Secure SNMP-based OSDP key distribution system

The secure provisioning process using a production server to generate and distribute a random SCBK based on the PAC reader's SNMP engine ID addresses the vulnerability of default keys in OSDP, ensuring secure communication sessions and preventing key interception, thus enhancing the security of access control systems.

WO2026158790A1PCT designated stage Publication Date: 2026-07-30ASSA ABLOY AB
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ASSA ABLOY AB
Filing Date
2025-01-24
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

Conventional access control systems using Open Supervised Device Protocol (OSDP) rely on a publicly known default Secure Channel Base Key (SCBK-D) for initial secure sessions, which are vulnerable to eavesdropping and decryption by attackers, compromising the security of credential information.

Method used

A secure provisioning process utilizing a production server to generate and distribute a random SCBK based on the PAC reader's SNMP engine ID, ensuring secure communication sessions without direct key exchange, and disabling the OSDP install mode to prevent use of the default key.

Benefits of technology

This approach enhances security by preventing key interception during installation, maintaining secure communication channels, and ensuring compatibility with existing OSDP specifications without hardware modifications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025051840_30072026_PF_FP_ABST
    Figure EP2025051840_30072026_PF_FP_ABST
Patent Text Reader

Abstract

A system for configuring a physical access control (PAC) reader device is described. The system receives, from a controller, a request including identification information read from a physical access control (PAC) reader device. The system retrieves a pre-generated secure message using the identification information, the pre-generated secure message comprising a command to write a random secure channel base key (SCBK) to the PAC reader device. The system transmits the pre-generated secure message comprising the command to write the random SCBK to the controller through a secure connection and enables the controller to configure the PAC reader device to establish a secure communication session with the PAC reader device using the random SCBK.
Need to check novelty before this filing date? Find Prior Art

Description

SECURE SNMP-BASED OSDP KEY DISTRIBUTION SYSTEMBACKGROUND

[0001] Access control systems have become integral to securing physical spaces, ensuring that only authorized individuals can enter or exit specific areas. Physical access control (PAC) reader devices are wall-mounted readers that interface with controllers to manage secure access to facilities. These readers serve as the front-end hardware components that communicate with access control system controllers to authenticate and process credential information.BRIEF SUMMARY

[0002] In some aspects, the techniques described herein relate to a system including: one or more hardware processors; and at least one machine- storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations including: receiving, from a controller, a request including identification information read from a physical access control (PAC) reader device; retrieving a pre-generated secure message using the identification information, the pre-generated secure message including a command to write a random secure channel base key (SCBK) to the PAC reader device; transmitting the pre-generated secure message including the command to write the random SCBK to the controller through a secure connection; and enabling the controller to configure the PAC reader device to establish a secure communication session with the PAC reader device using the random SCBK.

[0003] In some aspects, the techniques described herein relate to a system, wherein the identification information includes at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.

[0004] In some aspects, the techniques described herein relate to a system, wherein the operations further include: disabling an install mode of the PAC reader device that uses a default secure channel base key.

[0005] In some aspects, the techniques described herein relate to a system, wherein the identification information is obtained by the controller using a manufacturer-specific command.

[0006] In some aspects, the techniques described herein relate to a system, wherein the controller performs operations including: communicating by the controller with the PAC reader device to obtain a response to a reader information command; and extracting, by the controller, the identification information from the response to the reader information command, the identification information including a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device, wherein the controller communicates the SNMP engine ID to a production server.

[0007] In some aspects, the techniques described herein relate to a system, wherein the controller communicates with the PAC reader device over an Open Supervised Device Protocol (OSDP) communication session using a manufacturer-provided SCBK.

[0008] In some aspects, the techniques described herein relate to a system, wherein the communication to obtain the response is performed using a first manufacturer command, and wherein the operations include: generating, by the production server, the random SCBK; and generating by the production server the secure message in response to receiving the SNMP engine ID from the controller and based on the SNMP engine ID of the PAC reader device and the SCBK.

[0009] In some aspects, the techniques described herein relate to a system, wherein the controller performs further operations including: transmitting the pre-generated secure message to the PAC reader device using a second manufacturer command, the controller transmits the pre-generated secure message to the PAC reader device to configure the PAC reader device to write the random SCBK to a secure access module (SAM) of the PAC reader device.

[0010] In some aspects, the techniques described herein relate to a system, wherein causing the controller to establish the secure channel session includes: providing the random SCBK to the controller in response to receiving the identification information from the controller.

[0011] In some aspects, the techniques described herein relate to a system, wherein the controller performs operations including: establishing the secure communication session with the PAC reader device using the random SCBK.

[0012] In some aspects, the techniques described herein relate to a system, wherein providing the random SCBK includes: authenticating the controller through a secure connection before providing access to the random SCBK; and transmitting the random SCBK to the controller through the secure connection.

[0013] In some aspects, the techniques described herein relate to a system, wherein the controller performs operations including: establishing, as the secure channel session, a secure OSDP communication session with the PAC reader using the random SCBK.

[0014] In some aspects, the techniques described herein relate to a system, wherein the controller performs operations including: enabling the controller to change the random SCBK to a controller-generated SCBK after establishing the secure OSDP communication session.

[0015] In some aspects, the techniques described herein relate to a system, wherein the secure channel session enables encrypted communication of credential information between the controller and the PAC reader device.

[0016] In some aspects, the techniques described herein relate to a method including: receiving, from a controller, a request including identification information read from a physical access control (PAC) reader device; retrieving a pre-generated secure message using the identification information, the pre-generated secure message including a command to write a random secure channel base key (SCBK) to the PAC reader device; transmitting the pre-generated secure message including the command to write the random SCBK to the controller through a secure connection; and enabling the controller to configure the PAC reader device to establish a secure communication session with the PAC reader device using the random SCBK.

[0017] In some aspects, the techniques described herein relate to a method, wherein the identification information includes at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device. While the disclosed techniques pertain to SNMP, SNMP is used as an example and similar functionality can be performed with any other suitable secure message protocol.

[0018] In some aspects, the techniques described herein relate to a method, further including: disabling an install mode of the PAC reader device that uses a default secure channel base key.

[0019] In some aspects, the techniques described herein relate to a machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations including: receiving, from a controller, a request including identification information read from a physical access control (PAC) reader device; retrieving a pre-generated secure messageusing the identification information, the pre-generated secure message including a command to write a random secure channel base key (SCBK) to the PAC reader device; transmitting the pre-generated secure message including the command to write the random SCBK to the controller through a secure connection; and enabling the controller to configure the PAC reader device to establish a secure communication session with the PAC reader device using the random SCBK.BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS

[0020] To easily identify the discussion of any particular element or act, the most significant digit or digits in a reference number refer to the figure number in which that element is first introduced.

