Electronic key issuing method, electronic key issuing system, key device, and electric lock
The electronic key issuing method and system address the security issue of shared electronic keys by generating unique or shared keys based on lock permissions, ensuring secure and convenient access.
Patent Information
- Application Number
- JP2024120404
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-25
- Publication Date
- 2026-02-05
AI Technical Summary
Sharing an electronic key among multiple electric locks weakens security, as multiple locks can be unlocked with a single key, compromising security.
An electronic key issuing method and system that determines whether an electronic key should be unique to a specific lock or shared among multiple locks, ensuring that unique keys are generated and stored by the lock when necessary, and shared keys are generated and stored by the key device, enhancing security.
Ensures that electronic keys are either unique to a lock or shared among multiple locks, maintaining security by preventing easy regeneration of shared keys and simplifying user access.
Smart Images

Figure 2026019009000001_ABST
Abstract
Description
[Technical Field]
[0001] The present application relates to a technology for issuing an electronic key required to unlock an electric lock. [Background technology]
[0002] Electric locks are used in houses, vehicles, etc. (see, for example, Patent Document 1). An electric lock is a device that uses electrical power to manage the locking and unlocking of a locking mechanism. The key for an electric lock is not a conventional physical key, but an electronic key, which is electronic information. In this application, a device that stores an electronic key is called a key device. The electric lock uses the electronic key stored in the electric lock to authenticate authentication information obtained from the key device, and if authentication of the authentication information is successful, the locking mechanism managed by the electric lock is unlocked. The authentication information obtained from the key device may be the electronic key itself, or it may be information generated using the electronic key.
[0003] In vehicles, etc., there may be multiple users who need to open the same lock (electric lock). When using a physical key, it is necessary to prepare a duplicate key for the lock and provide it to each of the multiple users. In contrast, when using an electronic key, the electronic key corresponding to the electric lock can be stored in multiple key devices.
[0004] In addition, in company buildings, one user may need to unlock multiple electric locks. For example, an electric lock may be installed for each door in the building. When using physical keys, one key corresponds to one lock, so the user must carry a key for each lock. In contrast, when using electronic keys, an electronic key for each electric lock can be stored in a key device, or an electronic key shared by multiple electric locks can be stored in a key device. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Publication No. 2023-65083 Summary of the Invention [Problem to be solved by the invention]
[0006] When a single user needs to unlock multiple electronic locks, sharing an electronic key among multiple electric locks eliminates the need to select an electronic key, which increases user convenience. However, sharing an electronic key among multiple electric locks weakens the security of the electric locks, since multiple electric locks can be unlocked with a single electronic key.
[0007] Therefore, in this application, when issuing an electronic key, in the case of an electric lock that is not permitted to share an electronic key, an electronic key that is unique to the electric lock and difficult to regenerate is issued, and in the case of an electric lock that is permitted to share an electronic key, an electronic key that is shared by multiple electric locks and difficult to regenerate is issued. [Means for solving the problem]
[0008] The first invention that solves the above-mentioned problem is an electronic key issuing method executed by an electric lock and a key device, comprising: step a) in which the electric lock transmits electric lock identification information, which is information that identifies the electric lock, to the key device, and then requests the key device to determine the issuance type of the electronic key; step b) in which the key device determines the issuance type by referring to the electric lock identification information; step c) in which, if the determination result of the issuance type in step b is the issuance of a shared key, which is an electronic key that is permitted to be shared, the key device generates and stores the shared key based on the electric lock identification information and stores the shared key in the electric lock; and step d) in which, if the determination result of the issuance type in step b is the issuance of a unique key, which is an electronic key that is not permitted to be shared, the key device requests the electric lock to issue the unique key, the electric lock generates the unique key based on the electric lock identification information and stores the unique key, and stores the unique key in the key device.
[0009] Furthermore, a second invention is an electronic key issuing system comprising an electric lock and a key device, wherein the electric lock transmits electric lock identification information, which is information that identifies the electric lock, to the key device and then requests the key device to determine the issuance type of an electronic key; when a shared key, which is an electronic key that is permitted to be shared, is transmitted from the key device, the electric lock stores the shared key transmitted from the key device; when a request for issuance of a unique key, which is an electronic key that is not permitted to be shared, is transmitted from the key device, the electric lock generates and stores the unique key based on the electric lock identification information and includes a lock-side issuing unit that stores the unique key in the key device; and when the electric lock requests the key device to determine the issuance type, the key device determines the issuance type by referring to the electric lock identification information, and if it determines that the shared key should be issued, generates and stores the shared key based on the electric lock identification information and stores the shared key in the electric lock; and if it determines that the unique key should be issued, the key device requests the electric lock to issue the unique key and includes a device-side issuing unit that stores the unique key transmitted from the electric lock.
