Configuring an electronic lock

WO2026201908A1PCT designated stage Publication Date: 2026-10-01ASSA ABLOY AB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2026/058148
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-28
Filing Date
2026-03-23
Publication Date
2026-10-01

Smart Images

  • Figure EP2026058148_01102026_PF_FP_ABST
    Figure EP2026058148_01102026_PF_FP_ABST
Patent Text Reader

Abstract

It is provided a method for configuring an electronic lock (12). The method is performed by the electronic lock (12). The method comprises: receiving (40) a passcode (31) having been input on a user interface device (17), the passcode (31) comprising a sequence of characters; decrypting (42) at least part of the passcode (31) to obtain decrypted data (32); determining (46), from the passcode (31), a configuration to apply; and applying (48) the configuration to the electronic lock (12).
Need to check novelty before this filing date? Find Prior Art

Description

CONFIGURING AN ELECTRONIC LOCKTECHNICAL FIELD

[0001] The present disclosure relates to the field of electronic locks and in particular to configuring an electronic lock.BACKGROUND

[0002] Electronic locks are widely used in various applications, including residential, commercial, hospital, and industrial settings, to control access to secured areas. The variety of scenarios in which electronic locks are deployed ranges from single-family homes and small retail shops to office complexes, warehouses, and high-security sites. Electronic locks can evaluate access based on different authentication mechanisms, such as physical keys, keycards, biometric credentials, or passcodes (such as PIN codes) entered through a user interface, and their popularity has been driven by increasing demands for convenient access control, potential integration with automation systems, and the growing importance of security across many sectors.

[0003] Passcode-based electronic locks are convenient to use and support multiple users without requiring the users themselves to carry dedicated hardware. In these systems, a user typically enters a passcode via a keypad, touchscreen, or other user input device, and the lock evaluates this passcode before deciding whether to grant access. Because such locks do not necessarily need to be connected to a network, they can be installed in settings where network connectivity is limited, intermittent, or intentionally avoided for security reasons. This offline nature can reduce vulnerabilities associated with remote hacking attempts, but it also raises practical questions about how best to manage or update the configuration of the electronic locks. When the electronic lock is not connected to a network, administrators may face challenges in efficiently deploying new passcodes, adjusting access schedules, or modifying user credentials. How can an electronic lock be securely configured if it is not connected to the network?SUMMARY

[0004] One object is to improve how configuration of electronic locks is achieved.

[0005] According to a first aspect, it is provided a method for configuring an electronic lock, the method being performed by the electronic lock. The method comprises: receiving a passcode having been input on a user interface device, the passcode comprising a sequence of characters; decrypting at least part of the passcode to obtain decrypted data; determining, from the passcode, a configuration to apply; and applying the configuration to the electronic lock.

[0006] The method may further comprise, after the decrypting: deriving an access right for the electronic lock from the decrypted data.

[0007] The deriving an access right may comprise granting access for the same passcode only once.

[0008] The deriving an access right may comprise deriving a validity time of the access right.

[0009] The determining the configuration to apply may comprise determining to enroll a credential of a different type than the passcode, in which case the applying the configuration comprises: reading a credential of a different type than the passcode; and associating the credential with the derived access right.

[0010] The credential may be in the form of an electronic key or a biometric credential.

[0011] The method may further comprise: transmitting a message to associate the credential with the derived access right in at least one other electronic lock.

[0012] The transmitting a message may comprise transmitting the message to the at least one other electronic lock within a vicinity of the electronic lock.

[0013] The transmitting a message may comprise transmitting the message to a central server, for propagation to the at least one other electronic lock.

[0014] The message may comprise biometric data of the credential.

[0015] The access right may be associated with each one of the at least one other electronic lock, based on an access role or a group of electronic locks.

[0016] The method may further comprise: storing the passcode in association with the derived access right for subsequent use of the passcode without the need to again decrypt the passcode.

[0017] In one embodiment, the associating the credential with the derived access right is only performed within a predefined duration from processing the passcode.

[0018] The decrypting may be performed based on a symmetric key.

[0019] According to a second aspect, it is provided an electronic lock comprising: processing circuitry; and memory circuitry. The memory circuitry stores instructions that, when executed by the processing circuitry, cause the electronic lock to: receive a passcode having been input on a user interface device, the passcode comprising a sequence of characters; decrypt at least part of the passcode to obtain decrypted data; determine, from the passcode, a configuration to apply; and apply the configuration to the electronic lock.

