Public key pinning without pre-shared secret

By using public key pinning to dynamically generate symmetric secret keys from ephemeral keypairs, the system addresses the security vulnerabilities of static key management in access control systems, ensuring secure and unique communication channels for each session.

WO2025108533A1PCT designated stage expired Publication Date: 2025-05-30ASSA ABLOY AB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2023/082366
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-20
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing access control systems rely on static symmetric secret keys for secure communication, which are prone to security breaches if leaked, as they do not dynamically generate keys for each session.

Method used

The system employs public key pinning to dynamically generate symmetric secret keys using ephemeral keypairs, eliminating the need for pre-shared secrets and reducing the risk of key leakage.

Benefits of technology

This approach enhances the security of communication between devices by ensuring that each session has unique, dynamically generated keys, thereby mitigating the risks associated with static key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2023082366_30052025_PF_FP_ABST
    Figure EP2023082366_30052025_PF_FP_ABST
Patent Text Reader

Abstract

Methods and systems are provided for performing asymmetric public key pinning authentication without a pre-shared secret. The methods and systems store, by a first device, a second identifier of a second device and a second public key of the second device and generate, by the first device, a first ephemeral keypair comprising a first ephemeral public key and a first ephemeral private key. The methods and systems transmit, by the first device to the second device, a first identifier of the first device and the first ephemeral public key and receive, by the first device from the second device, a second ephemeral public key of a second ephemeral keypair that has been generated by the second device. The methods and systems compute, by the first device, a symmetric secret key based on the first and second ephemeral keypairs.
Need to check novelty before this filing date? Find Prior Art

Description

PUBLIC KEY PINNING WITHOUT PRE-SHARED SECRETBACKGROUND

[0001] Access control readers are widely used in various settings to control access to restricted areas. These readers are typically connected to a server that manages access control policies and configurations. In order to securely communicate with such readers, user devices employ various encryption protocols.SUMMARY

[0002] In some aspects, the techniques described herein relate to a method including: storing, by a first device, a second identifier of a second device and a second public key of the second device; generating, by the first device, a first ephemeral keypair including a first ephemeral public key and a first ephemeral private key; transmitting, by the first device to the second device, a first identifier of the first device and the first ephemeral public key; receiving, by the first device from the second device, a second ephemeral public key of a second ephemeral keypair that has been generated by the second device; and computing, by the first device, a symmetric secret key based on the first and second ephemeral keypairs.

[0003] In some cases, the symmetric secret key is optionally also computed based on a device key (e.g., static key, private key, or public key) of the first device and a device key (e.g., static key, private key, or public key) of the second device. For example, the symmetric secret key can be computed by the first device based on a first ephemeral private key, the second ephemeral public key, a first private key of the first device, and the second public key of the second device. For example, the symmetric secret key can be computed by the second device based on a second ephemeral private key (corresponding to the second ephemeral keypair), the first ephemeral public key (corresponding to the first ephemeral keypair), a second private key of the second device, and a first public key of the first device.

[0004] In some aspects, the techniques described herein relate to a method, further including: establishing a secure communication channel between the first device and the second device using the symmetric secret key.

[0005] In some aspects, the techniques described herein relate to a method, further including: storing, by the second device, the first identifier of the first device and the first public key of the first device.

[0006] In some aspects, the techniques described herein relate to a method, wherein the first identifier and the first public key are stored by the second device during device personalization and prior to generating the first ephemeral key.

[0007] In some aspects, the techniques described herein relate to a method, wherein the second identifier and the second public key are stored by the first device during the device personalization and prior to generating the first ephemeral key.

[0008] In some aspects, the techniques described herein relate to a method, further including: in response to receiving, by the second device, the first identifier of the first device, searching, by the second device, a table to find the first public key that is associated with the first identifier.

[0009] In some aspects, the techniques described herein relate to a method, further including: generating, by the second device, the second ephemeral keypair including the second ephemeral public key and a second ephemeral private key; and in response to receiving the first identifier of the first device, computing, by the second device, the symmetric secret key based on the first and second ephemeral key pairs.

[0010] In some aspects, the techniques described herein relate to a method, further including: transmitting, by the second device to the first device, the second ephemeral public key along with the second identifier of the second device.

[0011] In some aspects, the techniques described herein relate to a method, further including: in response to receiving, by the first device, the second identifier of the second device, searching, by the first device, a table to find the second public key that is associated with the second identifier; and computing, by the first device, the symmetric secret key in response to retrieving the second public key that is associated with the second identifier from the table.

[0012] In some aspects, the techniques described herein relate to a method, wherein the symmetric secret key is computed by the second device based on the second ephemeral private key, the first ephemeral public key, a first public key of the first device, and the second private key of the second device.

[0013] In some aspects, the techniques described herein relate to a method, further including computing a signature by the second device using the second private key, the signature being computed over the second identifier, the second ephemeral public key, and a set of data received from the first device, the set of data having been received by the second device from the first device in an individual message including the first ephemeral public key and the first identifier.

[0014] In some aspects, the techniques described herein relate to a method, wherein the set of data includes at least one of an access credential request or a data request.

[0015] In some aspects, the techniques described herein relate to a method, wherein the message including the second public ephemeral key includes a response of the second device to the set of data.

[0016] In some aspects, the techniques described herein relate to a method, further including: signing a message by the first device using the first device private key computed over the first identifier, the first ephemeral public key, and the second ephemeral public key.

[0017] In some aspects, the techniques described herein relate to a method, wherein the symmetric secret key is dynamically computed for each new session and for each new ephemeral key that is generated.

[0018] In some aspects, the techniques described herein relate to a method, wherein the second device includes a user device; and wherein the first device includes an access control reader.

[0019] In some aspects, the techniques described herein relate to a method, further including: controlling, by the first device, access to a protected resource based on a message including a credential received from the second device using the symmetric secret key.BRIEF DESCRIPTION OF THE DRAWINGS

[0020] FIG. l is a block diagram of an example access control system, according to some examples.

[0021] FIG. 2 illustrates an example public key table, according to some examples.