[0010] Furthermore, the third invention is a key device that is used to unlock an electric lock, and when the electric lock requests a determination of the type of electronic key to be issued after electric lock identification information, which is information that identifies the electric lock, is sent from the electric lock, the key device determines the type of issue by referring to the electric lock identification information, and when it determines that a shared key, which is an electronic key that is permitted to be shared, is to be issued, the key device generates and stores the shared key based on the electric lock identification information and stores the shared key in the electric lock, and when it determines that a unique key, which is an electronic key that is not permitted to be shared, is to be issued, the key device requests the electric lock to issue the unique key and stores the unique key sent from the electric lock.
[0011] Furthermore, the fourth invention is an electric lock that uses a key device to manage at least the unlocking of a lock mechanism, and is characterized in that it sends electric lock identification information, which is information that identifies the electric lock, to the key device, and then requests the key device to determine the type of electronic key to be issued, and when a shared key, which is an electronic key that is permitted to be shared, is sent from the key device, it stores the shared key sent from the key device, and when it receives a request from the key device to issue a unique key, which is an electronic key that is not permitted to be shared, it generates and stores the unique key based on the electric lock identification information and also has a lock-side issuing unit that stores the unique key in the key device. [Effects of the Invention]
[0012] According to the invention disclosed in this application, when issuing an electronic key, in the case of an electric lock that cannot share its electronic key with other electric locks, an electronic key unique to the electric lock is issued, and in the case of an electric lock that can share its electronic key with other electric locks, an electronic key that can be shared by multiple electric locks can be issued. [Brief explanation of the drawings]
[0013] [Figure 1] FIG. 1 is a diagram illustrating the overall configuration of an electronic key issuing system. [Figure 2] FIG. 4 is a diagram illustrating a procedure for issuing an electronic key. [Figure 3] FIG. 10 is a diagram illustrating a procedure for issuing a unique key. [Figure 4] FIG. 10 is a diagram illustrating a shared key issuing procedure. [Figure 5] 10A and 10B are diagrams illustrating the procedure for unlocking the locking mechanism of an electric lock. DETAILED DESCRIPTION OF THE INVENTION
[0014] Hereinafter, an embodiment of the present invention will be described. This embodiment is intended to facilitate understanding of the present invention, and the present invention is not limited to this embodiment. Furthermore, unless otherwise specified, the drawings are schematic diagrams drawn to facilitate understanding of the present invention.
[0015] FIG. 1 is a diagram illustrating the overall configuration of an electronic key issuing system 1 disclosed in this embodiment. The electronic key issuing system 1 shown in FIG. 1 is a system comprising at least an electric lock 2 and a key device 3. The electric lock 2 is a device that uses electrical power to manage the locking and unlocking of a locking mechanism. The key device 3 is a device equipped with an IC chip and secretly stores an electronic key 10 required to unlock the locking mechanism 22 managed by the electric lock 2. An IC card, a smartphone, a USB memory, a key fob, or the like can be used as the key device 3. In FIG. 1, the electric lock 2 is installed on a door 2a of a building, but the object on which the electric lock 2 is installed is not limited to the door 2a of a building. The object on which the electric lock 2 is installed may also be, for example, a vehicle door or a safety deposit box.
[0016] The electric lock 2 and the key device 3 store an electronic key 10. The electronic key 10 is information required to unlock the electric lock 2. When unlocking the electric lock 2, the key device 3 generates authentication information using the electronic key 10 stored in the key device 3, and the electric lock 2 authenticates the authentication information generated by the key device 3 using the electronic key 10 stored in the electric lock 2. Information indicating the algorithm used to generate the authentication information can be added to the electronic key 10. Any algorithm can be used to generate the authentication information, but in this embodiment, the key device 3 generates the authentication information by encrypting a random number value received from the electric lock 2 with the electronic key 10. The electric lock 2 authenticates the authentication information by comparing the value decrypted by the electronic key 10 from the authentication information received from the key device 3 with the random number value sent to the key device 3.