[0020] According to a third aspect, it is provided a computer program for configuring an electronic lock. The computer program comprises computer program code which, when executed on an electronic lock causes the electronic lock to: receive a passcode having been input on a user interface device, the passcode comprising a sequence of characters; decrypt at least part of the passcode to obtain decrypted data; determine, from the passcode, a configuration to apply; and apply the configuration to the electronic lock.

[0021] According to a fourth aspect, it is provided a computer program product comprising a computer program according to the third aspect and a computer readable means comprising non-transitory memory in which the computer program is stored.

[0022] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, step, etc." are to beinterpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Aspects and embodiments are now described, by way of example, with reference to the accompanying drawings, in which:

[0024] Fig 1 is a schematic diagram showing an environment in which embodiments presented herein can be applied;

[0025] Figs 2A-C are schematic diagrams illustrating structures of passcodes that can be applied in the environment of Fig 1 according to one or more embodiments;

[0026] Figs 3A-B are swimlane diagrams illustrating embodiments of methods for configuring an electronic lock of Fig 1 according to one or more embodiments;

[0027] Fig 4 is a schematic diagram illustrating components of the electronic lock of Fig 1; and

[0028] Fig 5 shows one example of a computer program product comprising computer readable means.DETAILED DESCRIPTION

[0029] The aspects of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the invention are shown. These aspects may, however, be embodied in many different forms and should not be construed as limiting; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and to fully convey the scope of all aspects of invention to those skilled in the art. Like numbers refer to like elements throughout the description.

[0030] According to embodiments presented herein, an electronic lock can be configured using a passcode that can carry not only access credentials but also lockconfiguration data. In one example, a portion of the passcode is encrypted to securely convey access rights (e.g., validity time), while another portion (encrypted or unencrypted) specifies configurations such as unlocking duration or to enrol new credentials. The access rights are only optionally included as input to the encryption. By providing configuration information as a passcode, administrators can conveniently manage multiple aspects of the lock offline, avoiding reliance on network connectivity. This approach simplifies updates, reduces the time spent on reprogramming, and enhances security by minimising external communication channels.

[0031] Fig 1 is a schematic diagram showing an environment in which embodiments presented herein can be applied. Access to a physical space 16 is restricted by a physical barrier 15 which is selectively unlockable. The physical barrier 15 stands between the restricted physical space 16 and an accessible physical space 14. Note that the accessible physical space 14 can be a restricted physical space in itself, but in relation to this physical barrier 15, the accessible physical space 14 is accessible. The barrier 15 can be a door, gate, hatch, cabinet door, drawer, window, etc. An electronic lock 12 is provided in order to control access to the physical space 16, by selectively unlocking the barrier 15. The electronic lock 12 can include a credential reader or can connect to an external credential reader, for reading credentials such as electronic keys or biometrics.

[0032] The electronic lock 12 can be provided in the structure 11 surrounding the barrier 15 (as shown) or the electronic lock 12 can be provided in the barrier 15 itself (not shown). The electronic lock 12 is controllable to be in a locked state or in an unlocked state.

[0033] A user 5 can carry an electronic key 2. The electronic key 2 can be in any suitable format that allows an access control device to communicate (wirelessly or conductively) with the reader of the electronic lock 12 to evaluate whether to grant access. For instance, the electronic key 2 can be in the form of a key fob, a key card, a hybrid mechanical / electronic key or embedded in a smartphone. The electronic key can communicate with the electronic lock 12 using the reader of the electronic lock 12.Alternatively or additionally, the reader can also perform biometric reading of the user 5, e.g. using face recognition, fingerprint identification, iris identification, etc.

[0034] The electronic lock 12 comprises or is connected to a user input device 17, e.g. in the form of a keypad, keyboard, touchscreen, etc. The user input device 17 enables the user 5 to input a passcode. The passcode is made up of a sequence of characters, such as digits, optionally including a checkmark “V” and / or a cross “x”, or the pound sign ‘#’ and / or the asterisk ‘*’. Alternatively, the passcode can also include alphabetic (in one or two cases) and / or special characters that are neither digits nor alphabetic characters.

[0035] The electronic lock 12 can determine access rights based on the passcode, the electronic key 2 and / or biometric readings of the user 5. Depending on the access rights, the electronic lock 12 grants or denies access.

