Electronic Locking Device Segmentation for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic locking devices face security concerns due to the placement of safety-relevant components in easily accessible areas, and they are not modular enough to accommodate different security technologies and form factors without compromising security.

Innovation Solution

The electronic locking device is designed with a first module in an accessible location for signal reception and a second module in a physically protected area for evaluation and control, allowing for modular and secure operation with interchangeable first modules and standardized second modules, using a combination of RFID and auxiliary processors for secure authentication and energy management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If safety-relevant elements (evaluation electronics) are arranged in the easily accessible knob area, then the device is simpler to manufacture and assemble, but security is compromised as the elements become vulnerable to manipulation and direct access

Engineering Contradiction:
Improveease of assemblyVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The electronic locking device is divided into two separate modules: a first module containing the receiving unit for signal reception (can be placed in the accessible knob area) and a second module containing the evaluation unit for secure evaluation (placed in the protected cylinder housing). This segmentation allows each module to be optimized for its specific function while maintaining overall system security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A communication interface acts as an intermediary between the first module (receiving unit) and the second module (evaluation unit). This interface enables secure signal transmission between the accessible and protected areas, ensuring that evaluation electronics never directly access user-provided inputs without going through the protected evaluation path.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If reading electronics are placed in the doorknob and evaluation electronics in a separate location, then security is improved, but modularity is reduced as each cylinder becomes individually programmable and cannot be easily replaced

Engineering Contradiction:
ImprovesecurityVSAvoidmodularity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The device is segmented into a reusable first module (receiving unit) that can be interchangeably installed in different cylinders, and a second module (evaluation unit) that is cylinder-specific but securely housed. This segmentation enables modular replacement of the first module while maintaining security through the protected second module.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first module (receiving unit) is designed with universal functionality that allows it to be used across different cylinder types and applications. It contains the necessary receiving elements and control means to work with various electronic keys and access media, making it a versatile component that can be replaced without reprogramming.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If the evaluation unit is placed in the accessible knob area, then the device structure is simplified, but the sequential logic for authentication decision-making becomes vulnerable to manipulation and bypassing

Engineering Contradiction:
Improvestructural complexityVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The evaluation unit with its sequential logic for authentication decision-making is segmented into a separate second module housed in the protected cylinder housing, isolated from the accessible first module. This ensures that the critical authentication logic remains protected from manipulation while the receiving unit handles only signal acquisition.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The sequential logic for authentication decisions is extracted from the accessible first module and placed in the protected second module. This extraction ensures that the decision-making process for authentication cannot be manipulated or bypassed from the accessible areas, while still allowing the receiving unit to function independently for signal reception.

Inventive Principle:
Principle #2Taking out (Extraction)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This design enhances security and modularity, allowing for easy interchange of first modules without reprogramming the second module, supports various security technologies, and reduces energy consumption while maintaining high security standards.

Implementation Method 1

The receiving unit has a receiving element - antenna or the like - for receiving signals from the electronic key

Methodology Applied
Scientific EffectElectromagnetic induction: Electromagnetic Induction

Data Source

PatentEP2460147B1Electronic locking device
Publication Date: 2019.08.21 DORMAKABA SCHWEIZ AG
  • EP2460147B1 patent drawingFigure 1
  • EP2460147B1 patent drawingFigure 2~4

AI summary

According to an aspect of the invention, an electronic locking device is substantially characterized by a first module (1) and a second module (2), the first module being located at a location that is accessible to the user — for example, in the doorknob or outside on the door fitting — and having a receiving unit (4) for receiving signals from an electronic key. The receiving unit has a receiving element — an antenna or the like — for receiving signals from the electric key and also has corresponding activation means. The second module is arranged in a physically protected area — for example, possibly in the rotor of the lock cylinder; in any case, behind the mechanical attack protection — and contains an evaluation unit (5) for evaluating the signals from the receiving unit and activation means for activating the electromechanical drive (M). This also means that the sequential logic for deciding whether an authorization exists or not is present in the second module.