[0021] FIG. 1 is a diagrammatic representation of a networked environment in which the present disclosure may be deployed, in accordance with some examples.

[0022] FIG. 2 illustrates a diagram for provisioning a PAC reader, in accordance with some examples.

[0023] FIG. 3 illustrates a routine for provisioning a PAC reader, in accordance with some examples.

[0024] FIG. 4 is a block diagram illustrating a representative software architecture, which may be used in conjunction with various hardware architectures herein described, in accordance with some examples.

[0025] FIG. 5 is a diagrammatic representation of a machine in the form of a computer system within which a set of instructions may be executed for causing the machine to perform any one or more of the methodologies discussed herein, in accordance with some examples.DETAILED DESCRIPTION

[0026] Example methods and systems for an access control system are described. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the disclosed examples. It will be evident, however, to one of ordinary skill in the art that examples of the disclosure may be practiced without these specific details.

[0027] Conventional approaches to securing communications between PAC readers and controllers rely on the OSDP specification's "install mode" mechanism. The install modeuses a default key known as SCBK-D (Secure Channel Base Key - Default). This default key consists of a known sequence (0x30, 0x31, 0x32... 0x3E, 0x3F) that is published and accessible to everyone. Conventionally, readers are shipped and delivered with "install mode" enabled by default. Using the known SCBK-D, the controller (at a customer premises) initiates what appears to be a secure OSDP session. Once this initial session is established using the default key, the controller can then use the osdp KEYSET command to change the SCBK-D to a new value. After changing the key to the new value, the initial secure session is dropped and install mode is disabled. Then, the controller can establish a new secure session with the PAC reader using the newly changed SCBK.

[0028] This conventional approach has a fundamental security flaw. Since the SCBK-D is publicly known, the initial "secure" session created with this default key is not actually secure at all. Any eavesdropper can decode the encrypted OSDP traffic during this key exchange process, allowing the eavesdropper to discover the newly changed SCBK. Once an attacker obtains the new SCBK, the attacker can decode all subsequent OSDP traffic, including credential information and other sensitive communications.

[0029] The OSDP specification attempts to mitigate this vulnerability by suggesting to enable the install mode only in a “secure environment.” However, some controller implementations always remain in install mode. Therefore a man-in-the middle attack could force the secure session to be dropped and restarted allowing the attacker to decrypt all future communications.

[0030] The disclosed system addresses these technical issues by implementing a secure provisioning process. In this process, the disclosed system utilizes a production server (or other web-accessible server / entity, such as a post-manufacturing server system) to manage configuration of the SCBK into the PAC reader device. Particularly, the controller can obtain reader identification information from the PAC reader device, such as an SNMP engine identifier. The controller can provide that information to the production server which generates a pre-generated secure message that includes a random SCBK based on the SNMP engine identifier. The production server transmits the pre-generated secure message to the controller. The controller can then use an existing or new OSDP connection (which can be secure or non-secure) with the PAC reader device to send the pre-generated secure message. The pre-generated secure message can include manufacturer commands that configure the PAC reader device to store in a secure accessmodule (SAM) the random SCBK that is in the message. Separately, the production server provides or transmits to the controller the same random SCBK message. Now the controller can establish a new OSDP connection (that is secure) that uses or is based on the random SCBK. This enables the controller and the PAC reader device to communicate securely without ever exchanging the random SCBK with each other directly. This eliminates the need for manual key setup in supposedly "secure environments" and prevents eavesdroppers from intercepting key exchanges, since the initial key sharing occurs during manufacturing rather than during field installation.

[0031] Specifically, the disclosed techniques can configure a PAC reader device through a series of operations. The disclosed techniques receive a request including identification information read from the PAC reader device. The disclosed techniques can retrieve a pre-generated secure message using the identification information, where the pre-generated secure message includes a command to write a random secure channel key to the PAC reader device. The disclosed techniques can transmit the pre-generated secure message to the controller through a secure connection and enable the controller to establish a secure communication session with the PAC reader device using the random secure channel base key (SCBK).

[0032] FIG. 1 is a block diagram showing an example access control system 103, according to various examples. The access control system 103 can include a client device 104 (e.g., mobile device), a production server 105, a controller 106, server 107, and PAC device 101. The client device 104 (which can in some cases perform functionality of the controller 106) and the PAC device 101 are communicatively coupled over a network 102 (e.g., Internet, BLE, ultra-wideband (UWB) communication protocol, Near Field Communication (NFC), and / or telephony network) with each other and with the server 107. In some cases, the production server 105 and the server 107 can be the same servers or part of the same system or component even though they are drawn as separate components. While the disclosed techniques are discussed in the context of PAC devices, similar techniques are applicable to any other type of access control device, such as a logical access control (LAC) device.

[0033] As used herein, the term “client device” may refer to any machine that interfaces to a communications network (such as network 102) to exchange credentials with an access control device, such as the PAC device 101, the server 107 associated with the access control device, another client device 104, or any other component to obtain accessto a logical or physical asset or resource protected by the access control device. In some examples, the client device 104 can additionally or alternatively communicate directly with, for example, an access control device or another client device 104. The client device 104 can include or store one or more credentials which can be provided to the access control device 101 for obtaining access to a protected physical or logical asset or resource.

[0034] A client device 104 may be, but is not limited to, a mobile phone, desktop computer, laptop, portable digital assistant (PDA), smart phone, a wearable device (e.g., a smart watch), tablet, ultrabook, netbook, multi-processor system, microprocessor-based or programmable consumer electronics, physical card, or any other communication device that a user may use to access a network.

[0035] The access control device (e.g., the PAC device 101) can include an access reader device (also referred to as an access control reader) connected to a secure / protected resource (e.g., a door locking mechanism or backend server) that controls the secure / protected resource (e.g., door locking mechanism). The resource associated with the access control device can include a door lock, an ignition system for a vehicle, or any other device that grants or denies access to a physical component or that can be operated to grant or deny access to the physical component. For example, in the case of a door lock, the access control device can deny access, in which case the door lock remains locked and the door cannot be opened; or can grant access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, the access control device can deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or can grant access, in which case the vehicle ignition becomes enabled to allow the vehicle to be started.

