A system and method for secure access management of an access point

The NFC-powered electronic lock system with secure access codes addresses the limitations of battery-powered smart locks by offering a convenient, cost-effective, and secure access management solution that minimizes infrastructure needs and maintenance, enhancing user experience and security across multiple environments.

WO2025234946A1PCT designated stage Publication Date: 2025-11-13IGLOOHOME PTE LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/SG2025/050317
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-10
Filing Date
2025-05-10
Publication Date
2025-11-13

AI Technical Summary

Technical Problem

Existing secure access management systems face challenges related to user convenience, maintenance requirements, safety, and cost, particularly in battery-powered smart locks, which are cumbersome, require frequent battery replacements, and pose safety risks in certain industries.

Method used

A system and method utilizing NFC-powered electronic locks with a shared cryptographic key for secure access management, enabling secure access codes that can be encoded on access devices like NFC cards or mobile devices, allowing proximity-based authentication and revocation based on duration or use commands, eliminating the need for external readers and reducing infrastructure requirements.

Benefits of technology

Provides a frictionless, maintenance-free, and secure access management solution that reduces infrastructure costs, enhances user convenience, and ensures secure access control without battery anxiety, suitable for various industries and environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SG2025050317_13112025_PF_FP_ABST
    Figure SG2025050317_13112025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for secure access management of one or more access points secured by electronic locks. The system comprises at least one processor, a server communicatively connected with an access management system, and a memory storing instructions. The system is configured to receive a request for a guest credential associated with a guest user, the guest credential including reader identifiers, a unique identifier, a command identifier, and an access identity. The request is sent to the server which generates a payload key using a shared key, the unique identifier, and reader identifiers. The system encodes an access device with an access code comprising the payload key and guest credential. The access code is authenticated by a reader on close proximity to permit entry and is revoked upon expiry of the duration or the use command.
Need to check novelty before this filing date? Find Prior Art

Description

A SYSTEM AND METHOD FOR SECURE ACCESS MANAGEMENT OF AN ACCESS POINTTechnical Field

[0001] The present disclosure relates to secure access management systems, and more particularly to a system and method for secure access management of multiple secured access points.Background

[0002] The following discussion of the background to the invention is intended to facilitate an understanding of the present invention. However, it should be appreciated that the discussion is not an acknowledgment or admission that any of the material referred to was published, known or part of the common general knowledge in any jurisdiction as at the priority date of the application

[0003] In the realm of secure access management, there is a growing need to streamline and modernize the process of entering secured access points. Conventional systems — utilizing physical keys, access cards, or magnetic cards — are widely deployed in turnstiles, entry way systems, electronic locks, and other access control mechanisms. However, these traditional methods present notable limitations in terms of convenience, administrative overhead, security, and flexibility.

[0004] A prior solution to these limitations involves the use of an executable program, such as a mobile application, leveraging wireless technologies to unlock a lock. In such electronic lock systems, granting and sharing access with a guest is a common practice. Typically, the grantee must search for the relevant mobile application in an app store, download and install it on their device, register a user account, and only then can the grantor provide keyless access. After these steps, the grantee is able to unlock the system. This multi-step process is often cumbersome, particularly for one-time or infrequent use scenarios.

[0005] Another prior solution involves the use of matrix codes (such as barcodes or QR codes) or images encoded with access credential information. The grantee presents the code or image to a camera integrated into the access control system, which reads the information and verifies its validitywith an internal system or server. If the credential is valid, access is granted. Despite their effectiveness, these solutions are often perceived as complex and inconvenient, especially given the proliferation of mobile applications and the reluctance of users to download an app for single-use access.

[0006] Another prior solution involves a grantee receiving a matrix code (barcode or QR code), or a picture encoded with bits of the relevant information in the access credential. The grantee presents the code or picture to a camera present in the access control system. The camera reads the information from the picture, and the access control system checks with its internal system or a server to see if the information in the access credential is valid, and the secured access will unlock if the access credential is valid The aforesaid solutions do so in a way that are complex and cumbersome to the user. With the proliferation of apps in the mobile application store, users are less inclined to download a mobile application or executable program for a one-time use.

[0007] Recently, battery-powered smart electronic locks with shared access functionalities have gained popularity in both consumer and industrial markets. However, reliance on batteries introduces significant challenges. Outdoor environments, with fluctuating temperatures and harsh conditions, can drastically reduce battery lifespan. Tn indoor settings, the need for frequent battery replacements, especially across multiple locks — can lead to substantial maintenance costs. Additionally, safety concerns in industries such as oil, gas, mining, and aviation necessitate caution regarding the use of lithium (Li) batteries.

[0008] To address battery dependence, there is ongoing exploration of alternative, sustainable energy-harvesting technologies. Photovoltaic solutions, while promising, are limited by sunlight availability. Piezoelectric and thermoelectric alternatives typically provide only micro-watt (pW) power outputs, requiring extended harvesting periods to ensure continuous operation. These constraints present significant hurdles to achieving reliable, maintenance-free smart lock systems.

[0009] Prevailing smart lock solutions operate on battery-powered microcontroller systems, offering connectivity options like BLE, NFC, or Wi-Fi. To maintain a competitive edge and distinguish themselves, smart lock vendors continually introduce new features to their products. Among these advancements are modern features such as distance sensing and face recognition, whichcollaborate to deliver a seamless door access experience for users. However, enhancing battery life remains a persistent challenge that vendors diligently address. Customer preference heavily factors in battery life when selecting a smart lock, underscoring its criticality.

[0010] Despite technological advancements, the adoption of smart electronic lock solutions remains limited in certain contexts. Large organizations, both industrial and consumer, are often reluctant to implement such systems due to the costs and logistical challenges of regular battery replacement. Safety regulations may prohibit the use of Li-battery-powered smart locks in sensitive industries like oil and aviation. In consumer applications — such as outdoor mailboxes, indoor cabinets, and bicycles — battery-powered solutions are often constrained by battery-related issues, size limitations, or cost considerations.

[0011] Accordingly, there remains a need for secure access management solutions that overcome the limitations of traditional and current smart lock technologies, particularly with respect to user convenience, maintenance requirements, safety, and cost. The present invention seeks to address or overcome at least some of these challenges.Summary of the Invention

[0012] It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the invention, as claimed.

[0013] In a first aspect of the invention, there is provided a system for secure access management of one or more access points secured by the respective one or more electronic locks. The system comprises at least one processor, a server communicatively connected with an access management system, and a memory communicatively connected to the at least one processor. The memory stores instructions which, when executed, cause the system to receive a request for a guest credential associated with a guest user. The guest credential includes one or more reader identifiers associated with one or more readers installed on the one or more electronic locks, a unique identifier associated with an access device, a command identifier and an access identity of the guest user, wherein the command identifier includes a duration command and a use command. The request is sent to the server which is configured to generate a payload key using a shared key stored in the server, the uniqueidentifier and the one or more reader identifiers. The system encodes the access device with an access code comprising the payload key and the guest credential, wherein the access code is configured to be received and authenticated by the one or more readers on close proximity to gain entry to the one or more respective electronic locks and revokes the access code on expiry of at least one of the duration command and the use command.

[0014] In a second aspect of the present invention, there is provided an electronic lock for controlling access to a secured access point comprising a lock mechanism coupled to a physical lock and a lock processor in electrical communication with the lock mechanism. A reader is communicatively connected with the lock processor, wherein the reader includes a memory communicatively connected to the lock processor The memory stores instructions which, when executed, cause the reader to receive an access code from an access device provisioned to a guest user on close proximity to the reader, wherein the access code includes a payload key and a guest credential of a guest user, wherein the payload key is generated by a server using a shared key stored in the server, the unique identifier of the access device and a reader identifier associated with the reader. The next step is to authenticate the access code by decrypting and validating the payload key using the shared key stored in the memory, wherein the shared key configured to generate the payload key is the same as the shared key stored in the memory. It then sends a control signal to the lock processor to activate the lock mechanism to control the physical lock upon a successful authentication of the access code

[0015] In a third aspect of the present invention, there is provided an NFC-powered electronic lock for controlling access to a secured access point comprising a lock mechanism coupled to a physical lock and a lock processor in electrical communication with the lock mechanism. A reader is communicatively connected with the lock processor, wherein the reader includes a memory communicatively connected to the lock processor. The memory stores instructions which, when executed, cause the reader to receive an access code from an access device provisioned to a guest user on close proximity to the reader, wherein the access code includes a payload key and a guest credential of a guest user, wherein the payload key is generated by a server using a shared key stored in the server, the unique identifier of the access device and a reader identifier associated with the reader. The next step is to authenticate the access code by decrypting and validating the payload key using the shared key stored in the memory, wherein the shared key configured to generate the payload key is the same as the shared key stored in the memory. It then sends a control signal to the lock processorto activate the lock mechanism to control the physical lock upon a successful authentication of the access code.

