Key with radio communication device

The key system addresses flexibility and security limitations by connecting directly to the internet via NB-IoT or LTE-M, allowing centralized management and secure, flexible operation with enhanced features like time-based authorization and extended battery life.

EP4610953A1Pending Publication Date: 2025-09-03ASSA ABLOY SICHERHEITSTECHNIK GMBH
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
EP2025160487
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-01
Filing Date
2025-02-27
Publication Date
2025-09-03

AI Technical Summary

Technical Problem

Existing key systems require local access control devices for authorization verification, limiting their flexibility and security, and centralized management is not feasible without continuous radio connection.

Method used

A key system with integrated key electronics and radio communication that connects directly to the internet via NB-IoT or LTE-M, enabling centralized management and flexible functionality through a server, including wireless data exchange and energy-efficient communication protocols.

Benefits of technology

Enables location-independent management, secure operation in areas without radio reception, and extended battery life, with flexible functionality and enhanced security features like time-based authorization and firmware updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IMGAF001_ABST
    Figure IMGAF001_ABST
Patent Text Reader

Abstract

The invention relates to a key with a key bow (22) and a key shaft (21) for actuating a locking cylinder (5), comprising key electronics (24) arranged in the key bow (22), which transmit an opening signal or a coded opening signal to the locking cylinder (5), and comprising a radio communication device (242) that connects the key (2) to the Internet via a mobile radio network (68). In order to be able to use the key (2) in the most versatile way possible, the radio communication device (242) connects the key (2) directly and wirelessly to the Internet via NB-IoT or LTE-M in order to exchange either a locking authorization list, and / or parameterization, and / or firmware with a server (63) connected to the Internet.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a key with a key blade and a key shank according to the features of the preamble of claim 1.

[0002] In practice, keys with radio communication devices are used to connect the key to a local access control system, for example. The access control system can determine whether a specific key has access authorization for a lock or a locking cylinder. To do this, the key can establish a radio connection with the access control device or exchange locking data.

[0003] A generic key is known from EP 2 821 972 B1. The key has a radio communication module for establishing a connection with an access control device. The access control device is a local access control device. The key checks whether a trigger condition for a locking cylinder to be opened is met. Communication with the access control device is only established if the trigger condition for a corresponding cylinder is met. The access control device checks whether the key's trigger condition corresponds to a current validity period for the key device. Only if this check is positive can the key open the corresponding locking cylinder. This makes it possible to increase the security of the key or to store time-dependent locking authorizations.One disadvantage, however, is that an appropriate access control device must be installed locally to check whether the key has the locking authorization.

[0004] US 2020 / 0399928 A1 discloses digitally scanning a mechanical key and generating a digital key, which is then sent to a central server via a network. The central server checks whether the generated code is authorized to open a specific locking cylinder and either grants or denies access to the lock. A disadvantage of this method is that the access authorization must be verified in every case, and the key cannot be operated without a corresponding radio connection.

[0005] The object of the present invention is to create a key or a lock-key system that has a flexible range of functions and, in particular, can be used anywhere. Preferably, the range of functions of the key or lock-key system should be manageable from a central location, preferably expanded and / or reduced. In particular, the key should be highly secure and should be easy for the user to handle like a normal key.

[0006] This object is achieved according to the invention by a key having the features of claim 1, as well as by a method for operating a key having the features of claim 13.

[0007] The key has a key bow and a key shaft for actuating a locking cylinder, in particular for a mechatronic lock-key system, comprising key electronics arranged in the key bow, which transmits an opening signal or a coded opening signal to a locking cylinder and has an energy storage device for supplying the key electronics with electrical energy. The key electronics has a radio communication device that connects the key to the internet via a mobile network. It is essential that the radio communication device connects the key directly and wirelessly to the internet via NB-IoT or LTE-M in order to exchange either a locking authorization list, and / or parameterization, and / or firmware with a server connected to the internet.

[0008] The advantage is that the key is directly connected to the internet and can therefore be managed centrally, i.e., location-independently, via a server. For example, the key's functionality and / or locking authorization and / or parameterization and / or firmware updates can be controlled via the server. A local device for communication and / or control and / or management of the key is thus no longer required. It is also possible to subsequently transfer additional functionality to the key via the internet or to delete it from the key. This creates new application profiles for the key.

[0009] Preferably, the key or key electronics can be connected to the IoT (Internet of Things) via the radio communication device. Specifically, the Internet of Things (IoT) refers to a network of physical objects that connects them to other devices and systems via the internet. These objects, also referred to as "things," can be diverse, ranging from simple devices like fitness trackers to complex machines like factory equipment.

[0010] Preferably, the energy storage device can be a replaceable battery, for example a lithium battery or a rechargeable battery.

[0011] In particular, a radio communication device is understood to be a radio modem that allows electronic data to be exchanged bidirectionally between the key electronics and a computer or server connected to the Internet. The first part of the transmission path is wireless, between the key and an internet access point.

[0012] Preferably, the wireless data exchange between the key electronics and a computer or server connected to the Internet takes place using an existing mobile communications infrastructure, in particular a GPRS, 3G, 4G, or 5G, or 6G or LTE network.