[0036] PAC covers a range of systems and methods to govern access, for example by people, to secure areas or secure assets. PAC includes identification of authorized users or devices (e.g., vehicles, drones, etc.) and actuation of a gate, door, or other facility used to secure an area, or actuation of a control mechanism, for example, a physical or electronic / software control mechanism, permitting access to a secure asset. The access control device may form part of a physical access control system (PACS), which can include a reader (e.g., an online or offline reader) that may hold authorization data (also referred to access control information) and can be capable of determining whethercredentials (e.g., from credential or key devices such as radio frequency identification (RFID) chips in cards, fobs, or personal electronic devices such as mobile phones) are authorized for an actuator or control mechanism (e.g., door lock, door opener, software control mechanism, turning off an alarm, etc.), or a PACS can include a host server 107 to which readers and actuators are connected (e.g., via a controller) in a centrally managed configuration.

[0037] In centrally managed configurations, readers can obtain credentials from credential or key devices (e.g., from one or more client devices 104) and pass those credentials to the PACS host server (e.g., server 107) or headend system. The readers can send the credentials over a wired or wireless link, such as network 102. The host server then determines whether the credentials authorize access to the secure area or secure asset (or resource) and commands the actuator or other control mechanism of the PAC device 101 accordingly by sending an allow / deny message back to the reader over the wired or wireless link. While examples in physical access control are used herein, the disclosure applies similarly to LACS use cases (e.g., logical access to personal electronic devices, logical access to personal online or electronic accounts or documents, etc.).

[0038] In general, the PAC device 101 can include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, a display, and a power source or supply. The memory of the PAC device 101 can be used in connection with the execution of application programming or instructions by the processor of the PAC device 101, and for the temporary or long-term storage of program instructions or instruction sets and / or credential or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory can contain executable instructions that are used by the processor to run other components of PAC device 101 and / or to make access determinations based on credential or authorization data, such as by communicating with the authorization system 108 of the server 107.

[0039] The memory of the PAC device 101, server 107, and / or client device 104 can include a transitory or non-transitory computer-readable medium. The computer-readable medium can be, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer-readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as aportable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device.Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar examples of computer-readable media.

[0040] The processor of the PAC device 101 can correspond to one or more computer processing devices or resources. For instance, the processor can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, the processor can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory and / or memory of the access control device.

[0041] The antenna of the PAC device 101 can correspond to one or multiple antennas and can be configured to provide for wireless communications between PAC device 101 and a credential or key device (e.g., client device 104). The antenna can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 502.15.1, Bluetooth, BLE, NFC, ZigBee, Global System for Mobile communications (GSM), Code Division Multiple Access (CDMA), Wi-Fi, RF, UWB, and the like. By way of example, the antenna(s) can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by a credential or key device having an RF transceiver.

[0042] A communication module or communication component of the PAC device 101 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to the PAC device 101, such as one or more client devices 104 and / or servers / controllers, such as server 107. In some cases, the communication module uses a same wired or wireless link between the PAC device 101 and the server 107 for all the communication modes. In some cases, the communication module uses one wired or wireless link between the PAC device 101 and the server 107 to communicate access control information to the authorization system 108 and uses a different wired or wireless link to communicate orreceive configuration information updates from the server 107 over the Internet Protocol (IP) communication mode. The PAC device 101 can communicate with any of the disclosed devices / components over OSDP and / or over SNMP.

[0043] The network interface device of the PAC device 101 includes hardware to facilitate communications with other devices, such as a one or more client devices 104 and / or server / controller (e.g., server 107, controller 106, and / or production server 105), over a communication network, such as network 102, utilizing any one of a number of transfer protocols (e.g., frame relay, IP, transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 502.11 family of standards known as Wi-Fi, IEEE 502.16 family of standards known as WiMax), IEEE 502.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.

[0044] A user interface of the PAC device 101 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in the user interface include, without limitation, one or more buttons, a keyboard or keypad, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, and so forth.Examples of suitable user output devices that can be included in the user interface include, without limitation, one or more light emitting diodes (LEDs), a liquid crystal display (LCD) panel, a display screen, a touchscreen, one or more lights, a speaker, and so forth. It should be appreciated that the user interface can also include a combined user input and user output device, such as a touch-sensitive display or the like.

[0045] The network 102 may include, or operate in conjunction with, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a LAN, a wireless network, a wireless LAN (WLAN), a WAN, a wireless WAN (WWAN), a metropolitan area network (MAN), BLE, UWB, the Internet, a portion of the Internet, a portion of thePublic Switched Telephone Network (PSTN), a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless or cellular network and the coupling may be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling may implement any of a variety of types of data transfer technology, such as Single Carrier Radio Transmission Technology (IxRTT), Evolution-Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, third Generation Partnership Project (3GPP) including 3G, fourth generation wireless (4G) networks, fifth generation wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standard, others defined by various standard setting organizations, other short range or long range protocols, or other data transfer technology.

[0046] In an example, as the client device 104 approaches the PAC device 101 (e.g., comes within range of a BLE communication protocol), the client device 104 transmits credentials of the client device 104 over the network 102. In one example, the client device 104 provides the credentials directly to the PAC device 101. In such cases, the PAC device 101 communicates the credentials with the server 107. The server 107 includes an authorization system 108. The server 107, client device 104, and / or the PAC device 101 can further include elements described with respect to FIG. 4 and FIG. 5, such as a processor and memory, having instructions stored thereon, that when executed by the processor, causes the processor to control the functions of the server / controller, client device 104, and / or the PAC device 101. The server 107 can be implemented on a centralized set of servers of a cloud-based system.

[0047] The server 107 searches a list of credentials stored in the authorization system 108 to determine whether the received credentials match credentials from the list of authorized credentials for accessing a secure asset or resource (e.g., door or secure area) protected by the PAC device 101. In response to determining that the received credentials are authorized to access the PAC device 101, the server 107 (also referred to as the controller) instructs the PAC device 101 to perform an operation granting accessfor the client device 104 (e.g., instructing the PAC device 101 to unlock a lock of a door).

[0048] In some examples, the PAC device 101 serves as a wall-mounted reader that interfaces with controllers to manage secure access to facilities, where the controller 106 needs to configure the PAC reader 210 with specific encryption keys and security parameters for that installation location. This configuration process is important since each PAC reader 210 may need to be properly set up with unique secure channel keys chosen by the controller 106 to enable encrypted communication of credential information specific to that facility's security requirements. The controller 106 can change the initial random SCBK to a controller-generated SCBK after establishing the secure OSDP communication session, allowing the controller to customize the security parameters for that specific installation location. This enables the controller 106 to maintain unique encryption keys across different reader installations while ensuring secure access management for each facility.

