Access Control Device Secure Channel Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems face security vulnerabilities due to the risk of unauthorized interception and manipulation of wireless access right data, particularly in larger locking systems, where ensuring authenticity, integrity, and confidentiality of access authorizations is challenging, and power consumption is a concern for long-term battery operation.
Innovation Solution
Implementing a secure transmission channel using a common system key shared between the system management unit and access control device, with the electronic authorization carrier storing a carrier-specific key, derived via a key derivation function, and employing a zero-knowledge protocol and symmetrical encryption with Authenticated Encryption with Associated Data (AEAD) to establish authenticity and integrity, eliminating the need for individual programming of access control devices and reducing power consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless transmission of access right data is used, then ease of operation and remote programming are improved, but security against interception and manipulation deteriorates
Solution Approach 1:
The patent applies preliminary anti-action by pre-establishing a secure transmission channel using cryptographic authentication before any access right data is transmitted. The system management unit and access control device mutually authenticate each other and establish encrypted communication channels in advance, preventing unauthorized interception and manipulation before they can occur during data transmission
Solution Approach 2:
The patent uses cryptographic protocols and authentication mechanisms as intermediaries between the system management unit and access control device. These intermediary security layers verify identities, establish secure channels, and protect the actual access right data transmission from direct exposure to potential attackers
2Reliability
If individual access control devices are programmed with unique keys, then security is improved, but device complexity and programming time increase
Solution Approach 1:
The patent applies preliminary action by having the system management unit perform all key generation and distribution operations in advance during system initialization. Access control devices are pre-programmed with necessary security parameters and authentication credentials before deployment, eliminating the need for complex individual programming later while maintaining high security standards
Solution Approach 2:
The patent implements a universal key management approach where the system management unit serves multiple functions: generating keys, distributing credentials, authenticating devices, and managing security policies. This centralized universal system simplifies individual device complexity while maintaining strong security through standardized cryptographic protocols
3Reliability
If secure cryptographic protocols are implemented, then security against unauthorized access is improved, but power consumption increases
Solution Approach 1:
The patent applies preliminary action by performing computationally intensive cryptographic operations, including key generation and mutual authentication, during system initialization and setup phases. Once the secure channel is established, subsequent access control operations use pre-computed credentials and lighter verification protocols, significantly reducing power consumption during actual access control events
Solution Approach 2:
The patent implements local quality by optimizing cryptographic operations for the specific capabilities and constraints of battery-powered access control devices. The system uses asymmetric cryptography only when necessary for initial authentication, then switches to more efficient symmetric cryptography for ongoing operations, and implements sleep modes to minimize power consumption during idle periods
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
In a method for operating an access control system for access control, particularly in buildings, a secure transmission channel is established between an electronic authorization carrier (5) and an access control device (2), and access rights data is transmitted via the secure transmission channel, whereby, depending on the determined access authorization, a blocking device is activated to selectively release or block access.A system management unit (1) and the access control device (2), but not the electronic authorization carrier (5), have a common system key stored, and the electronic authorization carrier (5) has a carrier identifier and a carrier-specific key stored, wherein the establishment of the secure transmission channel includes verifying the authenticity and integrity of the transmission channel by deriving the carrier-specific key in the access control device (2) from the system key and the carrier identifier using a key derivation function, and verifying the conformity of the derived carrier-specific key with the carrier-specific key stored in the authorization carrier, preferably using a zero-knowledge protocol.