[0022] FIG. 3 illustrates an example message structure, according to some examples.

[0023] FIG. 4 illustrates an example message structure, according to some examples.

[0024] FIG. 5 is a flowchart illustrating example operations of the access control system, according to some examples.

[0025] FIG. 6 is a block diagram illustrating an example software architecture, which may be used in conjunction with various hardware architectures herein described.

[0026] FIG. 7 is a block diagram illustrating components of a machine, according to some examples.DETAILED DESCRIPTION

[0027] Typically, access control readers (or various devices) can enable access to various protected physical or logical assets or information using an exchanged access credential. For example, a user device can store the credential and can transmit that credential to another device, such as an access control reader. In some cases, the devices can first establish a secure communication session or channel prior to (or as part of) exchanging credentials and / or other private or sensitive information. One way of establishing such a secure channel is by performing device personalization operations in which a symmetric secret key is generated and stored by each device. This way, when the devices need to communicate with each other at a different time, the devices can identify themselves and retrieve the previously established static symmetric secret key. While these approaches generally work, communicating securely with a secret key that is static is prone to some security breaches. Namely, if the secret key is leaked by any of the devices, messages exchanged between the devices can be decrypted by an unauthorized device / party.

[0028] The present disclosure provides a mechanism to dynamically generate secret keys for use in establishing a secure channel between devices in a more secure and efficient manner. Specifically, according to the disclosed techniques, a secure version of an asymmetric one sided and mutual authentication is held between an initiator device (e.g., a first device) and a responder device (e.g., second device) using public key pinning. The public key pinning is then used to dynamically generate new secret keys for a secure channel based on ephemeral keys that are generated by the devices. Namely, the first and second devices know each other’s public key and use that information to base generation of the secret key on the fly. Custom data can also be exchanged, such as an access credential, which can be used for physical access control systems (PACS).According to the disclosed techniques, there is no need to store pre-calculated secrets that can leak. Also, the device public keys are not exchanged during the authentication, which reduces possible attacks.

[0029] In particular, the disclosed techniques store, by a first device, a second identifier of a second device and a second public key of the second device and generate, by the first device, a first ephemeral keypair comprising a first ephemeral public key and a first ephemeral private key. The disclosed techniques transmit, by the first device to the second device, a first identifier of the first device and the first ephemeral public key and receive, by the first device from the second device, a second identifier of the second device and the second ephemeral public key of a second ephemeral keypair that has been generated by the second device. The disclosed techniques compute, by the first device, a symmetric secret key based on the first and second ephemeral keypairs.

[0030] The symmetric secret key can be used to exchange encrypted messages in an encrypted and secure communication channel between the first and second devices. After the secure channel is closed, a new symmetric secret key can be computed based on a newly generated ephemeral key in a similar manner. This substantially improves the security of communicating messages between devices in an efficient manner. The disclosed examples refer to access readers as particular types of access control devices, but the disclosed examples apply to any type of access control device.

[0031] FIG. 1 is a block diagram showing an example system 100, according to various examples. The system 100 can be an access control system that includes a client device 120, one or more access control devices 110 that control access to a protected asset or secure resource (e.g., a physical or logic resource), such as through a lockable door, and a server / controller 140 that are communicatively coupled over a network 130 (e.g., LAN, WAN such as the Internet, WiFi, BLE, ultra-wideband (UWB) communication protocol, telephony network, or other wired or wireless communication protocols).

[0032] The client device 120 and the access control devices 110 can be communicatively coupled via electronic messages (e.g., packets exchanged over the Internet, BLE, UWB, WiFi Direct, NFC, or any other protocol). While FIG. 1 illustrates a single access control device 110 and a single client device 120, it is understood that a plurality of access control devices 110 and a plurality of client devices 120 can be included in the system 100 in other examples. As used herein, the term “client device”may refer to any machine that interfaces to a communications network (such as network 130) to exchange credentials with an access control device 110 (or vice versa), the server / controller 140, another client device 120, or any other component to obtain access to the asset or resource protected by the access control device 110. In some examples, the client device 120 can additionally or alternatively communicate directly with, e.g., an access control device or another client device 120.

[0033] In some cases, some or all of the components and functionality of the server / controller 140 can be included in the client device 120 and / or the access control device 110. A client device 120 may be, but is not limited to, a mobile phone, desktop computer, laptop, portable digital assistant (PDA), smart phone, a wearable device (e.g., a smart watch), tablet, ultrabook, netbook, multi-processor system, microprocessor-based or programmable consumer electronics, or any other communication device that a user may use to access a network.

[0034] The access control device 110 can include an access reader device (also referred to as an “access control reader” or “reader”) connected to a secure / protected resource (e.g., a door locking mechanism or backend server) that controls the secure / protected resource (e.g., door locking mechanism). The resource associated with the access control device 110 can include a door lock, an ignition system for a vehicle, or any other device that grants or denies access to a physical component or that can be operated to grant or deny access to the physical component. For example, in the case of a door lock, the access control device 110 can deny access, in which case the door lock remains locked and the door cannot be opened; or can grant access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, the access control device 110 can deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or can grant access, in which case the vehicle ignition becomes enabled to allow the vehicle to be started.

[0035] Physical access control covers a range of systems and methods to govern access, for example by people, to secure areas or secure assets. Physical access control includes identification of authorized users or devices (e.g., vehicles, drones, etc.) and actuation of a gate, door, or other facility used to secure an area or actuation of a control mechanism, e.g., a physical or electronic / software control mechanism, permitting access to a secure asset. The access control device 110 forms part of a PACS, which can include a reader(e.g., an online or offline reader) that may hold authorization data (also referred to as access control information) and can be capable of determining whether credentials (e.g., from credential or key devices such as radio frequency identification (RFID) chips in cards, fobs, or personal electronic devices such as mobile phones) are authorized for an actuator or control mechanism (e.g., door lock, door opener, software control mechanism, turning off an alarm, etc.), or a PACS can include a host server to which readers and actuators are connected (e.g., via a controller) in a centrally managed configuration.

