Access Control Authentication via Secure Session Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic access control systems face security vulnerabilities due to the risk of data interception and manipulation during wireless transmission of access rights, particularly between the access control center and mobile devices, as well as potential attacks on access control devices.
Innovation Solution
Implementing a method that uses digital certificates for authentication and a key exchange or derivation protocol to establish a secure transmission channel between the electronic identification medium and the access control device, utilizing a session key generated from access control device-specific codes and random numbers, ensuring the integrity and confidentiality of access rights data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless transmission of access rights data is used between access control center and mobile devices, then convenience and flexibility of access control is improved, but security against data interception and manipulation deteriorates
Solution Approach 1:
The patent applies preliminary anti-action by implementing authentication protocols and secure transmission channels before actual data transmission occurs. The system establishes cryptographic security measures in advance to prevent interception and manipulation of access rights data during wireless communication between the access control center and mobile devices.
Solution Approach 2:
The patent introduces cryptographic protocols and secure transmission channels as intermediaries between the access control center and mobile devices. These intermediaries encrypt the access rights data and establish authenticated communication paths, preventing direct interception by unauthorized parties while maintaining the convenience of wireless access control.
2Speed
If access rights data is stored in electronic identification medium for wireless transmission, then access speed and user convenience are improved, but vulnerability to security attacks and data copying increases
Solution Approach 1:
The patent implements preliminary action by pre-storing access rights data in electronic identification media such as mobile devices and RFID tags. This allows for rapid authentication and access control decisions without requiring real-time network communication, while security measures are established in advance through secure data provisioning and encryption.
Solution Approach 2:
The patent employs the principle of disposable short-living objects by using single-use or limited-use access credentials. Access rights data can be programmed into electronic identification media for specific purposes and time periods, then invalidated or reprogrammed, preventing long-term vulnerability to copying and unauthorized reuse.
3Reliability
If access control devices are made autonomous without network connection, then operational independence and reliability are improved, but ability to receive security updates and remote programming deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-configuring access control devices with necessary security credentials, access rights data, and operational parameters during installation or maintenance periods when network connection is available. This allows the devices to operate autonomously without continuous network connectivity while maintaining security through pre-established cryptographic measures.
Solution Approach 2:
The patent implements dynamics by allowing access control devices to transition between autonomous operation mode and network-connected programming mode. The system can dynamically update access rights data and security parameters when network access is available, then return to autonomous operation, balancing operational independence with adaptability to security updates.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In an access control procedure, access rights data are transmitted from an electronic identification medium (5) to an access control device (13), whereby the access rights data are evaluated in the access control device (13) to determine access authorization and, depending on the determined access authorization, a blocking device is activated to either grant or deny access. Authentication of the electronic identification medium (5) takes place on the basis of at least one digital certificate.The data transmission includes the use of a key exchange or derivation protocol, whereby at least one secret, common session key is made available to the electronic identification medium (5) and the access control device (13), whereupon the at least one session key is used to establish a secure transmission channel between the electronic identification medium (5) and the access control device (13), wherein the access rights data are transmitted via the secure channel from the electronic identification medium (5) to the access control device (13).