[0013] In particular, LTE-M (Long Term Evolution for Machines) is a mobile communications standard specifically developed for connecting devices in the Internet of Things (IoT). It is based on the LTE standard but optimized for the needs of IoT devices. Advantageously, LTE-M offers high network coverage because it uses the existing LTE network, which offers extensive coverage worldwide. Another advantage is that LTE-M is very energy-efficient, which extends the battery life of the key. Furthermore, LTE-M offers a relatively high data rate of up to 1 Mbps.

[0014] Narrowband IoT (NB-IoT) is a mobile communications standard developed for the Internet of Things (IoT). NB-IoT is based on LTE technology but uses narrower bandwidths and lower transmission power than traditional LTE devices. NB-IoT has the advantage of low power consumption and therefore a long battery life for the key. Good coverage is also an advantage, as NB-IoT signals can penetrate buildings and other obstacles, meaning that the key or key electronics can be connected to the Internet even indoors. The data rate of NB-IoT is lower than that of LTE-M and is limited to a maximum of 200 kHz, which only allows data rates of up to 250 kbit / s in the downlink. Data rates of up to 66 kbit / s are possible in the uplink. In practice, the key or key electronics canTo save power, the key electronics can be operated at lower data rates of up to 60 kbit / s or 30 kbit / s in NB-IoT mode. A major advantage of NB-IoT is its lower power consumption than LTE-M and its greater range. The range of NB-IoT can be up to 60 km under favorable conditions. In practice, average ranges of up to 30 km can be expected. However, in urban areas with tall buildings and other obstacles, the range can be limited to 1 to 2 km.

[0015] In particular, actuation of the locking cylinder, especially mechanical actuation of the locking cylinder, means rotation of the locking cylinder or the locking cylinder core by the key. For this purpose, the key shaft is inserted into a keyway of the locking cylinder. The locking cylinder is designed in particular as a so-called e-locking cylinder and has locking cylinder electronics and an electronically switchable locking element. The electronically switchable locking element normally blocks actuation of the locking cylinder. Only after the locking cylinder electronics or the locking cylinder has received a correct or valid opening signal from the key or the key electronics is the electronically switchable locking element released and the locking cylinder can be actuated by turning the key.

[0016] In particular, the locking cylinder is intended for installation in a building door lock, for example, a mortise lock with a single locking mechanism or with a multi-point locking mechanism. The locking cylinder can be designed as a locking cylinder according to a DIN standard, a so-called Swiss locking cylinder, or a locking cylinder according to a Scandinavian standard. These locking cylinders differ in their external dimensions.

[0017] A locking cylinder is preferably a mechatronic locking cylinder or a so-called e-locking cylinder. In addition to the mechanical components of a locking cylinder, these have locking cylinder electronics to read and preferably evaluate an electronically coded opening signal. The locking cylinder electronics only authorizes actuation of the locking cylinder when a valid opening signal is received.

[0018] Preferably, a mechanical code can be attached to the key shaft. This mechanical code can be scanned by the locking cylinder when the key shaft is inserted into the locking cylinder and used as a security feature in addition to the coded opening signal.

[0019] Preferably, in alternative embodiments, it can be provided that the key shaft does not have a mechanical coding, but the opening authorization is carried out solely by the electronically coded opening signal.

[0020] An electronically coded opening signal is preferably understood to be a signal that has a code or encryption. The opening signal can be generated by the key electronics or stored in the key electronics via parameterization or programming. The opening signal can then be encrypted, for example, using RSA encryption, DES encryption, or AES encryption.

[0021] Different opening signals can be provided or generated in the key electronics. For example, group opening signals, individual opening signals, or general opening signals can be provided. An individual opening signal authorizes the operation of a single locking cylinder. A group opening signal authorizes the operation of multiple locking cylinders, i.e., a group of locking cylinders. A general opening signal can operate all locking cylinders in a locking system, similar to a master key.

[0022] The coded opening signal can be transmitted to a locking cylinder via a wired connection. Alternatively or additionally, the coded opening signal can also be transmitted wirelessly. For example, the key electronics can have a wireless interface, preferably ZigBee or Bluetooth, or an RFID interface.

[0023] Advantageously, it can be provided that an electrical contact is arranged on the key shaft in order to connect the key electronics to the locking cylinder electronics, preferably that the locking cylinder electronics are supplied with electrical energy via this contact. The key shaft is preferably electrically conductive and the electrical contact is insulated from the key shaft. This makes it possible to set up an electrical circuit having two poles, for example by the key shaft serving as ground and the electrical contact as the second pole. Thus, when the key is fully inserted into a locking cylinder, an electrical circuit can be closed with the locking cylinder by means of the electrical contact. Both data and electrical energy can be exchanged via the circuit.

[0024] In particular, it can be provided that the electrical contact is designed to establish a wired data connection between the key electronics and the locking cylinder electronics. Thus, in addition to the power supply, the electrical contact can also be designed as a data interface, in particular a bidirectional data interface. For example, an encrypted, electronically coded opening signal can be exchanged between the locking cylinder electronics and the key electronics via this data interface. Common encryption mechanisms such as AES encryption or RSA encryption can be used for encryption.

[0025] In particular, it can be provided that the radio communication device connects the key wirelessly, in particular without the interposition of a mobile device, in particular a mobile phone or tablet, and without the interposition of a modem or router, directly to the internet, in particular wirelessly to an APN (Access Point Name). Eliminating the need for a local device, be it a mobile device such as a mobile phone, a smartphone, a tablet, or the like, or a modem, a router, or a local access control system, makes the use of the key more flexible. Furthermore, the security of the key increases, since any interposition of an interface or additional device poses a security risk.