[0036] In centrally managed configurations, readers can obtain credentials from credential or key devices and pass those credentials to the PACS host server or headend system. The host server then determines whether the credentials authorize access to the secure area or secure asset and commands the actuator or other control mechanism accordingly by sending an allow / deny message back to the reader over the wired or wireless link. While examples in physical access control are used herein, the disclosure applies equally to logical access control system (LACS) use cases (e.g., logical access to personal electronic devices, rider identification in transport services, access and asset control in unmanned stores, files stored securely on a storage device, etc.).

[0037] In general, the access control device 110 can include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, and a power source or supply. The memory of the access control device 110 can be used in connection with the execution of application programming or instructions by the processor of the access control device 110, and for the temporary or long-term storage of program instructions or instruction sets and / or credential or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory can contain executable instructions that are used by the processor to run other components of access control device 110 and / or to make access determinations based on credential or authorization data.

[0038] The memory of the access control device 110 can include a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with access control device 110. The computer readable medium can be, for example, but is not limited to, an electronic,magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non- transitory, or similar examples of computer-readable media.

[0039] The processor of the access control device 110 can correspond to one or more computer processing devices or resources. For instance, the processor can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, the processor can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory and / or memory of the access control device 110.

[0040] The antenna of the access control device 110 can correspond to one or multiple antennas and can be configured to provide for wireless communications between access control device 110 and a credential or key device (e.g., client device 120). The antenna can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, BLE, NFC, ZigBee, Global System for Mobile communications (GSM), Code Division Multiple Access (CDMA), Wi-Fi, RF, UWB, and the like. By way of example, the antenna(s) can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by a credential or key device having an RF transceiver.

[0041] A communication module of the access control device 110 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to access control device 110, such as one or more client devices 120 and / or server / controller 140. In some cases, thecommunication module of the access control device 110 is configured to perform the disclosed credential exchange and additional data exchange efficiently. Namely, the communication module can be implemented as part of the access control device 110 and / or the client device 120 to perform the authentication protocol, discussed in connection with FIGS. 2-5.

[0042] The network interface device of the access control device 110 includes hardware to facilitate communications with other devices, such as a one or more client devices 120 and / or server / controller 140 (e.g., a PACS server), over a communication network, such as network 130, utilizing any one of a number of transfer protocols (e.g., frame relay, IP, transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a LAN, a WAN, a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 802.11 family of standards known as Wi-Fi, IEEE 802.16 family of standards known as WiMax), IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.

[0043] A user interface of the access control device 110 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in the user interface include, without limitation, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, and so forth. Examples of suitable user output devices that can be included in the user interface include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, and so forth. It should be appreciated that the user interface can also include a combined user input and user output device, such as a touch-sensitive display or the like.

[0044] The network 130 may include, or operate in conjunction with, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a LAN, a wirelessnetwork, a wireless LAN (WLAN), a WAN, a wireless WAN (WWAN), a metropolitan area network (MAN), BLE, UWB, the Internet, a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless or cellular network and the coupling may be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling may implement any of a variety of types of data transfer technology, such as Single Carrier Radio Transmission Technology (IxRTT), Evolution- Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, third Generation Partnership Project (3 GPP) including 3G, fourth generation wireless (4G) networks, fifth generation wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standard, others defined by various standard setting organizations, other short range or long range protocols, or other data transfer technology.

[0045] In some examples, as the client device 120 approaches the access control device 110 (e.g., comes within range of a BLE communication protocol), the client device 120 transmits credentials of the client device 120 over the network 130, such as by using the certificate associated with the access control device 110. In some cases, the credentials can be selected from a plurality of credentials based on a current geographical location of the client device 120. For example, multiple credentials, each associated with a different geographical location, can be stored on the client device 120. When the client device 120 comes within a certain distance of a geographical location associated with one of the credentials (e.g., within 10 meters), the client device 120 retrieves the associated credentials from local memory.

[0046] In some examples, the client device 120 provides the credentials directly to the access control device 110. In such cases, the access control device 110 communicates the credentials with the server / controller 140. The server / controller 140 in FIG. 1 includes an authentication system 142. The server / controller 140, client device 120, and / or the access control device 110 can further include elements described with respect to FIGS. 6and 7, such as a processor and memory, having instructions stored thereon, that when executed by the processor, causes the processor to control the functions of the server / controller 140, client device 120, and / or the access control device 110.

[0047] The server / controller 140 searches a list of credentials stored in the authentication system 142 to determine whether the received credentials match credentials from the list of authorized credentials for accessing a secure asset or resource (e.g., door or secure area) protected by the access control device 110. In response to determining that the received credentials are authorized to access the access control device 110, the server / controller 140 instructs the access control device 110 to perform an operation granting access for the client device 120 (e.g., instructing the access control device 110 to unlock a lock of a door). In some cases, the server / controller 140 can verify a signature of a credential received from the client device 120 and access is granted if the signature is successfully verified.

[0048] In some examples, the credential can be exchanged through a secure channel after the controller 140 and the client device 120 engage in an authentication protocol. In some cases, the controller 140 and the client device 120 perform a set of device personalization operations. During these device personalization operations, the controller 140 and the client device 120 exchange various information to allow the devices to identify each other in subsequent communications. For example, the controller 140 can transmit an identifier of the controller 140 along with a static public key associated with the controller 140. The client device 120 can receive that information and add that information to a public key table 200, shown in FIG. 2.

[0049] Specifically, the client device 120 can add an entry to the public key table 200 in response to receiving the identifier of the controller 140 and the static public key associated with the controller 140. The entry can include the identifier 210 of the controller 140 and the static public key 220 of the controller 140. Other entries in the public key table 200 can include other identifiers of other devices that the client device 120 has previously paired with and the corresponding static public keys of those devices. During personalization, the client device 120 can transmit an identifier of the client device 120 along with a static public key associated with the client device 120. The controller 140 can receive that information and add that information to another public key table 200 instance that is stored and maintained by the controller 140. The publickey table 200 that is maintained by the client device 120 can differ from that which is maintained by the controller 140 because the devices can be paired with different groups of other devices.

