Electronic Access Medium Asymmetric Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Locking systems with electronic access media, such as transponders, are vulnerable to unauthorized reading and manipulation of access rights, which compromises security.
Innovation Solution
The implementation of an electronic access medium with a computing unit, communication interface, and security module that uses asymmetric key pairs and symmetrical keys for encryption and decryption, ensuring that access rights are encrypted with a public key and decrypted with a private key, and utilizing a block memory for efficient storage and quick access, along with a separate security module for secure key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If access rights are stored in an electronic access medium, then convenience of access is improved, but vulnerability to unauthorized reading and manipulation increases
Solution Approach 1:
The patent divides the key management into separate components: public keys are stored in the electronic access medium while private keys are stored in the security module of the locking system. This segmentation ensures that even if the access medium is compromised, the private keys remain protected in the locking system's security module, preventing unauthorized access rights extraction.
Solution Approach 2:
The patent introduces cryptographic keys as intermediaries between the electronic access medium and the locking system. Public keys encrypt access rights during transmission and storage, while private keys decrypt them in the security module. This intermediary encryption layer prevents direct unauthorized reading or manipulation of access rights.
2Reliability
If access rights are encrypted with public key, then security is improved, but processing time increases
Solution Approach 1:
The patent performs public key encryption of access rights in advance during the authentication process. The electronic access medium encrypts access rights with its public key before transmission, and the locking system decrypts them with the corresponding private key in the security module. This preliminary encryption ensures security while allowing efficient subsequent verification.
Solution Approach 2:
The patent changes the cryptographic parameters by using asymmetric encryption (public/private key pairs) for secure transmission and storage of access rights, while potentially using symmetric encryption for faster local verification within the security module. This parameter change balances security requirements with processing efficiency.
3Reliability
If separate security module is used for key management, then security is improved, but device complexity increases
Solution Approach 1:
The patent extracts the private key storage and decryption functionality from the electronic access medium and places it in a separate security module within the locking system. This extraction ensures that sensitive private keys never leave the controlled environment of the locking system's security module, enhancing security despite increased system complexity.
Solution Approach 2:
The security module in the locking system provides self-service by autonomously managing private keys, decrypting access rights, and verifying authentication data without requiring external intervention. This self-contained security management reduces the need for additional external security infrastructure.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to an electronic access medium (200) for a locking system (100), a locking system (100) and a method (500) for operating a locking system (100), wherein a cryptographic encryption method is used.