Secure factory-provisioned OSDP key distribution
By generating and storing a unique random SCBK in PAC readers during manufacturing, associated with identification information in a secure database, the system addresses vulnerabilities in conventional access control systems, ensuring secure key distribution and encrypted communication without relying on a default key.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- ASSA ABLOY AB
- Filing Date
- 2025-01-24
- Publication Date
- 2026-07-30
AI Technical Summary
Conventional access control systems rely on a publicly known default key (SCBK-D) for initial secure channel establishment between PAC readers and controllers, making them vulnerable to eavesdropping and man-in-the-middle attacks, as the initial secure session is not truly secure.
Implement a secure manufacturing-time provisioning process where a unique random SCBK is generated and stored in each PAC reader device during production, associated with identification information in a secure database, enabling secure key distribution and disabling the insecure install mode mechanism, allowing controllers to obtain the proper SCBK through authenticated web services during deployment.
This approach eliminates reliance on the vulnerable default key, ensuring secure key exchanges and encrypted communication between controllers and PAC readers, preventing eavesdropping and man-in-the-middle attacks by leveraging existing production infrastructure and secure web services.
Smart Images

Figure EP2025051833_30072026_PF_FP_ABST
Abstract
Description
SECURE FACTORY-PROVISIONED OSDP KEY DISTRIBUTIONBACKGROUND
[0001] Access control systems have become integral to securing physical spaces, ensuring that only authorized individuals can enter or exit specific areas. Physical access control (PAC) reader devices are wall-mounted readers that interface with controllers to manage secure access to facilities. These readers serve as the front-end hardware components that communicate with access control system controllers to authenticate and process credential information.BRIEF SUMMARY
[0002] In some aspects, the techniques described herein relate to a system including: one or more hardware processors; and at least one machine- storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations including: storing, during a manufacturing process, a unique random secure channel base key (SCBK) in a secure storage location of a PAC reader device; storing the unique random SCBK in association with identification information of the PAC reader device in a database; and causing a controller to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database.
[0003] In some aspects, the techniques described herein relate to a system, wherein the identification information includes at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.
[0004] In some aspects, the techniques described herein relate to a system, wherein the operations further include: disabling an install mode of the PAC reader device that uses a default secure channel base key.
[0005] In some aspects, the techniques described herein relate to a system, wherein storing the unique random SCBK includes injecting, by a production server, the unique random SCBK into a secure access module (SAM) of the PAC reader device.
[0006] In some aspects, the techniques described herein relate to a system, wherein the operations further include: reading, by a production server, the identification information from the PAC reader device during the manufacturing process.
[0007] In some aspects, the techniques described herein relate to a system, wherein the operations further include: communicating, by the production server, with the PAC reader device to obtain a response to a reader information command; and extracting, by the production server, the identification information from the response to the reader information command.
[0008] In some aspects, the techniques described herein relate to a system, wherein the operations further include: generating the unique random SCBK using a production server during the manufacturing process.
[0009] In some aspects, the techniques described herein relate to a system, wherein causing the controller to establish the secure channel session includes: providing the unique random SCBK to the controller from the database in response to receiving the identification information from the controller.
[0010] In some aspects, the techniques described herein relate to a system, wherein the controller performs operations including: communicating with the PAC reader device to obtain a response to a reader information command; and extracting the identification information from the response to the reader information command.
[0011] In some aspects, the techniques described herein relate to a system, wherein providing the unique random SCBK includes: receiving a request from the controller including the identification information read from the PAC reader device; and retrieving the unique random SCBK from the database using the received identification information.
[0012] In some aspects, the techniques described herein relate to a system, wherein providing the unique random SCBK includes: authenticating the controller with the database through a secure connection before providing access to the unique random SCBK; and transmitting the unique random SCBK to the controller through the secure connection.
[0013] In some aspects, the techniques described herein relate to a system, wherein the controller performs operations including: establishing, as the secure channel session, a secure Open Supervised Device Protocol (OSDP) communication session with the PAC reader using the unique random SCBK obtained through the secure connection with the database.
[0014] In some aspects, the techniques described herein relate to a system, wherein the controller performs operations including: enabling the controller to change the uniquerandom SCBK to a controller-generated SCBK after establishing the secure OSDP communication session.
[0015] In some aspects, the techniques described herein relate to a system, wherein the secure channel session enables encrypted communication of credential information between the controller and the PAC reader device.
[0016] In some aspects, the techniques described herein relate to a system, wherein the operations further include: encrypting the unique random SCBK before storing the unique random SCBK in the database.
[0017] In some aspects, the techniques described herein relate to a system, wherein the operations include: decrypting the encrypted unique random SCBK from the database using secure authentication credentials provided by the controller; and transmitting the decrypted unique random SCBK through a secure network connection.
[0018] In some aspects, the techniques described herein relate to a method including: storing, during a manufacturing process, a unique random SCBK in a secure storage location of a PAC reader device; storing the unique random SCBK in association with identification information of the PAC reader device in a database; and causing a controller to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database.
[0019] In some aspects, the techniques described herein relate to a method, wherein the identification information includes at least one of a serial number, a UUID, or an SNMP engine ID associated with the PAC reader device.
[0020] In some aspects, the techniques described herein relate to a method, further including: disabling an install mode of the PAC reader device that uses a default secure channel base key.
[0021] In some aspects, the techniques described herein relate to a machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations including: storing, during a manufacturing process, a unique random SCBK in a secure storage location of a PAC reader device; storing the unique random SCBK in association with identification information of the PAC reader device in a database; and causing a controller to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database.BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS
[0022] To easily identify the discussion of any particular element or act, the most significant digit or digits in a reference number refer to the figure number in which that element is first introduced.
[0023] FIG. 1 is a diagrammatic representation of a networked environment in which the present disclosure may be deployed, in accordance with some examples.
[0024] FIG. 2 illustrates a diagram for provisioning a PAC reader, in accordance with some examples.
[0025] FIG. 3 illustrates a database that stores SCBK information, in accordance with some examples.
[0026] FIG. 4 illustrates a routine for provisioning a PAC reader, in accordance with some examples.