[0036] Other electronic locks 12’ can be provided at the same site as the electronic lock 12, or at other sites. It is possible that the same user has been given access to both the electronic lock 12 and one or more of the other electronic locks 12’. Access for multiple electronic locks can be defined in the form of an access role, where each electronic lock 12, 12’ grants access for one or more access roles. Alternatively, the user can be granted access to a group of locks, in which case each electronic lock 12, 12’ can determine whether to grant access depending on whether the electronic lock 12, 12’ belongs to a group of locks for which the user has been granted access.

[0037] The communication between the electronic lock 12 and the other electronic locks 12’ occur over a local wireless (or wired) link, or via a communication network 7. The communication network 7 can be a mesh network, a local area network, and / or a wide area network, such as the Internet. The communication network 7 can be based on various communication protocols, for instance Internet Protocol (IP).

[0038] Optionally, one or more servers 3 are provided for various purposes. Each one of the one or more servers 3 can be any suitable type of server or other computer that is capable of performing one or more actions of a server that are described herein. For instance, each one of the one or more servers 3 can be implemented as a standalone computer system, and / or as a cloud service where resources can be statically or dynamically assigned. The one or more servers 3 are connected to the communication network 7, e.g. via Ethernet, Wi-Fi, etc

[0039] One of the one or more servers 3 can e.g. be used to generate a passcode. Alternatively or additionally, one of the one or more of the servers 3 can be used as an intermediary node for signalling a credential from the electronic lock 12 to one or more other electronic locks 12’, as described in more detail below.

[0040] When a passcode is to be generated, this can be performed by a server 3. Specifically, an operator interface to the server, such as using a web browser, client application, or smartphone application, can be used by an operator (not shown) to generate a passcode. Alternatively or additionally, the server 3 provides an application programming interface, API, to allow another computer to request the server to generate a passcode. As known in the art per se, the server authenticates and authorises the operator or external computer to determine whether the generation of the passcode is allowed. An input to the passcode generation in the server 3 can be access data. The access data can comprise a validity time, indicating for how long access should be granted. Optionally, the validity time is open-ended, i.e. only containing a start time from when the passcode is valid from. In one embodiment, this validity time, when verified by an electronic lock, is sufficient to grant access. In other embodiments, other data is included in the access data to allow the electronic lock to evaluate whether to grant access or not.

[0041] The server 3 encrypts at least part of the access data in such a way that the output is in line with a predefined format for the passcode. For instance, when the passcode is made up of a certain number of digits, the encrypted data is presented in that format, i.e. a sequence of the certain number of digits.

[0042] The passcode is provided to the user 5 in any suitable way. For instance, the passcode can be provided in a text message, e-mail, phone call, app communication, orally, on a post-it note, etc. Once the user 5 has received the passcode, the user can enter the passcode into the user device 17 of the electronic lock 12. The electronic lock 12 decrypts the passcode to obtain decrypted access data, which is used to determine whether to grant access or not. If the decryption does not result in any valid access data, access is denied. When the access data comprises the validity time, access is only granted if the validity time is complied with.

[0043] Additionally, according to embodiments presented herein, the passcode also contains an indication of a configuration that should be applied in the electronic lock. This is described in more detail below.

[0044] Figs 2A-C are schematic diagrams illustrating structures of passcodes that can be applied in the environment of Fig 1 according to one or more embodiments.

[0045] Looking first to Fig 2A, a passcode 31 has been provided to the user 5, such that the user 5 can enter the passcode into the user input device 17. The passcode comprises encrypted data 30. By decrypting 28 the encrypted data 30, decrypted data 32 is obtained. The decrypted data 32 here comprises access data 33, allowing the electronic lock 12 to determine whether to grant access or not. Additionally, the decrypted data 32 can comprise configuration data 34, which indicates to the electronic lock 12 a configuration to apply.

[0046] Turning now to Fig 2B, in comparison with the embodiment illustrated by Fig 2A, there is here no access data 33. In this case, the passcode is to be used only for configuration and not for access. The decrypted data 32 (and its configuration data 34) contains a command that indicates that the subsequent data of the configuration data 34 defines a configuration that is to be applied by the electronic lock 12.

[0047] Turning now to Fig 2C, the passcode 31 here comprises encrypted data 30 and configuration data 34 in unencrypted form. In this case, the decryption 28 results in decrypted data 32 which here contains the access data 33 but not the configuration data 34. Nevertheless, the configuration data 34 is available as an extraction from the passcode 31.

