Offline Access Control via Peer-to-Peer Key Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current building or enclosure termination opening and closing systems rely on server-based authentication, limiting access without an Internet connection, requiring powerful components, and often use manufacturer-specific secret keys, which can compromise security and are inconvenient for scenarios like holiday homes.

Innovation Solution

A system using a mobile user terminal with encryption and authentication devices that generates and forwards time-limited user keys via Bluetooth Low Energy, allowing secure access without an Internet connection, supporting large user groups, and using device-specific secrets for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If server-based authentication is used for building termination access control, then authentication can be performed, but the system requires Internet connection and server components which limits usability in offline scenarios

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidoffline operation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a peer-to-peer communication mechanism where the first user terminal acts as an intermediary to transfer authentication data to the second user terminal. This eliminates the need for server-based authentication and Internet connection, allowing offline operation while maintaining security through encrypted direct communication between terminals.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into independent components: the first user terminal generates authentication data, transfers it via peer-to-peer communication, and the second terminal uses it for authentication. This segmentation removes the central server dependency and enables offline functionality.

Inventive Principle:
Principle #1Segmentation

2Reliability

If manufacturer-specific secret keys are used for authentication, then device-specific security is achieved, but security is compromised if the manufacturer's key management is breached

Engineering Contradiction:
Improvedevice-specific securityVSAvoidsecurity vulnerability from centralized key management
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication key management from the manufacturer's centralized system and places it in the user's own device. Each user terminal generates and stores its own authentication data locally, eliminating the security vulnerability of centralized key management while maintaining device-specific security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Each user terminal independently generates, stores, and manages its own authentication data without relying on the manufacturer's key management system. This self-service approach to authentication eliminates the security risk of centralized key storage while maintaining strong device-specific security.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If traditional access control systems are used, then basic access control is provided, but the system requires separate physical devices like mechanical keys or RFID chips which reduces convenience

Engineering Contradiction:
Improveaccess control convenienceVSAvoidnumber of separate devices required
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the authentication functionality into the user's existing mobile terminal device, eliminating the need for separate physical devices like mechanical keys, RFID chips, or remote controls. The mobile terminal combines communication, encryption, and authentication functions in a single device that users already carry.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile terminal is utilized for multiple functions: it serves as both the authentication credential and the communication device. The same device used for general communication purposes is also used for secure authentication, eliminating the need for dedicated access control devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11139965B2Building or enclosure termination closing and/or opening apparatus, and method for operating a building or enclosure termination
Publication Date: 2021.10.05 HORMANN ANTRIEBSTECHN
  • US11139965B2 patent drawing
  • US11139965B2 patent drawing
  • US11139965B2 patent drawing

AI summary

The invention relates to a building or enclosure termination opening and/or closing apparatus (10) having communication signed or encrypted by means of a key, and to a method for operating such. To allow simple, convenient and secure use by exclusively authorised users, the apparatus comprises: a first and a second user terminal (14, 30), with secure forwarding of a time-limited key from the first to the second user terminal being possible. According to an alternative, individual keys are generated by a user identification (42) and a secret device key (40).