[0049] To establish secure communication with the PAC device 101, the controller 106 can generate a set of custom SCBK. The custom SCBK can be stored in a SAM of the PAC device 101 in order to enable the controller 106 and the PAC device 101 to communicate securely over an OSDP connection. To do so, the controller 106 can communicate with both the PAC device 101 and a secure web service (e.g., a production server 105) to establish secure communications. Initially, the controller 106 can first read identification information from the PAC device 101 using an OSDP manufacturing command to obtain the reader's SNMP engine ID. The OSDP manufacturing command can be provided from the controller 106 to the PAC device 101 over an OSDP connection that is established using default or manufacturer-provided keys.

[0050] The controller 106 can then provide this SNMP engine ID to a secure web service, such as the production server 105. Using this identification information, the web service generates a pre-generated SNMP message (e.g., an device-specific message) that contains a manufacturer command to write a random SCBK to the storage location, such as SAM, of the PAC reader 210. Device-specific commands can use a native protocol or command set that the PAC device 101 understands natively. The device-specific commands allows for SNMP messages to be embedded within it as part of the reader's secure messaging capabilities. The device-specific command set includes the ability to do secure SNMP messages using admin keys that are embedded in the reader duringmanufacturing for various other functions. This SNMP message can be encrypted using the admin keys that are already embedded in the reader during manufacturing.

[0051] The web service then securely transmits two items to the controller 106 through an authenticated secure connection. The web service (e.g., the production server 105) can send the pre-generated SNMP message that includes the command with the random SCBK and can also send the random SCBK itself. In some cases, the pre-generated SNMP message is sent separately to the controller 106 from the random SCBK. In some cases, the SNMP message is sent over a first secure connection with the controller 106 and the random SCBK is sent over a second secure connection with the controller 106.

[0052] The controller 106 can then transmit the pre-generated SNMP message received from the production server 105 to the PAC device 101 using an OSDP manufacturing command. In some cases, the OSDP manufacturing command is sent without a preexisting secure channel with the PAC device 101. In some cases, the controller 106 sends the OSDP manufacturing command including the pre-generated SNMP message received from the production server 105 over a previously established OSDP connection with the PAC device 101. In response to receiving and processing the pre-generated SNMP message, the PAC device 101 stores or updates the SAM with the random SCBK that is included in the payload of the SNMP message.

[0053] The controller 106 can then use the random SCBK the controller 106 received from the production server 105 to establish a secure or non-secure OSDP channel session with the PAC device 101. In this way, the controller 106 and the PAC device 101 communicate over a secure or non-secure connection without ever exchanging the random SCBK. After establishing the secure or non-secure OSDP channel with the PAC device 101, the controller 106 can instruct the PAC device 101 to change the SCBK stored in the SAM of the PAC device 101 with a newly generated SCBK selected / generated by the controller 106. The controller 106 can then re-establish a new OSDP secure channel with the PAC device 101 using the newly generated SCBK.

[0054] This enables encrypted communication of credential information between the controller 106 and PAC device 101 without relying on the vulnerable default key approach. The entire system operates with the PAC reader device's install mode disabled, preventing use of the default SCBK-D. This ensures all key exchanges occur through the secure web service infrastructure rather than through potentially compromised field installations.

[0055] FIG. 2 illustrates a diagram 204 for provisioning a PAC reader 210, in accordance with some examples. PAC reader devices serve as wall-mounted readers that interface with controllers to manage secure access to facilities. These readers need to be properly configured with specific encryption keys and security parameters for each installation location to enable secure credential management and access control for that facility. The OSDP specification provides a communication protocol between PAC readers and controllers, featuring encrypted communication capabilities through secure channel sessions. However, the specification's default approach using a known key (SCBK-D) creates security vulnerabilities that could allow eavesdroppers to intercept and decode credential information.

[0056] To address this security weakness, the system configured in the manner shown in diagram 204, delivers a PAC reader 210 with the OSDP install mode disabled to prevent use of the default SCBK. This ensures that secure key distribution occurs through the system's secure web service infrastructure rather than through potentially compromised field installations. During field installation, the controller 106 first reads identification information from the PAC reader using an OSDP manufacturing command. This can take place over an OSDP session that is established using default keys or without establishing a secure session.

[0057] Specifically, the controller 106 obtains the SNMP engine ID of the PAC reader 210, which serves as a unique identifier for secure communications. The controller 106 then establishes a secure connection with a production server 105, authenticating itself before proceeding with the key distribution process. This authentication helps ensure that only authorized controllers can participate in the secure key exchange. After authentication, the controller 106 provides the SNMP engine ID of the PAC reader 210 to the production server 105. The production server 105 uses this identification information to generate a pre-generated device-specific SNMP message - a native protocol command that the reader inherently understands.

[0058] The pre-generated SNMP message contains a specific command to write a random SCBK to the designated storage location of the PAC reader 210, such as the SAM. This message is encrypted using admin keys that are embedded in the PAC reader 210 during the manufacturing process. The production server 105 then securely downloads two pieces of information to the controller 106. The production server 105 transmits the pre-generated device-specific SNMP message containing the "WriteRandom SCBK to SCBK OID" command to the controller 106 and also transmits the random SCBK itself to the controller 106. This dual delivery ensures both components needed for secure communication are available to the controller 106.

[0059] Using an OSDP manufacturing command, the controller 106 transmits the pregenerated SNMP message to the PAC reader 210. Since this message is encrypted with the admin keys of the PAC reader 210, it can securely write the SCBK to the PAC reader 210 even though the OSDP manufacturing command itself is sent without requiring a pre-existing secure channel. The encryption of the SNMP message using the reader's admin keys provides a security layer, ensuring that even if an eavesdropper intercepts the message, they cannot decode the random SCBK being written to the PAC reader 210.

[0060] At this point, both the PAC reader 210 and controller 106 possess the same random SCBK, obtained through secure means without having to exchange the key directly between them. This eliminates the vulnerability of key interception during the exchange process. The controller 106 can now establish an OSDP secure session with the reader using this shared random SCBK. This creates an encrypted communication channel between the controller and reader for secure transmission of credential information.

[0061] As an optional final step aligned with OSDP specification recommendations, the controller 106 may use the osdp KEYSET command to change the SCBK to a new random value that the controller 106 generates locally. This provides an additional layer of security by replacing the SCBK provided by the production server 105 with a controller-specific one. This approach offers several technical advantages over traditional key distribution methods. It eliminates the need for production-time provisioning changes or maintenance of a reader database, instead leveraging the existing admin key infrastructure.