[0026] APN (Access Point Name) is typically understood as a gateway between the backbone of a mobile network (e.g., GPRS, 3G, 4G, or 5G or LTE) and the public internet. The APN contains information such as the name of the mobile provider, the network used, and the security settings. This information is required for a mobile device (e.g., smartphone, tablet, or IoT device) to connect to the internet. In particular, the APN settings are stored in the key electronics settings. To change network providers, these APN settings can be changed in the key electronics.

[0027] The APN can preferably be designed to check whether the key has a valid SIM card. For this purpose, it can be provided that an e-SIM is stored in the key electronics or that the key electronics has an interface and is connected to a SIM card via this interface. In particular, the SIM card or e-SIM has an ICCID (Integrated Circuit Card Identification Number). The ICCID can comprise an 18- to 22-digit numerical code. This numerical code can contain information about the country and home network as well as the identification number of the SIM card itself. In particular, the numerical code is unique. The APN can check the validity of the requested mobile connection using the SIM card or e-SIM, in particular using the ICCID. Only if the validity is positive can the APN establish a data connection to the Internet or a server.

[0028] In one embodiment, it is particularly provided that the range of the wireless connection, in particular the connection between the radio communication device and the APN, is at least 2 km, preferably up to 15 km, especially 30 km, and most preferably 60 km. This makes it possible to use the key even in a large-cell network with relatively weak network coverage and still connect securely to the Internet.

[0029] Advantageously, it can be provided that the key does not have to establish a radio connection for each opening and / or closing process. The key electronics exchanges the locking authorization with the locking cylinder electronics in the conventional manner, i.e., the key has electronic access authorization in the form of a code, which it exchanges with the locking cylinder electronics to establish locking authorization. A radio connection or an internet connection is therefore not required for locking authorization. This has the advantage that the key can also be used in buildings or in areas without radio reception, for example, in underground garages or corresponding basements of buildings.

[0030] In particular, it can be provided that a connection to the Internet is established on an event-based basis. For example, a user of the key can establish a connection to the Internet through an event, such as pressing a key. Alternatively or additionally, the key can have a timer to establish a connection to the Internet at regular intervals, for example, twice a day or once a day. This connection can also be established in conjunction with a heartbeat signal or a stay-alive signal.

[0031] It can be configured, for example, that a locking authorization list is exchanged with the server during the internet connection. This allows the key to be individually updated with regard to its locking authorization at regular intervals.

[0032] Additionally, the key's locking authorization list can be provided with a timestamp or a validity period. For example, a locking authorization list can have a limited validity period. A period of validity of 12 hours, 24 hours, 48 ​​hours, or even longer can be selected. After this period, the locking authorization list loses its validity and must be revalidated by establishing a connection to the server connected to the Internet. This can further increase the security of the key, since, for example, a lost or stolen key can be blocked on the server after the expiration of the period, thus automatically losing its locking authorization.

[0033] In one embodiment, it can be provided that the radio communication device is switchable between an NB-IoT or an LTE-M connection, in particular is switchable automatically. By switching the radio protocol between NB-IoT or LTE-M, in particular the range and / or the transmission capacity of the established data channel can be controlled. If the data requirement to be transmitted is relatively high, an LTE-M connection can be selected. Its data transmission rate is higher than that of the NB-IoT connection. In contrast, the range of the LTE-M connection is shorter than the range of the NB-IoT connection. Thus, by selecting the appropriate connection, adaptation to the radio conditions prevailing in the reception area can be made. Also, for example, the appropriate operating mode, i.e. NB-IoT or LTE-M, can be selected or set depending on the volume of data to be transmitted.In particular, the key electronics can make this setting automatically based on the amount of data to be transmitted and / or the prevailing transmission and / or reception characteristics at the location of the key.

[0034] In order to be able to use the key as flexibly as possible, it can be provided that the key has a rechargeable energy storage device. In particular, it can be provided that the energy storage device is rechargeable in that the key has either a USB-C interface for charging the energy storage device and / or an inductive charging interface for charging the energy storage device, and / or that contacts are arranged on the key shaft or on the key blade in order to charge the energy storage device. Via a USB-C interface, the key can be plugged into a standard charger and charged in a similar way to a mobile phone. Such a process is familiar and common to users from the field of mobile phones. Alternatively, it can be provided that the key is charged via an inductive interface.To do this, a user can place the key on an inductive charger, which charges the key virtually without having to connect it anywhere. Furthermore, the key blade or key shaft can be provided with contacts that create an electrical connection to charge the energy storage device. For example, the key blade or key blade can be inserted into a charging station, thereby charging the energy storage device.