[0017] Thus, to unlock the electric lock 2, the electric lock 2 and the key device 3 must each store the same electronic key 10. When one user unlocks multiple electric locks 2, if the multiple electric locks 2 can share the electronic key 10, the user does not need to select the electronic key 10, which increases convenience for the user. However, if the electronic key 10 is shared by multiple electric locks 2, the security of the electric locks 2 is weakened because multiple electric locks 2 can be unlocked with one electronic key 10.
[0018] In consideration of this, the electronic key issuing system 1 according to this embodiment is configured such that, when issuing an electronic key 10, if the electric lock 2 does not permit sharing of the electronic key 10, the electric lock 2 issues a unique electronic key 10 that is unique to the electric lock 2, i.e., an electronic key 10 that is not permitted to be shared. If the electric lock 2 permits sharing of the electronic key 10, the key device 3 issues a shared electronic key 10 that is shared among multiple electric locks 2, i.e., an electronic key 10 that is permitted to be shared. The reason for having the electric lock 2 issue the unique key is to enable the electric lock 2 to issue a unique key that is unique and difficult to regenerate. The reason for having the key device 3 issue the shared key is to make it difficult to regenerate the shared key. If the electric lock 2 generates the shared key, all electric locks 2 that share the shared key must be able to generate the same shared key, making it possible to regenerate the shared key. In contrast, if the key device 3 is provided with a shared key generation function, only the key device 3 can obtain the shared key.
[0019] Next, the electric lock 2 and the key device 3 that constitute the electronic key issuing system 1 disclosed in the present application will be described in detail.
[0020] First, the electric lock 2 will be described. Figure 1 shows an example of a block diagram of the electric lock 2. The electric lock 2 comprises a processor 200, a non-volatile memory (NVM) 201, a communication interface 202, and a locking mechanism 22. Note that Figure 1 only shows elements necessary for explaining the electronic key issuing system 1. Naturally, the electric lock 2 also comprises elements that are necessary for functioning as the electric lock 2 but are not shown in Figure 1. For example, elements not shown in Figure 1 include a random access memory (RAM) that serves as the main memory used by the processor 200, and a power supply circuit that supplies power to the electric lock 2.
[0021] The communication interface 202 is an interface used for communication with the key device 3. It is desirable for the electric lock 2 and key device 3 to communicate wirelessly, but they may also communicate wired. The communication interface 202 provided in the electric lock 2 depends on the key device 3. In this embodiment, a contactless IC card is used for the key device 3. For this reason, the communication interface 202 provided in the electric lock 2 is a circuit compatible with NFC (Near Field Communication). Note that if a smartphone is used as the key device 3, Bluetooth (registered trademark) can be used for communication between the electric lock 2 and the key device 3. Furthermore, if a USB memory is used as the key device 3, communication between the electric lock 2 and the key device 3 will be via USB (Universal Serial Bus).
[0022] The locking mechanism 22 is a mechanism for locking and unlocking doors, etc. Since the invention disclosed in this application relates to the issuance of the electronic key 10, the locking mechanism 22 may have any structure. For example, the locking mechanism 22 is a mechanism that uses a motor to operate a deadbolt that acts as a latch to lock the locking mechanism 22.
[0023] The NVM 201 of the electric lock 2 is an electrically rewritable non-volatile memory. The NVM 201 of the electric lock 2 stores electric lock identification information 21. The electric lock identification information 21 is information for identifying the electric lock 2. In this application, the electric lock identification information 21 includes an administrator code, a sharing attribute, and a serial number. The administrator code is information indicating the administrator of the electric lock 2, for example, information indicating the installer of the electric lock 2. The sharing attribute is information indicating whether sharing of the electronic key 10 is permitted. For an electric lock 2 that is permitted to share the electronic key 10 with other electric locks 2, information permitting sharing of the electronic key 10 is written in the sharing attribute. For an electric lock 2 that is not permitted to share the electronic key 10 with other electric locks 2, information not permitting sharing of the electronic key 10 is written in the sharing attribute. The serial number is information unique to each electric lock 2.
[0024] Furthermore, when the electronic key 10 is issued, the same electronic key 10 as that of the key device 3 is stored in the NVM 201 of the electric lock 2. If sharing of the electronic key 10 is not permitted, a unique key, which is an electronic key 10 unique to the electric lock 2, is stored in the NVM 201 of the electric lock 2. If sharing of the electronic key 10 is permitted, a shared key, which is an electronic key 10 that is permitted to be shared with other electric locks 2, is stored in the NVM 201 of the electric lock 2.
