Local Mobile Key Distribution for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems require complex account setup and management processes for guests, which can be cumbersome and inefficient, especially when issuing mobile credentials for access to electronic locks or other restricted areas.

Innovation Solution

A system that allows a local portal to generate and encrypt a mobile key, which is then communicated to a mobile device for decryption and use in accessing access controls, eliminating the need for complex account management by using a pre-shared password and local or cloud-based encryption keys, and enabling communication via Bluetooth, NFC, email, or SMS.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cloud-based credential service is used to issue mobile credentials, then secure access control is achieved, but complex account setup and management processes are required

Engineering Contradiction:
Improvesecure access controlVSAvoidaccount management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the credential issuance function from the cloud-based system and implements it locally on the mobile device. The mobile device generates cryptographic key pairs and credentials locally without requiring cloud service account setup, thereby eliminating complex account management while maintaining secure access control through local cryptographic operations

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a local portal as an intermediary that enables keyless credential issuance. The portal communicates with the mobile device through standardized protocols to provision credentials directly to the device's secure element, bypassing the need for cloud-based account management while ensuring secure credential distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud services are used for credential management, then centralized control is achieved, but the process becomes cumbersome and inefficient

Engineering Contradiction:
Improvecentralized controlVSAvoidcredential issuance efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments the credential management system into independent components: local credential generation on mobile devices, standalone portal systems for keyless provisioning, and distributed access control points. This segmentation enables parallel operations and eliminates sequential dependencies on cloud services, significantly improving credential issuance efficiency while maintaining centralized policy control through configurable access rules

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-provisioning credentials to mobile devices before guests arrive at the property. The local portal can issue credentials in advance through keyless provisioning, eliminating check-in delays and enabling guests to access their rooms immediately upon arrival without requiring real-time cloud verification

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11798333B2Access control system with local mobile key distribution
Publication Date: 2023.10.24 HONEYWELL INTERNATIONAL INC
  • US11798333B2 patent drawing
  • US11798333B2 patent drawing
  • US11798333B2 patent drawing

AI summary

A system includes an application on a mobile device operable to communicate with a local portal, the application is operable to receive a mobile key from the local portal and from that to retrieve a mobile credential for authorizing a user to access an access control. A method of local key distribution can include entering a pre-shared password to a local portal to encrypt a mobile credential; communicating the encrypted mobile credential to an application on the mobile device; and entering the pre-shared password to the application on the mobile device to decrypt the mobile credential.