[0027] FIG. 5 is a block diagram illustrating a representative software architecture, which may be used in conjunction with various hardware architectures herein described, in accordance with some examples.
[0028] FIG. 6 is a diagrammatic representation of a machine in the form of a computer system within which a set of instructions may be executed for causing the machine to perform any one or more of the methodologies discussed herein, in accordance with some examples.DETAILED DESCRIPTION
[0029] Example methods and systems for an access control system are described. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the disclosed examples. It will be evident, however, to one of ordinary skill in the art that examples of the disclosure may be practiced without these specific details.
[0030] Conventional approaches to securing communications between PAC readers and controllers rely on the OSDP specification's "install mode" mechanism. The install mode uses a default key known as SCBK-D (Secure Channel Base Key - Default). This default key consists of a known sequence (0x30, 0x31, 0x32... 0x3E, 0x3F) that is published and accessible to everyone. Conventionally, readers are shipped and delivered with "install mode" enabled by default. Using the known SCBK-D, the controller (at a customer premises) initiates what appears to be a secure OSDP session. Once this initial session isestablished using the default key, the controller can then use the osdp KEYSET command to change the SCBK-D to a new value. After changing the key to the new value, the initial secure session is dropped and install mode is disabled. Then, the controller can establish a new secure session with the PAC reader using the newly changed SCBK.
[0031] This conventional approach has a fundamental security flaw. Since the SCBK-D is publicly known, the initial "secure" session created with this default key is not actually secure at all. Any eavesdropper can decode the encrypted OSDP traffic during this key exchange process, allowing the eavesdropper to discover the newly changed SCBK. Once an attacker obtains the new SCBK, the attacker can decode all subsequent OSDP traffic, including credential information and other sensitive communications.
[0032] The OSDP specification attempts to mitigate this vulnerability by suggesting to enable the install mode only in a "secure environment." However, some controller implementations always remain in install mode. Therefore a man-in-the middle attack could force the secure session to be dropped and restarted allowing the attacker to decrypt all future communications.
[0033] The disclosed system addresses these technical issues by implementing a secure manufacturing-time provisioning process. In this process, a unique random SCBK can be generated and injected / stored into secure storage of each PAC reader device during production. This approach eliminates reliance on the vulnerable default key by storing the unique SCBK in association with reader identification information in a secure database. When deployment occurs (e.g., when the PAC reader is delivered to a customer), controllers at the customer premises can securely obtain the proper SCBK through an authenticated web service connection with the secure database, rather than using the published default key. The system enables secure key distribution by leveraging existing production infrastructure and secure web services to manage key provisioning and distribution, while completely disabling the insecure install mode mechanism. Namely, the PAC reader device can be delivered with the install mode disabled by default, which provides for a secure connection between the controller at a customer premises and the PAC reader device. This eliminates the need for manual key setup in supposedly "secure environments" and prevents eavesdroppers from intercepting key exchanges, since the initial key sharing occurs during manufacturing rather than during field installation.
[0034] Specifically, the disclosed techniques can configure a PAC reader device. The disclosed techniques can store, during a manufacturing process, a unique random SCBK in a secure storage location of a PAC reader device. The disclosed techniques can store the unique random SCBK in association with identification information of the PAC reader device in a database and can cause a controller to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database.
[0035] FIG. 1 is a block diagram showing an example access control system 103, according to various examples. The access control system 103 can include a client device 104 (e.g., mobile device), a production server 105, a controller 106, server 107, and PAC device 101. The client device 104 (which can in some cases perform functionality of the controller 106) and the PAC device 101 are communicatively coupled over a network 102 (e.g., Internet, BLE, ultra-wideband (UWB) communication protocol, Near Field Communication (NFC), and / or telephony network) with each other and with the server 107. In some cases, the production server 105 and the server 107 can be the same servers or part of the same system or component even though they are drawn as separate components. While the disclosed techniques are discussed in the context of PAC devices, similar techniques are applicable to any other type of access control device, such as a logical access control (LAC) device.
[0036] As used herein, the term “client device” may refer to any machine that interfaces to a communications network (such as network 102) to exchange credentials with an access control device, such as the PAC device 101, the server 107 associated with the access control device, another client device 104, or any other component to obtain access to a logical or physical asset or resource protected by the access control device. In some examples, the client device 104 can additionally or alternatively communicate directly with, for example, an access control device or another client device 104. The client device 104 can include or store one or more credentials which can be provided to the access control device 101 for obtaining access to a protected physical or logical asset or resource.
[0037] A client device 104 may be, but is not limited to, a mobile phone, desktop computer, laptop, portable digital assistant (PDA), smart phone, a wearable device (e.g., a smart watch), tablet, ultrabook, netbook, multi-processor system, microprocessor-basedor programmable consumer electronics, physical card, or any other communication device that a user may use to access a network.
[0038] The access control device (e.g., the PAC device 101) can include an access reader device (also referred to as an access control reader) connected to a secure / protected resource (e.g., a door locking mechanism or backend server) that controls the secure / protected resource (e.g., door locking mechanism). The resource associated with the access control device can include a door lock, an ignition system for a vehicle, or any other device that grants or denies access to a physical component or that can be operated to grant or deny access to the physical component. For example, in the case of a door lock, the access control device can deny access, in which case the door lock remains locked and the door cannot be opened; or can grant access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, the access control device can deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or can grant access, in which case the vehicle ignition becomes enabled to allow the vehicle to be started.
[0039] PAC covers a range of systems and methods to govern access, for example by people, to secure areas or secure assets. PAC includes identification of authorized users or devices (e.g., vehicles, drones, etc.) and actuation of a gate, door, or other facility used to secure an area, or actuation of a control mechanism, for example, a physical or electronic / software control mechanism, permitting access to a secure asset. The access control device may form part of a physical access control system (PACS), which can include a reader (e.g., an online or offline reader) that may hold authorization data (also referred to access control information) and can be capable of determining whether credentials (e.g., from credential or key devices such as radio frequency identification (RFID) chips in cards, fobs, or personal electronic devices such as mobile phones) are authorized for an actuator or control mechanism (e.g., door lock, door opener, software control mechanism, turning off an alarm, etc.), or a PACS can include a host server 107 to which readers and actuators are connected (e.g., via a controller) in a centrally managed configuration.