[0048] The use of the different structures of Figs 2A-C will now be illustrated with a couple of scenarios.

[0049] In a first scenario, in line with the structure of Fig 2A, the server 3 obtains access rights, e.g. including a representation of validity time, as access data 33.Additionally, the server 3 includes configuration data 34, such as a configuration to change an unlock duration to 15 seconds after each unlock operation. The server 3 then encrypts 29 the combination of the access data 33 and the configuration data 34 intoencrypted data 30 that make up the passcode 31. Optionally, no access data 33 is provided, in which case the server 3 encrypts the configuration data 34 (without any access data 33) into encrypted data 30 that make up the passcode 31, as illustrated by the structure of Fig 2B. The passcode 31 is provided to a user 5 in any suitable manner, e.g. text message, e-mail, phone call, app communication, orally, on a post-it note, etc. Once the user 5 is by the electronic lock 12, the user 5 enters the passcode 31 into the user input device 17 of the electronic lock 12. The electronic lock 12 decrypts 28 the encrypted data 30 of the passcode 31, to be able to read both the access data 33 and the configuration data 34. The electronic lock 12 can then both evaluate access based on the access data 33 as well as apply the configuration in line with the configuration data 34.

[0050] In a second scenario, in line with the structure of Fig 2C, the server 3 obtains an indication of access rights, e.g. including a representation of validity time, as access data 33. The server 3 encrypts 29 the access data 33 into encrypted data 30. The encrypted data 30, as well as an indication of configuration data 34, is provided to the user 5 in any suitable manner, e.g. text message, e-mail, phone call, app communication, orally, on a post-it note, etc. In this case, the configuration data 34 is in unencrypted form, and can be one or more characters that are appended to or prepended to the encrypted data 30, to make up the passcode 31. Once the user is by the electronic lock 12, the user enters the passcode 31 into the user input device 17 of the electronic lock 12. The electronic lock 12 decrypts 28 the encrypted data 30 and obtains the configuration data 34 (in unencrypted form from the passcode 31), to thereby be able to read both the access data 33 and the configuration data 34. Again, the electronic lock 12 can both evaluate access based on the access data 33 as well as apply the configuration in line with the configuration data 34. An example applicable for this scenario is if the user would like to enrol another credential, such as an electronic key or biometrics. The electronic lock 12 can then be configured to enrol a credential when the input passcode ends with ‘##’ The configuration data 34 can then be appended to the encrypted data 30, for instance as a known character sequence. If the encrypted data is given to the user and is ‘710931’, the user can enter ‘710931##’, where ‘##’ is the configuration data 34, to make the electronic lock 12 enrol a subsequently presented credentiali to have the same access as that which is granted for the decrypted access data 33.

[0051] The main difference between the structures of the passcode in Fig 2A and Fig 2B, compared to the structure of Fig 2B is whether the configuration data is encrypted or not.

[0052] Figs 3A-B are swimlane diagrams illustrating embodiments of methods for configuring an electronic lock 12 of Fig 1 according to one or more embodiments. The swimlane diagrams can be considered to comprise a flow chart for methods in the electronic lock 12 in the penultimate section on the right. Selected communication between the various entities is also shown. First, embodiments covered by Fig 3A will be described.

[0053] In an enter passcode step 140, the user 5 enters a passcode into the user input device 17 of, or connected to, the electronic lock 12. The passcode is made up of a sequence of characters, such as digits, optionally including other characters such as a checkmark “V” and / or a cross “x”, or the pound sign ‘#’ and / or the asterisk ‘*’.Alternatively, the passcode can also include alphabetic (in one or two cases) and / or special characters that are neither digits nor alphabetic characters.

[0054] In a receive passcode step 40, the electronic lock 12 receives the passcode 31 having been input on the user interface device 17.

[0055] In a decrypt passcode step 42, the electronic lock 12 decrypts at least part of the passcode 31 to obtain decrypted data 32, in line with the decryption 28 of Figs 2A-C. The decrypting 42 can be performed based on a symmetric key, in which case the server does not need to keep track of an asymmetric public key of the particular electronic lock 12 when the passcode is generated. Optionally, to prevent attacks, the symmetric key is rotated at regular (configurable) time interval. For instance, the time interval can be twelve hours. The rotation is based on previous key. Optionally, the electronic lock accepts passcodes that have been encrypted with the current and previous key. When this is applied, the generated passcode will have a specific time interval when it works, based on when the symmetric key instance (in the sequence of rotated symmetric keys) is valid. With the symmetric key, the encryption (e.g. by the server 3) and the decryption is performed using the same cryptographic key. Nevertheless, the passcode can also be based on asymmetric encryption, in which case the electronic lock 12 is associated witha keypair comprising a public key and a private key. During generation, the passcode is generated based on encrypting with the public key, and during access control the electronic lock 12 decrypts using the private key.