[0016] In a fourth aspect of the invention, there is provided a computer-implemented method for secure access management of one or more access points secured by the respective one or more electronic locks, the method comprising the steps of receiving a request from a grantor for a guest credential associated with a guest user, the guest credential comprising one or more reader identifiers associated with one or more readers installed on the one or more electronic locks, a unique identifier associated with an access device, a command identifier and an access identity of the guest user, wherein the command identifier includes a duration command and a use command. The next step is sending the request to a server configured to generate a payload key using a shared key stored in the server, the unique identifier and the one or more reader identifiers. It is followed by encoding the access device with an access code comprising the payload key and the guest credential, wherein the access code is configured to be received and authenticated by the one or more readers on close proximity to gain entry to the one or more respective electronic locks. Finally, it also revokes the access code on expiry of at least one of the duration command and the use command.Brief Description of the Drawings

[0017] In the drawings, like reference characters generally refer to the same parts throughout the different views. The drawings are not necessarily to scale, emphasis instead generally being placed upon illustrating the principles of the invention. The dimensions of the various features or elements may be arbitrarily expanded or reduced for clarity. In the following description, various embodiments of the invention are described with reference to the following drawings, in which:

[0018] FIG. 1 shows a high-level overview diagram of a system for secure access management of one or more secured access points according to various embodiments;

[0019] FIG. 2 shows a high-level overview diagram of another system for secure access management of one or more secured access point according to various embodiments;

[0020] FIG. 3 shows a high-level overview diagram of a facility management application according to various embodiments;

[0021] FIG. 4 is a high-level overview diagram of an encoding module according to various embodiments;

[0022] FIG. 5 shows a flow diagram of a revoke command of an access code according to various embodiments;

[0023] FIG. 6 shows a flow diagram of a method for secure access management of a secured access point according to various embodiments; and

[0024] FIG. 7 shows a high-level overview diagram of an NFC-powered electronic lock with enhanced access control to a secured access point according to various embodiments.Detailed Description

[0025] The following detailed description refers to the accompanying drawings that show, by way of illustration, specific details and embodiments in which the invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the invention. Other embodiments may be utilized and structural, and logical changes may be made without departing from the scope of the invention. The various embodiments are not necessarily mutually exclusive, as some embodiments can be combined with one or more other embodiments to form new embodiments.

[0026] Reference throughout this specification to “one embodiment,” “an embodiment,” “one example,” or “an example” means that a particular feature, structure, or characteristic described in connection with the embodiment or example is included in at least one embodiment of the present disclosure. Thus, appearances of the phrases “in one embodiment,” “in an embodiment,” “one example,” or “an example” in various places throughout this specification are not necessarily all referring to the same embodiment or example. Furthermore, the particular features, structures, databases, or characteristics may be combined in any suitable combinations and / or sub-combinations in one or more embodiments or examples. In addition, it should be appreciated that the figures provided herewith are for explanation purposes to persons ordinarily skilled in the art and that the drawings are not necessarily drawn to scale.

[0027] Accordingly, in one or more example embodiments, the functions described may be implemented in hardware, software, or any combination thereof. If implemented in software, thefunctions may be stored on or encoded as one or more instructions or code on a computer-readable medium.

[0028] In the specification the term “comprising” shall be understood to have a broad meaning similar to the term “including” and will be understood to imply the inclusion of a stated integer or step or group of integers or steps but not the exclusion of any other integer or step or group of integers or steps. This definition also applies to variations on the term “comprising” such as “comprise” and “comprises”.

[0029] In order that the invention may be readily understood and put into practical effect, particular embodiments will now be described by way of examples and not limitations, and with reference to the figures. It will be understood that any property described herein for a specific system may also hold for any system described herein. It will be understood that any property described herein for a specific method may also hold for any method described herein. Furthermore, it will be understood that for any system or method described herein, not necessarily all the components or steps described must be enclosed in the system or method, but only some (but not all) components or steps may be enclosed.

[0030] In addition, as used herein, the term “or” is an inclusive “or” operator, and is equivalent to the term “and / or,” unless the context clearly dictates otherwise. The term “based on” is not exclusive and allows for being based on additional factors not described, unless the context clearly dictates otherwise. In addition, throughout the specification, the meaning of “a,”“an,” and “the” include plural references. The meaning of “in” includes “in” and “on.”

[0031] The term “lock” is broadly intended to include any type of lock, including but not limited to, deadbolts, knob locks, lever handle locks, mortise locks, and slide locks, whether mechanical, electrical, or electro-mechanical locks. The locking points may have various mounting configurations and / or locations, including but not limited to: mortised within the doorframe, mounted externally to the doorframe or support structure, affixed directly to the door, to turnstiles, gantries, or any other types of locks affixed on an entry point.

[0032] The term “electronic lock” is broadly intended to include any electronic lock that is operated using electric current and electronic components instead of traditional mechanical mechanisms. They can include electronic locks powered by alternative energy sources or by alternative technologies such as NFC. They combine physical locking mechanisms with digital authentication methods, offering features like keyless entry, remote access control, and integration with smart systems. These locks provide enhanced security through encryption, access logging, and customizable permissions, and includes electronic locks powered by traditional and non-traditional sources of power.

[0033] The term “NFC-powered electronic lock” is broadly intended to include any electronic lock that is powered not solely by the use of an NFC controller or an NFC controller that is capable of storing energy via the use of NFC. It is broadly intended that the NFC-powered electronic lock may be powered by supplementary or additional sources of power such as a battery.

[0034] Accordingly, in one or more example embodiments, the functions described may be implemented in hardware, software, or any combination thereof. If implemented in software, the functions may be stored on or encoded as one or more instructions or code on a computer-readable medium.

[0035] Traditional WiFi network deployment in residential properties and condominiums presents significant challenges and costs that impact both property managers and residents. The initial setup requires substantial infrastructure investments in equipment such as access points, cabling, and network management systems. Furthermore, retrofitting existing buildings with community WiFi can be particularly challenging and costly, especially when new wiring is required. Ongoing maintenance expenses, including regular updates, hardware replacements, and 24 / 7 technical support, create additional financial burden. These challenges are further compounded by physical obstacles such as walls and furniture that can degrade signal quality, as well as high user density in multi-unit buildings that strains network capacity.

[0036] Traditional property touring solutions present their own set of operational inefficiencies and security concerns. The conventional approach requires significant time investment from both agents and clients, leading to scheduling conflicts and limited touring capacity. This method incurs highpersonnel costs as real estate agents or property managers must be physically present for each tour. Additionally, traditional touring methods restrict the potential audience to those who can visit in person, potentially missing remote or international clients. Security concerns arise from the need to manage physical access during tours, with traditional keys or manual access systems being susceptible to unauthorized use or duplication.

[0037] The present invention addresses these challenges through an NFC-powered electronic lock system which significantly reduces infrastructure requirements and associated costs. Unlike traditional WiFi -dependent systems that require extensive network deployment, the NFC-powered solution operates independently of WiFi infrastructure, eliminating the need for complex network setup and maintenance. The system's ability to harvest energy from mobile phones for temporary power further reduces infrastructure requirements and provides reliable operation even when primary power sources are unavailable. This also allows the use of such electronic locks in remote areas, in logistics, and in oil and gas applications. This approach substantially lowers the total cost of ownership by eliminating the need for physical credentials and reducing administrative overhead.

[0038] The integration capabilities of the present invention with existing access control infrastructure provide additional cost benefits and operational efficiencies. The system's ability to work seamlessly with current electronic lock systems, turnstiles, and building management systems means that properties can implement the solution without requiring extensive infrastructure overhauls. This scalability and flexibility allow for gradual adoption and expansion of the system across multiple access points while maintaining centralized control and monitoring capabilities. The solution combined with its enhanced security features such as prevention of unauthorized tampering, access sharing and reuse, addresses both the operational inefficiencies of traditional systems and the growing demand for touchless, secure access control solutions.

[0039] To achieve the stated features, advantages and objects, the present invention offers improvements over current access control systems, such as those provided by electronic lock systems, turnstile systems, facility control systems, building management systems, hotel reservation management systems, concert and stadium management systems, by enabling access managers to distribute configurable access codes for such aforesaid systems. These configurable access codes provide the following capabilities:io• Ability to revoke the access granted to a user;• Ability to prevent unauthorized access of the the access granted to a user;• Ability to configure a predetermined time period;• Ability to prevent reusing or sharing of access; and• Ability to expand from one-time-use functionality to multiple uses.

[0040] Embodiments of the present invention are directed to providing a system and method for secure access management of a secured access point using configurable access codes. The access codes are configurable for a limited use: for a predetermined number of uses and / or a predetermined time period.

[0041] The present invention proposes to provide a frictionless experience for users by minimizing the steps for a user to access a secured access point. The present invention proposes to prevent unauthorized access while allowing only legitimate users to access a secured access point. The present invention also proposes to accommodate a large number of temporary guests and uses across multiple secured access points. The present disclosure can be applied to electronic locks with wireless communication capabilities such as bluetooth or wifi or multi-factor authentication capabilites, electronic locks that have both offline and online access, access control systems utilized at secured access points such as turnstiles at office and residential buildings, concert and stadium facilities, elevators in residential buildings, hotel booking systems, hotel room management systems, shared facilities within a residential complex, meeting and function rooms in offices.

[0042] To achieve the stated features, advantages and objects, the present invention also provides a near-field communication-powered (NFC-powered) electronic lock with enhanced access control. It offers improvements over current electronic locks. Particularly, the NFC-powered electronic lock is particularly well-suited for locks that demand minimal mechanical exertion Some applications of the use of NFC-powered electronic locks include the following:• Indoor applications o Shared office spaces o Fitness centers o Shopping mallso Educational institutions o Medical facilities o Transportation hubs (airports, railway stations)• Outdoor security applications o Construction site equipment o Infrastructure machinery o Trucks and containers o Consumer goods (bicycles, scooters, luggage)• Emergency backup applications o Operate when primary batteries are depleted o Harvests energy from mobile phones for temporary power o Eliminates need for locksmith services in emergency situations

[0043] In addition, NFC-powered electronic locks provide enhanced access control to electronic lock systems without the use of external access code readers, which are usually devices that are remote but in communication with the electronic lock. For example, NFC-powered electronic locks can be used on turnstile systems, facility control systems, building management systems, concert and stadium management systems, or in remote, underground or areas not accessibly networks, by enabling access managers to distribute configurable access codes for such aforesaid systems to mobile devices for use with the NFC-powered electronic locks. These configurable access codes provide the following capabilities:• Ability to revoke the access granted to a user;• Ability to configure a predetermined time period;• Ability to prevent reusing or sharing of access; and• Ability to expand from one-time-use functionality to multiple uses.Embodiments of the present invention are directed to a system and method of providing a secured access management of an NFC-powered electronic lock using configurable access codes without use of external access code readers or devices that can read access codes.