[0035] In an advantageous embodiment, it can be provided that the key electronics optimize the power consumption of the key by automatically switching the radio communication device between NB-IoT and LTE-M for data transmission based on the amount of data to be transmitted and based on the bandwidth provided for NB-IoT and the bandwidth provided for LTE-M, the power consumption required for the NB-IoT connection, the power consumption required for the LTE-M connection, and the resulting transmission time in each case, such that the power consumption required for data transmission is minimized. The NB-IoT operating mode has the advantage that the radio range is relatively large and the resulting power consumption for data transmission is relatively low compared to the LTE-M operating mode.However, if the amount of data to be transmitted is relatively large, the required transmission time in NB-IoT operating mode is significantly longer than in LTE-MDh operating mode. If the amount of data to be transmitted is relatively large, correspondingly longer switch-on times for the radio communication module and thus increased power consumption can be expected. Advantageously, the key electronics determines the radio conditions prevailing on the key at the time of a desired transmission, i.e., the possible operating modes and bandwidths for connecting the radio communication module to the Internet. Based on the data required for the transmission, the key electronics can easily calculate which operating mode offers the lowest power consumption, taking into account the resulting transmission time.For example, transmission in LTE-M mode can be more efficient despite the higher power consumption of the LTE-M connection, as the corresponding transmission time is significantly shorter than with a more power-efficient NB-IoT connection. Through appropriate calculations based on the amount of data to be transmitted and taking into account the currently available bandwidth, the key electronics can select the most efficient operating mode and switch the radio communication device in such a way that power consumption is minimized for a specific data transmission. This can extend the key's operating life accordingly, and the time between two recharging processes of the energy storage device can be extended accordingly.

[0036] In particular, it can be provided that the key electronics triggers a data transmission via the radio communication device to a server connected to the Internet after the expiry of a specific, in particular adjustable, period of time, and / or in response to an event, in particular upon pressing a button on the key.

[0037] To optimize power consumption, the key electronics can be configured to switch the radio communication device to a sleep or power-saving mode during periods when no data transmission is active. This significantly reduces or even eliminates the data consumption of the radio communication device during times when no data connection is required.

[0038] Preferably, in one embodiment, the key can have a visual display for indicating the charge level of the energy storage device, wherein the visual display comprises a multi-colored LED or an RGB LED, or several multi-colored LEDs or several RGB LEDs. The visual display can signal to a user that it is time to charge the energy storage device. For example, during a locking process, the visual display can provide color information, with green indicating a sufficiently charged energy storage device and red indicating a discharged energy storage device. If a user of the key then sees a red display when unlocking a lock, they can charge the key accordingly to ensure uninterrupted and trouble-free operation of the key.

[0039] In particular, it can be provided that the key electronics have a preferably rewritable memory for storing a locking authorization list and / or for storing one or more locking processes and / or for storing an executable program, in particular firmware. This makes it possible, for example, to receive a locking authorization list via the Internet and to store it, in particular temporarily, in the rewritable memory. Furthermore, it is possible to store a locking history, i.e. the most recent locking processes, in the memory in order to transmit these to the central server as part of a data transfer over the Internet. Furthermore, firmware can be stored or temporarily stored in the memory in order to be able to control software updates or maintenance centrally via the Internet, for example. The firmware can be firmware for the key electronics.Advantageously, a software update can be installed on the key without the user having to forego using the key, for example because it would have to be sent in for maintenance. Alternatively, it can also be a locking cylinder update, i.e. locking cylinder firmware. The key can temporarily store the locking cylinder firmware in its memory and, as soon as it is inserted into a locking cylinder that requires updating, transfer this firmware to the locking cylinder electronics in order to provide the locking cylinder with a firmware update. For example, when connected to locking cylinder electronics, the key electronics can query a version number of the locking cylinder's firmware. If the locking cylinder firmware stored in the key electronics is newer or has a newer version number, the key electronics can renew or update the locking cylinder's firmware.

[0040] In a similar way, operating parameters and / or operating times can also be transmitted to the key electronics via the Internet and temporarily stored in the memory.

[0041] In particular, the key electronics can be equipped with a clock or timer that deletes a locking authorization list or marks it as invalid after a certain period of time. This increases the security of the key, as a locking authorization list, once issued, automatically becomes invalid after a certain period of time, for example, after 12 hours, 24 hours, or 48 hours. This means that a key automatically loses its locking authorization if it is lost and / or stolen, and revalidation of the locking authorization list is no longer possible.

[0042] In one embodiment, the key electronics may include a real-time clock. The real-time clock is designed to record physical time and can be set via the Internet.

[0043] One advantage is that the real-time clock can be used to create an additional security feature to increase the key's security. The real-time clock can be used to add a time stamp to the electronically coded signal. The time stamp can be used as an additional security feature to verify whether the coded opening signal is valid or not.

[0044] In particular, the real-time clock can electronically provide a time signal or a time. The time signal can be an electronic signal from which a time can be derived, or it can represent a time. The time signal can be read or evaluated by the key electronics and / or transmitted as a time signal to the locking cylinder electronics.

[0045] For example, it can be specified that an electronically coded opening signal is only valid at a specific time of day or during a specific period of time. This means that the key with the electronically coded opening signal is only able to operate a locking cylinder at these specified times. Outside of these times or time ranges, the electronically coded opening signal has no opening authorization. This makes it possible, for example, to grant certain people or groups of people access to a room only at specific times of day, such as during normal business hours. Outside of business hours, the people or groups of people with the respective key are not authorized to open the door or enter the room or building.

[0046] Furthermore, the real-time clock's time signal can be used to specify a maximum validity period for the coded opening signal. For example, it can be specified that a coded opening signal is only valid for a maximum period of 2 days, 4 days, or one week. After this predefined period of time has elapsed, the opening authorization of the coded opening signal automatically expires. This creates an additional security feature, as a lost key automatically loses its opening authorization after the specified period of time has elapsed. The period of the opening authorization of the coded opening signal can be extended or refreshed by revalidation over the internet.