[0050] After completing the device personalization operations, each device can store and maintain a respective instance of the public key table 200. The devices may not store secret keys as such keys will be derived and computed when a secure channel needs to be established. For example, the client device 120 can determine a need to communicate securely with the controller 140. This can be performed in response to receiving input from a user requesting to transmit a credential or other secure message to another device that is nearby without knowing the identifier of the nearby device.

[0051] In some examples, in response to determining a need to communicate securely with another device, the controller 140 (or the client device 120, in case client device 120 is the initiator) can generate a set of ephemeral or session keys that include an ephemeral private key that is paired with an ephemeral public key (this is referred to as an ephemeral keypair). In some cases, the set of ephemeral or session keys (the ephemeral keypair) can be generated using a random number generator and / or using a public or private key associated with the controller 140. The controller 140 can then generate a message or packet 300, shown in FIG. 3.

[0052] The packet 300 can include various fields including an identifier 312 of the controller 140 and the ephemeral public key 310 generated by the controller 140. In some cases, the packet 300 includes a set of data 314, such as one or more parameters of a command, mutual authentication information, a request to access a credential, and / or a request to access data from the client device 120. In some cases, the packet 300 can be encrypted using a previously established static key associated with a target device, such as client device 120. The client device 120 can receive the information from the controller 140 in the packet 300 and can now have all the information it needs to generate a symmetric secret key for communicating securely with the controller 140.

[0053] In some cases, the client device 120 can retrieve the identifier 312 from the packet 300. The client device 120 can search the public key table 200 based on the identifier 312 to obtain or find the previously established public key associated with the controller 140. The client device 120 can also, in response to receiving the packet 300, generate a second set of ephemeral or session keys (e.g., another ephemeral keypair) thatinclude another ephemeral private key that is paired with another ephemeral public key. In some cases, the second set of ephemeral or session keys generated by the client device 120 can be different and independent of the set of ephemeral or session keys generated by the controller 140 to start the authentication. In some cases, second set of ephemeral or session keys can be generated by the client device 120 using a random number generator and / or using a public or private key associated with the client device 120 and / or any data included in the packet 300.

[0054] The client device 120 can generate the symmetric secret key by applying a key generation / derivation function to the ephemeral public key 310 received in the packet 300 from the controller 140, the ephemeral private key generated by the client device 120, and optionally the static public key (e.g., the static public key 220) associated with the controller 140 that has been retrieved from the public key table 200, and optionally the static private key associated with the client device 120. The client device 120 can generate a message or packet 401, shown in FIG. 4, based on the symmetric secret key. Any operation that is initiated by or referred to being performed by the controller 140 can in the alternative be initiated by or be performed by the client device 120 and vice versa.

[0055] Generally, as used herein and shown in the drawings, the terms I. ID refers to the initiator identifier (controller 140), R.ePK refers to the responder (e.g., client device 120) ephemeral public key, R.eSK refers to the responder ephemeral private key, R.ID refers to the responder identifier, R.SK refers to the static private key of the responder, I.SK refers to the initiator (e.g., controller 140) static private key, I.PK refers to the initiator static public key, I.ePK refers to the initiator ephemeral public key. In some cases, the client device 120 generates the symmetric secret key in accordance with application of the following function Ks = KDF (I.ePK, R.eSK, [I.PK, R.SK]), where the bracketed items are optional elements of the function. In some cases, the roles are reversed in which case the initiator is the client device 120 and the responder is the controller 140.

[0056] The packet 401 can include various fields, such as the ephemeral public key 420 generated by the client device 120, an identifier 422 of the client device 120, an authentication message 424, and / or various data sets 426 that can be protected. Specifically, the client device 120 can sign the packet 401 using the second privatedevice key of the client device 120. A signature of the packet 401 can be computed over the second identifier of the client device 120, the second ephemeral public key of the client device 120, and a set of data received from the controller 140. The set of data may have been received by the client device 120 from the controller 140 in an individual message including the first ephemeral public key of the controller 140 and the first identifier of the controller 140. The various data sets 426 of the packet 401 can include a response generated by the client device 120 to the set of data 314 received from the controller 140. For example, if the set of data 314 included a request to access a credential, the various data sets 426 can include the credential itself and / or a set of assets protected by the credential.

[0057] The controller 140 can receive the packet 401 from the client device 120 and can now compute the same symmetric secret key using the information contained in the packet 401. For example, the controller 140 can retrieve, from the packet 401, the identifier 422 of the client device 120. The controller 140 can search the public key table 200 (stored by the client device 120) based on the identifier 422 to obtain or find the previously established public key associated with the client device 120. The controller 140 can generate the symmetric secret key by applying a key generation / derivation function (which can correspond to the same key generation / derivation function used by the client device 120 to compute the symmetric secret key) to the ephemeral public key 420 received in the packet 401 from the client device 120, the ephemeral private key generated by the controller 140, and optionally the static public key (e.g., the static public key 220) associated with the client device 120 that has been retrieved from the public key table 200, and / or the static public or private key associated with the controller 140. In some cases, the controller 140 generates the symmetric secret key in accordance with application of the following function Ks = KDF(I.eSK, R.ePK, [I.SK, R.PK]), where the bracketed items are optional elements of the function.

[0058] Now that both the client device 120 and the controller 140 have independently computed and derived the symmetric secret key, the devices can communicate with each other securely over an encrypted channel. For example, the controller 140 can generate and send a message 402 that includes a set of protected data 432 and that is signed or includes an authenticated message 430. Namely, the controller 140 sign the message 402 using the first device private key computed over the first identifier of the controller 140,the first ephemeral public key of the controller 140, and the second ephemeral public key of the client device 120 to generate the authenticated message 430. In response to receiving the message 402, the client device 120 can generate an acknowledgement message 403 that acknowledges authentication and that can include a set of protected data. The set of protected data can be encrypted using the symmetric secret key that has been independently computed and derived by the client device 120 and the controller 140.