[0044] The present invention proposes to provide a frictionless, seamless and maintenance-free experience for users by avoiding battery anxiety from loss of power due to battery depletion of theNFC-powered electronic lock and minimizing the steps for a user to access an access point. The present invention also proposes to provide a frictionless, seamless and maintenance-free experience for real estate operators and building management operators by avoiding use of access code reader or devices for reading access codes to access a secured access point.

[0045] Notwithstanding the above disclosure of NFC-power electronic locks, a skilled person would understand that the system and method for secure access management can be implemented on electronic locks that need not be NFC-powered and can be implemented on various electronic locks capable of communicating data via wireless communication.

[0046] FIG. 1 shows a high-level overview diagram of a system for secured access management of a secured access point by an electronic lock according to various embodiments. The system 100 comprises an access management system 110 communicatively connected with a server 120 and a computing device 130 for allowing a user input on the access management system 110. The server 120 can be wirelessly connected via a network or it resides on a computing device that includes the access management system 110. The access management system 110 includes a credential generation module 115 and an encoding module 145. The access management system 110 is configured to manage key distribution and credential generation for access devices and readers integrated into electronic locks. The credential generation module 1 15 is configured to generate one or more keys and one or more guest credentials for guest users. Guest users may include, but are not limited to, users, visitors, hotel guests, short-term stay residents, office pass holders, and other permitted individuals. In various embodiments, the access device 150 is a physical device, for example, an NFC card, tag, token, a ticket or other suitable forms of a portable device, capable of being encoded with an access code. The access device 150 can also be mobile device storing the access code associated with the guest user. A reader 160 integrated within an electronic lock is configured to interact with the access device 150 for the purpose of granting or denying access to a secured area, such as a property, building, or room. The reader 160 is configured to interact with the access device 150 regardless of whether the electronic lock is online or offline, i.e. when it is not connected to the network 900.

[0047] The access management system (AMS) 110 establishes a robust basis of trust by leveraging cryptographic principles to ensure secure and reliable access control with the securedaccess points (electronic locks). At the core of this trust is the use of a shared cryptographic key or a shared key shared, which will be used interchangeably throughout the specification, between the AMS and the electronic lock. The shared key forms the foundation for secure communication, enabling the AMS to encrypt and digitally sign an access code before encoding it on an access device, for example, a mobile device, a NFC-controlled key card, a ticket, a tag, or a token. The shared key is kept secret between the AMS and the electronic locks and is used to encode or decode the payload which only the AMS can generate.

[0048] The system 100 establishes secure communication channels between the server 120 and readers 160 using a unique shared key. In an embodiment, the shared key is a unique symmetric key, for example, a unique symmetric AES GCM 256-bit key and this shared key is kept on the reader 160 and the access management system 110. The reader 160 also possesses a key pair, for example, an Ed25519 key pair, where the private key is securely stored within each reader and the public key is shared with the server for cryptographic operations. In some embodiments, the server 120 uses the shared key to generate a reader key. The reader key is generated by the server 120 for ensuring that each reader 160 operates securely and independently. Each reader is identified by a reader identifier. The reader key is generated by the server 120 based on the reader identifier and the shared key. In some embodiments, the reader key is also distributed to offline systems, such as property management PCs, enabling secure encoding and management of access devices without requiring constant online connectivity. The server 120, or the AMS 110, which holds the shared keys, is responsible for generating the payload and reader keys for encoding applications, ensuring that only authorized systems can create or modify card data.

[0049] A reader 160 is associated with an electronic lock on a secured access point and is configured to interact with access devices 150 for the purpose of granting or denying access to the secured access point, such as a property, building, or room. As mentioned above, each reader is assigned a shared key to ensure secure communication with the server and access devices. Each reader is identified by a reader identifier and each reader is assigned a unique application identifier (AID) that corresponds to its application on the access device. For example, a reader with AID 000001 can access and manage its specific application on the access device.

[0050] In an embodiment, the encoding module 145 allows the grantor to configure and to encode an access code for guest users on an access device based on the command identifier, the locks to be accessed and the access identity of the guest user. In other words, the encoding module 145 allows a grantor to provision an access device 150, for example, an NFC card, a ticket, a tag, or a token, for guest users for enabling them to access certain secured access points during their stay In one embodiment, the grantor generates a request for a credential based on the duration of access, the locks to be accessed and the access identity of the guest user. The credential request is sent to the server 120 and the credential generation module 115 generates a credential payload for the specific access device 150. The credential payload includes the guest access permissions, the validity period of the credential and the locks the guest is authorized to access. The credential payload is signed and encrypted ensuring that the credential cannot be tampered with or reused outside the specified validity period The encoding module 145 then provisions an access device 150 by encoding the access device with an access code comprising the credential payload and other access permissions and the access device is handed to the guest user who can use it to access the designated locks. Once the guest’s stay is over, the credential is revoked by the access management system which updates the facility management application to invalidate the guest’s credential ensuring that the access device can no longer be used to access the designated locks.

[0051] FIG. 2 shows a high-level overview diagram of another system for secured access management of a secured access point by an electronic lock according to various embodiments.

[0052] The system 200 comprises an access management system 110 communicatively connected with a server 120 and a computing device 130 for allowing a user input on the access management system 110. The access management system 110 includes a credential generation module 115. The access management system 110 is configured to manage key distribution and credential generation for access devices and readers integrated into electronic locks. The credential generation module 1 15 is configured to generate one or more keys and one or more guest credentials for guest users.

[0053] The system 200 also includes an application 210 for facility or property managers to issue and manage access devices such as NFC cards, tickets, tags or tokens. The application 210 may be a property management application, hotel reservation system, building management system or any other suitable application that facilitates the management of secured access points within a facility. In someembodiments, the application 210 resides as an application on a mobile device. A reader 160, similar to the reader 160 in FIG. 1, is integrated within an electronic lock configured to interact with the access device 150 for the purpose of granting or denying access to a secured area, such as a property, building, or room. The reader 160 and the electronic lock are configured to interact with the access device 150 where the electronic lock is offline and online, i.e. when it is not connected to the network 900.

[0054] The encoding module 245 is similar to the encoding module 145 in FIG. 1. The encoding module 245 allows the grantor to encode an access code for guest users on an access device based on the command identifier, the locks to be accessed and the access identity of the guest user. In other words, the encoding module 145 allows a grantor to provision an access device 150, for example, an NFC card, a ticket, for guest users for enabling them to access certain secured access points during their stay.

[0055] The system 100, 200 is designed to be broadly applicable across a wide range of industries, including hotel and property operators, accommodation reservation platforms, facility and building management operators and oil and gas industries. It offers improvements over current access control systems, such as those provided by electronic lock systems by enabling access managers to distribute keys and credentials for such aforesaid systems for the purpose of granting and denying access to secured access points even in remote areas where network may not be accessible.

[0056] FIG. 3 shows a high-level overview diagram of a facility management application according to various embodiments. The facility management application 210 is similar to the application 210 in FIG. 2. In various embodiments, the facility management application 210 includes a guest user management module 220 that creates and defines roles for different types of people who may be permanent or temporary visitors to a physical space. The guest user management module 220 also generates an access identity associated with a guest user. The access identity comprises one or more user identifiers of the guest user. For example, the user identifiers can include, but not limited to, a name, an address, an email address or a mobile number. The access identity can be obtained from an external database in communication with the facility management application 200. Once the access identity of a guest user is created, the grantor is able to generate a credential for the guest user for accessing one or more secured access points in a facility.

[0057] In various embodiments, the facility management application 200 includes a lock management module 240 that provides an overview of the electronic locks in a physical facility under management. Each electronic lock is associated with a lock identifier and a named secured access point Each electronic lock is also associated with a reader and a reader identifier that is tied to the reader. The reader is configured to receive the credential from the guest user for granting or denying access to the guest user. In some embodiments, the lock management module 240 is configured to assign one or more electronic locks in the physical space to a lock group for a single action unlock.

[0058] In various embodiments, the facility management application 200 includes a command module 230 that provides an overview of all the command identifiers for use with one or more lock identifiers. The command identifiers include a use command, a duration command and a revoke command In various embodiments, the use command includes a reusable command and a non- reusable command. The reusable command allows the grantee unlimited number of entries subject to a duration command, if any. In some embodiments, the non-reusable command includes a non- reusable command that is time-based and a non-reusable command that is use-based. A time-based non-reusable command is configured for the purpose of security and prevent external users from hacking the access code. The time-based non-reusable command unlocks the lock at the secured access point provided the access code with the time-based non-reusable command is validated within a predetermined time from a timestamp at the NFC-powered electronic lock. The use-based non- reusable command unlocks the lock at the secured access point provided the access code with the usebased non-reusable command has a use quantity of more than the last used quantity stored on the NFC-powered electronic lock.