[0025] The processor 200 is an integrated circuit capable of executing a computer program. The electric lock 2 includes a lock issuing unit 20 as a function realized by a computer program that operates the processor 200. The operation of the lock issuing unit 20 included in the electric lock 2 will be described in detail later, but here, the operation of the lock issuing unit 20 will be briefly described. When an instruction to issue an electronic key 10 is given, the lock issuing unit 20 of the electric lock 2 requests the key device 3 to determine the issue type of the electronic key 10. The issue type is information indicating the type of electronic key 10 to be issued, and is either information indicating the issuance of a unique key that is unique to the electric lock 2, or information indicating the issuance of a shared key that is permitted to be shared with other electric locks 2. When a unique key is issued, the electric lock 2 is the entity that issues the electronic key 10, and the lock issuing unit 20 of the electric lock 2 generates a unique key that is unique to the electric lock 2, stores the unique key in the NVM 201 of the electric lock 2, and transmits the unique key to the key device 3. When issuing a shared key, the entity that issues the electronic key 10 is the key device 3, and the lock side issuing unit 20 of the electric lock 2 causes the key device 3 to generate a shared key and stores the generated shared key in the NVM 201 of the electric lock 2.
[0026] Next, the key device 3 will be described. Figure 1 shows an example of a block diagram of the key device 3. The key device 3 includes a processor 300, an NVM 301, and a communication interface 302. Figure 1 shows only the elements necessary for explaining the electronic key issuing system 1. Naturally, the key device 3 also includes elements that are necessary for functioning as the key device 3 and are not shown in Figure 1. For example, elements not shown in Figure 1 include RAM, which serves as the main memory used by the processor 300, and a power generation circuit that supplies power to the key device 3.
[0027] The communication interface 302 is an interface used for communication with the electric lock 2. The key device 3 is equipped with a communication interface 302 compatible with the electric lock 2. In this embodiment, a contactless IC card is used as the key device 3, so the communication interface 302 equipped in the key device 3 is an NFC-compatible circuit.
[0028] The NVM 301 of the key device 3 is an electrically rewritable non-volatile memory. The NVM 301 of the key device 3 stores device identification information 31. The device identification information 31 is information for identifying the device. In this application, the device identification information 31 includes an administrator code and a serial number. The administrator code is information indicating the administrator of the key device 3, for example, information indicating the issuer of the key device 3. The serial number is information unique to each key device 3, for example, information indicating the owner of the key device 3.
[0029] Furthermore, when the electronic key 10 is issued, the electronic key 10 shared with the electric lock 2 is stored in the NVM 301 of the key device 3. If the electronic key 10 is made unique in the electric lock 2, a unique key unique to the electric lock 2 is stored in the NVM 301 of the key device 3. If the electronic key 10 is shared with another electric lock 2, a shared key shared with the other electric lock 2 is stored in the NVM 301 of the key device 3.
[0030] The processor 300 is an integrated circuit having the function of executing a computer program. The key device 3 has a device-side issuing unit 30 as a function realized by a computer program that operates the processor 300. The detailed operation of the device-side issuing unit 30 of the key device 3 will be described later, but here, the operation of the device-side issuing unit 30 will be briefly described. After the electric lock 2 transmits the electric lock identification information 21, when the electric lock 2 requests the device to determine the issuance type, the device-side issuing unit 30 determines the issuance type by referring to the electric lock identification information 21 obtained from the electric lock 2. When a unique key that is unique to the electric lock 2 is issued, the entity that issues the unique key is the electric lock 2. The device-side issuing unit 30 of the key device 3 causes the electric lock 2 to generate a unique key and stores the unique key generated by the electric lock 2 in the NVM 301 of the key device 3. When a shared key to be shared by multiple electric locks 2 is issued, the entity that issues the shared key is the key device 3. The device-side issuing unit 30 of the key device 3 generates a shared key based on the electric lock identification information 21, stores the shared key in the NVM 301 of the electric lock 2, and transmits the shared key to the electric lock 2.
[0031] 2 to 4, the processing executed by the electronic key issuing system 1 will be described in detail. The description of the processing executed by the electronic key issuing system 1 also includes a description of the electronic key issuing method, which is an invention related to the method of the present application.