[0062] The system's use of device-specific commands provides a robust framework for secure messaging, as these commands are part of the reader's native protocol set and can securely carry SNMP messages using pre-existing security infrastructure. The SNMP messaging system itself adds another security layer, using the reader's engine ID for secure communications and enabling encrypted command transmission even without a pre-established secure channel.

[0063] By disabling the OSDP install mode and its associated default key mechanism, the system prevents attackers from exploiting the known vulnerabilities of the defaultkey approach, such as intercepting and decoding key exchanges during installation. The entire process occurs without requiring any direct key exchange between the controller and reader, eliminating the security risks associated with transmitting sensitive key material over potentially compromised communication channels.

[0064] The system maintains security throughout the key distribution process by using multiple layers of encryption and authentication: secure HTTPS connections for controller-to-web-service communication, encrypted SNMP messages for key delivery to the reader, and finally encrypted OSDP sessions for ongoing credential management. This comprehensive approach ensures secure key distribution while maintaining compatibility with existing OSDP specifications and reader firmware, requiring no hardware modifications while significantly enhancing the security of physical access control systems.

[0065] FIG. 3 illustrates a routine 300 (e.g., method or process) in accordance with some examples. The operations discussed in connection with FIG. 3 can be performed sequentially, in parallel, and in any suitable order. The operations discussed in FIG. 3 can be performed by the access control system 103.

[0066] In operation 302, a production server 105 receives, from a controller 106, a request including identification information read from a PAC device 101, as discussed above.

[0067] In operation 304, the production server 105 retrieves a pre-generated secure message using the identification information, the pre-generated secure message comprising a command to write a random secure channel base key (SCBK) to the PAC device 101, as discussed above.

[0068] In operation 306, the production server 105 transmits the pre-generated secure message comprising the command to write the random SCBK to the controller through a secure connection, as discussed above.

[0069] In operation 314, the production server 105 enables the controller to configure the PAC reader device to establish a secure communication session with the PAC device 101 using the random SCBK, as discussed above.

[0070] FIG. 4 is a block diagram illustrating an example of a software architecture 402 that may be installed on a machine, according to some examples. FIG. 4 is merely a nonlimiting example of a software architecture, and it will be appreciated that many other architectures may be implemented to facilitate the functionality described herein. Thesoftware architecture 402 may be executing on hardware such as a machine 500 of FIG.5 that includes, among other things, processors 510, memory 504, and input / output (I / O) components 542. A representative hardware layer 444 is illustrated and can represent, for example, the machine 500 of FIG. 5. The representative hardware layer 444 comprises one or more processing units 446 having associated executable instructions 448. The executable instructions 448 represent the executable instructions of the software architecture 402. The hardware layer 444 also includes memory 504, which also have the executable instructions 448. The hardware layer 444 may also comprise other hardware 452, which represents any other hardware of the hardware layer 444, such as the other hardware illustrated as part of the machine 500.

[0071] The instructions 448 may be transmitted or received over the network using a transmission medium via a network interface device (e.g., a network interface component included in the communication components 540) and utilizing any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 448 may be transmitted or received using a transmission medium via the coupling (e.g., a peer-to-peer coupling) to the devices. The terms “transmission medium” and “signal medium” mean the same thing and may be used interchangeably in this disclosure. The terms “transmission medium” and “signal medium” shall be taken to include any intangible medium that is capable of storing, encoding, or carrying the instructions 448 for execution by the machine 500, and include digital or analog communications signals or other intangible media to facilitate communication of such software. Hence, the terms “transmission medium” and “signal medium” shall be taken to include any form of modulated data signal, carrier wave, and so forth. The term “modulated data signal” means a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal.

[0072] The terms “machine-readable medium,” “computer-readable medium,” and “device-readable medium” mean the same thing and may be used interchangeably in this disclosure. The terms are defined to include both machine-storage media and transmission media. Thus, the terms include both storage devices / media and carrier waves / modulated data signals.

[0073] As used herein, the terms “machine-storage medium,” “device-storage medium,” and “computer-storage medium” mean the same thing and may be used interchangeably in this disclosure. The terms refer to a single or multiple storage devices and / or media(e.g., a centralized or distributed database, and / or associated caches and servers) that store executable instructions and / or data. The terms shall accordingly be taken to include, but not be limited to, solid-state memories, and optical and magnetic media, including memory internal or external to processors. Specific examples of machine¬ storage media, computer-storage media, and / or device-storage media include nonvolatile memory, including by way of example semiconductor memory devices, e.g., erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), field-programmable gate arrays (FPGAs), and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The terms “machinestorage medium,” “computer-storage medium,” and “device- storage medium” are non-transitory computer-readable media and specifically exclude carrier waves, modulated data signals, and other such media, at least some of which are covered under the term “signal medium.”

[0074] In the example architecture of FIG. 4, the software architecture 402 may be conceptualized as a stack of layers, where each layer provides particular functionality. For example, the software architecture 402 may include layers such as an operating system 436, libraries 428, frame work / middleware 422, applications 416, and a presentation layer 414. Operationally, the applications 416 or other components within the layers may invoke API calls API calls 424 through the software stack and receive a response, returned values, and so forth (illustrated as messages 426) in response to the API calls 424. The layers illustrated are representative in nature, and not all software architectures have all layers. For example, some mobile or special -purpose operating systems may not provide a framework / middleware 422 layer, while others may provide such a layer. Other software architectures may include additional or different layers.

[0075] The operating system 436 may manage hardware resources and provide common services. The operating system 436 may include, for example, a kernel 438, services 440, and drivers 442. The kernel 438 may act as an abstraction layer between the hardware and the other software layers. For example, the kernel 438 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, and so on. The services 440 may provide other common services for the other software layers. The drivers 442 may be responsible for controlling or interfacing with the underlying hardware. For instance, the drivers 442 may includedisplay drivers, camera drivers, Bluetooth® drivers, flash memory drivers, serial communication drivers (e.g., Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, and so forth depending on the hardware configuration.

[0076] The libraries 428 may provide a common infrastructure that may be utilized by the applications 416 and / or other components and / or layers. The libraries 428 typically provide functionality that allows other software modules to perform tasks in an easier fashion than by interfacing directly with the underlying operating system 436 functionality (e.g., kernel 438, services 440, or drivers 442). The libraries 428 may include system libraries 430 (e.g., C standard library) that may provide functions such as memory allocation functions, string manipulation functions, mathematic functions, and the like. In addition, the libraries 428 may include API libraries 432 such as media libraries (e.g., libraries to support presentation and manipulation of various media formats such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG), graphics libraries (e.g., an OpenGL framework that may be used to render 2D and 3D graphic content on a display), database libraries (e.g., SQLite that may provide various relational database functions), web libraries (e.g., WebKit that may provide web browsing functionality), and the like. The libraries 428 may also include a wide variety of other libraries 434 to provide many other APIs to the applications 416 and other software components / modules.