[0059] FIG. 5 is a flowchart illustrating an example process or method 500 of the access control system 100, according to some examples. The process or method 500 may be embodied in computer-readable instructions for execution by one or more processors such that the operations of the process or method 500 may be performed in part or in whole by the functional components of the system 100; accordingly, the process or method 500 is described below by way of example with reference thereto. However, in other examples, at least some of the operations of the process or method 500 may be deployed on various other hardware configurations. Some or all of the operations of process or method 500 can be in parallel, out of order, or entirely omitted.

[0060] At operation 501, the server / controller 140 (e.g., a PACS server), the access control device 110, and / or client device 120 (e.g., a first device) stores a second identifier of a second device and a second public key of a different one of the server / controller 140 (e.g., a PACS server), the access control device 110, and / or client device 120 (e.g., a second device), as discussed above.

[0061] At operation 502, the first device generates a first ephemeral keypair comprising a first ephemeral public key and a first ephemeral private key, as discussed above.

[0062] At operation 503, the first device transmits, to the second device, a first identifier of the first device and the first ephemeral public key, as discussed above.

[0063] At operation 504, the first device receives, from the second device, a second ephemeral public key of a second ephemeral keypair that has been generated by the second device, as discussed above.

[0064] At operation 505, the first device computes a symmetric secret key based on the first and second ephemeral keypairs, as discussed above.

[0065] FIG. 6 is a block diagram illustrating an example software architecture 606, which may be used in conjunction with various hardware architectures herein described.FIG. 6 is a non-limiting example of a software architecture and it will be appreciated that many other architectures may be implemented to facilitate the functionality described herein. The software architecture 606 may execute on hardware such as machine 700 of FIG. 7 that includes, among other things, processors 704, memory 714, and input / output (I / O) components 718. A representative hardware layer 652 is illustrated and can represent, for example, the machine 700 of FIG. 7. The representative hardware layer 652 includes a processing unit 654 having associated executable instructions 604. Executable instructions 604 represent the executable instructions of the software architecture 606, including implementation of the methods, components, and so forth described herein. The hardware layer 652 also includes memory and / or storage devices memory / storage 656, which also have executable instructions 604. The hardware layer 652 may also comprise other hardware 658. The software architecture 606 may be deployed in any one or more of the components shown in FIG. 1.

[0066] In the example architecture of FIG. 6, the software architecture 606 may be conceptualized as a stack of layers where each layer provides particular functionality. For example, the software architecture 606 may include layers such as an operating system 602, libraries 620, frameworks / middl eware 618, applications 616, and a presentation layer 614. Operationally, the applications 616 and / or other components within the layers may invoke API calls 608 through the software stack and receive messages 612 in response to the API calls 608. The layers illustrated are representative in nature and not all software architectures have all layers. For example, some mobile or special purpose operating systems may not provide a frameworks / middl eware 618, while others may provide such a layer. Other software architectures may include additional or different layers.

[0067] The operating system 602 may manage hardware resources and provide common services. The operating system 602 may include, for example, a kernel 622, services 624, and drivers 626. The kernel 622 may act as an abstraction layer between the hardware and the other software layers. For example, the kernel 622 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, and so on. The services 624 may provide other common services for the other software layers. The drivers 626 are responsible for controlling or interfacing with the underlying hardware. For instance, the drivers 626include display drivers, camera drivers, BLE drivers, UWB drivers, Bluetooth® drivers, flash memory drivers, serial communication drivers (e.g., Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, and so forth depending on the hardware configuration.

[0068] The libraries 620 provide a common infrastructure that is used by the applications 616 and / or other components and / or layers. The libraries 620 provide functionality that allows other software components to perform tasks in an easier fashion than to interface directly with the underlying operating system 602 functionality (e.g., kernel 622, services 624 and / or drivers 626). The libraries 620 may include system libraries 644 (e.g., C standard library) that may provide functions such as memory allocation functions, string manipulation functions, mathematical functions, and the like. In addition, the libraries 620 may include API libraries 646 such as media libraries (e.g., libraries to support presentation and manipulation of various media format such as MPREG4, H.264, MP3, AAC, AMR, JPG, PNG), graphics libraries (e.g, an OpenGL framework that may be used to render two-dimensional (2D) and three-dimensional (3D) in a graphic content on a display), database libraries (e.g., SQLite that may provide various relational database functions), web libraries (e.g., WebKit that may provide web browsing functionality), and the like. The libraries 620 may also include a wide variety of other libraries 648 to provide many other APIs to the applications 616 and other software components / devices.

[0069] The frameworks / middl eware 618 (also sometimes referred to as middleware) provide a higher-level common infrastructure that may be used by the applications 616 and / or other software components / devices. For example, the frameworks / middleware 618 may provide various graphic user interface functions, high-level resource management, high-level location services, and so forth. The frameworks / middleware 618 may provide a broad spectrum of other APIs that may be utilized by the applications 616 and / or other software components / devices, some of which may be specific to a particular operating system 602 or platform.

[0070] The applications 616 include built-in applications 638 and / or third-party applications 640. Examples of representative built-in applications 638 may include, but are not limited to, a contacts application, a browser application, a book reader application, a location application, a media application, a messaging application, and / ora game application. Third-party applications 640 may include an application developed using the ANDROID™ or IOS™ software development kit (SDK) by an entity other than the vendor of the particular platform and may be mobile software running on a mobile operating system such as IOS™, ANDROID™, WINDOWS® Phone, or other mobile operating systems. The third-party applications 640 may invoke the API calls 608 provided by the mobile operating system (such as operating system 602) to facilitate functionality described herein.

[0071] The applications 616 may use built-in operating system functions (e.g., kernel 622, services 624, and / or drivers 626), libraries 620, and frameworks / middl eware 618 to create user interfaces to interact with users of the system. Alternatively, or additionally, in some systems, interactions with a user may occur through a presentation layer, such as presentation layer 614. In these systems, the application / component "logic" can be separated from the aspects of the application / component that interact with a user.

[0072] FIG. 7 is a block diagram illustrating components of a machine 700, according to some examples, able to read instructions from a machine-readable medium (e.g., a machine-readable storage medium) and perform any one or more of the methodologies discussed herein. Specifically, FIG. 7 shows a diagrammatic representation of the machine 700 in the example form of a computer system, within which instructions 710 (e.g., software, a program, an application, an applet, an app, or other executable code) for causing the machine 700 to perform any one or more of the methodologies discussed herein may be executed.

