Electronic Lock Initialization via Mobile Manager Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing lock management systems face challenges in securely initializing and controlling multiple electronic locks, particularly in ensuring unique identification and encryption for secure communication between locks and management systems.

Innovation Solution

A centralized management system uses unique identifiers and encryption keys, stored on memory devices like Maxim iButton, to initialize locks, ensuring secure communication and preventing unauthorized access by using manager keys generated on mobile devices for remote initialization and command execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a centralized management system is used to manage multiple electronic locks, then the control and communication between the management system and locks is facilitated, but the security risk increases due to the need to initialize and integrate multiple locks into a single system

Engineering Contradiction:
Improvecontrol capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the centralized management into distributed initialization operations. Each lock is initialized independently through its own unique identifier and encryption key pair, allowing the management system to control multiple locks without creating a single point of failure. The encryption keys are segmented and stored locally in each lock's memory device rather than centralized in one database.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Unique identifiers and encryption keys act as intermediaries between the management system and individual locks. These cryptographic elements mediate the communication and authorization process, allowing secure control without direct exposure of the management system's core security infrastructure to each lock.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unique identifiers and encryption keys are implemented for each lock, then secure communication is ensured, but the system complexity increases due to key management and initialization processes

Engineering Contradiction:
Improvecommunication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each lock performs self-initialization using its own unique identifier stored in its memory device. The lock independently generates its encryption key pair and stores the private key locally without requiring external key distribution or manual configuration. This self-service approach eliminates the need for complex centralized key management infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses digital copies of encryption keys stored in secure memory devices (iButtons) that can be replicated and distributed to multiple locks. Each lock receives a unique cryptographic copy rather than requiring physical key distribution, simplifying the key management process while maintaining security.

Inventive Principle:
Principle #26Copying

3Ease of operation

If manager keys are generated on mobile devices for remote initialization, then remote management capability is enhanced, but the vulnerability to unauthorized access increases

Engineering Contradiction:
Improveremote management capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of the mobile device's authenticity and authorization status before generating or accepting manager keys. The unique identifier and encryption keys are pre-configured in the lock's memory device, and the initialization process validates the mobile device's credentials before allowing any key operations, preventing unauthorized access attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements preliminary security measures by requiring cryptographic verification and authentication protocols before any remote initialization or command execution. The encryption keys and unique identifiers are used to preemptively block unauthorized devices from gaining access to the lock system.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10134208B2System and method of initializing and controlling locks
Publication Date: 2018.11.20 SARGENT & GREENLEAF INC
  • US10134208B2 patent drawing
  • US10134208B2 patent drawing
  • US10134208B2 patent drawing

AI summary

A method of initializing an electronic lock in the field includes the steps of providing a unique lock identifier for a lock, providing a unique organization identifier for an organization, generating master encryption keys for the organization derived from the unique organization identifier for that organization, communicating the unique organization identifier and master encryption keys for the organization to a remote mobile device, using the mobile device to remotely generate individual encryption keys for the lock utilizing one of the master encryption keys, the unique organization identifier and the unique lock identifier for the one of the plurality of locks, and using the mobile device to remotely program a manager key to communicate the individual encryption keys to the lock. Communicating the individual encryption keys initializes the lock to the organization's lock management system and permits the lock to encrypt and decrypt communications exclusively with the organization's lock management system.