[0032] FIG. 2 is a diagram illustrating the procedure for issuing an electronic key 10. When an instruction to issue an electronic key 10 is given to the electric lock 2 (step S1), the lock-side issuing unit 20 of the electric lock 2 starts the process of issuing the electric key 2. The specific content of the instruction to issue the electronic key 10 may be arbitrary. For example, the instruction to issue the electronic key 10 may be given by operating a predetermined operation button provided on the electric lock 2. Furthermore, if the electric lock 2 is connected to a network, the instruction to issue the electronic key 10 can be remotely transmitted to the electric lock 2 from a predetermined server.
[0033] The lock issuing unit 20 of the electric lock 2, which has received an instruction to issue the electronic key 10, activates the key device 3 (step S2). In this embodiment, a contactless IC card is used for the key device 3. Since the key device 3 is a contactless IC card and does not have a power source, the communication interface of the electric lock 2 transmits a carrier wave from the contactless IC card, and the key device 3 converts the received carrier wave into power to activate it. When the key device 3 receives the carrier wave emitted by the electric lock 2 and activates, it transmits an initial response to the electric lock 2, which is output when the key device 3 is activated (step S3). Note that since this is a general-purpose technology, detailed explanation will be omitted here, but once the key device 3 sends the initial response, it is desirable for the electric lock 2 to establish a secure channel with the key device 3 to encrypt the communication content.
[0034] The lock-side issuing unit 20 of the electric lock 2 exchanges the electric lock identification information 21 stored in the electric lock 2 with the device identification information 31 stored in the key device 3 (step S4). In this process, the electric lock 2 transmits the electric lock identification information 21 stored in the electric lock 2 to the key device 3. The electric lock 2 also transmits a command to the key device 3 to read the device identification information 31 stored in the key device 3, and acquires the device identification information 31 from the key device 3.
[0035] The lock issuing unit 20 of the electric lock 2 uses the device identification information 31 acquired from the key device 3 to confirm whether the key device 3 is authorized to issue the electronic key 10 (step S5). For example, by confirming whether the administrator code included in the device identification information 31 is an administrator code authorized to issue the electronic key 10, it is possible to confirm whether the key device 3 is authorized to issue the electronic key 10. In addition, it may be possible to confirm whether the serial number included in the device identification information 31 is a serial number authorized to issue the electronic key 10. Here, the key device 3 is a key device 3 authorized to issue the electronic key 10.
[0036] After the information exchange with the key device 3 is completed, the electric lock 2 requests the key device 3 to determine the issue type of the electronic key 10 (step S6). When the electric lock 2 requests the determination of the issue type, the device-side issuing unit 30 of the key device 3 determines the issue type of the electronic key 10 by referring to the electric lock identification information 21 sent from the electric lock 2 in step S4 of FIG. 2 (step S7).
[0037] The issuance type of the electronic key 10 is determined using the shared attribute included in the electric lock identification information 21 sent from the electric lock 2. If the shared attribute allows sharing of the electronic key 10, the device-side issuance unit 30 of the key device 3 determines that the issuance type of the electronic key 10 is to be a shared key. If the shared attribute does not allow sharing of the electronic key 10, the device-side issuance unit 30 of the key device 3 determines that the issuance type of the electronic key 10 is to be a unique key.
[0038] When the device-side issuing unit 30 of the key device 3 determines the issue type of the electronic key 10, it transmits the determination result of the issue type of the electronic key 10 to the electric lock 2 (step S8). The lock-side issuing unit 20 of the electric lock 2 branches the process depending on the determination result of the issue type of the electronic key 10 (step S9). If the determination result of the issue type of the electronic key 10 indicates that a unique key should be issued, the lock-side issuing unit 20 of the electric lock 2 executes a unique key issuing procedure to issue a unique key (step S10), and the procedure in Fig. 2 ends. On the other hand, if the determination result of the issue type of the electronic key 10 indicates that a shared key should be issued, the lock-side issuing unit 20 of the electric lock 2 executes a shared key issuing procedure to issue a shared key (step S11), and the procedure in Fig. 2 ends.