[0077] The frameworks / middleware 422 (also sometimes referred to as middleware) may provide a higher-level common infrastructure that may be utilized by the applications 416 or other software components / modules. For example, the frameworks / middleware 422 may provide various graphical user interface functions, high-level resource management, high-level location services, and so forth. The frameworks / middleware 422 may provide a broad spectrum of other APIs that may be utilized by the applications 416 and / or other software components / modules, some of which may be specific to a particular operating system or platform.

[0078] The applications 416 include built-in applications 418 and / or third-party applications 420. Examples of representative built-in applications 418 may include, but are not limited to, a home application, a contacts application, a browser application, a book reader application, a location application, a media application, a messaging application, or a game application.

[0079] The third-party applications 420 may include any of the built-in applications 418, as well as a broad assortment of other applications. In a specific example, the third-partyapplications 420 (e.g., an application developed using the Android™ or iOS™ software development kit (SDK) by an entity other than the vendor of the particular platform) may be mobile software running on a mobile operating system such as iOS™, Android™, or other mobile operating systems. In this example, the third-party applications 420 may invoke the API calls 424 provided by the mobile operating system such as the operating system 436 to facilitate functionality described herein.

[0080] The applications 416 may utilize built-in operating system functions (e.g., kernel 438, services 440, or drivers 442), libraries (e.g., system libraries 430, API libraries 432, and other libraries 434), or framework / middleware 422 to create user interfaces to interact with users of the system. Alternatively, or additionally, in some systems, interactions with a user may occur through a presentation layer, such as the presentation layer 414. In these systems, the application / module “logic” can be separated from the aspects of the application / module that interact with the user.

[0081] Some software architectures utilize virtual machines. In the example of FIG. 4, this is illustrated by a virtual machine 404. The virtual machine 404 creates a software environment where applications / modules can execute as if they were executing on a hardware machine (e.g., the machine 500 of FIG. 5). The virtual machine 404 is hosted by a host operating system (e.g., the operating system 436) and typically, although not always, has a virtual machine monitor, which manages the operation of the virtual machine 404 as well as the interface with the host operating system (e.g., the operating system 436). A software architecture executes within the virtual machine 404, such as an operating system 412, libraries 410, frameworks 408, applications 416, or a presentation layer 406. These layers of software architecture executing within the virtual machine 404 can be the same as corresponding layers previously described or may be different.

[0082] FIG. 5 is a diagrammatic representation of the machine 500 within which instructions 508 (e.g., software, a program, an application, an applet, an app, or other executable code) for causing the machine 500 to perform any one or more of the methodologies discussed herein may be executed. For example, the instructions 508 may cause the machine 500 to execute any one or more of the methods described herein. The instructions 508 transform the general, non-programmed machine 500 into a particular machine 500 programmed to carry out the described and illustrated functions in the manner described. The machine 500 may operate as a standalone device or may be coupled (e.g., networked) to other machines. In a networked deployment, the machine500 may operate in the capacity of a server machine or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine 500 may comprise, but not be limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a set-top box (STB), a PDA, an entertainment media system, a cellular telephone, a smart phone, a mobile device, a wearable device (e.g., a smart watch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of executing the instructions 508, sequentially or otherwise, that specify actions to be taken by the machine 500. Further, while only a single machine 500 is illustrated, the term “machine” shall also be taken to include a collection of machines that individually or jointly execute the instructions 508 to perform any one or more of the methodologies discussed herein.

[0083] The machine 500 may include processors 502, memory 504, and I / O components 542, which may be configured to communicate with each other via a bus 544. In an example, the processors 502 (e.g., a Central Processing Unit (CPU), a Reduced Instruction Set Computing (RISC) processor, a Complex Instruction Set Computing (CISC) processor, a Graphics Processing Unit (GPU), a Digital Signal Processor (DSP), an ASIC, a Radio-Frequency Integrated Circuit (RFIC), another processor, or any suitable combination thereof) may include, for example, a processor 506 and a processor 510 that execute the instructions 508. The term “processor” is intended to include multi-core processors that may comprise two or more independent processors (sometimes referred to as “cores”) that may execute instructions contemporaneously. Although FIG. 5 shows multiple processors 502, the machine 500 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiples cores, or any combination thereof.

[0084] The memory 504 includes a main memory 512, a static memory 514, and a storage unit 516, both accessible to the processors 502 via the bus 544. The main memory 504, the static memory 514, and storage unit 516 store the instructions 508 embodying any one or more of the methodologies or functions described herein. The instructions 508 may also reside, completely or partially, within the main memory 512, within the static memory 514, within machine-readable medium 518 within the storage unit 516, within at least one of the processors 502 (e.g., within the processor’s cachememory), or any suitable combination thereof, during execution thereof by the machine 500.

[0085] The I / O components 542 may include a wide variety of components to receive input, provide output, produce output, transmit information, exchange information, capture measurements, and so on. The specific I / O components 542 that are included in a particular machine will depend on the type of machine. For example, portable machines such as mobile phones may include a touch input device or other such input mechanisms, while a headless server machine will likely not include such a touch input device. It will be appreciated that the I / O components 542 may include many other components that are not shown in FIG. 5. In various examples, the I / O components 542 may include output components 528 and input components 530. The output components 528 may include visual components (e.g., a display such as a plasma display panel (PDP), a light emitting diode (LED) display, a liquid crystal display (LCD), a projector, or a cathode ray tube (CRT)), acoustic components (e.g., speakers), haptic components (e.g., a vibratory motor, resistance mechanisms), other signal generators, and so forth. Theinput components 530 may include alphanumeric input components (e.g., a keyboard, a touch screen configured to receive alphanumeric input, a photo-optical keyboard, or other alphanumeric input components), point-based input components (e.g., a mouse, a touchpad, a trackball, a joystick, a motion sensor, or another pointing instrument), tactile input components (e.g., a physical button, a touch screen that provides location and / or force of touches or touch gestures, or other tactile input components), audio input components (e.g., a microphone), and the like.

