Electronic Lock Access Delegation With Encrypted Service Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for electronic locks are limited in providing flexible access management for various services, as they are primarily designed for specific applications like delivery services and lack a general method for granting access across different types of services.

Innovation Solution

A method and device that allow a service consumer to securely delegate access to an electronic lock using public key encryption and electronic signatures, enabling a service provider agent to access a physical space for service provision, with optional double confirmation and time-scheduled access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If electronic locks use traditional access methods (mechanical keys, simple electronic keys), then the system is simple to operate, but the system lacks flexibility and security for service-based access management

Engineering Contradiction:
Improveflexibility in access managementVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a coordinator as an intermediary component that manages access delegations between service consumers and service providers. The coordinator receives access requests, validates them against delegation rules, and grants access permissions. This intermediary layer enables flexible service-based access management without requiring complex direct authentication mechanisms between all parties, thus improving adaptability while controlling system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access management system is segmented into distinct functional components: service consumers who create delegations, coordinators that manage and validate delegations, and service providers who receive access. This segmentation allows each component to have specialized, simpler functionality while the overall system achieves high flexibility through the coordinated interaction of these segments.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the system implements comprehensive security measures (encryption, electronic signatures, multiple confirmations), then security is improved, but the ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of access delegation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by establishing cryptographic key pairs and creating delegation templates in advance. Service consumers set up their public/private key pairs beforehand, and access delegations are prepared with predefined parameters such as time windows and service scopes. This preliminary setup enables secure access management without requiring complex real-time cryptographic operations during the actual access event, thus maintaining security while improving ease of operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses electronic copies of cryptographic keys and delegation credentials instead of physical security artifacts. The service consumer's public key and delegation tokens are digitally copied and transmitted through the coordinator to the service provider. This copying mechanism enables secure access management with simple digital operations rather than complex physical security procedures, improving ease of operation while maintaining reliability through cryptographic protection.

Inventive Principle:
Principle #26Copying

3Reliability

If access delegations are created with detailed parameters (time windows, service scope, multiple confirmations), then control and security are improved, but the time and complexity of setting up access increases

Engineering Contradiction:
Improveaccess controlVSAvoidtime for access setup
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements partial action by allowing service consumers to specify only the essential parameters for their access delegations, such as time windows and service scope, while optional advanced parameters like multiple confirmations can be added only when needed. This approach provides sufficient access control for most scenarios without requiring the overhead of configuring all possible security parameters, thus improving reliability where needed while minimizing setup time through selective parameter specification.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11030837B2Providing access to a lock by service consumer device
Publication Date: 2021.06.08 ASSA ABLOY AB
  • US11030837B2 patent drawing
  • US11030837B2 patent drawing
  • US11030837B2 patent drawing

AI summary

It is presented a method for providing access to a lock for provision of a service. The method comprises the steps of: receiving a request for access to the lock, the request being based on the service consumer ordering a service requiring access to a physical space, the request comprising a first public key associated with a co-ordinator and a second public key associated with a service provider agent; presenting a first consumer query to the service consumer; receiving a first positive consumer response indicating that the service consumer allows the service provider agent to access the physical space; and delegating access to the lock to the co-ordinator, which comprises encrypting at least part of a delegation using the first public key, encrypting at least part of the delegation using the second public key, and electronically signing the delegation, enabling further delegation to the service provider agent.