[0056] In an optional derive access right step 44, the electronic lock 12 derives an access right for the electronic lock 12 from the decrypted data 32. Optionally, the electronic lock 12 grants access for the same passcode 31 only once. In this way, the risk for a replay attack based on the passcode is greatly reduced.

[0057] Optionally, the deriving an access right comprises deriving a validity time of the access right.

[0058] In an optional store passcode step 45, the electronic lock 12 stores the passcode 31 in association with the derived access right for subsequent use of the passcode 31 without the need to again decrypt the passcode 31. The electronic lock 12 can store a look up table comprising passcodes and associated access rights. When the user 5 subsequently uses the same passcode (or associated other credential, see below), the electronic lock can simply consult the look up table for determining access, which is more computationally efficient than decrypting the passcode.

[0059] By storing the passcode 31 in association with the derived access right, subsequent evaluations of the same passcode 31 can be performed without repeating the decrypting 42. This can reduce processing load in the electronic lock 12, reduce response time when the same passcode 31 is used again, and reduce power consumption, which can be beneficial particularly for a battery-powered electronic lock 12. The storing can also reduce repeated execution of cryptographic operations, thereby freeing processing resources for other operations of the electronic lock 12. In embodiments where the same access right is subsequently used via an associated credential, the stored association can also allow efficient verification of the access right without requiring renewed decryption of the passcode 31.

[0060] In a determine configuration step 46, the electronic lock 12 determines, from the passcode 31, a configuration to apply. The configuration can be indicated as encrypted data, in which case the configuration is based on configuration data extractedfrom the decrypted data 32, as illustrated by Figs 2A-B. Alternatively, the configuration is indicated in plain text, i.e. unencrypted data, forming part of the passcode, as illustrated by Fig 2C. The configuration can contain any configuration that is applicable for the electronic lock 12, including settings for sound levels for sound feedback, length of an unlock duration after each unlock operation, operation mode (normally closed, normally open or pulse), Bluetooth parameters; Keyboard backlight brightness, etc.

[0061] In one embodiment, the determining the configuration to apply comprises determining that the configuration of the electronic lock 12 should be changed to enroll a credential of a different type than the passcode 31. The enrolment implies that the credential of the different type will be associated with the access right indicated by the passcode. Optionally, the passcode can then be inactivated so that it cannot be used in a replay attack.

[0062] In an apply configuration step 48, the electronic lock 12 applies the configuration (indicated by the passcode) to the electronic lock 12.

[0063] In one embodiment, when the configuration to apply comprises to enroll the credential in the form of an electronic key, in an optional provide credential step 248a, the electronic key 2 provides a credential 22 from the electronic key 2 to the electronic lock 12.

[0064] In an optional read credential step 48a, the electronic lock 12 reads the credential 22 (which is of a different type than the passcode 31) from the electronic key 2.

[0065] In an optional associate credential step 48b, the electronic lock 12 associates the credential 22 (when this is received in the read credential step 48a) with the derived access right, i.e. the access rights that are associated with the passcode. At this time, the passcode is optionally deactivated to prevent replay attacks. The user can still use the credential to gain access, which is much more difficult for an attacker to replicate, regardless whether the credential is an electronic key or based on biometrics.

[0066] Optionally, the associating 48b the credential with the derived access right is only performed within a predefined duration from processing the passcode 31. So, forinstance, if the passcode indicates to enroll the credential, the credential can only be associated with the derived access right if this is performed during an enrolment mode that is active for x seconds of processing the passcode 31. The processing the passcode is to be interpreted as any point in time from which the whole passcode has been entered until when the electronic lock 12 awaits to read the credential. It is not important exactly at what point in the method the duration is measured from since the time from interpreting the passcode to waiting for the credential is short in relation to the duration. Optionally, the enrolment mode is indicated to the user by lighting of a keypad or other LEDs (light-emitting diodes) of the electronic lock 12 by providing audio feedback using a beeper or speaker and / or by providing tactile feedback, e.g. as a vibration.