[0040] In centrally managed configurations, readers can obtain credentials from credential or key devices (e.g., from one or more client devices 104) and pass those credentials to the PACS host server (e.g., server 107) or headend system. The readerscan send the credentials over a wired or wireless link, such as network 102. The host server then determines whether the credentials authorize access to the secure area or secure asset (or resource) and commands the actuator or other control mechanism of the PAC device 101 accordingly by sending an allow / deny message back to the reader over the wired or wireless link. While examples in physical access control are used herein, the disclosure applies similarly to LACS use cases (e.g., logical access to personal electronic devices, logical access to personal online or electronic accounts or documents, etc.).
[0041] In general, the PAC device 101 can include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, a display, and a power source or supply. The memory of the PAC device 101 can be used in connection with the execution of application programming or instructions by the processor of the PAC device 101, and for the temporary or long-term storage of program instructions or instruction sets and / or credential or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory can contain executable instructions that are used by the processor to run other components of PAC device 101 and / or to make access determinations based on credential or authorization data, such as by communicating with the authorization system 108 of the server 107.
[0042] The memory of the PAC device 101, server 107, and / or client device 104 can include a transitory or non-transitory computer-readable medium. The computer-readable medium can be, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer-readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device.Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar examples of computer-readable media.
[0043] The processor of the PAC device 101 can correspond to one or more computer processing devices or resources. For instance, the processor can be provided as silicon,as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, the processor can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory and / or memory of the access control device.
[0044] The antenna of the PAC device 101 can correspond to one or multiple antennas and can be configured to provide for wireless communications between PAC device 101 and a credential or key device (e.g., client device 104). The antenna can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 602.15.1, Bluetooth, BLE, NFC, ZigBee, Global System for Mobile communications (GSM), Code Division Multiple Access (CDMA), Wi-Fi, RF, UWB, and the like. By way of example, the antenna(s) can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by a credential or key device having an RF transceiver.
[0045] A communication module or communication component of the PAC device 101 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to the PAC device 101, such as one or more client devices 104 and / or servers / controllers, such as server 107. In some cases, the communication module uses a same wired or wireless link between the PAC device 101 and the server 107 for all the communication modes. In some cases, the communication module uses one wired or wireless link between the PAC device 101 and the server 107 to communicate access control information to the authorization system 108 and uses a different wired or wireless link to communicate or receive configuration information updates from the server 107 over the Internet Protocol (IP) communication mode.
[0046] The network interface device of the PAC device 101 includes hardware to facilitate communications with other devices, such as a one or more client devices 104 and / or server / controller (e.g., server 107, controller 106, and / or production server 105), over a communication network, such as network 102, utilizing any one of a number of transfer protocols (e.g., frame relay, IP, transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network(WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 602.11 family of standards known as Wi-Fi, IEEE 602.16 family of standards known as WiMax), IEEE 602.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.
[0047] A user interface of the PAC device 101 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in the user interface include, without limitation, one or more buttons, a keyboard or keypad, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, and so forth.Examples of suitable user output devices that can be included in the user interface include, without limitation, one or more light emitting diodes (LEDs), an liquid crystal display (LCD) panel, a display screen, a touchscreen, one or more lights, a speaker, and so forth. It should be appreciated that the user interface can also include a combined user input and user output device, such as a touch-sensitive display or the like.
[0048] The network 102 may include, or operate in conjunction with, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a LAN, a wireless network, a wireless LAN (WLAN), a WAN, a wireless WAN (WWAN), a metropolitan area network (MAN), BLE, UWB, the Internet, a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless or cellular network and the coupling may be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling may implement any of a variety of types of data transfer technology, such as Single Carrier Radio Transmission Technology (IxRTT), Evolution-Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, third Generation Partnership Project (3GPP) including 3G, fourth generation wireless (4G) networks, fifthgeneration wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standard, others defined by various standard setting organizations, other short range or long range protocols, or other data transfer technology.
[0049] In an example, as the client device 104 approaches the PAC device 101 (e.g., comes within range of a BLE communication protocol), the client device 104 transmits credentials of the client device 104 over the network 102. In one example, the client device 104 provides the credentials directly to the PAC device 101. In such cases, the PAC device 101 communicates the credentials with the server 107. The server 107 includes an authorization system 108. The server 107, client device 104, and / or the PAC device 101 can further include elements described with respect to FIG. 5 and FIG. 6, such as a processor and memory, having instructions stored thereon, that when executed by the processor, causes the processor to control the functions of the server / controller, client device 104, and / or the PAC device 101. The server 107 can be implemented on a centralized set of servers of a cloud-based system.
[0050] The server 107 searches a list of credentials stored in the authorization system 108 to determine whether the received credentials match credentials from the list of authorized credentials for accessing a secure asset or resource (e.g., door or secure area) protected by the PAC device 101. In response to determining that the received credentials are authorized to access the PAC device 101, the server 107 (also referred to as the controller) instructs the PAC device 101 to perform an operation granting access for the client device 104 (e.g., instructing the PAC device 101 to unlock a lock of a door).
[0051] In some examples, the PAC device 101 serves as a wall-mounted reader that interfaces with controllers (e.g., the controller 106 and / or the server 107) to manage secure access to facilities. In some cases, functionality of the controller 106 can be included as part of the server 107 and / or the client device 104. During the manufacturing process, the production server 105 injects or stores a unique random SCBK into the PAC device's secure storage location. For example, during the manufacturing process, the production server 105 executes a comprehensive sequence of operations to securely provision each PAC device 101 with unique encryption keys. The process begins with the production server 105 generating a unique random SCBK specifically for eachindividual PAC reader device being manufactured. This unique SCBK is then securely injected into a designated storage location within the reader's SAM, where it is stored alongside other critical configuration data in a specific Object Identifier (OID) storage area.