[0047] The time signal of the real-time clock can be transmitted together with the coded opening signal to a locking cylinder electronics unit, whereby the locking cylinder electronics checks the coded opening signal together with the time signal of the real-time clock in order to grant or deny opening authorization.

[0048] Alternatively or additionally, the time signal from the real-time clock can be evaluated by the key electronics to generate a coded opening signal. For example, the key electronics can be configured such that, depending on the time provided by the real-time clock, it marks the coded opening signal as valid at defined times or within defined time ranges and marks it as invalid outside of the defined times or time ranges, or does not transmit a coded opening signal at all.

[0049] In particular, it can be provided that the key electronics revalidate a locking authorization list via a data connection to a server connected to the Internet by marking the locking authorization list as valid again, resetting the time period, or receiving and storing a new locking authorization list from the server. Preferably, the key has a timer that ensures that the key establishes a connection to the Internet at regular intervals, for example, once every 12 hours or once every 24 hours or more frequently, to revalidate the locking authorization list.A user can also trigger a revalidation of the locking authorization list manually, for example, by pressing a button on the key, whereupon the key electronics establishes a connection to a central server via the radio communication device and, for example, starts a revalidation of the locking authorization list.

[0050] In particular, it can be provided that the capacity of the rechargeable energy storage device is dimensioned such that the energy storage device supplies the key with electrical energy for at least one calendar month, in particular that the rechargeable energy storage device has a capacity in the range of 1 Wh to 5 Wh, preferably in the range of 1 Wh to 2 Wh. In practice, this results in relatively convenient handling of the key for a user, since a user only needs to charge the key once per calendar month.

[0051] In particular, it can be provided that the predicted power requirement of the key is in the range of 150 mAh to 300 mAh per month, in particular with a supply voltage of the key electronics of 3.7 V.

[0052] The predicted power requirement of the key can be determined by the key electronics determining the actual power requirement of the key over a specific period of time, or by determining the actual power requirement of the key over a specific period of time through measurements or simulations. The specific period of time can be, for example, one or more days, a week, or a month. The determined actual power requirement can be used as the basis for the predicted power requirement by determining the power requirement expected for a month, a week, or a day based on the actual power requirement. This determination can be performed by the key electronics itself, or it can be determined in advance and stored in the key electronics as a predefined parameter.

[0053] In one embodiment, it can be provided that the radio communication device uses a UDP protocol for data transmission to the APN.

[0054] In order to ensure the transmission security of the data despite the use of a UDP protocol, it can be provided that the data transmission between the radio communication device and the APN is secured by a VPN tunnel.

[0055] According to the invention, a lock-key system is also provided, comprising at least one key according to one of the preceding embodiments and a locking cylinder comprising locking cylinder electronics, wherein the energy storage of the key supplies the locking cylinder electronics with electrical energy when the key is inserted into the locking cylinder and the key electronics transmits an opening signal or a coded opening signal to the locking cylinder.

[0056] The lock-key system can, in particular, comprise a key according to one of the exemplary embodiments described above. Provision is made for the lock-key system to also comprise a mechatronic locking cylinder or a so-called e-cylinder, which has locking cylinder electronics. In particular, the locking cylinder electronics and the key electronics are programmed accordingly so that they can exchange and validate the opening signal with each other. When validating the opening signal, provision can be made, for example, for the key electronics to generate a coded opening signal and transmit it to the locking cylinder electronics. The locking cylinder electronics checks the opening signal, and if it is a valid opening signal, the locking cylinder electronics releases the switchable locking element to actuate the locking cylinder.

[0057] Furthermore, in one embodiment, it can be provided that the coded opening signal is exchanged bidirectionally between the locking cylinder electronics and the locking cylinder. For example, the key electronics can first check the locking cylinder electronics to see whether the locking cylinder electronics or the type of locking cylinder is approved for the corresponding key or for the corresponding lock-key system. Only after the locking cylinder has been validated will the locking cylinder electronics generate a coded opening signal and transmit it to the locking cylinder or the locking cylinder electronics. The locking cylinder or the locking cylinder electronics will then check the coded opening signal and, if it is valid, will enable the locking cylinder for operation. The locking cylinder can then be operated by turning the key, i.e.For example, it can be turned in the opening direction to open a lock, i.e. to retract locking elements of a lock into the lock housing and unlock a door.

[0058] In particular, it can be provided that the radio communication device is designed to receive a locking cylinder firmware via the Internet and that, when the key is inserted into the locking cylinder, the locking cylinder electronics transmits the locking cylinder firmware to the locking cylinder.

[0059] According to the invention, a method for operating a key is also included, in particular a key according to one of the preceding embodiments, wherein the key has a key bow and a key shaft for actuating a locking cylinder, in particular for a mechatronic lock-key system, wherein the key comprises key electronics arranged in the key bow, which transmits an opening signal or a coded opening signal to a locking cylinder and an energy store for supplying the key electronics with electrical energy, and wherein the key electronics has a radio communication device which connects the key to the Internet via a mobile radio network.What is essential here is that a direct wireless connection is established between the radio communication device and an APN via NB-IoT or LTE-M in order to transmit data from a server connected to the APN to the key electronics.

[0060] In particular, it can be provided that a connection between a server and the APN is established via a relay server, wherein an HTTP protocol is used for the connection between the server and the relay server and a UDP protocol is used for the connection between the relay server and the APN, or for the connection between the APN and the radio communication device.

