Electronic Lock Initialization via Mobile Manager Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing lock management systems face challenges in securely initializing and controlling multiple electronic locks, particularly in ensuring unique identification and encryption for secure communication between locks and management systems.
Innovation Solution
A centralized management system uses unique identifiers and encryption keys, stored on memory devices like Maxim iButton, to initialize locks, ensuring secure communication and preventing unauthorized access by using manager keys generated on mobile devices for remote initialization and command execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a centralized management system is used to manage multiple electronic locks, then the control and communication between the management system and locks is facilitated, but the security risk increases due to the need to initialize and integrate multiple locks into a single system
Solution Approach 1:
The system divides the centralized management into distributed initialization operations. Each lock is initialized independently through its own unique identifier and encryption key pair, allowing the management system to control multiple locks without creating a single point of failure. The encryption keys are segmented and stored locally in each lock's memory device rather than centralized in one database.
Solution Approach 2:
Unique identifiers and encryption keys act as intermediaries between the management system and individual locks. These cryptographic elements mediate the communication and authorization process, allowing secure control without direct exposure of the management system's core security infrastructure to each lock.
2Reliability
If unique identifiers and encryption keys are implemented for each lock, then secure communication is ensured, but the system complexity increases due to key management and initialization processes
Solution Approach 1:
Each lock performs self-initialization using its own unique identifier stored in its memory device. The lock independently generates its encryption key pair and stores the private key locally without requiring external key distribution or manual configuration. This self-service approach eliminates the need for complex centralized key management infrastructure.
Solution Approach 2:
The system uses digital copies of encryption keys stored in secure memory devices (iButtons) that can be replicated and distributed to multiple locks. Each lock receives a unique cryptographic copy rather than requiring physical key distribution, simplifying the key management process while maintaining security.
3Ease of operation
If manager keys are generated on mobile devices for remote initialization, then remote management capability is enhanced, but the vulnerability to unauthorized access increases
Solution Approach 1:
The system performs preliminary verification of the mobile device's authenticity and authorization status before generating or accepting manager keys. The unique identifier and encryption keys are pre-configured in the lock's memory device, and the initialization process validates the mobile device's credentials before allowing any key operations, preventing unauthorized access attempts.
Solution Approach 2:
The system implements preliminary security measures by requiring cryptographic verification and authentication protocols before any remote initialization or command execution. The encryption keys and unique identifiers are used to preemptively block unauthorized devices from gaining access to the lock system.
Data Source
AI summary
A method of initializing an electronic lock in the field includes the steps of providing a unique lock identifier for a lock, providing a unique organization identifier for an organization, generating master encryption keys for the organization derived from the unique organization identifier for that organization, communicating the unique organization identifier and master encryption keys for the organization to a remote mobile device, using the mobile device to remotely generate individual encryption keys for the lock utilizing one of the master encryption keys, the unique organization identifier and the unique lock identifier for the one of the plurality of locks, and using the mobile device to remotely program a manager key to communicate the individual encryption keys to the lock. Communicating the individual encryption keys initializes the lock to the organization's lock management system and permits the lock to encrypt and decrypt communications exclusively with the organization's lock management system.