[0052] Before or after the key injection / storage, the production server 105 can initiate communication with the PAC device 101 to obtain identification information through a reader information command. The production server 105 extracts unique identifying details including the PAC device 101 serial number, UUID, and / or SNMP engine ID from the reader's response to the reader information command. This extracted identification information, along with the corresponding unique random SCBK, can then be securely stored in a database maintained by the production server 105. This creates a permanent association between each PAC device 101 identity and its unique encryption key. As a final security measure during the provisioning process, the production server 105 can explicitly disable the install mode functionality of the PAC device 101 that may rely on the default secure channel base key (SCBK-D). This step ensures that the PAC device 101 can only utilize its securely injected / stored unique random SCBK for future communications, which can eliminate the vulnerability associated with the default key mechanism.
[0053] In some cases, the server 107 includes an authorization system 108 that maintains the secure database storing the unique random SCBKs in association with reader identification information. In some cases, this database can be part of or stored on the production server 105. This identification information can include serial numbers, UUIDs, and SNMP engine IDs that uniquely identify each PAC device 101.
[0054] The controller 106 communicates with both the PAC device 101 and the server 107 and / or the production server 105 to establish secure communications. The controller 106 can first read identification information from the PAC device 101 through an OSDP manufacturing command. The controller 106 can then extract identification information from a response received from the PAC device 101 based on the OSDP manufacturing command. The controller 106 can provide this extracted information to the production server 105 and / or the server 107. For example, the authorization system 108 can authenticate the controller 106 requesting access to stored SCBKs. When the controller 106 provides valid reader identification information to the production server 105 and / orthe server 107, the authorization system 108 can retrieve and securely transmit the corresponding unique random SCBK through an encrypted connection.
[0055] The controller 106 uses the retrieved SCBK to establish a secure OSDP channel session with the PAC device 101. This enables encrypted communication of credential information between the controller 106 and PAC device 101 without relying on the vulnerable default key approach. The entire system operates with the PAC device's install mode disabled, preventing use of the default SCBK-D. This ensures all key exchanges occur through the secure web service infrastructure rather than through potentially compromised field installations.
[0056] FIG. 2 illustrates a diagram 204 for provisioning a PAC reader 210, in accordance with some examples. The PAC reader 210 can represent a single instance of the PAC device 101 but similar operations can be performed for other PAC devices 101. Specifically, the diagram 204 illustrates a comprehensive factory provisioning and field installation process for secure SCBK distribution. The process begins at a production facility where a production server (e.g., the production server 105) generates and injects or stores unique random SCBKs into PAC reader devices during manufacturing, such as the PAC reader 210.
[0057] In certain examples, the production server 105 first generates a unique random SCBK specifically for each individual PAC reader device being manufactured. This random key generation ensures that each PAC reader 210 receives its own unique encryption key, rather than relying on a shared or default key. During the manufacturing process, in some cases, the production server 105 injects the generated unique random SCBK into a SAM of the PAC reader 210. The SCBK can be stored in a designated OID storage location within the SAM, alongside other configuration data.
[0058] Following key injection / storage, in some implementations, the production server 105 communicates with the PAC reader 210 to obtain identification information of the PAC reader 210 through a reader information command. The PAC reader 210 can establish a secure or un-secure connection (e.g., an OSDP connection) with the PAC reader 210 and transmit the reader information command. In response, the PAC reader 210 provides a response including various configuration information via the connection, such as the OSDP connection. The production server 105 extracts identifying details including the PAC reader 210 serial number, UUID, and / or SNMP engine ID from the response.
[0059] In certain circumstances, the production server 105 stores both the unique random SCBK and the extracted reader identification information in a secure database 208. For example, an example database 308 representing the contents of the database 208 is shown in FIG. 3. The database 308 can include multiple entries. Each entry can include a reader identification information field and a corresponding SCBK field. For example, the PAC device 101 can be associated with an entry that includes the reader identification information 1 304 and the SCBK 1 306. This creates a permanent association between each reader's identity and its unique encryption key. This database 208 serves as a secure repository for later key retrieval during field installation. In some cases, the information stored in the database 308 is encrypted by the production server 105 to enhance security.
[0060] As part of the manufacturing process, in some examples, the production server 105 explicitly disables the reader's install mode functionality that would typically rely on the default secure channel base key (SCBK-D). This security measure ensures the PAC reader device can only utilize its securely injected unique random SCBK. The PAC reader 210 can then be delivered to a customer premises, such as with the OSDP install mode in a disabled state.
[0061] During field installation, in some implementations, the controller 106 first reads the reader information command from the PAC reader 210 using OSDP manufacturing commands. This allows the controller 106 to obtain the necessary identification information to request the correct SCBK from the server. For example, the controller 106 transmits the reader information command through a secure or non-secure OSDP communication session with the PAC reader 210. The controller 106 receives a response from the PAC reader 210 via the OSDP session. The response can include various information from which the controller 106 extracts or retrieves the reader identification information - including serial number, UUID, and SNMP engine ID. This reader identification information serves as a unique identifier to request the corresponding SCBK from the secure database 208.
[0062] Following identification extraction, in some examples, the controller 106 establishes a secure connection with the database 208, such as via the production server 105. This connection can use HTTPS or another secure protocol to ensure the confidentiality of subsequent communications. In some circumstances, the controller 106 authenticates itself with the production server 105 or the database 208 before requestingaccess to any SCBKs. This authentication process helps ensure that only authorized controllers can retrieve the secure keys.
[0063] Once authenticated, in certain implementations, the controller 106 provides the extracted reader identification information to the database 208. The database 208 uses this information to locate the corresponding unique random SCBK. For example, the controller 106 transmits the reader identification information. The database 208 searches the database 308 to find an entry having a reader identification information field that matches. For example, the database 308 may determine that the reader identification information 1 304 matches the reader identification information received from the controller 106. In response, the production server 105 provides a response to the controller 106 that includes the corresponding SCBK 1 306 retrieved from the database 308.