[0061] In particular, it may be provided that the key electronics include a SIM card with an ICCID number, or an e-SIM with an ICCID number, and that the APN checks the validity of the ICCID number before the APN establishes a connection to the server or relay server. If the ICCID number is found to be invalid when checking the validity of the number, the APN may not establish the connection to the server or relay server and / or may refuse or terminate a mobile connection to the key or key electronics.

[0062] In particular, a relay server is a computer or network device that transfers messages between the APN and a server connected to the Internet.

[0063] The HTTP protocol refers specifically to the widely used Hypertext Transfer Protocol. It is a protocol for transmitting data over networks. It is a universally accepted technical standard that defines how a web client communicates with a server so that the data requested by the client can be loaded and displayed.

[0064] UDP, or User Datagram Protocol (UDP), is a connectionless transport protocol belonging to the transport layer of the Internet Protocol family. UDP enables applications to send datagrams in IP-based computer networks. UDP datagrams are simple packets consisting of a header and a payload. The header contains information such as the source and destination addresses, port numbers, and a checksum. The checksum is used to detect errors in the data. UDP offers several advantages over the connection-oriented transport protocol TCP. UDP is simpler in structure and more energy-efficient than TCP. Furthermore, UDP has lower latency than TCP.

[0065] In an advantageous embodiment, it can be provided that the server queries a locking history by controlling the key electronics via the radio communication device of the key, in particular in order to transmit the last locking actions and / or opening actions of the key to the server.

[0066] In order to increase the security of the key, it can be provided that the key electronics send a watchdog signal to the server at regular intervals and that the server confirms receipt of the watchdog signal from the key electronics.

[0067] The key or lock-key system according to the invention can be used, for example, in larger buildings and locking systems. Alternatively, it is also possible to use the key in individual, smaller properties, such as single-family homes. The central management of the key or lock-key system enables convenient and flexible use of the key and lock-key system according to the invention.

[0068] Further advantageous embodiments of the invention are shown in the figures and described below. Fig. 1a: an exploded view of a key according to the invention; Fig. 1b: an embodiment of the key according to the invention; Fig. 2: a schematic representation of a lock-key system according to the invention; Fig. 3:an arrangement for data transmission with the key according to the invention and a possible network structure for the Internet.

[0069] The figures illustrate various embodiments of the invention. These are intended to be descriptive and not limiting. In the figures, components with equivalent functions are provided with the same reference symbols. A person skilled in the art can vary or interchange various features of the illustrated embodiments based on their technical skill without departing from the scope of the invention as defined by the claims.

[0070] The Figures 1a and 1b show an exemplary embodiment of the key 2 according to the invention. In the Figure 1a The key 2 according to the invention is shown in an exploded view. In Figure 1b the key 2 according to the invention is shown ready for use.

[0071] The key 2 has a key shaft 21 and a key blade 22 connected to the key shaft 21. The key blade 22 is designed as a housing with a space for accommodating components. The key electronics 24 are arranged inside the key blade 22.

[0072] As in Figure 1a As shown, the key electronics 24 comprises a rechargeable energy storage device 241 as well as a radio communication device 242, a button 243 and an antenna 244.

[0073] The radio communication device 242 is supplied with electrical energy by the rechargeable energy storage device 241. To establish a radio connection, the radio communication device 242 has an antenna 244. The antenna allows the radio communication device 242 to establish a radio connection with a mobile network, for example, a 5G network, an LTE network, or a 6G network.

[0074] The key bow 22 has a cover 22a and a base 22b. By closing the cover 22a and base 22b, the key bow is locked and the key electronics 24 arranged within the key bow are protected from external influences. An optical display 25 is embedded in the housing of the key bow 22. The optical display can have one or more multi-colored LEDs and / or RGB LEDs and is designed to display operating states of the key 2 and / or charge states of the energy storage device 241. For example, if the energy storage device is discharged, a color change from green to red can be indicated via the optical display. It is also possible to equip the optical display with several LEDs, for example three LEDs in the form of a conveyor belt, to indicate different charge states. If all LEDs light up green, the energy storage device is fully charged.If only one LED is lit green, the energy storage unit is already partially discharged. If the LED then turns red, it indicates that the energy storage unit 241 needs to be recharged.

[0075] The key shank 21 has a first electrical contact 23a and a second electrical contact 23b. The first electrical contact 23a is arranged on the key shank 21 itself or is formed by a conductive key shank 21 itself. The second electrical contact 23b is insulated from the key shank 21 and forms the second pole of an electrical connection. The rechargeable energy storage device 241 can be charged via the two electrical contacts 23a and 23b, for example, by inserting the key into a charging station. Furthermore, when the key is inserted into a locking cylinder, the electrical contacts 23a and 23b can establish an electrical connection to the locking cylinder or locking cylinder electronics. The key electronics 24 can exchange an opening signal or a coded opening signal with the locking cylinder via this electrical connection.

[0076] In Figure 2 A lock-key system 1 according to the invention is shown. The lock-key system 1 comprises the key 2 according to the invention and a locking cylinder 5. The locking cylinder 5 comprises a locking cylinder housing 51, a rotatable locking cylinder core 52, and a locking channel 53 into which a key shank of the key 2 according to the invention can be inserted.