[0073] As such, the instructions 710 may be used to implement devices or components described herein. The instructions 710 transform the general, non-programmed machine 700 into a particular machine 700, such as the client device 120, access control device 110, or server / controller 140, programmed to carry out the described and illustrated functions in the manner described. In alternative examples, the machine 700 operates as a standalone device or may be coupled (e.g., networked) to other machines. In a networked deployment, the machine 700 may operate in the capacity of a server machine or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine 700 may comprise, but not be limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a set-top box (STB), a PDA, anentertainment media system, a cellular telephone, a smart phone, a mobile device, a wearable device (e.g., a smart watch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of executing the instructions 710, sequentially or otherwise, that specify actions to be taken by machine 700. Further, while only a single machine 700 is illustrated, the term "machine" shall also be taken to include a collection of machines that individually or jointly execute the instructions 710 to perform any one or more of the methodologies discussed herein.

[0074] The machine 700 may include processors 704, memory / storage 706, and I / O components 718, which may be configured to communicate with each other such as via a bus 702. In an example, the processors 704 (e.g., a CPU, a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, a graphics processing unit (GPU), a digital signal processor (DSP), an ASIC, a radiofrequency integrated circuit (RFIC), another processor, or any suitable combination thereof) may include, for example, a processor 708 and a processor 712 that may execute the instructions 710. The term “processor” is intended to include multi-core processors 704 that may comprise two or more independent processors (sometimes referred to as “cores”) that may execute instructions contemporaneously. Although FIG. 7 shows multiple processors 704, the machine 700 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiple cores, or any combination thereof.

[0075] The memory / storage 706 may include a memory 714, such as a main memory, or other memory storage, database, and a storage unit 716, both accessible to the processors 704 such as via the bus 702. The storage unit 716 and memory 714 store the instructions 710 embodying any one or more of the methodologies or functions described herein. The instructions 710 may also reside, completely or partially, within the memory 714, within the storage unit 716, within at least one of the processors 704 (e.g., within the processor’s cache memory), or any suitable combination thereof, during execution thereof by the machine 700. Accordingly, the memory 714, the storage unit 716, and the memory of processors 704 are examples of machine-readable media.

[0076] The I / O components 718 may include a wide variety of components to receive input, provide output, produce output, transmit information, exchange information, capture measurements, and so on. The specific I / O components 718 that are included in a particular machine 700 will depend on the type of machine. For example, portable machines such as mobile phones will likely include a touch input device or other such input mechanisms, while a headless server machine will likely not include such a touch input device. It will be appreciated that the I / O components 718 may include many other components that are not shown in FIG. 7. The I / O components 718 are grouped according to functionality merely for simplifying the following discussion and the grouping is in no way limiting. In various examples, the I / O components 718 may include output components 726 and input components 728. The output components 726 may include visual components (e.g., a display such as a plasma display panel (PDP), a LED display, a LCD, a projector, or a cathode ray tube (CRT)), acoustic components (e.g., speakers), haptic components (e.g., a vibratory motor, resistance mechanisms), other signal generators, and so forth. The input components 728 may include alphanumeric input components (e.g., a keyboard, a touch screen configured to receive alphanumeric input, a photo-optical keyboard, or other alphanumeric input components), point-based input components (e.g., a mouse, a touchpad, a trackball, a joystick, a motion sensor, or other pointing instrument), tactile input components (e.g., a physical button, a touch screen that provides location and / or force of touches or touch gestures, or other tactile input components), audio input components (e.g., a microphone), and the like.

[0077] In further examples, the I / O components 718 may include biometric components 739, motion components 734, environmental components 736, or position components738 among a wide array of other components. For example, the biometric components739 may include components to detect expressions (e.g., hand expressions, facial expressions, vocal expressions, body gestures, or eye tracking), measure biosignals (e.g., blood pressure, heart rate, body temperature, perspiration, or brain waves), identify a person (e.g., voice identification, retinal identification, facial identification, fingerprint identification, or electroencephalogram based identification), and the like. The motion components 734 may include acceleration sensor components (e.g., accelerometer), gravitation sensor components, rotation sensor components (e.g., gyroscope), and so forth. The environmental components 736 may include, for example, illumination sensorcomponents (e.g., photometer), temperature sensor components (e.g., one or more thermometer that detect ambient temperature), humidity sensor components, pressure sensor components (e.g., barometer), acoustic sensor components (e.g., one or more microphones that detect background noise), proximity sensor components (e.g., infrared sensors that detect nearby objects), gas sensors (e.g., gas detection sensors to detection concentrations of hazardous gases for safety or to measure pollutants in the atmosphere), or other components that may provide indications, measurements, or signals corresponding to a surrounding physical environment. The position components 738 may include location sensor components (e.g., a GPS receiver component), altitude sensor components (e.g., altimeters or barometers that detect air pressure from which altitude may be derived), orientation sensor components (e.g., magnetometers), and the like.

[0078] Communication may be implemented using a wide variety of technologies. The I / O components 718 may include communication components 740 operable to couple the machine 700 to a network 737 or devices 729 via coupling 724 and coupling 722, respectively. For example, the communication components 740 may include a network interface component or other suitable device to interface with the network 737. In further examples, communication components 740 may include wired communication components, wireless communication components, cellular communication components, NFC components, Bluetooth® components (e.g., BLE), Wi-Fi® components, and other communication components to provide communication via other modalities. The devices 729 may be another machine or any of a wide variety of peripheral devices (e.g., a peripheral device coupled via a USB).