[0064] The production server 105 can transmit the factory-injected SCBK which has been retrieved from the database 208 to the controller 106 through the secure connection. In some cases, the production server 105 can decrypt the SCBK prior to transmitting the SCBK to the controller 106. In some cases, the production server 105 transmits the SCBK retrieved from the database 308 in encrypted form. The controller 106 can separately communicate with the production server 105 to obtain a decryption key to decrypt the encrypted SCBK after or before receiving the encrypted SCBK from the production server 105. Upon receiving the SCBK (and optionally decrypting the SCBK), in certain circumstances, the controller 106 can establish an OSDP secure session with the PAC reader 210 using the downloaded or retrieved SCBK. This creates an encrypted communication channel between the controller 106 and PAC reader 210.
[0065] In some implementations, after establishing the secure session, the controller 106 may optionally use the OSDP KEYSET command to change the SCBK that is currently stored in the secure storage of the PAC reader 210 (e.g., in the SAM of the PAC reader 210) to a new random value. This new random value may be locally generated by the controller 106. During the entire process, in some cases, the system maintains detailed audit logs of key access and changes. This helps track and monitor all interactions with the secure keys.
[0066] FIG. 4 illustrates a routine 400 (e.g., method or process) in accordance with some examples. The operations discussed in connection with FIG. 4 can be performedsequentially, in parallel, and in any suitable order. The operations discussed in FIG. 4 can be performed by the access control system 103.
[0067] In operation 402, a production server 105 stores, during a manufacturing process, a unique random SCBK in a secure storage location of a PAC reader device, as discussed above.
[0068] In operation 404, the production server 105 stores the unique random SCBK in association with identification information of the PAC reader device in a database, as discussed above.
[0069] In operation 406, the production server 105 causes a controller 106 to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database, as discussed above.
[0070] FIG. 5 is a block diagram illustrating an example of a software architecture 502 that may be installed on a machine, according to some examples. FIG. 5 is merely a nonlimiting example of a software architecture, and it will be appreciated that many other architectures may be implemented to facilitate the functionality described herein. The software architecture 502 may be executing on hardware such as a machine 600 of FIG.6 that includes, among other things, processors 610, memory 604, and input / output (I / O) components 642. A representative hardware layer 544 is illustrated and can represent, for example, the machine 600 of FIG. 6. The representative hardware layer 544 comprises one or more processing units 546 having associated executable instructions 548. The executable instructions 548 represent the executable instructions of the software architecture 502. The hardware layer 544 also includes memory 604, which also have the executable instructions 548. The hardware layer 544 may also comprise other hardware 552, which represents any other hardware of the hardware layer 544, such as the other hardware illustrated as part of the machine 600.
[0071] The instructions 548 may be transmitted or received over the network using a transmission medium via a network interface device (e.g., a network interface component included in the communication components 640) and utilizing any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 548 may be transmitted or received using a transmission medium via the coupling (e.g., a peer-to-peer coupling) to the devices. The terms “transmission medium” and “signal medium” mean the same thing and may be used interchangeably in this disclosure. The terms “transmission medium” and “signalmedium” shall be taken to include any intangible medium that is capable of storing, encoding, or carrying the instructions 548 for execution by the machine 600, and include digital or analog communications signals or other intangible media to facilitate communication of such software. Hence, the terms “transmission medium” and “signal medium” shall be taken to include any form of modulated data signal, carrier wave, and so forth. The term “modulated data signal” means a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal.
[0072] The terms “machine-readable medium,” “computer-readable medium,” and “device-readable medium” mean the same thing and may be used interchangeably in this disclosure. The terms are defined to include both machine-storage media and transmission media. Thus, the terms include both storage devices / media and carrier waves / modulated data signals.
[0073] As used herein, the terms “machine-storage medium,” “device-storage medium,” and “computer-storage medium” mean the same thing and may be used interchangeably in this disclosure. The terms refer to a single or multiple storage devices and / or media (e.g., a centralized or distributed database, and / or associated caches and servers) that store executable instructions and / or data. The terms shall accordingly be taken to include, but not be limited to, solid-state memories, and optical and magnetic media, including memory internal or external to processors. Specific examples of machinestorage media, computer-storage media, and / or device-storage media include nonvolatile memory, including by way of example semiconductor memory devices, e.g., erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), field-programmable gate arrays (FPGAs), and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto -optical disks; and CD-ROM and DVD-ROM disks. The terms “machinestorage medium,” “computer-storage medium,” and “device- storage medium” are non-transitory computer-readable media and specifically exclude carrier waves, modulated data signals, and other such media, at least some of which are covered under the term “signal medium.”
[0074] In the example architecture of FIG. 5, the software architecture 502 may be conceptualized as a stack of layers, where each layer provides particular functionality. For example, the software architecture 502 may include layers such as an operating system 536, libraries 528, frame work / middleware 522, applications 516, and a presentation layer514. Operationally, the applications 516 or other components within the layers may invoke API calls API calls 524 through the software stack and receive a response, returned values, and so forth (illustrated as messages 526) in response to the API calls 524. The layers illustrated are representative in nature, and not all software architectures have all layers. For example, some mobile or special -purpose operating systems may not provide a framework / middleware 522 layer, while others may provide such a layer. Other software architectures may include additional or different layers.
[0075] The operating system 536 may manage hardware resources and provide common services. The operating system 536 may include, for example, a kernel 538, services 540, and drivers 542. The kernel 538 may act as an abstraction layer between the hardware and the other software layers. For example, the kernel 538 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, and so on. The services 540 may provide other common services for the other software layers. The drivers 542 may be responsible for controlling or interfacing with the underlying hardware. For instance, the drivers 542 may include display drivers, camera drivers, Bluetooth® drivers, flash memory drivers, serial communication drivers (e.g., Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, and so forth depending on the hardware configuration.
[0076] The libraries 528 may provide a common infrastructure that may be utilized by the applications 516 and / or other components and / or layers. The libraries 528 typically provide functionality that allows other software modules to perform tasks in an easier fashion than by interfacing directly with the underlying operating system 536 functionality (e.g., kernel 538, services 540, or drivers 542). The libraries 528 may include system libraries 530 (e.g., C standard library) that may provide functions such as memory allocation functions, string manipulation functions, mathematic functions, and the like. In addition, the libraries 528 may include API libraries 532 such as media libraries (e.g., libraries to support presentation and manipulation of various media formats such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG), graphics libraries (e.g., an OpenGL framework that may be used to render 2D and 3D graphic content on a display), database libraries (e.g., SQLite that may provide various relational database functions), web libraries (e.g., WebKit that may provide web browsing functionality), and the like. The libraries 528 may also include a wide variety of other libraries 534 to provide many other APIs to the applications 516 and other software components / modules.