[0059] In various embodiments, the facility management application 200 includes an encoding module 210 that allows the grantor to configure and to encode a credential for guest users on an access device based on the command identifier, the locks to be accessed and the access identity of the guest user. In other words, the encoding module 210 allows a grantor to provision an access device, for example, an NFC card, or a ticket for guest users for enabling them to access certain electronic locks during their stay. The grantor generates a request for a credential based on the duration of access, the locks to be accessed and the access identity of the guest user. The credential request is sent to the access management system and the credential generation module generates a credential payload for the guest user. The credential payload includes the guest access permissions, the validity period of thecredential and the locks the guest is authorized to access. The credential payload is signed and encrypted ensuring that the credential cannot be tampered with or reused outside the specified validity period. The encoding module 210 then provisions an access device with the credential pay load and other access permissions and the access device is handed to the guest user who can use it to access the designated locks. Once the guest’s stay is over, the credential is revoked by the access management system which updates the facility management application to invalidate the guest’s credential ensuring that the access device can no longer be used to access the designated locks.

[0060] In various embodiments, a computing device 260 is in communication with the facility management application 200 and may include a display 262, a processor 266, an input unit 264, a communication unit 265 and a storage 268 In some embodiments, any other suitable component, including but not limited to a system bus or a controller (not shown), may also be included in the computing device 260. The computing device 260 may be a computer, laptop, handheld computer, mobile device, smartphone, tablet, or any other suitable device. In some embodiments, a mobile operating system (e g., iOSTM, AndroidTM, Windows PhoneTM, etc.) and one or more applications (not shown), for example, the facility management application 200, may be loaded into a memory (not shown) from the storage 268 in order to be executed by the processor 266. The applications may include a browser or any other suitable mobile apps for receiving information relating to the facility management application 200. As appreciated by a person skilled in the art, user interactions with the information stream may be achieved via the I / O devices (not shown) and provided to the processor and / or other components of the system via a network.

[0061] In various embodiments, the computing device 260 includes a display 262 and an input unit 264. The display unit 262 and the input unit 264 can be a single entity although it is shown separately. The input unit 264 is configured to receive input alphanumeric information and various input signals to edit, configure, manage and generate access codes. In some embodiments, the input unit 264 may include a touch screen, a touch pad, a remote controller device, a key pad that is capable of receiving an input gesture. In some embodiments, the input unit may integrated with the display. In some embodiments, the input unit may function without a display and may include a physical button configured to be depressed to send a control signal.I S

[0062] Although the singular is used to describe the server 120, a server as described herein may operate as a single computing device, a set of computing devices, or a distributed computing cluster. Similarly, a computing device may be one or more programming devices capable of running a web application or native application to communicate with the application server. The server and / or computing device may have one or more processors configured to execute instructions retained in the database or memory. In some embodiments, server and / or computing device may include servers, computers, laptops, notebooks, portable handheld computers, mobile communication devices, smart phones, personal digital assistants, tablets, wearable devices, Internet of Things (loT) devices, or any other communication devices capable of sending and receiving data over the network.

[0063] In various embodiments, the term ‘network’ refers to a Local Area Network (LAN), a Metropolitan Area Network (MAN), a Wide Area Network (WAN), a Low Power Wide Area Network (LPWAN), a cellular network, a proprietary network, and / or Internet Protocol (IP) network such as the Internet, an Intranet or an extranet. Each device, module or component within the system may be connected over a network or may be directly connected. A person skilled in the art will recognize that the terms ‘network’, ‘computer network’ and ‘online’ may be used interchangeably and do not imply a particular network embodiment. In general, any type of network may be used to implement the online or computer networked embodiment of the present invention. The network may be maintained by a server or a combination of servers or the network may be serverless. Additionally, any type of protocol (for example, HTTP, FTP, ICMP, UDP, WAP, SIP, H.323, NDMP, TCP / IP) may be used to communicate across the network. The devices as described herein may communicate via one or more such communication networks. The communication over the network may utilize data encryption. Encryption may be performed by way of any of the techniques available now available in the art or which may become available.

[0064] The access management system 110 establishes a robust basis of trust by leveraging cryptographic principles to ensure secure and reliable access control with the secured access points (electronic locks). At the core of this trust is the use of a shared cryptographic key shared between the AMS and the electronic lock. The shared cryptographic key forms the foundation for secure communication, enabling the AMS to encrypt and digitally sign an access code before encoding it on an access device, for example, a mobile device, a NFC-controlled key card, a ticket, a tag, or a token. The shared cryptographic key is kept secret between the AMS and the electronic locks and is used toencode or decode the payload which only the AMS can generate. When a reader receives the access code via NFC from an NFC-powered electronic lock, it decrypts the access code and validates the digital signature to confirm the authenticity and integrity of the access code. This process ensures that only legitimate access codes generated by the AMS can control the electronic locks at the secured access points, preventing unauthorized access Controlling the electronic locks include unlocking and locking the electronic locks and revoking the access codes that allows unlocking the electronic locks. Additionally, for common access points that may be connected online, the system allows real-time revocation of access codes, further enhancing security by enabling immediate response to potential threats or changes in access permissions. By combining cryptographic techniques with centralized access management, the system fosters a secure and trustworthy environment for managing access to physical spaces.Server-Reader Communication

[0065] The system establishes secure communication channels between the server and readers using a unique shared key. In an embodiment, the shared key is a unique symmetric key, for example, a unique symmetric AES GCM 256-bit key and this shared key is kept on the reader and the access management system. The reader also possesses a key pair, for example, an Ed25519 key pair, where the private key is securely stored within each reader and the public key is shared with the server for cryptographic operations. In some embodiments, the server uses the shared key to generate a reader key. The reader key is generated by the server for ensuring that each electronic lock with the reader operates securely and independently. Each reader is identified by a reader identifier. The reader key is generated by the server based on the reader identifier and the shared key. This process ensures that each reader has a unique key that is derived from the established secure communication channel with the server. In some embodiments, the reader key is also distributed to offline systems, such as property management PCs, enabling secure encoding and management of access devices without requiring constant online connectivity. The server, or the AMS, which holds the shared keys, is responsible for generating the payload and reader keys for encoding applications, ensuring that only authorized systems can create or modify card data. The reader key is a symmetric key and can be used for both encryption and decryption operations. The reader key is essential for the reader’s interactions with the access devices and allows it to securely read and write data on the access device. Once the reader key is generated, it is securely stored within the reader’s hardware. This ensures that the reader keyremains confidential and is not exposed to unauthorized entities. The reader is utilized in various operations involving the access devices and includes encrypting and decrypting access codes during communication with the access device or deriving additional application-specific keys that control access to different functionalities within the access device.

[0066] By employing this method of key generation, the system ensures that each reader operates with a unique and secure key, facilitating secure access control and data management in environments utilizing NFC technology. This approach enhances the overall security posture of the system while providing the necessary flexibility for managing multiple readers and access scenarios.

[0067] In use, a grantor (for example, an administrator, a receptionist) generates a request for a guest credential on a property management application The guest credential includes one or more reader identifiers associated with the readers on the electronic locks at secured access points that are permitted for access by the guest user, a command identifier that includes at least one of a use command, a duration command and a revoke command, and the access identity of the guest. Details of the command identifier will be provided in the specification. The access identity comprises one or more user identifiers of the guest user. For example, the user identifiers can include, but not limited to, a name, an address, an email address or a mobile number. The request is sent to the access management system 1 10 for generation of a payload key by the credential generation module 1 15. The payload key is generated based on the following:• the shared key• the unique identifier of the access device• the one or more reader identifiers associated with the readers the guest is authorized to accessThe payload key is signed and encrypted using the same process as described above, ensuring that the payload cannot be tampered with or reused outside the specified validity period. The grantor proceeds to provision using the encoding module 245 the access device 150 with an access code comprising the payload key and the guest credential. In some embodiments, the access code includes a master key that is associated with the access device that the encoding module is provisioning access to. The master key includes at least one of a reader key, the unique identifier of the access device, the one or more reader identifiers and a shared application key. The reader key is generated by the encoding moduleand includes the shared key and at least one of a reader identifier or a group reader identifier. The access device with the access code is then handed to the guest user, who can use it to access the designated locks. Once the guest user’s stay is over, the access code can be revoked by the access management system. The access management system updates the facility management application to invalidate the guest user’s access code, ensuring that the access device can no longer be used to access the electronic locks.

[0068] In various embodiments, the payload key is generated by the access management system based on an individual reader identifier comprising a single reader or a group reader identifier comprising a group of readers. For a single reader identifier, the access management system generates the payload key based on a reader identifier, the unique identifier of the access device, and the shared key. For a group reader identifier, the access management system generates the payload key based on the group reader identifier, the unique identifier of the access device, and the shared key.

[0069] In other embodiments, the electronic lock includes a reader capable of reading a graphical image or optical data comprising machine-readable optical identifier. The reader on the electronic lock decodes the access code provided by the guest user on the access device and authenticates the access code.

[0070] The above-mentioned provisioning of access devices provides significant advantages in the context of secure access management of electronic locks. These advantages include:• Security: The provisioning method employs a hierarchical key management system and advanced cryptographic techniques to ensure that credentials are securely generated, distributed, and stored. By leveraging symmetric and asymmetric cryptographic operations, the system protects sensitive data from unauthorized access and ensures the integrity of the credentials throughout the provisioning process.• Flexibility: The system supports both reader- specific and group-wide credentials, enabling fine-grained access control. This flexibility allows property managers to define access permissions at various levels, such as individual readers or logical groups (e.g., departments, properties, or organizations), ensuring that access rights can be tailored to meet specific operational requirements.• Convenience: The provisioning method enables the rapid and secure issuance of NFC cards to guest users. Guest credentials can be generated and encoded onto NFC cards in a time-efficient manner, enhancing the overall user experience. This feature is particularly beneficial in scenarios such as hotels, vacation rentals, or temporary access to facilities, where quick and secure provisioning is essential.• Scalability: The system is designed to accommodate a large number of readers, groups, and users, making it suitable for complex property management scenarios. The hierarchical key management structure ensures that the system can scale efficiently without compromising security or performance, even in environments with extensive access control requirements.