[0039] The unique key issuing procedure will be described with reference to Figure 3. Figure 3 is a diagram illustrating the unique key issuing procedure. In the unique key issuing procedure, the entity that issues the unique key is the electric lock 2. In the unique key issuing procedure, the lock-side issuing unit 20 of the electric lock 2 generates a unique key that is unique to the electric lock 2 and difficult to regenerate (step S20). Any algorithm can be used to generate the unique key, but for example, if the unique key is a hash value of data obtained by adding a random number value generated by the electric lock 2 to the electric lock identification information 21, it is possible to generate a unique key that is unique to the electric lock 2 and difficult to regenerate. After generating the unique key, the electric lock 2 stores the unique key in the NVM 201 of the electric lock 2 (step S21), and then transmits the unique key to the key device 3 (step S22). The device-side issuing unit 30 of the key device 3 stores the unique key in the NVM 301 of the key device 3 while associating it with the electric lock identification information 21 (step S23), and then sends information indicating that the unique key has been stored to the electric lock 2 (step S24), and the procedure in Figure 3 ends.
[0040] The shared key issuance procedure will be described with reference to FIG. 4. FIG. 4 is a diagram illustrating the shared key issuance procedure. In the key issuance procedure, the entity that issues the shared key is the key device 3, not the electric lock 2. In the shared key issuance procedure, the lock-side issuance unit 20 of the electric lock 2 sends a shared key issuance request to the key device 3 (step S30). The device-side issuance unit 30 of the key device 3 checks whether the shared key corresponding to the electric lock 2 is already stored in the NVM, and branches the processing based on the check result (step S31). For this, the electric lock identification information 21 received from the electric lock 2 in step S4 of FIG. 2 is used. The device-side issuance unit 30 of the key device 3 searches the NVM 301 for the shared key to which the administrator code included in the electric lock identification information 21 received from the electric lock 2 in step S4 of FIG. 2 has been added. If this shared key is found, it is determined that the shared key corresponding to the electric lock 2 is already stored in the NVM 301. If this shared key cannot be found, it is determined that the shared key corresponding to electric lock 2 is not stored in NVM 301.
[0041] If it is determined that the shared key corresponding to the electric lock 2 is stored in the NVM 301, the device-side issuing unit 30 of the key device 3 transmits the shared key retrieved from the NVM 301 to the electric lock 2 (step S32). The lock-side issuing unit 20 of the electric lock 2 stores the shared key received from the key device 3 in the NVM 201 of the electric lock 2 (step S36), and the procedure in FIG. 4 ends.
[0042] If it is determined that the shared key corresponding to the electric lock 2 is not stored in the NVM 301, the device-side issuing unit 30 of the key device 3 generates a common key that is difficult to regenerate from the shared key corresponding to the electric lock 2 (step S33). The shared key is generated using at least the administrator code included in the electric lock identification information 21 as a seed. This is because the administrator code will be the same for multiple electric locks 2 that share a shared key. For example, if the hash value of data obtained by adding a random number value generated by the key device 3 to the administrator code is used as the shared key, a common key that is difficult to regenerate can be generated.
[0043] Once the shared key is generated, the device-side issuing unit 30 of the key device 3 stores the shared key in the NVM 301 of the key device 3 in association with the administrator code included in the electric lock identification information 21 (step S34). Once the shared key is stored in the NVM 301 of the key device 3, the device-side issuing unit 30 of the key device 3 transmits the shared key to the electric lock 2 (step S35). The lock-side issuing unit 20 of the electric lock 2 stores the shared key received from the key device 3 in the NVM 201 of the electric lock 2 (step S36), and the procedure in FIG. 4 ends.
[0044] Finally, the operation when unlocking the locking mechanism 22 of the electric lock 2 will be described with reference to Fig. 5. Fig. 5 is a diagram illustrating the procedure for unlocking the locking mechanism 22 of the electric lock 2. When unlocking the locking mechanism 22 of the electric lock 2, the electric lock 2 activates the key device 3, and the key device 3 outputs an initial response. These procedures are the same as steps S2 to S3 in Fig. 2, so a detailed description will be omitted here.
[0045] The electric lock 2 sends a request to the key device 3 for authentication information required to unlock the lock mechanism 22 (step S40). The request for authentication information includes a random number value of a predetermined length generated by the electric lock 2. The key device 3 uses the electronic key 10 stored in the key device 3 to generate authentication information from the random number value included in the request for authentication information (step S41). Here, the electronic key 10 is used as an encryption key to encrypt the random number value included in the request for authentication information, and the encrypted value is used as the authentication information.
