Asymmetric Cryptography for Physical Lock Controllers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security systems for physical resources, especially those at remote or infrequently accessed locations, are inadequate due to reliance on physical keys that can be copied, lost, or stolen, and lack robust security measures for unauthorized access prevention.
Innovation Solution
A system using a server that stores public and private key pairs for electronic lock controllers, enabling encrypted and authenticated communication with mobile devices, and digitally signed lock-access data to securely grant access based on time, version, and identity data, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If physical keys are used to secure remote or infrequently accessed physical resources, then ease of operation is improved, but security is worsened because physical keys can be easily copied, lost, or stolen
Solution Approach 1:
The patent replaces mechanical key-based access systems with electronic cryptographic authentication systems. Mobile devices use asymmetric cryptography and digital certificates to authenticate with electronic lock controllers, eliminating physical keys entirely. This substitution provides both ease of operation through contactless mobile device access and enhanced security through cryptographic authentication that cannot be copied or lost like physical keys.
2Reliability
If electronic locks with wired power and data connections are used, then security is improved through encrypted communication, but device complexity and installation cost worsen due to requirement of wired infrastructure
Solution Approach 1:
The patent replaces wired electrical and data connections with wireless communication technologies. Mobile devices communicate with electronic lock controllers using wireless protocols, eliminating the need for complex wired infrastructure while maintaining secure encrypted communication through cryptographic protocols. This reduces installation complexity and cost for remote locations while preserving security through digital authentication.
Solution Approach 2:
The patent creates a universal access system where mobile devices can authenticate and control electronic locks without location-specific wired infrastructure. The cryptographic authentication protocol works across different locations and devices, providing a universal solution that eliminates the need for separate wired installations at each remote location while maintaining consistent security levels.
3Ease of operation
If conventional smart locks are used in residential applications, then ease of operation is improved, but security is worsened for remote resources because unauthorized access has more time and ability without timely detection
Solution Approach 1:
The patent implements feedback mechanisms where the server receives notifications when access attempts occur at remote physical resources. The system can send alerts to authorized users or security personnel when unauthorized access attempts are detected, providing timely detection and response capability that conventional residential smart locks lack for remote locations. This feedback loop enhances security by enabling real-time monitoring and response to security events.
Solution Approach 2:
The patent uses digital certificates and cryptographic authentication that are pre-configured and validated before access is granted. The server verifies the mobile device's credentials and the lock controller's digital certificate in advance of the actual access event, ensuring that only authenticated parties can interact with the system. This preliminary validation prevents unauthorized access before it can occur, addressing the security weakness of conventional systems that react rather than prevent.
Data Source
AI summary
Digital certificates are signed by a server's private key and installed at lock controllers that restrict access to physical resources. The server's public key is distributed to lock controllers and to mobile electronic devices operated by users who are given access to the physical resources. Lock-access data is digitally signed by the server's private key and provided to mobile electronic devices to facilitate access. The lock controller validates lock-access data and grants access conditionally based on time, version, and/or identity data provided within lock-access data. The use of certificates reduces the need to rely on a security scheme specific to the network. Lock controllers can also broadcast status notifications, so that updates and log data can be securely communicated with the server using mobile electronic devices as a proxy. The system is highly scalable, as each lock controller need not track the full scope of access permissions.