[0071] FIG. 4 is a high-level overview diagram of an encoding module according to various embodiments. The encoding module 245 encodes an access device with an access code for the purpose of granting and denying access to readers associated with electronic locks that the guest user is permitted access to. The access code can be generated for a group of readers that are associated with a group of electronic locks. For example, the group of readers includes a gym reader 410 defining a reader securing the gym, a pool reader 420 defining a reader securing the pool, and common access reader 430 defining a reader to access two or more common doors 470, 480. In various embodiments, the payload key is generated by the access management system based on an individual reader identifier comprising a single reader or a group reader identifier comprising a group of readers. For a group reader identifier, the access management system generates the payload key based on the group reader identifier that is associated with the reader identifiers of the gym, the pool and the common access reader, the unique identifier of the access device, and the shared key.

[0072] As mentioned above, each reader is assigned a shared key to ensure secure communication with the server and access devices. Each reader is identified by a reader identifier and each reader is assigned a unique application identifier (AID) that corresponds to its application on the access device. For example, a reader with AID 000001 can be assigned to a gym to access and manage access to the gym.

[0073] In some embodiments, where an access code allows access to multiple readers, the server generates a group shared key for each group and this group shared key is distributed to all the readersin the group via an encrypted command. The group is also assigned a group reader identifier that is associated with all the readers, i.e. the gym reader 310, the pool reader 420, and the common access reader 430. From the group shared key, each reader within the group can be assigned a group reader key based on the group shared key and the group reader identifier. Tn some embodiments, readers in the group can also access a shared application on the access device, identified by a unique AID (e.g., 000002 for group applications). The shared application includes keys derived from the group reader key, and include the following:• appKeyO: Master key for managing files within the group application.• appKey3: Key for read / write permissions, allowing readers to write transaction logs or update credentials.

[0074] Tn some embodiments, readers in the group write transaction logs to the shared application (e g , AID OxFFFFFF) on the access device. These logs are stored in a cyclic record file and secured using a Merkle chain structure, where each log entry includes a CMAC (Cipher-based Message Authentication Code) that incorporates the previous log's MAC for integrity verification.ACCESS CODE

[0075] The access code is a code capable of accessing electronic locks at secured access points that are managed by an access management system or a facility management application. The access code may be in the form of a matrix barcode, a two-dimensional code, data matrix, a Quick-Response code, a barcode, or a machine-readable code that can be decoded by readers. Access codes may be in widely available formats and data in the form of text, numeric data and instructions, can be encoded in the access code for performing certain functions when decoded by a reader. The access code comprises a graphical image or optical data that is capable of being interpreted by a reader.

[0076] In various embodiments, access code is a QR code that encodes text as a graphical image, and BASE45 encoding is used to encode binary data. For example, to encode binary data using BASE45, data is converted into an appropriate text format (eg. UTF-8 or ISO / IEC 8859-1, and BASE45 encoding is applied thereof. Decoding a BASE45-encoded string retrieves the original binary data.

[0077] In various embodiments, the access code comprises a payload transmitted via NFC to NFC-powered electronic locks at secured access points controlled by access control systems. This code may take the form of an NFC data pay load, capable of being interpreted by readers. Access codes can contain various data formats including text, numeric data, and instructions, encoded to perform specific functions when decoded by a reader. In an embodiment, the access code is configurable by a grantor or an authorized user according to predetermined usage and / or time periods.

[0078] Referring to FIG. 4, the access code 400 encoded on access device 150 permits access to the gym, pool and common access which are respectively secured by readers on electronic locks at the respective locations. Each reader 410, 420, 430, is associated with an electronic lock or an NFC- powered electronic lock, for example, a lock serial number, at a secured access point

[0079] When the guest user is at any one of the secured access points, the access device 150 with the access code 400 is presented to the readers. In an embodiment, the readers are a NFC reader residing on an NFC -powered electronic lock, or a QR code reader or a camera or an image sensing device that is communicatively connected with an electronic lock to read the access code. When the reader reads the access device on proximity with the electronic lock, it authenticates the access code received from the access device and derives the master key of the access device using the combination of the lock reader key, unique identifier and lock reader identifier. The reader then reads the application data from the access device and derives the payload key using a combination of the shared key, unique identifier and lock reader identifier to decrypt and validate the payload. In some embodiments, the electronic lock checks the nonce in the payload to ensure it is greater than the last stored nonce, preventing replay attacks. If valid, the electronic lock begins a transaction, increments the nonce in the value file, and logs the activity in the access device log application. The log entry includes the application ID (AID), log type, timestamp, and a signature that chains it to the previous log entry for integrity. Once the transaction is committed, the lock opens, granting access. This process ensures that every step, from access device encoding to reader validation, is cryptographically secure, tamper-resistant, and auditable, creating a robust and trustworthy access management system.

[0080] In various embodiments, when the guest user approaches the common access reader 430, the guest user approaches the electronic lock at a secured access point and presents the access code to the common access reader 430. Where the electronic lock is an NFC electronic lock, the reader is configured to receive wirelessly, through close proximity to the NFC electronic lock, the access codefrom the guest user’s access device which is also NFC-enabled. Where the electronic lock has a camera to read the access code, the camera receives the access code when presented with it. The electronic lock is configured to decrypt and validate the access code through use of the shared key that is stored in the electronic lock, which is also the same shared key with the access management system. The common access reader 430 is linked to two common doors. The access code 400 includes both lock identifiers associated with common door 1 and common door 2 that allows the access code to open both common door 1 and common door 2 upon successful authentication of the access code at common access reader 430. In this case, a single reader is in communication with multiple secured access points. In another scenario, the electronic lock is in wireless communication with multiple lockboxes or mailboxes. In this case, on successful verification by the electronic lock, only the lockboxes associated with the lock identifiers associated with the access code will be opened.Command Identifier

[0081] In various embodiments, the command identifier allows the grantor to manage control and access to one or more readers associated with corresponding one or more electronic locks, by revoking an access code, setting duration and / or time-based access for the readers. The command identifier includes one or more of the following instructions:• Revoke an issued access code - this includes revoking an access code or a previously issued one or more access codes for the one or more lock identifiers by invalidating the access codes and denying entry to the guest users holding the access codes when the command identifier is activated.• Unlock duration - this command identifier allows the guest user to open the lock for a specific period, for example, between a start date and / or start time and an end date and / or start time. The command identifier also includes the access code being reusable or non-reusable.• Unlock multi-use - this command identifier allows the guest user to unlock a lock multiple times up to a predetermined number of times for a specific duration, for example, between a start date and an end date. It also allows the grantee to unlock two or more locks up to a predetermined number of times for a specific duration, for example, between a start date and an end date. Similarly, the command identifier also includes the access code being reusable or non-reusable.• Unlock schedule - this command identifier allows the grantee to access a lock at a fixed schedule between a start date and an end date. Similarly, the command identifier also includes the access code being reusable or non-reusable.• Synchronize Clock - this command identifier ensures that the internal clock of an electronic lock or an NFC-powered electronic lock is synchronized with the mobile device 140 when the electronic lock or the NFC-powered electronic lock receives the access code. In the case of an NFC-powered electronic lock, an NFC payload received by the NFC-powered electronic lock includes a current time and day of the mobile device to be sent to the NFC-powered electronic lock in order to synchronize the internal clock of the electronic lock. This will ensure that the other command identifiers can work if the NFC-powered electronic lock is not powered.

[0082] In various embodiments, the command identifier includes a use command that allows the guest user to unlock one or more electronic locks at secured access points multiple times up to a predetermined number of times for a specific duration, for example, between a start date and an end date. In some embodiments, the use command includes the access code being reusable or non- reusable, i.e. only for a one-time use.

[0083] In various embodiments, the command identifier includes a duration command that allows the guest user to unlock one or more locks at secured access points for a predetermined duration of time, for example, between a start date and an end date, or between a start date and time and an end date and time.

[0084] In various embodiments, the command identifier includes a revoke command that instructs the one or more electronic locks to revoke the access code after a duration of specified time. In some embodiments, the access code includes a revoke command that instructs the one or more electronic locks to revoke an old or a previously issued access code, or to revoke the access code upon expiry of the predetermined number of times defined by the use command or the predetermined dates defined by the duration command.Access Device

[0085] In various embodiments, the access device 150 is a physical device, for example, an NFC card, a ticket, tag, token or other suitable forms of a portable device, capable of being encoded with an access code. The ticket which can be a piece of paper can be encoded with the access code and provided to a guest user. The access device 150 can also be mobile device associated with the guest user. A reader integrated within an electronic lock is configured to interact with the access device 150 for the purpose of granting or denying access to a secured area, such as a property, building, or room.

[0086] In various embodiments, the use of an access device 150 such as an NFC card, for example, those based on the MIFARE DESFire EV3 technology, establishes a strong basis of trust in access management systems by employing advanced cryptographic methods and secure key management. At the core of this trust is a master key, which governs the security of the access device 150 and its applications. Each access device 150 can host multiple applications, each protected by unique application keys that define specific permissions, such as read-write access for encoding software or write-only access for secure data encoding. In an embodiment, and as mentioned above, the access management system (AMS) and a reader identifier defined by an NFC reader at an electronic lock at a secured access point, share a shared key. Each NFC reader is assigned an application that is unique to the NFC reader. The shared key is used to encrypt a credential payload. The credential payload includes the guest access permissions, the validity period of the credential and the readers the guest are authorized to access. The credential payload is signed and encrypted ensuring that the credential cannot be tampered with or reused outside the specified validity period. The encoding module 145 then provisions an access device 150 by encoding the access device with an access code comprising the credential payload and other access permissions and the access device is handed to the guest user who can use it to access the designated locks.

