Electronic Credential Management via Diversification Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic credential management systems for lock systems rely on physical credentials, requiring direct interaction with lock devices for operation and management, which limits flexibility and security, especially when adding or revoking credentials.

Innovation Solution

A method using a diversification algorithm to generate keys for encrypting and decrypting control system payloads on mobile devices, allowing secure communication and management of credentials between mobile devices and lock devices, including revocation and administrative updates without direct physical presence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If physical credentials are used for lock system management, then direct interaction with lock devices is required, but this reduces flexibility and security for remote credential distribution and management

Engineering Contradiction:
ImproveflexibilityVSAvoiddirect interaction requirement
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces a credential management server as an intermediary between the lock device and the user's mobile device. The server handles credential distribution, storage, and revocation remotely, eliminating the need for direct physical interaction between the user and lock device while maintaining security through encrypted communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If physical credentials are manually added to each lock device, then credential distribution is straightforward, but this process is time-consuming and inefficient

Engineering Contradiction:
Improvecredential distribution efficiencyVSAvoidtime for manual credential addition
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-generating and storing credential templates on the credential management server. When a user needs access, the system rapidly instantiates and distributes the specific credential from the template to the user's mobile device and relevant lock devices simultaneously, eliminating the need for manual, sequential credential addition to each device.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If credentials are stored on mobile devices, then remote access is enabled, but security risks from playback attacks increase

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity against playback attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic credentials that are time-limited and single-use. Each credential has an expiration time and can only be used once to unlock a door. After use or expiration, the credential becomes invalid, preventing playback attacks where recorded credential data is replayed. The system continuously generates new credentials and revokes old ones, making the credential set dynamic rather than static.

Inventive Principle:
Principle #15Dynamics

4Reliability

If credential revocation is implemented remotely, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex credential management functions (generation, distribution, storage, revocation, and validation) from the lock devices and concentrates them on a dedicated credential management server. The lock devices are simplified to only perform credential verification, while all complex operations are handled remotely by the server, reducing on-device complexity while maintaining comprehensive security control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11023875B2Electronic credential management system
Publication Date: 2021.06.01 SCHLAGE LOCK CO LLC
  • US11023875B2 patent drawing
  • US11023875B2 patent drawing
  • US11023875B2 patent drawing

AI summary

A system and method for the management of electronic credentials stored on mobile devices. The system may encrypt information that is provided to a lock device and an access control system using diversification keys. The diversification keys may be generated by supplying a master key and a component identifier such as, for example, a mobile device identifier, to a diversification algorithm. The mobile device may be a conduit for the communication of information between the access control system and the lock device. The mobile device may be unable to decrypt information that has been encrypted by a diversification key. Embodiments also provide for enrolling administrative mobile devices with the access control system, the distribution and revocation of credential identifiers for user mobile device, and removing administrative mobile devices that are enrolled with lock devices.