[0079] Moreover, the communication components 740 may detect identifiers or include components operable to detect identifiers. For example, the communication components 740 may include RFID tag reader components, NFC smart tag detection components, optical reader components (e.g., an optical sensor to detect one-dimensional bar codes such as Universal Product Code (UPC) bar code, multi-dimensional bar codes such as Quick Response (QR) code, Aztec code, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D bar code, and other optical codes), or acoustic detection components (e.g., microphones to identify tagged audio signals). In addition, a variety of information may be derived via the communication components 740, such as location viaIP) geo-location, location via Wi-Fi® signal triangulation, location via detecting a NFC beacon signal that may indicate a particular location, and so forth.Glossary:

[0080] " CARRIER SIGNAL" in this context refers to any intangible medium that is capable of storing, encoding, or carrying transitory or non-transitory instructions for execution by the machine, and includes digital or analog communications signals or other intangible medium to facilitate communication of such instructions. Instructions may be transmitted or received over the network using a transitory or non-transitory transmission medium via a network interface device and using any one of a number of well-known transfer protocols.

[0081] " CLIENT DEVICE" in this context refers to any machine that interfaces to a communications network to obtain resources from one or more server systems or other client devices or that communicates directly with such other devices or server systems. A client device may be, but is not limited to, a mobile phone, desktop computer, laptop, PDA, smart phone, tablet, ultrabook, netbook, multi-processor system, microprocessorbased or programmable consumer electronics, game console, STB, or any other communication device that a user may use to access a network.

[0082] "COMMUNICATIONS NETWORK" in this context refers to one or more portions of a network that may be an ad hoc network, an intranet, an extranet, a VPN, a LAN, a BLE network, a UWB network, a WLAN, a WAN, a WWAN, a MAN, the Internet, a portion of the Internet, a portion of the PSTN, a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless or cellular network and the coupling may be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling may implement any of a variety of types of data transfer technology, such as IxRTT, EVDO technology, GPRS technology, EDGE technology, 3 GPP including 3G, 4G networks, UMTS, HSPA, WiMAX, LTE standard, others defined by various standard setting organizations, other long range protocols, or other data transfer technology.

[0083] "MACHINE -RE AD ABLE MEDIUM" in this context refers to a component, device, or other tangible media able to store instructions and data temporarily or permanently and may include, but is not limited to, RAM, ROM, buffer memory, flash memory, optical media, magnetic media, cache memory, other types of storage (e.g., Erasable Programmable Read-Only Memory (EEPROM)) and / or any suitable combination thereof. The term "machine-readable medium" should be taken to include a single medium or multiple media (e.g., a centralized or distributed database, or associated caches and servers) able to store instructions. The term "machine-readable medium" shall also be taken to include any medium, or combination of multiple media, that is capable of storing instructions (e.g., code) for execution by a machine, such that the instructions, when executed by one or more processors of the machine, cause the machine to perform any one or more of the methodologies described herein. Accordingly, a "machine-readable medium" refers to a single storage apparatus or device, as well as "cloud-based" storage systems or storage networks that include multiple storage apparatus or devices. The term "machine-readable medium" excludes signals per se.

[0084] " COMPONENT" in this context refers to a device, physical entity, or logic having boundaries defined by function or subroutine calls, branch points, APIs, or other technologies that provide for the partitioning or modularization of particular processing or control functions. Components may be combined via their interfaces with other components to carry out a machine process. A component may be a packaged functional hardware unit designed for use with other components and a part of a program that usually performs a particular function of related functions. Components may constitute either software components (e.g., code embodied on a machine-readable medium) or hardware components. A "hardware component" is a tangible unit capable of performing certain operations and may be configured or arranged in a certain physical manner. In various examples, one or more computer systems (e.g., a standalone computer system, a client computer system, or a server computer system) or one or more hardware components of a computer system (e.g., a processor or a group of processors) may be configured by software (e.g., an application or application portion) as a hardware component that operates to perform certain operations as described herein.

[0085] A hardware component may also be implemented mechanically, electronically, or any suitable combination thereof. For example, a hardware component may include dedicated circuitry or logic that is permanently configured to perform certain operations. A hardware component may be a special-purpose processor, such as a FPGA or an ASIC. A hardware component may also include programmable logic or circuitry that is temporarily configured by software to perform certain operations. For example, a hardware component may include software executed by a general-purpose processor or other programmable processor. Once configured by such software, hardware components become specific machines (or specific components of a machine) uniquely tailored to perform the configured functions and are no longer general-purpose processors. It will be appreciated that the decision to implement a hardware component mechanically, in dedicated and permanently configured circuitry, or in temporarily configured circuitry (e.g., configured by software) may be driven by cost and time considerations. Accordingly, the phrase "hardware component"(or "hardware-implemented component") should be understood to encompass a tangible entity, be that an entity that is physically constructed, permanently configured (e.g., hardwired), or temporarily configured (e.g., programmed) to operate in a certain manner or to perform certain operations described herein. Considering examples in which hardware components are temporarily configured (e.g., programmed), each of the hardware components need not be configured or instantiated at any one instance in time. For example, where a hardware component comprises a general-purpose processor configured by software to become a specialpurpose processor, the general-purpose processor may be configured as respectively different special-purpose processors (e.g., comprising different hardware components) at different times. Software accordingly configures a particular processor or processors, for example, to constitute a particular hardware component at one instance of time and to constitute a different hardware component at a different instance of time.

[0086] Hardware components can provide information to, and receive information from, other hardware components. Accordingly, the described hardware components may be regarded as being communicatively coupled. Where multiple hardware components exist contemporaneously, communications may be achieved through signal transmission (e.g., over appropriate circuits and buses) between or among two or more of the hardware components. In examples in which multiple hardware components are configured or instantiated at different times, communications between such hardwarecomponents may be achieved, for example, through the storage and retrieval of information in memory structures to which the multiple hardware components have access. For example, one hardware component may perform an operation and store the output of that operation in a memory device to which it is communicatively coupled. A further hardware component may then, at a later time, access the memory device to retrieve and process the stored output.