[0086] In further examples, the I / O components 542 may include biometric components 532, motion components 534, environmental components 536, or position components 538, among a wide array of other components. For example, the biometric components 532 include components to detect expressions (e.g., hand expressions, facial expressions, vocal expressions, body gestures, or eye tracking), measure biosignals (e.g., blood pressure, heart rate, body temperature, perspiration, or brain waves), identify a person (e.g., voice identification, retinal identification, facial identification, fingerprint identification, or electroencephalogram-based identification), and the like. The motion components 534 include acceleration sensor components (e.g., accelerometer), gravitation sensor components, rotation sensor components (e.g., gyroscope), and so forth. The environmental components 536 include, for example, illumination sensorcomponents (e.g., photometer), temperature sensor components (e.g., one or more thermometers that detect ambient temperature), humidity sensor components, pressure sensor components (e.g., barometer), acoustic sensor components (e.g., one or more microphones that detect background noise), proximity sensor components (e.g., infrared sensors that detect nearby objects), gas sensors (e.g., gas detection sensors to detection concentrations of hazardous gases for safety or to measure pollutants in the atmosphere), or other components that may provide indications, measurements, or signals corresponding to a surrounding physical environment. The position components538 include location sensor components (e.g., a GPS receiver component), altitude sensor components (e.g., altimeters or barometers that detect air pressure from which altitude may be derived), orientation sensor components (e.g., magnetometers), and the like.

[0087] Communication may be implemented using a wide variety of technologies. The I / O components 542 further include communication components 540 operable to couple the machine 500 to a network 520 or devices 522 via a coupling 524 and a coupling 526, respectively. For example, the communication components 540 may include a network interface component or another suitable device to interface with the network 520. In further examples, the communication components 540 may include wired communication components, wireless communication components, cellular communication components, Near Field Communication (NFC) components, Bluetooth® components (e.g., Bluetooth® Low Energy), Wi-Fi® components, and other communication components to provide communication via other modalities. The devices 522 may be another machine or any of a wide variety of peripheral devices (e.g., a peripheral device coupled via a USB).

[0088] Moreover, the communication components 540 may detect identifiers or include components operable to detect identifiers. For example, the communication components 540 may include Radio Frequency Identification (RFID) tag reader components, NFC smart tag detection components, optical reader components (e.g., an optical sensor to detect one-dimensional bar codes such as Universal Product Code (UPC) bar code, multi-dimensional bar codes such as Quick Response (QR) code, Aztec code, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D bar code, and other optical codes), or acoustic detection components (e.g., microphones to identify tagged audio signals). In addition, a variety of information may be derived via thecommunication components 540, such as location via Internet Protocol (IP) geolocation, location via Wi-Fi® signal triangulation, location via detecting an NFC beacon signal that may indicate a particular location, and so forth.

[0089] The various memories (e.g., memory 504, main memory 512, static memory 514, and / or memory of the processors 502) and / or storage unit 516 may store one or more sets of instructions and data structures (e.g., software) embodying or used by any one or more of the methodologies or functions described herein. These instructions (e.g., the instructions 508), when executed by processors 502, cause various operations to implement the disclosed examples.

[0090] The instructions 508 may be transmitted or received over the network 520, using a transmission medium, via a network interface device (e.g., a network interface component included in the communication components 540) and using any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 508 may be transmitted or received using a transmission medium via the coupling 526 (e.g., a peer-to-peer coupling) to the devices 522.

[0091] Although examples have been described, it will be evident that various modifications and changes may be made to these examples without departing from the broader scope of the present disclosure. Accordingly, the specification and drawings are to be regarded in an illustrative rather than a restrictive sense. The accompanying drawings that form a part hereof, show by way of illustration, and not of limitation, specific examples in which the subject matter may be practiced. The examples illustrated are described in sufficient detail to enable those skilled in the art to practice the teachings disclosed herein. Other examples may be utilized and derived therefrom, such that structural and logical substitutions and changes may be made without departing from the scope of this disclosure. This Detailed Description, therefore, is not to be taken in a limiting sense, and the scope of various examples is defined only by the appended claims, along with the full range of equivalents to which such claims are entitled.

[0092] Such examples of the inventive subject matter may be referred to herein, individually and / or collectively, by the term "invention" merely for convenience and without intending to voluntarily limit the scope of this application to any single invention or inventive concept if more than one is in fact disclosed. Thus, although specific examples have been illustrated and described herein, it should be appreciated that any arrangement calculated to achieve the same purpose may be substituted for thespecific examples shown. This disclosure is intended to cover any and all adaptations or variations of various examples. Combinations of the above examples, and other examples not specifically described herein, will be apparent to those of skill in the art upon reviewing the above description.

[0093] The Abstract of the Disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in a single example for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed examples require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter lies in less than all features of a single disclosed example. Thus the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate example.

[0094] In view of the disclosure above, various examples are set forth below. It should be noted that one or more features of an example, taken in isolation or combination, should be considered within the disclosure of this application.

[0095] Example 1. A system comprising: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising: receiving, from a controller, a request including identification information read from a physical access control (PAC) reader device; retrieving a pregenerated secure message using the identification information, the pre-generated secure message comprising a command to write a random secure channel base key (SCBK) to the PAC reader device; transmitting the pre-generated secure message comprising the command to write the random SCBK to the controller through a secure connection; and enabling the controller to configure the PAC reader device to establish a secure communication session with the PAC reader device using the random SCBK.

[0096] Example 2. The system of Example 1, wherein the identification information comprises at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.

[0097] Example 3. The system of any one of Examples 1-2, wherein the operations further comprise: disabling an install mode of the PAC reader device that uses a default secure channel base key.

[0098] Example 4. The system of any one of Examples 1-3, wherein the identification information is obtained by the controller using a manufacturer-specific command.

[0099] Example 5. The system of any one of Examples 1-4, wherein the controller performs operations comprising: communicating by the controller with the PAC reader device to obtain a response to a reader information command; and extracting, by the controller, the identification information from the response to the reader information command, the identification information comprising an Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device, wherein the controller communicates the SNMP engine ID to a production server.

[0100] Example 6. The system of Example 5, wherein the controller communicates with the PAC reader device over an Open Supervised Device Protocol (OSDP) communication session using a manufacturer-provided SCBK.

[0101] Example 7. The system of any one of Examples 5-6, wherein the communication to obtain the response is performed using a first manufacturer command, and wherein the operations comprise: generating, by the production server, the random SCBK; and generating by the production server the secure message in response to receiving the SNMP engine ID from the controller and based on the SNMP engine ID of the PAC reader device and the SCBK.