[0077] To open a lock, the key shaft 21 of the key 2 according to the invention is inserted into the locking cylinder 5 or its locking channel 53. In doing so, an electrical circuit to the locking cylinder 5 or its locking cylinder electronics is closed via the two electrical contacts 23a and 23b. The locking cylinder 5 or its locking cylinder electronics is supplied with electrical energy from the rechargeable energy store 241 of the key 2 according to the invention via this electrical circuit or the contacts 23a and 23b. At the same time, data is exchanged via the contacts 23a and 23b, in particular a coded opening signal. However, it is also conceivable that further data, which can be used to parameterize the locking cylinder, or a firmware update for the locking cylinder electronics, can be exchanged via the contacts 23a and 23b. Data from the locking cylinder 5 or its locking cylinder electronics can also be exchanged via the contacts 23a and 23b.whose locking cylinder electronics are queried, for example regarding the locking history, in particular how many locking operations have been carried out on the locking cylinder since a certain date.

[0078] Such locking cylinder data can be transmitted to a central server via the radio communication device 242 of the key according to the invention. Alternatively, data packets for the locking cylinder 5 can also be received via a central server and temporarily stored in a memory of the key 2 according to the invention until the key 2 is inserted into a locking cylinder 5 and can transmit this data to the locking cylinder 5.

[0079] In Figure 3The arrangement for transmitting data from key 2 to the Internet 65 is shown. The illustrated transmission arrangement 6 comprises key 2 with its radio communication device 242 and at least one access point to the Internet 65, namely the Access Point Name or APN 61. In practice, an existing mobile radio infrastructure is used. Therefore, in practice, several APNs are usually present. In particular, the APNs form a radio cell network.

[0080] The connection between the key 2 according to the invention and the APN 61 is established as a wireless radio connection 68 using the existing mobile communications infrastructure, in particular the 4G network, 5G network, 6G network, or LTE network. The APN 61 is in turn connected to a relay server 62. This connection can be wired or wireless. The relay server 62 forwards the messages from the radio communication device 242 of the key 2, which are received via the APN 61, to a server 63. This connection can be wired or wireless. The relay server 62 transcribes the transmission protocols. The connection between the APN 61 and the relay server 62 uses the UDP protocol. The relay server 62 transcribes the UDP protocol into the Internet's HTTP protocol. The connection between the relay server 62 and the server 63 is established via an HTTP protocol 66.

[0081] To secure communication with key 2, a VPN tunnel is established for communication. For example, a VPN connection to key 2 can be established from server 63 or relay server 62 to secure the data to be transmitted. For this purpose, either relay server 62 and / or server 63 can be configured as a VPN server.

[0082] Server 63 can be implemented as a central hardware server, for example, installed at a service provider's site. It can be a single computer or a computer network. Server 63 can also be implemented as a software server with a distributed hardware architecture.

[0083] Several clients 64a and 64b, etc., are connected to the server. A plurality of clients may be used to serve the server 63. In particular, it may be provided that a specific group of keys 2 can be addressed via each individual client 64a. For example, a locking object may have a specific group of keys 2, each of which can be addressed via its address. This group of keys is controlled by a specific client 64a. In particular, the client 64a is limited to this group with regard to the keys that can be addressed, so that only a specific locking object and a specific group of keys can be managed from a specific client. In order to manage multiple objects, a plurality of clients are necessary, which are connected to the Internet via the central server 63 in order to control the respective keys 2 via the Internet 6.

[0084] The number of keys centrally controlled via server 63 ultimately depends on the available address space and is sufficient in any case. Using IPv6 technology, it is possible to individually address several billion keys 2. List of reference symbols

[0085] 1 lock-key system 2Key 21Key shaft 22Key blade 22aCover 22bBase 23aFirst contact 23bSecond contact 24Key electronics 241Energy storage, battery 242Radio communication device 243Button 244Antenna 25Optical display 5Locking cylinder 51Locking cylinder housing 52Locking cylinder core 53Locking channel 6Transmission arrangement 61APN (Access Point Name) 62Relay server 63Server 64aClient 64bClient 65Internet 66HTTP connection 67UDP connection 68Radio link

Claims

1. A key with a key bow (22) and with a key shaft (21) for actuating a locking cylinder (5), in particular for a mechatronic lock-key system (1), comprising key electronics (24) arranged in the key bow (22), which transmits an opening signal or a coded opening signal to a locking cylinder (5) and has an energy store (241) for supplying the key electronics (24) with electrical energy, and wherein the key electronics (24) has a radio communication device (242) which connects the key (2) to the Internet via a mobile radio network (68), characterized by that the radio communication device (242) connects the key (2) directly wirelessly to the Internet via NB-IoT or LTE-M in order to exchange either a locking authorization list, and / or a parameterization, and / or a firmware with a server (63) connected to the Internet.

2. Key according to claim 1, characterized by that the radio communication device (242) connects the key (2) wirelessly, in particular without the interposition of a mobile device, in particular a mobile phone or a tablet, and without the interposition of a modem or a router, directly to the Internet, in particular wirelessly to an APN (Access Point Name) (61), wherein it is preferably provided, that the range of the wireless connection, in particular the connection between the radio communication device (242) and the APN (61), is at least 2 km, preferably up to 15 km, in particular 30 km, most preferably 60 km.

3. Key according to one of the preceding claims, characterized by that the radio communication device (242) is switchable between an NB-IoT or an LTE-M connection, in particular is switchable automatically.