[0087] Hardware components may also initiate communications with input or output devices and can operate on a resource (e.g., a collection of information). The various operations of example methods described herein may be performed, at least partially, by one or more processors that are temporarily configured (e.g., by software) or permanently configured to perform the relevant operations. Whether temporarily or permanently configured, such processors may constitute processor-implemented components that operate to perform one or more operations or functions described herein. As used herein, "processor-implemented component" refers to a hardware component implemented using one or more processors. Similarly, the methods described herein may be at least partially processor-implemented, with a particular processor or processors being an example of hardware. For example, at least some of the operations of a method may be performed by one or more processors or processor-implemented components. Moreover, the one or more processors may also operate to support performance of the relevant operations in a "cloud computing" environment or as a "software as a service" (SaaS). For example, at least some of the operations may be performed by a group of computers (as examples of machines including processors), with these operations being accessible via a network (e.g., the Internet) and via one or more appropriate interfaces (e.g., an API). The performance of certain of the operations may be distributed among the processors, not only residing within a single machine, but deployed across a number of machines. In some examples, the processors or processor- implemented components may be located in a single geographic location (e.g., within a home environment, an office environment, or a server farm). In other examples, the processors or processor-implemented components may be distributed across a number of geographic locations.

[0088] " PROCESSOR" in this context refers to any circuit or virtual circuit (a physical circuit emulated by logic executing on an actual processor) that manipulates data valuesaccording to control signals (e.g., "commands," "op codes," "machine code," etc.) and which produces corresponding output signals that are applied to operate a machine. A processor may, for example, be a CPU, a RISC processor, a CISC processor, a GPU, a DSP, an ASIC, a RFIC, or any combination thereof. A processor may further be a multicore processor having two or more independent processors (sometimes referred to as "cores") that may execute instructions contemporaneously.

[0089] Changes and modifications may be made to the disclosed examples without departing from the scope of the present disclosure. These and other changes or modifications are intended to be included within the scope of the present disclosure, as expressed in the following claims.

[0090] The Abstract of the Disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in a single example for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed examples require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter may lie in less than all features of a single disclosed example. Thus, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate example.

Claims

WHAT IS CLAIMED IS:

1. A method comprising: storing, by a first device, a second identifier of a second device and a second public key of the second device; generating, by the first device, a first ephemeral keypair comprising a first ephemeral public key and a first ephemeral private key; transmitting, by the first device to the second device, a first identifier of the first device and the first ephemeral public key; receiving, by the first device from the second device, a second ephemeral public key of a second ephemeral keypair that has been generated by the second device; and computing, by the first device, a symmetric secret key based on the first and second ephemeral keypairs.

2. The method of claim 1, further comprising: establishing a secure communication channel between the first device and the second device using the symmetric secret key.

3. The method of claim 1, further comprising: storing, by the second device, the first identifier of the first device and the first public key of the first device.

4. The method of claim 3, wherein the first identifier and the first public key are stored by the second device during device personalization and prior to generating the first ephemeral key.

5. The method of claim 4, wherein the second identifier and the second public key are stored by the first device during the device personalization and prior to generating the first ephemeral key.

6. The method of claim 1, further comprising: in response to receiving, by the second device, the first identifier of the first device, searching, by the second device, a table to find the first public key that is associated with the first identifier.

7. The method of claim 6, further comprising: generating, by the second device, the second ephemeral keypair, the second ephemeral keypair comprising the second ephemeral public key and a second ephemeral private key; and in response to receiving the first identifier of the first device, computing, by the second device, the symmetric secret key based on the first and second ephemeral keypairs.

8. The method of claim 7, further comprising: transmitting, by the second device to the first device, the second ephemeral public key along with the second identifier of the second device.

9. The method of claim 8, further comprising: in response to receiving, by the first device, the second identifier of the second device, searching, by the first device, a table to find the second public key that is associated with the second identifier; and computing, by the first device, the symmetric secret key in response to retrieving the second public key that is associated with the second identifier from the table.

10. The method of claim 9, wherein the symmetric secret key is computed by the second device based on the second ephemeral private key, the first ephemeral public key, a first public key of the first device, and the second private key of the second device.

11. The method of claim 10, further comprising computing a signature by the second device using the second private key, the signature being computed over the second identifier, the second ephemeral public key, and a set of data received from the first device, the set of data having been received by the second device from the first device in an individual message comprising the first ephemeral public key and the first identifier.

12. The method of claim 11, wherein the set of data includes at least one of an access credential request or a data request.

13. The method of claim 11, wherein the message comprising the second public ephemeral key includes a response of the second device to the set of data.

14. The method of claim 1, further comprising: signing a message by the first device using the first device private key computed over the first identifier, the first ephemeral public key, and the second ephemeral public key.

15. The method of claim 1, wherein the symmetric secret key is computed by the first device based on the first ephemeral private key, the second ephemeral public key, a first public key of the first device, and the second public key of the second device.

16. The method of claim 15, wherein the second device comprises a user device.

17. The method of claim 16, wherein the first device comprises an access control reader.

18. The method of claim 17, further comprising: controlling, by the first device, access to a protected resource based on a message comprising a credential received from the second device using the symmetric secret key.

19. A system comprising: one or more processors coupled to a memory comprising non-transitory computer instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: storing, by a first device, a second identifier of a second device and a second public key of the second device; generating, by the first device, a first ephemeral keypair comprising a first ephemeral public key and a first ephemeral private key; transmitting, by the first device to the second device, a first identifier of the first device and the first ephemeral public key; receiving, by the first device from the second device, a second ephemeral public key of a second ephemeral keypair that has been generated by the second device; and computing, by the first device, a symmetric secret key based on the first and second ephemeral keypairs.

20. A non-transitory computer readable medium comprising non-transitory computer- readable instructions that, when executed by one or more processors, configure the one or more processors to perform operations comprising: storing, by a first device, a second identifier of a second device and a second public key of the second device; generating, by the first device, a first ephemeral keypair comprising a first ephemeral public key and a first ephemeral private key; transmitting, by the first device to the second device, a first identifier of the first device and the first ephemeral public key; receiving, by the first device from the second device, a second ephemeral public key of a second ephemeral keypair that has been generated by the second device; and computing, by the first device, a symmetric secret key based on the first and second ephemeral keypairs.

Citation Information

Patent Citations

  • Improved digital signature and key agreement schemes

    EP2363976A1

  • Techniques for authenticating building / room access terminals

    US20220392286A1