[0087] The shared key is further used to generate a reader key, ensuring that each electronic lock with the NFC reader operates securely and independently. Each NFC reader is identified by a reader identifier. Each access device, or in this embodiment, an NFC card is uniquely identified by a unique identifier, and the master key is generated using the combination of the reader key, the unique identifier, and the reader identifier. This ensures that even if a card is duplicated, it cannot be used without the correct shared cryptographic key. The reader key can also be distributed to offline systems, such as property management PCs, enabling secure encoding and management of cards without requiring constant online connectivity. The server, or the AMS, which holds the shared cryptographickeys, is responsible for generating the payload and reader keys for encoding applications, ensuring that only authorized systems can create or modify card data.

[0088] When a reader reads an access device 150, it decrypts and validates the credential payload using the shared key stored in the reader, ensuring that the access code is authentic and has not been tampered with. In some embodiments, electronic locks are organized into logical groups, each protected by a group reader key, which allows for centralized management of access permissions across multiple electronic locks while maintaining security at the group level. This layered approach to cryptographic security, combined with the advanced features of the DESFire EV3 cards, ensures a high level of trust, making the system resilient to unauthorized access and tampering while providing flexibility for both online and offline use cases.

[0089] When a guest user wishes to enter a secured access point that is secured by the electronic lock, the user provides the access code for verification by placing the access device 150 in close proximity to the reader. The electronic lock receives the access code through an NFC transceiver within the electronic lock and decrypts and validates the access code with the shared cryptographic key to ensure that the access code is authentic. Once authenticated, a signal is sent to the lock controller to activate the lock mechanism to control the electronic lock to allow entry to the guest user. In some embodiments, controlling the electronic locks include unlocking and locking the electronic locks and revoking the access codes that allows unlocking the electronic locks. In some embodiments, and as mentioned above, the NFC controller and the lock controller are integrated and functions as a single unit and send instructions to the respective components of the NFC-powered electronic lock, for example, the input device, biometric sensor, wireless transceiver and lock mechanism.

[0090] The property management application 220 encodes the access device 150 by creating the necessary applications and files, writing the final payload, and setting up a log application for activity tracking. When the reader on the electronic lock reads the access device 150 on close proximity with the electronic lock, it authenticates the access code and derives the master key using the combination of the lock reader key, unique identifier and lock reader identifier. The reader then reads the card's application data and derives the payload key using a combination of the shared cryptographic key, unique identifier and lock reader identifier to decrypt and validate the payload. In some embodiments, the electronic lock checks the nonce in the payload to ensure it is greater than the last stored nonce,preventing replay attacks. If valid, the lock begins a transaction, increments the nonce in the value file, and logs the activity in the card's log application. The log entry includes the application ID (AID), log type, timestamp, and a signature that chains it to the previous log entry for integrity. Once the transaction is committed, the lock opens, granting access. This process ensures that every step, from card encoding to lock validation, is cryptographically secure, tamper-resistant, and auditable, creating a robust and trustworthy access management system.

[0091] FIG. 5 shows a flow diagram of a revoke command of an access code according to various embodiments. An access management system 110 is communicatively connected to a facility management application via a network. The revoke command on the access code is configured to revoke the access code of a previously issued access code subject to the duration command. Alternatively, the revoke command on the access code is also configured to revoke any previously issued access codes to other grantees who may not have any revoke commands tied to the access codes. In this case, the new access code 520 with the revoke command will be sent to the access management system 110 for update to the facility management application. The revoke command instructs the reader 160 on the electronic lock to rej ect an old access code 510 or any previously issued access codes to the electronic lock and to only accept the new access code 520 with the revoke command

[0092] Figure 6 illustrates a high-level overview diagram of various access codes configured for reading by electronic locks or NFC-powered electronic locks. As mentioned previously, to safeguard the integrity and confidentiality of the data stored on the access code, various cryptographic techniques and key generation techniques are employed in encrypting the data within the access code. This encryption process encompasses a range of methodologies, including encryption, digital signing, or a combination thereof. Subsequently, Authenticated Encryption with Associated Data (AEAD) techniques are applied to encrypt both the payload and the signature, ensuring the authenticity, confidentiality, and integrity of the data stored on the access code. Encryption involves generating a pay load key by the server using a shared key, a unique identifier and the one or more reader identifiers permitted access. The encrypted data can only be decrypted back to its original form using the corresponding decryption key which is stored at the readers.

[0093] In some embodiments, where an access code allows access to multiple readers, the server generates a group shared key for each group and this group shared key is distributed to the readers in the group via an encrypted command. The group is also assigned a group reader identifier that is associated with all the readers. From the group shared key, each reader within the group can be assigned a group reader key based on the group shared key and the group reader identifier In some embodiments, readers in the group can also access a shared application on the access device, identified by a unique AID (e.g., 000002 for group applications). The shared application includes keys derived from the group reader key, and include the following:• appKeyO: Master key for managing files within the group application.• appKey3: Key for read / write permissions, allowing readers to write transaction logs or update credentials.

[0094] In some embodiments, readers in the group write transaction logs to the shared application (e.g., AID OxFFFFFF) on the access device. These logs are stored in a cyclic record file and secured using a Merkle chain structure, where each log entry includes a CMAC (Cipher-based Message Authentication Code) that incorporates the previous log's MAC for integrity verification.

[0095] Referring to FIG. 6, the access code 610 is encoded on an access device 150. The access code 610 comprises a group of readers 650, 660 associated with electronic lock 1 and electronic lock 2.

[0096] FIG. 7 shows a flow diagram of a method for secure access management of a secured access point according to various embodiments. At step 710, the property management application grantor receives a request for a guest credential for a guest user from a grantor that was requested through a user interface on the property management application. The guest credential includes one or more reader identifiers associated with the readers permitted for access by the guest user, a unique identifier associated with an access device (such as an NFC card or a ticket or mobile device), a command identifier, and an access identity of the guest user. The access identity comprises one or more user identifiers of the grantee. The user identifier of the grantee can include, but not limited to, a mobile number, name of the grantee, address or email address of the grantee, role, etc.. The access identity can also be generated based on the input of the guest user upon registration with the access management system or associated systems. For example, a guest user can make a booking of an apartment on a travel booking system with one or more user identifiers. The command identifierincludes a use command, a duration command and a revoke command. In various embodiments, the use command includes a reusable command and a non-reusable command. The reusable command allows the grantee unlimited number of entries subject to a duration command, if any. In some embodiments, the non-reusable command includes a non-reusable command that is time-based and a non-reusable command that is use-based. A time-based non-reusable command is configured for the purpose of security and prevent external users from hacking the access code.

[0097] At step 720, the property management application sends the request to the server configured to generate a pay load key using at least one of a shared key, the unique identifier associated with the access device and one or more reader identifiers that the guest user is permitted to access. The server generates a payload key using a combination of the shared key, a unique identifier of the access device and a lock reader identifier, which is then used to encrypt and sign the access code. Only the server can generate the payload key. In some embodiments, the server also generates a master key for each specific access device. Each master key includes a reader key, a unique identifier, a reader identifier, and a shared application key that includes log files, that is generated using the group lock key and the unique identifier. The reader key is generated by the server using the shared key and the unique identifier of the access device, and the one or more reader identifiers associated with the electronic locks given access to the guest user. The master key governs the security of the access device 150 and its applications.

[0098] At step 730, the property management application encodes the access device 140 with an access code using the encoding module. The access code comprises the payload key and the guest credential. In some embodiments, the access code includes a master key that is associated with the access device that the encoding module is provisioning access to. The master key includes at least one of a reader key, the unique identifier of the access device, the one or more reader identifiers and a shared application key The reader key is generated by the encoding module and includes the shared key and at least one of a reader identifier or a group reader identifier. The access device with the access code is then handed to the guest user, who can use it to access the designated locks. Once the guest user’ s stay is over, the access code can be revoked by the access management system. The access management system updates the facility management application to invalidate the guest user’s access code, ensuring that the access device can no longer be used to access the electronic locks. In otherembodiments, a shared application file is also created on the access device that is configured for setting up a log application for activity tracking.

[0099] When the reader reads the access device on close proximity with the electronic lock, it authenticates the access code received from the access device and derives the master key using the combination of the lock reader key, unique identifier and lock reader identifier. The lock then reads the card's application data and derives the payload key using a combination of the shared key, unique identifier and lock reader identifier to decrypt and validate the payload. In some embodiments, the electronic lock checks the nonce in the payload to ensure it is greater than the last stored nonce, preventing replay attacks. If valid, the lock begins a transaction, increments the nonce in the value file, and logs the activity in the card's log application. The log entry includes the application ID (AID), log type, timestamp, and a signature that chains it to the previous log entry for integrity. The activity log includes an entry timestamp, access identity, lock identifier or command identifier. Once the transaction is committed, the lock opens, granting access. This process ensures that every step, from access device encoding to reader validation, is cryptographically secure, tamper-resistant, and auditable, creating a robust and trustworthy access management system.

[0100] At step 740, the property management application revokes the access code subject to the expiry of at least one of the duration command and the use command.