[0102] Example 8. The system of Example 7, wherein the controller performs further operations comprising: transmitting the pre-generated secure message to the PAC reader device using a second manufacturer command, the controller transmits the pre-generated secure message to the PAC reader device to configure the PAC reader device to write the random SCBK to a secure access module (SAM) of the PAC reader device.

[0103] Example 9. The system of Example 8, wherein causing the controller to establish the secure channel session comprises: providing the random SCBK to the controller in response to receiving the identification information from the controller.

[0104] Example 10. The system of Example 9, wherein the controller performs operations comprising: establishing the secure communication session with the PAC reader device using the random SCBK.

[0105] Example 11. The system of any one of Examples 9-10, wherein providing the random SCBK comprises: authenticating the controller through a secure connection before providing access to the random SCBK; and transmitting the random SCBK to the controller through the secure connection.

[0106] Example 12. The system of Example 11, wherein the controller performs operations comprising: establishing, as the secure channel session, a secure OSDP communication session with the PAC reader using the random SCBK.

[0107] Example 13. The system of Example 12, wherein the controller performs operations comprising: enabling the controller to change the random SCBK to a controller-generated SCBK after establishing the secure OSDP communication session.

[0108] Example 14. The system of any one of Examples 1-13, wherein the secure channel session enables encrypted communication of credential information between the controller and the PAC reader device.

[0109] Example 15. A method comprising: receiving, from a controller, a request including identification information read from a physical access control (PAC) reader device; retrieving a pre-generated secure message using the identification information, the pre-generated secure message comprising a command to write a random secure channel base key (SCBK) to the PAC reader device; transmitting the pre-generated secure message comprising the command to write the random SCBK to the controller through a secure connection; and enabling the controller to configure the PAC reader device to establish a secure communication session with the PAC reader device using the random SCBK.

[0110] Example 16. The method of Example 15, wherein the identification information comprises at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.

[0111] Example 17. The method of any one of Examples 15-16, further comprising: disabling an install mode of the PAC reader device that uses a default secure channel base key.

[0112] Example 18. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising: receiving, from a controller, a request including identification information read from a physical access control (PAC) readerdevice; retrieving a pre-generated secure message using the identification information, the pre-generated secure message comprising a command to write a random secure channel base key (SCBK) to the PAC reader device; transmitting the pre-generated secure message comprising the command to write the random SCBK to the controller through a secure connection; and enabling the controller to configure the PAC reader device to establish a secure communication session with the PAC reader device using the random SCBK.

Claims

What is claimed is:

1. A system comprising:one or more hardware processors; andat least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising:receiving, from a controller, a request including identification information read from a physical access control (PAC) reader device;retrieving a pre-generated secure message using the identification information, the pre-generated secure message comprising a command to write a random secure channel base key (SCBK) to the PAC reader device;transmitting the pre-generated secure message comprising the command to write the random SCBK to the controller through a secure connection; andenabling the controller to configure the PAC reader device to establish a secure communication session with the PAC reader device using the random SCBK.

2. The system of claim 1, wherein the identification information comprises at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.

3. The system of claim 1, wherein the operations further comprise:disabling an install mode of the PAC reader device that uses a default secure channel base key.

4. The system of claim 1, wherein the identification information is obtained by the controller using a manufacturer-specific command.

5. The system of claim 1, wherein the controller performs operations comprising:communicating by the controller with the PAC reader device to obtain a response to a reader information command; andextracting, by the controller, the identification information from the response to the reader information command, the identification information comprising a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device, wherein the controller communicates the SNMP engine ID to a production server.

296. The system of claim 5, wherein the controller communicates with the PAC reader device over an Open Supervised Device Protocol (OSDP) communication session using a manufacturer-provided SCBK.

7. The system of claim 5, wherein the communication to obtain the response is performed using a first manufacturer command, and wherein the operations comprise: generating, by the production server, the random SCBK; andgenerating by the production server the secure message in response to receiving the SNMP engine ID from the controller and based on the SNMP engine ID of the PAC reader device and the SCBK.

8. The system of claim 7, wherein the controller performs further operations comprising:transmitting the pre-generated secure message to the PAC reader device using a second manufacturer command, the controller transmits the pre-generated secure message to the PAC reader device to configure the PAC reader device to write the random SCBK to a secure access module (SAM) of the PAC reader device.

9. The system of claim 8, wherein the controller performs further operations comprising:providing the random SCBK to the controller in response to receiving the identification information from the controller.

10. The system of claim 9, wherein the controller performs operations comprising:establishing the secure communication session with the PAC reader device using the random SCBK.

11. The system of claim 9, wherein providing the random SCBK comprises:authenticating the controller through a secure connection before providing access to the random SCBK; andtransmitting the random SCBK to the controller through the secure connection.

12. The system of claim 11, wherein the controller performs operations comprising: establishing, as the secure channel session, a secure OSDP communication session with the PAC reader using the random SCBK.

13. The system of claim 12, wherein the controller performs operations comprising:enabling the controller to change the random SCBK to a controller-generated SCBK after establishing the secure OSDP communication session.

14. The system of claim 1, wherein the secure channel session enables encrypted communication of credential information between the controller and the PAC reader device.

15. A method comprising:receiving, from a controller, a request including identification information read from a physical access control (PAC) reader device;retrieving a pre-generated secure message using the identification information, the pre-generated secure message comprising a command to write a random secure channel base key (SCBK) to the PAC reader device;transmitting the pre-generated secure message comprising the command to write the random SCBK to the controller through a secure connection; andenabling the controller to configure the PAC reader device to establish a secure communication session with the PAC reader device using the random SCBK.

16. The method of claim 15, wherein the identification information comprises at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.

17. The method of claim 15, further comprising:disabling an install mode of the PAC reader device that uses a default secure channel base key.

18. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising:receiving, from a controller, a request including identification information read from a physical access control (PAC) reader device;retrieving a pre-generated secure message using the identification information, the pre-generated secure message comprising a command to write a random secure channel base key (SCBK) to the PAC reader device;transmitting the pre-generated secure message comprising the command to write the random SCBK to the controller through a secure connection; andenabling the controller to configure the PAC reader device to establish a secure communication session with the PAC reader device using the random SCBK.

19. The machine-storage medium of claim 18, wherein the identification information comprises at least one of a serial number, a Universally Unique Identifier (UUID), or a Simple Network Management Protocol (SNMP) engine ID associated with the PAC reader device.

20. The machine-storage medium of claim 18, the operations further comprise:disabling an install mode of the PAC reader device that uses a default secure channel base key.