[0077] The frameworks / middleware 522 (also sometimes referred to as middleware) may provide a higher-level common infrastructure that may be utilized by the applications 516 or other software components / modules. For example, the frameworks / middleware 522 may provide various graphical user interface functions, high-level resource management, high-level location services, and so forth. The frameworks / middleware 522 may provide a broad spectrum of other APIs that may be utilized by the applications 516 and / or other software components / modules, some of which may be specific to a particular operating system or platform.
[0078] The applications 516 include built-in applications 518 and / or third-party applications 520. Examples of representative built-in applications 518 may include, but are not limited to, a home application, a contacts application, a browser application, a book reader application, a location application, a media application, a messaging application, or a game application.
[0079] The third-party applications 520 may include any of the built-in applications 518, as well as a broad assortment of other applications. In a specific example, the third-party applications 520 (e.g., an application developed using the Android™ or iOS™ software development kit (SDK) by an entity other than the vendor of the particular platform) may be mobile software running on a mobile operating system such as iOS™, Android™, or other mobile operating systems. In this example, the third-party applications 520 may invoke the API calls 524 provided by the mobile operating system such as the operating system 536 to facilitate functionality described herein.
[0080] The applications 516 may utilize built-in operating system functions (e.g., kernel 538, services 540, or drivers 542), libraries (e.g., system libraries 530, API libraries 532, and other libraries 534), or framework / middleware 422 to create user interfaces to interact with users of the system. Alternatively, or additionally, in some systems, interactions with a user may occur through a presentation layer, such as the presentation layer 514. In these systems, the application / module “logic” can be separated from the aspects of the application / module that interact with the user.
[0081] Some software architectures utilize virtual machines. In the example of FIG. 5, this is illustrated by a virtual machine 504. The virtual machine 504 creates a software environment where applications / modules can execute as if they were executing on a hardware machine (e.g., the machine 600 of FIG. 6). The virtual machine 504 is hosted by a host operating system (e.g., the operating system 536) and typically, although notalways, has a virtual machine monitor, which manages the operation of the virtual machine 504 as well as the interface with the host operating system (e.g., the operating system 536). A software architecture executes within the virtual machine 504, such as an operating system 512, libraries 510, frameworks 508, applications 516, or a presentation layer 506. These layers of software architecture executing within the virtual machine 504 can be the same as corresponding layers previously described or may be different.
[0082] FIG. 6 is a diagrammatic representation of the machine 600 within which instructions 608 (e.g., software, a program, an application, an applet, an app, or other executable code) for causing the machine 600 to perform any one or more of the methodologies discussed herein may be executed. For example, the instructions 608 may cause the machine 600 to execute any one or more of the methods described herein. The instructions 608 transform the general, non-programmed machine 600 into a particular machine 600 programmed to carry out the described and illustrated functions in the manner described. The machine 600 may operate as a standalone device or may be coupled (e.g., networked) to other machines. In a networked deployment, the machine 600 may operate in the capacity of a server machine or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine 600 may comprise, but not be limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a set-top box (STB), a PDA, an entertainment media system, a cellular telephone, a smart phone, a mobile device, a wearable device (e.g., a smart watch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of executing the instructions 608, sequentially or otherwise, that specify actions to be taken by the machine 600. Further, while only a single machine 600 is illustrated, the term “machine” shall also be taken to include a collection of machines that individually or jointly execute the instructions 608 to perform any one or more of the methodologies discussed herein.
[0083] The machine 600 may include processors 602, memory 604, and I / O components 642, which may be configured to communicate with each other via a bus 644. In an example, the processors 602 (e.g., a Central Processing Unit (CPU), a Reduced Instruction Set Computing (RISC) processor, a Complex Instruction Set Computing (CISC) processor, a Graphics Processing Unit (GPU), a Digital Signal Processor (DSP), an ASIC, a Radio-Frequency Integrated Circuit (RFIC), anotherprocessor, or any suitable combination thereof) may include, for example, a processor 606 and a processor 610 that execute the instructions 608. The term “processor” is intended to include multi-core processors that may comprise two or more independent processors (sometimes referred to as “cores”) that may execute instructions contemporaneously. Although FIG. 6 shows multiple processors 602, the machine 600 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiples cores, or any combination thereof.
[0084] The memory 604 includes a main memory 612, a static memory 614, and a storage unit 616, both accessible to the processors 602 via the bus 644. The main memory 604, the static memory 614, and storage unit 616 store the instructions 608 embodying any one or more of the methodologies or functions described herein. The instructions 608 may also reside, completely or partially, within the main memory 612, within the static memory 614, within machine-readable medium 618 within the storage unit 616, within at least one of the processors 602 (e.g., within the processor’s cache memory), or any suitable combination thereof, during execution thereof by the machine 600.
[0085] The I / O components 642 may include a wide variety of components to receive input, provide output, produce output, transmit information, exchange information, capture measurements, and so on. The specific I / O components 642 that are included in a particular machine will depend on the type of machine. For example, portable machines such as mobile phones may include a touch input device or other such input mechanisms, while a headless server machine will likely not include such a touch input device. It will be appreciated that the I / O components 642 may include many other components that are not shown in FIG. 6. In various examples, the I / O components 642 may include output components 628 and input components 630. The output components 628 may include visual components (e.g., a display such as a plasma display panel (PDP), a light emitting diode (LED) display, a liquid crystal display (LCD), a projector, or a cathode ray tube (CRT)), acoustic components (e.g., speakers), haptic components (e.g., a vibratory motor, resistance mechanisms), other signal generators, and so forth. Theinput components 630 may include alphanumeric input components (e.g., a keyboard, a touch screen configured to receive alphanumeric input, a photo-optical keyboard, or other alphanumeric input components), point-based input components (e.g., a mouse, atouchpad, a trackball, a joystick, a motion sensor, or another pointing instrument), tactile input components (e.g., a physical button, a touch screen that provides location and / or force of touches or touch gestures, or other tactile input components), audio input components (e.g., a microphone), and the like.
