new encrypted signed item of access request data to said medium to replace said encrypted signed item of access request data supported by said medium.

9. The access control method according to one of claims 1 to 8, in which said medium is further configured to support modification data of said reference database, said method further comprises: - a step of transferring said modification data from said medium to said reading device, and - a step of modifying said reference database by modifying or deleting one of said subsets, or by adding an additional subset.

10. The access control method according to one of claims 1 to 9, in which said medium is configured to furthermore support additional data, in which the reading device and / or the transfer device are configured to process said additional data, the method further comprises: - a step of transferring said additional data from the medium to the reading device and / or transfer device, and - a step of processing said additional data by said reading device and / or by said transfer device.

11. The access control method according to one of claims 1 to 10, whereby one or more of the authentication steps and / or one or more of the comparison steps and / or the verification step are implemented without the means employed in these steps communicating with any element external to said system.

12. A transfer device belonging to an access control system comprising: - a medium at least defined by a previously signed and authenticatable unique identifier, said medium being configured to support at least one signed item of access request data; - a data management system comprising a plurality of records, each record representing a specific item of data, and each specific item of data being a function of one of the following parameters: ▪ an authorized user ID; ▪ an item of information about an authorized period; ▪ an item of information about an authorized time slot; ▪ an item of information about an authorized geographical area; ▪ an item of information about an activity of said authorized user; - a device for generating an item of access request data to be signed, based on a plurality of said specific items of data and on the unique identifier of the medium, - a reading device configured to read a signed item of access request data from said medium and to transmit an access authorization signal to a locking device; - first authentication means connected to said reading device and configured to authenticate said signed item of access request data; - second authentication means connected to said reading device and configured to authenticate the medium; - verification means connected to said reading device and configured to verify the item of signature data of said signed item of access request data; - first comparison means connected to said reading device and configured to compare the unique identifier of the medium with said second item of data of said signed item of access request data; - second comparison means connected to said reading device and to a reference database in which one or more subsets of specific data are saved, each subset being representative of a predefined access authorization which is a function of a plurality of said parameters, said second comparison means being configured to compare the first item of data of said signed item of access request data with said subsets of data; said transfer device being connected to the management system and comprising: - means for reading the unique identifier of said medium, - means for receiving the item of access request data to be signed, - means for signing the item of access request data to be signed in order to obtain a signed item of access request data comprising a first item of data representative of a plurality of said specific items of data, a second item of data relating to said unique identifier of the medium, and an item of signature data, - means for sending said signed item of access request data to the medium.

13. A medium at least defined by a previously signed and authenticatable unique identifier and belonging to an access control system comprising: - a data management system comprising a plurality of records, each record representing a specific item of data, and each specific item of data being a function of one of the following parameters: ▪ an authorized user ID; ▪ an item of information about an authorized period; ▪ an item of information about an authorized time slot; ▪ an item of information about an authorized geographical area; ▪ an item of information about an activity of said authorized user; - a device for generating an item of access request data to be signed, based on a plurality of said specific items of data and on the unique identifier of the medium, - means for reading the unique identifier of said medium receiving the signed item of access request data, said reading means being connected to said generating device, - means for signing said item of access request data to be signed in order to obtain a signed item of access request data comprising a first item of data representative of a plurality of said specific items of data, a second item of data relating to said unique identifier of the medium, and an item of signature data, - a transfer device configured to transfer said signed item of access request data to said medium, said transfer device being connected to said signing means and to said management system; - a reading device configured to read said signed item of access request data from said medium and to transmit an access authorization signal to a locking device; - first authentication means connected to said reading device and configured to authenticate said signed item of access request data; - second authentication means connected to said reading device and configured to authenticate the medium; - verification means connected to said reading device and configured to verify the item of signature data of said signed item of access request data; - first comparison means connected to said reading device and configured to compare the unique identifier of the medium with said second item of data of said signed item of access request data; - second comparison means connected to said reading device and to a reference database in which one or more subsets of specific data are saved, each subset being representative of a predefined access authorization which is a function of a plurality of said parameters, said second comparison means being configured to compare the first item of data of said signed item of access request data with said subsets of data; said medium comprising: - means for receiving at least one signed item of access request data; - means for supporting said signed item of access request data; - means for sending said signed item of access request data.

14. A reading device belonging to an access control system comprising - a medium at least defined by a previously signed and authenticatable unique identifier, said medium being configured to support at least one signed item of access request data; - a data management system comprising a plurality of records, each record representing a specific item of data, and each specific item of data being a function of one of the following parameters: ▪ an authorized user ID; ▪ an item of information about an authorized period; ▪ an item of information about an authorized time slot; ▪ an item of information about an authorized geographical area; ▪ an item of information about an activity of said authorized user; - a device for generating an item of access request data to be signed, based on a plurality of said specific items of data and on the unique identifier of the medium, - means for reading the unique identifier of said medium receiving the signed item of access request data, said reading means being connected to said generating device, - means for signing said item of access request data to be signed in order to obtain a signed item of access request data comprising a first item of data representative of a plurality of said specific items of data, a second item of data relating to said unique identifier of the medium, and an item of signature data, - a transfer device configured to transfer said signed item of access request data to said medium, said transfer device being connected to said signing means and to said management system; said reading device comprising: - means for reading said signed item of access request data, - first authentication means configured to authenticate said signed item of access request data; - second authentication means configured to authenticate the medium; - verification means configured to verify the item of signature data of said signed item of access request data; - first comparison means configured to compare the unique identifier of the medium with said second item of data of said signed item of access request data; - second comparison means connected to a reference database in which one or more subsets of specific data are saved, each subset being representative of a predefined access authorization which is a function of a plurality of said parameters, said second comparison means being configured to compare the first item of data of said signed item of access request data with said subsets of data; - means for transmitting an access authorization signal to a locking device.

15. An access control system comprising a transfer device according to claim 12, a medium according to claim 13 and a reading device according to claim 14.

16. The access control system according to claim 15, further comprising means for encrypting said item of access request data to be signed or said signed item of access request data.

17. The access control system according to claim 16, wherein: - said transfer device is furthermore configured to transfer said encrypted signed item of access request data to said medium, and preferably to decrypt said encrypted signed item of access request data supported by said medium, and - said reading device is furthermore configured to read and decrypt said encrypted signed item of access request data.