Access Control Authentication via Secure Session Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic access control systems face security vulnerabilities due to the risk of data interception and manipulation during wireless transmission of access rights, particularly between the access control center and mobile devices, as well as potential attacks on access control devices.

Innovation Solution

Implementing a method that uses digital certificates for authentication and a key exchange or derivation protocol to establish a secure transmission channel between the electronic identification medium and the access control device, utilizing a session key generated from access control device-specific codes and random numbers, ensuring the integrity and confidentiality of access rights data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless transmission of access rights data is used between access control center and mobile devices, then convenience and flexibility of access control is improved, but security against data interception and manipulation deteriorates

Engineering Contradiction:
Improveconvenience of access controlVSAvoiddata interception and manipulation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing authentication protocols and secure transmission channels before actual data transmission occurs. The system establishes cryptographic security measures in advance to prevent interception and manipulation of access rights data during wireless communication between the access control center and mobile devices.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces cryptographic protocols and secure transmission channels as intermediaries between the access control center and mobile devices. These intermediaries encrypt the access rights data and establish authenticated communication paths, preventing direct interception by unauthorized parties while maintaining the convenience of wireless access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If access rights data is stored in electronic identification medium for wireless transmission, then access speed and user convenience are improved, but vulnerability to security attacks and data copying increases

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity attacks and data copying
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by pre-storing access rights data in electronic identification media such as mobile devices and RFID tags. This allows for rapid authentication and access control decisions without requiring real-time network communication, while security measures are established in advance through secure data provisioning and encryption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs the principle of disposable short-living objects by using single-use or limited-use access credentials. Access rights data can be programmed into electronic identification media for specific purposes and time periods, then invalidated or reprogrammed, preventing long-term vulnerability to copying and unauthorized reuse.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If access control devices are made autonomous without network connection, then operational independence and reliability are improved, but ability to receive security updates and remote programming deteriorates

Engineering Contradiction:
Improveoperational independenceVSAvoidremote programming capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-configuring access control devices with necessary security credentials, access rights data, and operational parameters during installation or maintenance periods when network connection is available. This allows the devices to operate autonomously without continuous network connectivity while maintaining security through pre-established cryptographic measures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by allowing access control devices to transition between autonomous operation mode and network-connected programming mode. The system can dynamically update access rights data and security parameters when network access is available, then return to autonomous operation, balancing operational independence with adaptability to security updates.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2624223B1Method and apparatus for access control
Publication Date: 2017.09.20 EVVA SICHERHEITSTECHNOLOGIE GMBH
  • EP2624223B1 patent drawingFigure 1
  • EP2624223B1 patent drawingFigure 2
  • EP2624223B1 patent drawingFigure 3

AI summary

In an access control procedure, access rights data are transmitted from an electronic identification medium (5) to an access control device (13), whereby the access rights data are evaluated in the access control device (13) to determine access authorization and, depending on the determined access authorization, a blocking device is activated to either grant or deny access. Authentication of the electronic identification medium (5) takes place on the basis of at least one digital certificate.The data transmission includes the use of a key exchange or derivation protocol, whereby at least one secret, common session key is made available to the electronic identification medium (5) and the access control device (13), whereupon the at least one session key is used to establish a secure transmission channel between the electronic identification medium (5) and the access control device (13), wherein the access rights data are transmitted via the secure channel from the electronic identification medium (5) to the access control device (13).