[0067] In this way, the passcode 31 can be used not only for immediate access but also to securely enrol another credential 22 having the same access right. This enables configuration of access credentials directly at the electronic lock 12 without requiring network connectivity or administrative programming interfaces. The use of the passcode 31 to derive the access right ensures that the enrolled credential can inherit the same access restrictions, such as validity time or access scope, thereby maintaining consistency of access control policies. Furthermore, since the passcode 31 can optionally be deactivated after enrolment, the risk of replay attacks based on the passcode 31 can be reduced while still enabling convenient subsequent authentication using the enrolled credential 22.

[0068] In an optional transmit message step 50, when the credential 22 is received in the read credential step 48a, the electronic lock 12 transmits a message 24 to associate the credential 22 with the derived access right in at least one other electronic lock 12’.

[0069] The message 24 can be transmitted to the at least one other electronic lock 12’ within a vicinity of the electronic lock 12, e.g. using a mesh network, over a local wireless (or wired) network or using a direct wireless (or wired) communication link. When the message is transmitted only locally, any sensitive data, such as biometrics or electronic key details, are not transmitted over a larger network which might be more vulnerable to attacks.

[0070] Alternatively, the message 24 is transmitted to a central server 3, for propagation to the at least one other electronic lock 12’, relying less on local physical infrastructure.

[0071] The access right can be associated with each one of the at least one other electronic lock 12’, based on an access role or a group of electronic locks, as described above.

[0072] In an optional receive message step 350, the other electronic lock(s) 12’ receive the message 24 from the electronic lock 12. Each one of the electronic lock(s) 12’ store the credential so that the credential can be used to gain access to the physical space controlled by the respective electronic lock.

[0073] Looking now to Fig 3B, only new or modified steps compared to Fig 3A will be described.

[0074] In an optional provide credential step 148a, the user 5 provides the credential 22 in the form of a biometric credential. The biometric credential can be in the form for face recognition, fingerprint identification, iris identification, etc.

[0075] In the read credential step 48a, the electronic lock 12 reads biometric credentials and associates these biometric credentials with access rights that are given by the passcode, e.g. in the lookup table mentioned above. It is to be noted that the electronic lock 12 does not need to have any biometric credentials prior to this step; the reading of biometrics of the user 5, i.e. the biometric credentials, can thereby be used as a template for subsequent access via the electronic lock.

[0076] It is to be noted that all details and features that are described above with a reference to the credential being an electronic key are also applicable for when the credential is biometric credential.

[0077] Using embodiments presented herein, the electronic lock can conveniently be configured using the passcode. The electronic lock does not need to be connected to a network; yet most if not all configuration operations can be implemented using the passcode. When the configuration is to enroll another credential, the new credential canbe used by the user, in line with the access associated with the passcode. In the prior art, it has been excessively difficult, if not impossible, to enroll new electronic keys or biometric credentials to an electronic lock without the electronic lock having network access. Not only is the enrolment made possible this way, but the enrolment is implemented in a secure way, where, optionally, the original passcode can be deactivated to prevent replay attacks.

[0078] Fig 4 is a schematic diagram illustrating components of the electronic lock 12 of Fig 1. Processing circuitry 60 is provided using any combination of one or more of a suitable central processing unit (CPU), graphics processing unit (GPU), multiprocessor, neural processing unit (NPU), microcontroller, digital signal processor (DSP), etc., capable of executing software instructions 67 stored in memory circuitry 64, which can thus be a computer program product. The processing circuitry 60 could alternatively be implemented using an application specific integrated circuit (ASIC), field programmable gate array (FPGA), etc. The processing circuitry 60 can be configured to execute the method described with reference to Figs 3A-B above.

[0079] The memory circuitry 64 can be any combination of random-access memory (RAM) and / or read-only memory (ROM). The memory circuitry 64 also comprises non-transitory persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid-state memory or even remotely mounted memory.

[0080] A data memory 66 is also provided for reading and / or storing data during execution of software instructions in the processing circuitry 60. The data memory 66 can be any combination of RAM and / or ROM.

[0081] The electronic lock 12 further comprises an I / O interface 62 for communicating with external and / or internal entities. Optionally, the I / O interface 62 also includes a user interface.

[0082] Other components of the electronic lock 12 are omitted in order not to obscure the concepts presented herein.

