Electromechanical Locking System with Segmented Digital Access Rights
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional locking systems face security risks and inefficiencies when dealing with lost keys, as master key systems can be misused and are often prohibited or not commercially viable, and electromechanical locks inherit these issues.
Innovation Solution
A locking system utilizing electromechanical locks with communication interfaces, processors, and encrypted data, where user keys and service keys can be programmed to grant access rights, allowing secure and temporary access without the need for physical key duplication, using a server and personal electronic devices for authorization and programming.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a master key system is used to allow access to multiple locks, then the ease of operation is improved, but the security is worsened due to the risk of key misuse and misplacement
Solution Approach 1:
The patent segments the master key functionality by distributing individual access rights to multiple user keys, each encoded with specific access permissions. Instead of one physical master key, the system creates multiple segmented digital keys (e.g., user keys 108, service keys 116) that collectively provide the same access control functionality without the security risks of a single master key.
Solution Approach 2:
The patent replaces the mechanical master key system with an electromechanical locking system (locks 104, 106) that uses electronic authentication. The mechanical key insertion and tumbling mechanism is substituted with electronic communication interfaces, processors, and encrypted data verification, eliminating the physical master key vulnerability while maintaining access control functionality.
2Device complexity
If traditional mechanical locks are used, then the device complexity is reduced, but the security and flexibility are worsened due to the inability to remotely manage access rights
Solution Approach 1:
The locking system is designed with multi-functionality to handle various access control scenarios. The electromechanical locks can authenticate different types of keys (user keys, service keys, temporary keys) with different permission levels. The system universally manages access rights through a centralized database that can grant, revoke, and modify permissions for any user or service key without hardware changes.
Solution Approach 2:
The patent introduces a server or centralized database as an intermediary between the physical locks and the keys. This intermediary manages the encrypted access right data, authenticates keys, and controls access permissions remotely. The intermediary enables flexible access management (granting temporary access to service keys, revoking lost keys) without requiring physical intervention at the lock location.
3Ease of operation
If physical key duplication is used to provide backup access, then the ease of operation is improved, but the security is worsened due to the risk of key loss and theft
Solution Approach 1:
The patent creates digital copies of access rights through service keys that can be programmed and distributed without physical duplication risks. Instead of cutting additional physical keys, the system generates digital copies (service keys 116) that contain encrypted access rights. These digital copies can be securely distributed, stored, and revoked through software management, eliminating the physical key loss problem while providing backup access capability.
Data Source
AI summary
This document discloses a solution for configuring access rights in a locking system comprising a plurality of electromechanical locks and a plurality of keys to users of the system. Each key stores encrypted data defining an opening right to a particular subset of the plurality of electromechanical lock, the subset of locks assigned to the respective user. The system further comprises a service key storing, as a default, no encrypted data to any of the subsets of locks. The system further comprises a computer program product configured to receive, via a user interface of a personal electronic device of a user, a write authorization from the user of a specific subset of the plurality of electromechanical locks that are assigned to the user; in response to the write authorization, an opening right of the service key is generated for the specific subset of the plurality of electromechanical locks as the encrypted data, and the generated encrypted data containing the opening right to the specific subset of the plurality of electromechanical locks is written to the service key after checking the user has access rights to the specific subset of the plurality of electromechanical locks. Thereafter, the service can be used to open the subset of the plurality of electromechanical locks.