4. Key according to one of the preceding claims, characterized by thatthe energy storage device (241) is rechargeable in that the key (2) has either a USB-C interface for charging the energy storage device (241), and / or an inductive charging interface for charging the energy storage device (241), and / or in that contacts (23a, 23b) are arranged on the key shaft (21) or on the key blade in order to charge the energy storage device (241).

5. Key according to one of the preceding claims, characterized by thatthe key electronics (24) optimizes the power consumption of the key (2) by automatically switching the radio communication device between NB-IoT and LTE-M for data transmission based on the amount of data to be transmitted and based on the bandwidth provided for NB-IoT and based on the bandwidth provided for LTE-M and the power requirement necessary for the NB-IoT connection and the power requirement necessary for the LTE-M connection and the resulting transmission time in each case in such a way that the power requirement necessary for the data transmission is minimized.

6. Key according to one of the preceding claims, characterized by thatthe key electronics (24) triggers a data transmission via the radio communication device (242) to a server (63) connected to the Internet after a specific, in particular adjustable, time period has elapsed, and / or in response to an event, in particular a keystroke of a button (243) located on the key.

7. Key according to one of the preceding claims, characterized by that the key electronics (24) switches the radio communication device (242) into a sleep mode or a power saving mode during periods outside of active data transmission.

8. Key according to one of the preceding claims, characterized by thatthe key electronics (24) has a rewritable memory for storing a locking authorization list, and / or for storing one or more locking processes and / or for storing an executable program, in particular a firmware, and / or that the key electronics (24) has a clock or a timer and deletes a locking authorization list after a certain period of time or marks it as invalid.

9. Key according to one of the preceding claims, characterized by that the key electronics (24) revalidates a locking authorization list by means of a data connection to a server (63) connected to the Internet, in that the key electronics (24) marks the locking authorization list as valid again or resets the time period or receives and stores a new locking authorization list from the server (63).

10. Key according to one of the preceding claims, characterized by that the capacity of the rechargeable energy store (241) is dimensioned such that the energy store (241) supplies the key (2) with electrical energy for at least one calendar month, in particular that the rechargeable energy store (241) has a capacity in the range from 1 Wh to 5 Wh, preferably in the range from 1 Wh to 2 Wh, in particular that the predicted power requirement of the key (2) is in the range of 150 mAh to 300 mAh per month, in particular with a supply voltage of the key electronics (24) of 3.7 V.

11. Key according to one of the preceding claims, characterized by that the radio communication device (242) uses a UDP protocol for data transmission to the APN (61), and / or that the data transmission between the radio communication device (242) and the APN (61) is secured by a VPN tunnel.

12. Lock-key system (1) comprising at least one key (2) according to one of the preceding claims and a locking cylinder (5) comprising locking cylinder electronics, wherein the energy store (241) of the key (2) supplies the locking cylinder electronics with electrical energy when the key is inserted into the locking cylinder (5), and the key electronics (24) transmits an opening signal or a coded opening signal to the locking cylinder (5), wherein it is preferably provided that the radio communication device (242) is designed to receive locking cylinder firmware via the Internet, and that when the key is inserted into the locking cylinder (5), the locking cylinder electronics (24) transmits the locking cylinder firmware to the locking cylinder (5).

13. A method for operating a key, in particular a key according to one of claims 1 to 11, wherein the key (2) has a key blade (22) and a key shaft (21) for actuating a locking cylinder (5), in particular for a mechatronic lock-key system (1), wherein the key (2) comprises key electronics (24) arranged in the key blade (22), which transmits an opening signal or a coded opening signal to a locking cylinder (5) and comprises an energy storage device (241) for supplying the key electronics (24) with electrical energy, and wherein the key electronics (24) has a radio communication device (242) which connects the key (2) to the Internet via a mobile radio network (68), characterized by thata direct wireless connection is established between the radio communication device (242) and an APN (61) via NB-IoT or via LTE-M in order to transmit data from a server (63) connected to the APN (61) to the key electronics (24).

14. A method for operating a key according to claim 13, characterized by thata connection is established between a server (63) and the APN (61) via a relay server (62), wherein an HTTP protocol is used for the connection between the server (63) and the relay server and a UDP protocol is used for the connection between the relay server (62) and the APN (61), or a UDP protocol is used for the connection between the APN (61) and the radio communication device (242), wherein it is preferably provided that the key electronics comprises a SIM card or an E-SIM with an ICCID number and the APN (61) checks the validity of the ICCID number before a connection to the server (63) or the relay server (62) is established by the APN (61).

15. A method for operating a key according to claim 13 or 14, characterized by thata locking history is queried by the server (63) in that the server (63) controls the key electronics (24) via the radio communication device (242) of the key (2), in particular in order to transmit the last locking actions and / or opening actions of the key (2) to the server (63), and / or that a watchdog signal is sent to the server (63) at regular intervals by the key electronics (24) and that the server (63) confirms receipt of the watchdog signal from the key electronics (24).

Citation Information

Patent Citations

  • Intelligent key and passive intelligent lock cylinder based on narrow band internet and application method thereof

    CN107230272A

  • Key device and associated method, computer program and computer program product

    EP2821972B1

  • Constructing physical keys by way of digital keys

    US20200399928A1

  • Wireless handheld beacon device for building management

    WO2022211795A1

  • Battery-powered gateway for enabling location-based access control by an access control server

    WO2023094260A1