[0101] In summary, and in an embodiment, the method for secure access management of secured access points supports the provisioning of access devices for guest users, such as hotel guests or temporary visitors, enabling them to access electronic locks during their stay. The process is as follows:1. Guest Credential Request: o The property management application generates a request for a guest credential, specifying the duration of access, the locks to be accessed, and the guest's details.2. Credential Generation: o The server generates a time-limited credential payload for the guest. The payload includes:■ The guest's access permissions■ The validity period of the credential■ The locks or readers the guest is authorized to access o The payload is signed and encrypted using the same process as described above, ensuring that the credential cannot be tampered with or reused outside the specified validity period.3 Access Device Issuance: o The access device (eg. mobile device, NFC card, ticket, or token) is provisioned with the access code using the encoding module. The access device is then handed to the guest, who can use it to access the designated locks.4. Access Revocation: o Once the guest's stay is over, the access code can be revoked by the server. The server updates the access control system to invalidate the access code, ensuring that the access device can no longer be used to access the locks.

[0102] The above-mentioned method offers several advantages:• Security: The use of hierarchical key management and cryptographic techniques ensures that access codes are securely generated, distributed, and stored.• Flexibility: The system supports both reader-specific and group-wide credentials, enabling fine-grained access control.• Convenience: Guest users can be provisioned with access devices (NFC cards) quickly and securely, enhancing the user experience.• Scalability: The system can accommodate a large number of readers, groups, and users, making it suitable for complex property management scenarios.

[0103] In the above embodiments, where multiple NFC-powered electronic locks are used at multiple secured access points, the NFC-powered electronic locks are particularly well-suited for such a large-scale implementation of locks that demand minimal mechanical exertion in both indoor and outdoor environments. They benefit from the use of the NFC-powered electronic lock with enhanced access control. Additionally, the NFC-powered electronic lock serves as an emergency power source for electronic door locks. In this scenario, the NFC-powered electronic lock offers a contingency solution where door lock batteries are used and are depleted. Energy can be harvested from a mobile phone to power the NFC-powered electronic locks, facilitating unlocking without necessitating the costly services of a locksmith. In addition, the NFC-powered electronic lock provides enhanced accesscontrol to electronic lock systems, turnstile systems, facility control systems, building management systems, concert and stadium management systems, by enabling access managers to distribute configurable access codes for such aforesaid systems.

[0104] FIG. 8 shows a high-level overview diagram of an NFC-powered electronic lock in which aspects of the present invention may be implemented. The NFC-powered electronic lock 10 comprises a lock controller 30 in data communication with a memory 40 and in electrical communication with a lock wireless transceiver 60 and a lock mechanism 20 coupled to a physical lock. The lock controller 30 is in electrical communication with an NFC controller 80 that comprises an antenna 85 and an NFC transceiver 86. The NFC controller 80 also includes a rectifier (not shown) for conversion of AC current received by the antenna 85 to DC current, an electronic circuitry in electrical communication with the rectifier and a capacitor (or energy storage) that stores power for driving the lock controller 80 and lock mechanism 20. The NFC transceiver 86 is configured for wireless communication with an access device 140. When an access device 140 is in close proximity with the NFC-powered electronic lock 10, a wireless communication is initiated by the NFC-powered electronic lock to receive the access code and any other data from the access device 140.

[0105] In some embodiments, data exchange and energy transfer between the access device 140 and the NFC-powered electronic lock 10 are achieved via Near Field Communication (NFC) technique. NFC is a set of short-range wireless technologies, typically requiring a distance of 4 cm or less. NFC operates at 13.56 MHz on ISO / IEC 18000-3 air interface and at rates ranging from 106 kbit / s to 424 kbit / s. NFC always involves an initiator and a target; the initiator actively generates a radio frequency (RF) field that can power a passive target. In various embodiments, access device 140 can include, but not limited, to mobile devices, tags, cards, key fobs. Throughout this specification, the use of the access device 140 when used in communication with the NFC-powered electronic lock, can also be used interchangeably with the NFC-enabled device.

[0106] The NFC controller 80 is configured for contactless exchange of data and energy transfer. This allows the mobile device 140 to transfer both data and power from the mobile device via a carrier signal or electromagnetic field to the NFC controller 80. The received carrier signal by the antenna 85 includes an AC current and is converted to a DC current by the rectifier and the electronic circuitry carries the converted DC current to charge a capacitor for storing energy within the capacitor. Whenpower is required to lock or unlock the lock mechanism of the electronic lock 10, the stored power from the capacitor is used to provide sufficient power to the lock controller 30 for communication with external devices, authentication and controlling the lock mechanism 20 for controlling the electronic lock 10. Controlling the electronic lock include unlocking and locking of the electronic lock and revoking the access codes that allows unlocking the electronic lock.

[0107] In an embodiment, the NFC controller 80 includes a reader that is configured to receive an access code from an access device (for example, an NFC card) from a guest user for accessing a secured access point secured by NFC-powered electronic locks 10 via the NFC transceiver 86.

[0108] As described above, the access code comprises the payload key and the guest credential. In some embodiments, the access code includes a master key that is associated with the access device that the encoding module of the access management system or the facility management application. The master key includes a reader key, the unique identifier of the access device, the one or more reader identifiers and a shared application key. The reader key is generated by the encoding module and includes the shared key and at least one of a reader identifier or a group reader identifier. The access device with the access code is then handed to the guest user, who can use it to access the designated locks. Once the guest user’s stay is over, the access code can be revoked by the access management system. The access management system updates the facility management application to revoke the guest user’s access code, ensuring that the access device can no longer be used to access the electronic locks. In other embodiments, a shared application file is also created on the access device that is configured for setting up a log application for activity tracking.

[0109] When the reader reads the access code from the access device on close proximity with the electronic lock, it authenticates the access code received from the access device and derives the master key using the combination of the lock reader key, unique identifier and lock reader identifier The lock then reads the card's application data and derives the payload key using a combination of the shared key, unique identifier and lock reader identifier to decrypt and validate the payload. In some embodiments, the electronic lock checks the nonce in the payload to ensure it is greater than the last stored nonce, preventing replay attacks. If valid, the lock begins a transaction, increments the nonce in the value file, and logs the activity in the card's log application. The log entry includes the application ID (AID), log type, timestamp, and a signature that chains it to the previous log entry forintegrity. The activity log includes an entry timestamp, access identity, lock identifier or command identifier. Once the transaction is committed, the lock opens, granting access. This process ensures that every step, from access device encoding to reader validation, is cryptographically secure, tamperresistant, and auditable, creating a robust and trustworthy access management system.

[0110] The reader stores the shared key in its memory that is used for authenticating the access code received from the access device. The shared key, as described above, is the same shared key that is stored in the server which is used for generating payload keys and master keys for enabling the encoding module to encode the access code on the access device. The use of the shared key that is shared between the server and the electronic lock forms the foundation for secure communication, enabling the access management system to encrypt and digitally sign an access code before encoding it on an access device, for example, NFC-controlled key card. The shared key is kept secret between the server and the electronic locks and is used to encode or decode the payload which only the server can generate. When a reader receives the access code, it decrypts the access code and validates the digital signature to confirm the authenticity and integrity of the access code. This process ensures that only legitimate access codes generated by the server can control the electronic locks on secured access points, preventing unauthorized access. Controlling the electronic locks include unlocking and locking of the electronic locks and revoking the access codes that allows unlocking the electronic locks. Additionally, for common access points that may be connected online, the system allows real-time revocation of access codes, further enhancing security by enabling immediate response to potential threats or changes in access permissions. By combining cryptographic techniques with centralized access management, the system fosters a secure and trustworthy environment for managing access to physical spaces.

[0111] In some embodiments, the NFC -powered electronic lock 10 is installed on a secured access point of a residential property, office facility, turnstiles, or mailboxes The entry point may include a door, such as a door of a building, a door in a residential or commercial unit, a door of a mailbox, a door of a safe, turnstile, door of a key installation, etc.. In some embodiments, the electronic lock 10 includes an input device 70 such as a touch screen or virtual keypad for entering an input. In some embodiments, the electronic lock 10 includes a biometric sensor 50 for capturing biometric data such as a fingerprint sensor for capturing fingerprint information or an image capturing sensor for capturing facial profile information of users.

[0112] In some embodiments, the NFC-powered electronic lock 10 includes a lock wireless transceiver 60 for wireless communication with an access device 140, or an access management application, details of which will be provided later. Tn one embodiment, the lock wireless transceiver 60 can communicate wirelessly with the access device 140 or through the access management application via a communication network. In various embodiments, the wireless transceiver 60 can communicate via any of various technologies already mentioned above, such as a short-range wireless network, a wireless local area network (WLAN), a low-power Wide Area Network (LP-WAN), etc. The cellular network can be any of various types, such as code division multiple access (CDMA), time division multiple access (TDMA), global system for mobile communication (GSM), long term evolution (LTE), 3G, 4G, 5G, etc. The short-range wireless network can also be any of various types, such as Bluetooth, Bluetooth Low Energy (BLE), near field communication (NFC) etc..

[0113] The NFC-powered electronic lock 10 includes a lock controller 30. For example, the lock controller 30 maintains an activity log of all entries and exit of users and transfers the information to the access management application via wireless communication facilitated by the wireless transceiver 60 for storage in the lock user database. In one embodiment, the NFC controller can maintain an activity log of all entries and exits of grantees and transfers the activity log data to the access management application. Whenever a guest user accesses a secured access point via the NFC-powered electronic lock 10, the lock controller 30 logs the unlocking and locking of the electronic locks as events. These events are saved on the access device and on the memory 40 of the NFC-powered electronic lock 10 and are sent via the network to the access management system and can be accessible by the access right owner or administrator. In some embodiments, unsuccessful attempts at entry or an unauthorized entry can be logged and transmitted to the access right owner or administrators for them to be notified via their user devices immediately.