[0046] The key device 3 transmits the authentication information to the electric lock 2 (step S42). The electric lock 2 authenticates the authentication information received from the key device 3 using the electronic key 10 stored in the NVM of the electric lock 2 (step S43). When authenticating the authentication information, the electric lock 2 performs the reverse procedure of the procedure for generating the authentication information, using the electronic key 10 stored in the NVM 201 of the electric lock 2. When generating the authentication information by encryption, the electric lock 2 decrypts the authentication information using the electronic key 10 stored in the NVM 201 of the electric lock 2, and authenticates the authentication information based on whether the result of decrypting the authentication information matches the random number transmitted to the key device 3. If the decrypted value of the authentication information received from the key device 3 matches the random number transmitted to the key device 3, the electric lock 2 determines that the authentication of the authentication information has been successful. If the decrypted value of the authentication information received from the key device 3 does not match the random number transmitted by the key device 3, the electric lock 2 determines that the authentication of the authentication information has failed. The electric lock 2 branches the process depending on the authentication result of the authentication information (step S44). If the authentication of the authentication information is successful, the electric lock 2 unlocks the locking mechanism 22 (step S45), and the procedure in Fig. 5 ends. If a predetermined condition (for example, a predetermined time has passed since unlocking) is met, the electric lock 2 locks the locking mechanism 22. If the authentication of the authentication information fails, the electric lock 2 does not unlock the locking mechanism 22, and the procedure in Fig. 5 ends. [Explanation of symbols]
[0047] 1. Electronic Key Issuance System 2. Electric lock 20 Lock side issuing department 21 Electric lock identification information 3 Key Devices 30 Device side issuing department 31 Device Identification Information
Claims
1. An electronic key issuing method executed by an electric lock and a key device, comprising: a step a) in which the electric lock transmits electric lock identification information, which is information for identifying the electric lock, to the key device, and then requests the key device to determine the type of electronic key to be issued; a step b in which the key device determines the issue type by referring to the electric lock identification information; a step c) of executing a step when the determination result of the issuance type in step b is the issuance of a shared key, which is an electronic key that is permitted to be shared, in which the key device generates and stores the shared key based on the electric lock identification information and stores the shared key in the electric lock; a step d, which is executed when the determination result of the issuance type in the step b indicates the issuance of a unique key, which is an electronic key that is not permitted to be shared, in which the key device requests the electric lock to issue the unique key, and the electric lock generates the unique key based on the electric lock identification information and stores the unique key in the key device; 10. A method for issuing an electronic key, comprising the steps of:
2. A system including an electric lock and a key device, The electric lock transmits electric lock identification information, which is information for identifying the electric lock, to the key device, and then requests the key device to determine the type of electronic key to be issued. When a shared key, which is an electronic key that is permitted to be shared, is transmitted from the key device, the electric lock stores the shared key transmitted from the key device. When a request for issuance of a unique key, which is an electronic key that is not permitted to be shared, is transmitted from the key device, the electric lock includes a lock-side issuing unit that generates and stores the unique key based on the electric lock identification information and stores the unique key in the key device. The key device includes a device-side issuing unit that, when requested by the electric lock to determine the issuance type, determines the issuance type by referring to the electric lock identification information, and when it determines that the shared key should be issued, generates and stores the shared key based on the electric lock identification information and stores the shared key in the electric lock, and when it determines that the unique key should be issued, requests the electric lock to issue the unique key and stores the unique key transmitted from the electric lock. An electronic key issuing system.
3. A device used to open an electric lock, and a device-side issuing unit that, when electric lock identification information that identifies the electric lock is transmitted from the electric lock and the electric lock requests the determination of an issuance type of an electronic key, determines the issuance type by referring to the electric lock identification information, and when it determines that a shared key, which is an electronic key that is permitted to be shared, is to be issued, generates and stores the shared key based on the electric lock identification information and stores the shared key in the electric lock, and when it determines that a unique key, which is an electronic key that is not permitted to be shared, is to be issued, requests the electric lock to issue the unique key and stores the unique key transmitted from the electric lock. A key device characterized by:
4. An electric lock that uses a key device to at least manage the unlocking of a lock mechanism, The key device includes a lock-side issuing unit that transmits electric lock identification information, which is information for identifying the electric lock, to the key device, then causes the key device to determine the type of electronic key to be issued, and when a shared key, which is an electronic key that is permitted to be shared, is transmitted from the key device, stores the shared key transmitted from the key device, and when a request for issuance of a unique key, which is an electronic key that is not permitted to be shared, is received from the key device, generates and stores the unique key based on the electric lock identification information and stores the unique key in the key device. An electric lock characterized by:
Citation Information
Patent Citations
Digital key issuing method and program
JP2023065083A