Electronic Lock Bluetooth Authentication Without Persistent Bonding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Bluetooth communication systems for IoT devices like electronic locks face limitations in managing secure connections, particularly in multifamily environments where a large number of users need access, due to storage constraints on bonding keys and cumbersome re-pairing processes, especially for iOS devices.

Innovation Solution

A method and system for establishing secure communication between a mobile device and an IoT device, such as an electronic lock, involving mutual authentication and key generation without requiring a bonding process, using short-range wireless protocols like Bluetooth, and managing encryption keys separately from the Bluetooth chipset.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Bluetooth bonding is used to establish secure connections, then connection security is improved, but the number of stored bonding keys increases beyond storage capacity

Engineering Contradiction:
Improveconnection securityVSAvoidnumber of bonding keys
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the bonding key storage requirement from the Bluetooth connection establishment process. Instead of storing bonding keys in the Bluetooth chipset, the system uses external servers to store and manage cryptographic keys, allowing secure connections without consuming limited on-device storage capacity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary server system that mediates the authentication process between mobile devices and electronic locks. The server acts as a third party that generates and manages cryptographic keys, replacing the traditional direct bonding mechanism and eliminating the need for the electronic lock to store multiple bonding keys locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If re-pairing is performed on iOS devices, then connection is restored, but manual removal of pairing is required

Engineering Contradiction:
Improvere-pairing processVSAvoidtime for manual removal
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent extracts the pairing management functionality from the mobile device's operating system Bluetooth stack. By using a custom authentication protocol that doesn't rely on standard Bluetooth bonding, the system avoids the iOS restriction that requires manual pairing removal, allowing seamless re-pairing without user intervention.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of following the conventional approach where the mobile device initiates and manages the bonding process, the patent inverts the approach by having the electronic lock and server manage the cryptographic credentials. This reversal allows the system to bypass iOS bonding restrictions and enable automatic re-pairing.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If Bluetooth bonding is used, then secure communication is established, but the process becomes complex and time-consuming

Engineering Contradiction:
Improvesecure communicationVSAvoidpairing process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service authentication mechanism where the server automatically generates cryptographic key pairs and manages the authentication process without requiring user configuration or complex pairing steps. The mobile device and electronic lock simply need to present their credentials to the server, which handles the complex cryptographic operations automatically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary cryptographic key generation and exchange during an initial setup phase. The server pre-generates bonding keys and distributes them to authorized devices before actual use, so that subsequent connections can be established quickly without going through complex bonding procedures each time.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If bonding keys are stored in the electronic lock, then authentication is maintained, but storage capacity is limited

Engineering Contradiction:
ImproveauthenticationVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSVolume of stationary object

Solution Approach 1:

The patent extracts the authentication credential storage function from the electronic lock's internal memory. Instead of storing bonding keys locally in the limited on-device storage, the system stores cryptographic credentials on external servers with ample capacity, allowing the electronic lock to support an unlimited number of authenticated devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transitions from local on-device storage to cloud-based storage, moving the authentication credentials from a constrained physical dimension (chipset memory) to an unconstrained remote dimension (server storage). This dimensional shift eliminates storage capacity limitations while maintaining authentication security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12437594B2Establishment of secure Bluetooth connection to internet of things devices, such as electronic locks
Publication Date: 2025.10.07 ASSA ABLOY AMERICAS RESIDENTIAL INC
  • US12437594B2 patent drawing
  • US12437594B2 patent drawing
  • US12437594B2 patent drawing

AI summary

Systems and methods are disclosed for managing secure connection between a mobile device and an Internet of things device, such as an electronic lock. In some instances, a mutual authentication process is performed, and public keys are exchanged. Once keys are exchanged, subsequent communication between the devices may be encrypted using a shared key generated using the exchanged keys.