[0086] In further examples, the I / O components 642 may include biometric components 632, motion components 634, environmental components 636, or position components 638, among a wide array of other components. For example, the biometric components 632 include components to detect expressions (e.g., hand expressions, facial expressions, vocal expressions, body gestures, or eye tracking), measure biosignals (e.g., blood pressure, heart rate, body temperature, perspiration, or brain waves), identify a person (e.g., voice identification, retinal identification, facial identification, fingerprint identification, or electroencephalogram-based identification), and the like. The motion components 634 include acceleration sensor components (e.g., accelerometer), gravitation sensor components, rotation sensor components (e.g., gyroscope), and so forth. The environmental components 636 include, for example, illumination sensor components (e.g., photometer), temperature sensor components (e.g., one or more thermometers that detect ambient temperature), humidity sensor components, pressure sensor components (e.g., barometer), acoustic sensor components (e.g., one or more microphones that detect background noise), proximity sensor components (e.g., infrared sensors that detect nearby objects), gas sensors (e.g., gas detection sensors to detection concentrations of hazardous gases for safety or to measure pollutants in the atmosphere), or other components that may provide indications, measurements, or signals corresponding to a surrounding physical environment. The position components638 include location sensor components (e.g., a GPS receiver component), altitude sensor components (e.g., altimeters or barometers that detect air pressure from which altitude may be derived), orientation sensor components (e.g., magnetometers), and the like.
[0087] Communication may be implemented using a wide variety of technologies. The I / O components 642 further include communication components 640 operable to couple the machine 600 to a network 620 or devices 622 via a coupling 624 and a coupling 626, respectively. For example, the communication components 640 may include a network interface component or another suitable device to interface with the network 620. In further examples, the communication components 640 may include wiredcommunication components, wireless communication components, cellular communication components, Near Field Communication (NFC) components, Bluetooth® components (e.g., Bluetooth® Low Energy), Wi-Fi® components, and other communication components to provide communication via other modalities. The devices 622 may be another machine or any of a wide variety of peripheral devices (e.g., a peripheral device coupled via a USB).
[0088] Moreover, the communication components 640 may detect identifiers or include components operable to detect identifiers. For example, the communication components 640 may include Radio Frequency Identification (RFID) tag reader components, NFC smart tag detection components, optical reader components (e.g., an optical sensor to detect one-dimensional bar codes such as Universal Product Code (UPC) bar code, multi-dimensional bar codes such as Quick Response (QR) code, Aztec code, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D bar code, and other optical codes), or acoustic detection components (e.g., microphones to identify tagged audio signals). In addition, a variety of information may be derived via the communication components 640, such as location via Internet Protocol (IP) geolocation, location via Wi-Fi® signal triangulation, location via detecting an NFC beacon signal that may indicate a particular location, and so forth.
[0089] The various memories (e.g., memory 604, main memory 612, static memory 614, and / or memory of the processors 602) and / or storage unit 616 may store one or more sets of instructions and data structures (e.g., software) embodying or used by any one or more of the methodologies or functions described herein. These instructions (e.g., the instructions 608), when executed by processors 602, cause various operations to implement the disclosed examples.
[0090] The instructions 608 may be transmitted or received over the network 620, using a transmission medium, via a network interface device (e.g., a network interface component included in the communication components 640) and using any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 608 may be transmitted or received using a transmission medium via the coupling 626 (e.g., a peer-to-peer coupling) to the devices 622.
[0091] Although examples have been described, it will be evident that various modifications and changes may be made to these examples without departing from the broader scope of the present disclosure. Accordingly, the specification and drawings areto be regarded in an illustrative rather than a restrictive sense. The accompanying drawings that form a part hereof, show by way of illustration, and not of limitation, specific examples in which the subject matter may be practiced. The examples illustrated are described in sufficient detail to enable those skilled in the art to practice the teachings disclosed herein. Other examples may be utilized and derived therefrom, such that structural and logical substitutions and changes may be made without departing from the scope of this disclosure. This Detailed Description, therefore, is not to be taken in a limiting sense, and the scope of various examples is defined only by the appended claims, along with the full range of equivalents to which such claims are entitled.
[0092] Such examples of the inventive subject matter may be referred to herein, individually and / or collectively, by the term "invention" merely for convenience and without intending to voluntarily limit the scope of this application to any single invention or inventive concept if more than one is in fact disclosed. Thus, although specific examples have been illustrated and described herein, it should be appreciated that any arrangement calculated to achieve the same purpose may be substituted for the specific examples shown. This disclosure is intended to cover any and all adaptations or variations of various examples. Combinations of the above examples, and other examples not specifically described herein, will be apparent to those of skill in the art upon reviewing the above description.
[0093] The Abstract of the Disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in a single example for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed examples require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter lies in less than all features of a single disclosed example. Thus the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate example.
[0094] In view of the disclosure above, various examples are set forth below. It should be noted that one or more features of an example, taken in isolation or combination, should be considered within the disclosure of this application.
[0095] Example 1. A system comprising: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising: storing, during a manufacturing process, a unique random secure channel base key (SCBK) in a secure storage location of a physical access control (PAC) reader device; storing the unique random SCBK in association with identification information of the PAC reader device in a database; and causing a controller to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database.
[0096] Example 2. The system of Example 1, wherein the identification information comprises at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.
[0097] Example 3. The system of any one of Examples 1-2, wherein the operations further comprise: disabling an install mode of the PAC reader device that uses a default secure channel base key.
[0098] Example 4. The system of any one of Examples 1-3, wherein storing the unique random SCBK comprises injecting, by a production server, the unique random SCBK into a secure access module (SAM) of the PAC reader device.
[0099] Example 5. The system of any one of Examples 1-4, wherein the operations further comprise: reading, by a production server, the identification information from the PAC reader device during the manufacturing process.
[0100] Example 6. The system of Example 5, wherein the operations further comprise: communicating, by the production server, with the PAC reader device to obtain a response to a reader information command; and extracting, by the production server, the identification information from the response to the reader information command.