[0083] Fig 5 shows one example of a computer program product 90 comprising computer readable means. On this computer readable means, a computer program 91 can be stored in a non-transitory memory. The computer program can cause processing circuitry to execute a method according to embodiments described herein. In this example, the computer program product 90 is in the form of a removable solid-state memory, e.g. a Universal Serial Bus (USB) drive. As explained above, the computer program product could also be embodied in a memory of a device, such as the computer program product 64 of Fig 4. While the computer program 91 is here schematically shown as a section of the removable solid-state memory, the computer program can be stored in any way which is suitable for the computer program product, such as another type of removable solid-state memory, or an optical disc, such as a CD (compact disc), a DVD (digital versatile disc) or a Blu-Ray disc.

[0084] The aspects of the present disclosure have mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the invention, as defined by the appended patent claims. Thus, while various aspects and embodiments have been disclosed herein, other aspects and embodiments will be apparent to those skilled in the art. The various aspects and embodiments disclosed herein are for purposes of illustration and are not intended to be limiting, with the true scope being indicated by the following claims.

Claims

CLAIMS1. A method for configuring an electronic lock (12), the method being performed by the electronic lock (12), the method comprising:receiving (40) a passcode (31) having been input on a user interface device (17), the passcode (31) comprising a sequence of characters;decrypting (42) at least part of the passcode (31) to obtain decrypted data (32); determining (46), from the passcode (31), a configuration to apply; and applying (48) the configuration to the electronic lock (12).

2. The method according to claim 1, further comprising, after the decrypting (42): deriving (44) an access right for the electronic lock (12) from the decrypted data (32).

3. The method according to claim 2, wherein the deriving (44) an access right comprises granting access for the same passcode (31) only once.

4. The method according to claim 2 or 3, wherein the deriving (44) an access right comprises deriving a validity time of the access right.

5. The method according to any one of claims 2 to 4, wherein the determining (46) the configuration to apply comprises determining to enroll a credential (22) of a different type than the passcode (31), and wherein the applying (48) the configuration comprises:reading (48a) a credential (22) of a different type than the passcode (31); and associating (48b) the credential (22) with the derived access right.

6. The method according to claim 5, wherein the credential (22) is in the form of an electronic key or a biometric credential.

7. The method according to claim 5 or 6, further comprising:transmitting (50) a message (24) to associate the credential (22) with the derived access right in at least one other electronic lock (12’).

8. The method according to claim 7, wherein the transmitting (50) a message (24) comprises transmitting the message (24) to the at least one other electronic lock (12’) within a vicinity of the electronic lock (12).

9. The method according to claim 7, wherein the transmitting (50) a message (24) comprises transmitting the message (24) to a central server (3), for propagation to the at least one other electronic lock (12’).

10. The method according to claim 8 or 9, wherein the message (24) comprises biometric data of the credential (22).

11. The method according to any one of claims 7 to 10 wherein the access right is associated with each one of the at least one other electronic lock (12’), based on an access role or a group of electronic locks.

12. The method according to any one of claims 2 to 11, further comprising:storing (45) the passcode (31) in association with the derived access right for subsequent use of the passcode (31) without the need to again decrypt the passcode (31).

13. The method according to any one of claims 5 to 12, wherein the associating (48b) the credential (22) with the derived access right is only performed within a predefined duration from processing the passcode (31).

14. The method according to any one of the preceding claims, wherein the decrypting (42) is performed based on a symmetric key.

15. An electronic lock (12) comprising:processing circuitry (60); andmemory circuitry (64) storing instructions (67) that, when executed by the processing circuitry, cause the electronic lock (12) to:receive a passcode (31) having been input on a user interface device (17), the passcode (31) comprising a sequence of characters;decrypt at least part of the passcode (31) to obtain decrypted data (32); determine, from the passcode (31), a configuration to apply; andapply the configuration to the electronic lock (12).

16. A computer program (67, 91) for configuring an electronic lock (12), the computer program comprising computer program code which, when executed on an electronic lock (12) causes the electronic lock (12) to:receive a passcode (31) having been input on a user interface device (17), the passcode (31) comprising a sequence of characters;19decrypt at least part of the passcode (31) to obtain decrypted data (32); determine, from the passcode (31), a configuration to apply; andapply the configuration to the electronic lock (12).

17. A computer program product (64, 90) comprising a computer program according to claim 16 and a computer readable means comprising non-transitory memory in which the computer program is stored.