[0114] The NFC-powered electronic lock 10 includes the standard structure of conventional door locks with moving parts to lock or to unlock the physical lock. The lock controller 30 controls a mechanical motor within the lock mechanism 20 which causes the mechanical motor to open or close the physical lock (not shown). The mechanical motor can have associated gears in order to generate the torque required to move the physical lock. The physical lock may take many form factors including padlocks, deadbolts, mortises, rim locks, latches and electro-magnetic door locks.

[0115] The lock controller 30 includes a memory 40 capable of storing associated roles and permission levels of access right owners and access right grantees, biometric data, access details, logs of user interactions or associated timestamps and a record of the access right owner or administrator data. It also secures storage for authorized device information and maintains access logs and verification data. The memory 40 may be a volatile memory, for example a DRAM (Dynamic Random Access Memory) or a non-volatile memory, for example a PROM (Programmable Read Only Memory), an EPROM (Erasable PROM), EEPROM (Electrically Erasable PROM), or a flash memory, e.g., a floating gate memory, a charge trapping memory, an MRAM (Magneto resistive Random Access Memory) or a PCRAM (Phase Change Random Access Memory). In some embodiments, the lock controller 30 is integrated with the NFC controller 80 to provide the functions required to operate the NFC-powered electronic lock For example, the NFC controller 80 can include the functions of the lock controller 50 for operating the NFC-powered electronic lock 10 by operating the lock mechanism, authentication and communication with mobile devices or access management systems.

[0116] As used herein, the term ‘controller’ broadly refers to and is not limited to single or multicore general purpose processor, a special purpose processor, a conventional processor, a graphical processing unit, a digital signal processor (DSP), a plurality of microprocessors, one or more microprocessors in association with a DSP core, a controller, a microcontroller, one or more Application Specific Integrated Circuits (ASICs), one or more Field Programmable Gate Array (FPGA) circuits, any other type of integrated circuit, a system on a chip (SOC), and / or a state machine.

[0117] In some embodiments, the NFC-powered electronic lock 10 includes an additional power source (not shown) that provides power supply to the NFC-powered electronic lock. The power source can be a battery energy source, for example, a rechargeable battery.

[0118] While the invention has been particularly shown and described with reference to specific embodiments, it should be understood by those skilled in the art that various changes in form and detail may be made therein without departing from the spirit and scope of the invention as defined by the appended claims. The scope of the invention is thus indicated by the appended claims and allchanges which come within the meaning and range of equivalency of the claims are therefore intended to be embrace.

Claims

CLAIMS1. A system for secure access management of one or more access points secured by the respective one or more electronic locks, the system comprising: at least one processor; a server communicatively connected with an access management system; a memory communicatively connected to the at least one processor, the memory storing instructions which, when executed, cause the system to: receive a request for a guest credential associated with a guest user, the guest credential comprising one or more reader identifiers associated with one or more readers installed on the one or more electronic locks, a unique identifier associated with an access device, a command identifier and an access identity of the guest user, wherein the command identifier includes a duration command and a use command; send the request to the server configured to generate a payload key using a shared key stored in the server, the unique identifier and the one or more reader identifiers; encode the access device with an access code comprising the payload key and the guest credential, wherein the access code is configured to be received and authenticated by the one or more readers on close proximity to gain entry to the one or more respective electronic locks; revoke the access code on expiry of at least one of the duration command and the use command.

2. The system according to claim 1, wherein the one or more readers include the shared key configured to validate the access code to thereby send a control signal to the one or more electronic locks for controlling the said electronic locks.

3. The system according to claim 1 , wherein the server is configured to generate a master key using a reader key associated with the one or more reader identifiers, the unique identifier and the one or more reader identifiers.

4. The system according to claim 3, wherein the reader key is generated by the server using the shared key, the unique identifier and the one or more reader identifiers.

5. The system according to claim 1 , wherein the one or more electronic locks is an NF C-powered electronic lock.

6. The system according to claim 1 , wherein the access device is at least one of a mobile device, an NFC card, and a ticket.

7. The system according to claim 1 , wherein the duration command defines a predetermined time period between a start date and an end date.

8. The system according to claim 1, wherein the use command includes a reusable command and a non-reusable command, wherein the reusable command defines a predetermined number of unlock attempts subject to the duration command, and wherein the non-reusable command is configured to grant entry to the guest user within a predetermined time-period.

9. The system according to claim 9, wherein the non-reusable command is configured to grant entry to the guest user if a use quantity on the access code is more than a last-used quantity stored on the electronic lock.

10. An electronic lock for controlling access to a secured access point comprising: a lock mechanism coupled to a physical lock; a lock processor in electrical communication with the lock mechanism, a reader communicatively connected with the lock processor, wherein the reader includes a memory communicatively connected to the lock processor, the memory storing instructions which, when executed, cause the reader to: receive an access code from an access device provisioned to a guest user on close proximity to the reader, wherein the access code includes a payload key and a guest credential of a guest user, wherein the payload key is generated by a server using a shared key stored in the server, the unique identifier of the access device and a reader identifier associated with the reader; authenticate the access code by decrypting and validating the payload key using the shared key stored in the memory, wherein the shared key configured to generate the payload key is the same as the shared key stored in the memory;send a control signal to the lock processor to activate the lock mechanism to control the physical lock upon a successful authentication of the access code.

11. The electronic lock according to claim 10, wherein the guest credential comprises the reader identifier, the unique identifier, a command identifier and an access identity of the guest user, wherein the command identifier includes a duration command and a use command.

12. The electronic lock according to claim 10, wherein the access code is a QR code.

13. The electronic lock according to claim 10, wherein the access device is at least one of a mobile device, an NFC card, and a ticket.

14. The electronic lock according to claim 10, wherein the reader is an image sensing device.

15. The electronic lock according to claim 11, wherein the duration command defines a predetermined time period between a start date and an end date.

16. The electronic lock according to claim 11, wherein the use command includes a reusable command and a non-reusable command, wherein the reusable command defines a predetermined number of unlock attempts subject to the duration command, and wherein the non-reusable command is configured to grant entry to the guest user within a predetermined time-period.

17. The electronic lock according to claim 10, wherein the control signal for activating the lock mechanism to control the physical lock includes at least one of unlocking, locking and revoking access to the access code.

18. An NFC-powered electronic lock for controlling access to a secured access point comprising: a lock mechanism coupled to a physical lock; a lock processor in electrical communication with the lock mechanism, an NFC controller comprising a reader, an antenna and an NFC transceiver,wherein the NFC controller includes a memory communicatively connected to the lock processor, the memory storing instructions which, when executed, cause the reader to: receive an access code from an access device provisioned to a guest user on close proximity to the reader, wherein the access code includes a payload key and a guest credential of a guest user, wherein the payload key is generated by a server using a shared key stored in the server, the unique identifier of the access device and a reader identifier associated with the reader; authenticate the access code by decrypting and validating the payload key using the shared key stored in the reader, wherein the shared key configured to generate the payload key is the same as the shared key stored in the reader; send a control signal to the lock processor to activate the lock mechanism to control the physical lock upon a successful authentication of the access code.

19. The NFC-powered electronic lock according to claim 18, wherein the guest credential comprises the reader identifier, the unique identifier, a command identifier and an access identity of the guest user, wherein the command identifier includes a duration command and a use command.

20. The NFC-powered electronic lock according to claim 18, wherein the control signal for activating the lock mechanism to control the physical lock includes at least one of unlocking, locking and revoking access to the access code.

21. The NFC-powered electronic lock according to claim 18, further comprising: revoke the access code on expiry of at least one of the duration command and the use command.

22. The NFC-powered electronic lock according to claim 18, wherein the access device is an NFC- enabled card.

23. The NFC-powered electronic lock according to claim 19, wherein the duration command defines a predetermined time period between a start date and an end date.

24. The NFC-powered electronic lock according to claim 19, wherein the use command includes a reusable command and a non-reusable command, wherein the reusable command defines a predetermined number of unlock attempts subject to the duration command, and wherein the non-reusable command is configured to grant entry to the guest user within a predetermined time-period25. The NFC-powered electronic lock according to claim 18, further comprising: a rectifier configured to convert AC current received by the antenna to DC current; a capacitor in electrical communication with the rectifier for storing the converted DC current, wherein the stored DC current in the capacitor provides the power to the lock controller for locking and unlocking the lock mechanism.

26. A computer-implemented method for secure access management of one or more access points secured by the respective one or more electronic locks, the method comprising the steps of: receiving a request from a grantor for a guest credential associated with a guest user, the guest credential comprising one or more reader identifiers associated with one or more readers installed on the one or more electronic locks, a unique identifier associated with an access device, a command identifier and an access identity of the guest user, wherein the command identifier includes a duration command and a use command; sending the request to a server configured to generate a pay load key using a shared key stored in the server, the unique identifier and the one or more reader identifiers; encoding the access device with an access code comprising the payload key and the guest credential, wherein the access code is configured to be received and authenticated by the one or more readers on close proximity to gain entry to the one or more respective electronic locks; revoking the access code on expiry of at least one of the duration command and the use command.

Citation Information

Patent Citations

  • Intelligent lock unlocking method, intelligent lock, terminal, server and system

    CN109905235A

  • Wireless key management for authentication

    US20160036594A1

  • Operation communication system

    US20170243421A1

  • System and method for premise management

    US20200160638A1

  • Virtual identification for granting secure access using location data

    US20240129732A1