[0101] Example 7. The system of any one of Examples 1-6, wherein the operations further comprise: generating the unique random SCBK using a production server during the manufacturing process.
[0102] Example 8. The system of any one of Examples 1-7, wherein causing the controller to establish the secure channel session comprises: providing the unique random SCBK to the controller from the database in response to receiving the identification information from the controller.
[0103] Example 9. The system of Example 8, wherein the controller performs operations comprising: communicating with the PAC reader device to obtain a response to a reader information command; and extracting the identification information from the response to the reader information command.
[0104] Example 10. The system of any one of Examples 8-9, wherein providing the unique random SCBK comprises: receiving a request from the controller including the identification information read from the PAC reader device; and retrieving the unique random SCBK from the database using the received identification information.
[0105] Example 11. The system of any one of Examples 8-10, wherein providing the unique random SCBK comprises: authenticating the controller with the database through a secure connection before providing access to the unique random SCBK; and transmitting the unique random SCBK to the controller through the secure connection.
[0106] Example 12. The system of Example 11, wherein the controller performs operations comprising: establishing, as the secure channel session, a secure Open Supervised Device Protocol (OSDP) communication session with the PAC reader using the unique random SCBK obtained through the secure connection with the database.
[0107] Example 13. The system of Example 12, wherein the controller performs operations comprising: enabling the controller to change the unique random SCBK to a controller-generated SCBK after establishing the secure OSDP communication session.
[0108] Example 14. The system of any one of Examples 1-13, wherein the secure channel session enables encrypted communication of credential information between the controller and the PAC reader device.
[0109] Example 15. The system of any one of Examples 1-14, wherein the operations further comprise: encrypting the unique random SCBK before storing the unique random SCBK in the database.
[0110] Example 16. The system of Example 15, wherein the operations comprise: decrypting the encrypted unique random SCBK from the database using secure authentication credentials provided by the controller; and transmitting the decrypted unique random SCBK through a secure network connection.
[0111] Example 17. A method comprising: storing, during a manufacturing process, a unique random secure channel base key (SCBK) in a secure storage location of a physical access control (PAC) reader device; storing the unique random SCBK inassociation with identification information of the PAC reader device in a database; and causing a controller to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database.
[0112] Example 18. The method of Example 17, wherein the identification information comprises at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.
[0113] Example 19. The method of any one of Examples 17-18, further comprising: disabling an install mode of the PAC reader device that uses a default secure channel base key.
[0114] Example 20. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising: storing, during a manufacturing process, a unique random secure channel base key (SCBK) in a secure storage location of a physical access control (PAC) reader device; storing the unique random SCBK in association with identification information of the PAC reader device in a database; and causing a controller to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database.
Claims
What is claimed is:
1. A system comprising:one or more hardware processors; andat least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising:storing, during a manufacturing process, a unique random secure channel base key (SCBK) in a secure storage location of a physical access control (PAC) reader device;storing the unique random SCBK in association with identification information of the PAC reader device in a database; andcausing a controller to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database.
2. The system of claim 1, wherein the identification information comprises at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.
3. The system of claim 1, wherein the operations further comprise:disabling an install mode of the PAC reader device that uses a default secure channel base key.
4. The system of claim 1, wherein storing the unique random SCBK comprises injecting, by a production server, the unique random SCBK into a secure access module (SAM) of the PAC reader device.
5. The system of claim 1, wherein the operations further comprise:reading, by a production server, the identification information from the PAC reader device during the manufacturing process.
6. The system of claim 5, wherein the operations further comprise:communicating, by the production server, with the PAC reader device to obtain a response to a reader information command; andextracting, by the production server, the identification information from the response to the reader information command.
7. The system of claim 1, wherein the operations further comprise:generating the unique random SCBK using a production server during the manufacturing process.
8. The system of claim 1, wherein causing the controller to establish the secure channel session comprises:providing the unique random SCBK to the controller from the database in response to receiving the identification information from the controller.
9. The system of claim 8, wherein the controller performs operations comprising:communicating with the PAC reader device to obtain a response to a reader information command; andextracting the identification information from the response to the reader information command.
10. The system of claim 8, wherein providing the unique random SCBK comprises: receiving a request from the controller including the identification information read from the PAC reader device; andretrieving the unique random SCBK from the database using the received identification information.
11. The system of claim 8, wherein providing the unique random SCBK comprises: authenticating the controller with the database through a secure connection before providing access to the unique random SCBK; andtransmitting the unique random SCBK to the controller through the secure connection.
12. The system of claim 11, wherein the controller performs operations comprising: establishing, as the secure channel session, a secure Open Supervised Device Protocol (OSDP) communication session with the PAC reader using the unique random SCBK obtained through the secure connection with the database.
13. The system of claim 12, wherein the controller performs operations comprising: enabling the controller to change the unique random SCBK to a controllergenerated SCBK after establishing the secure OSDP communication session.
14. The system of claim 1, wherein the secure channel session enables encrypted communication of credential information between the controller and the PAC reader device.
15. The system of claim 1, wherein the operations further comprise:encrypting the unique random SCBK before storing the unique random SCBK in the database.
16. The system of claim 15, wherein the operations comprise:decrypting the encrypted unique random SCBK from the database using secure authentication credentials provided by the controller; andtransmitting the decrypted unique random SCBK through a secure network connection.
17. A method comprising:storing, during a manufacturing process, a unique random secure channel base key (SCBK) in a secure storage location of a physical access control (PAC) reader device;storing the unique random SCBK in association with identification information of the PAC reader device in a database; andcausing a controller to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database.
18. The method of claim 17, wherein the identification information comprises at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.
19. The method of claim 17, further comprising:disabling an install mode of the PAC reader device that uses a default secure channel base key.
20. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising:storing, during a manufacturing process, a unique random secure channel base key (SCBK) in a secure storage location of a physical access control (PAC) reader device;storing the unique random SCBK in association with identification information of the PAC reader device in a database; andcausing a controller to establish a secure channel session with the PAC reader device using the unique random SCBK stored in the database.