Offline Access Control via Peer-to-Peer Key Forwarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current building or enclosure termination opening and closing systems rely on server-based authentication, limiting access without an Internet connection, requiring powerful components, and often use manufacturer-specific secret keys, which can compromise security and are inconvenient for scenarios like holiday homes.
Innovation Solution
A system using a mobile user terminal with encryption and authentication devices that generates and forwards time-limited user keys via Bluetooth Low Energy, allowing secure access without an Internet connection, supporting large user groups, and using device-specific secrets for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If server-based authentication is used for building termination access control, then authentication can be performed, but the system requires Internet connection and server components which limits usability in offline scenarios
Solution Approach 1:
The patent introduces a peer-to-peer communication mechanism where the first user terminal acts as an intermediary to transfer authentication data to the second user terminal. This eliminates the need for server-based authentication and Internet connection, allowing offline operation while maintaining security through encrypted direct communication between terminals.
Solution Approach 2:
The authentication system is segmented into independent components: the first user terminal generates authentication data, transfers it via peer-to-peer communication, and the second terminal uses it for authentication. This segmentation removes the central server dependency and enables offline functionality.
2Reliability
If manufacturer-specific secret keys are used for authentication, then device-specific security is achieved, but security is compromised if the manufacturer's key management is breached
Solution Approach 1:
The patent extracts the authentication key management from the manufacturer's centralized system and places it in the user's own device. Each user terminal generates and stores its own authentication data locally, eliminating the security vulnerability of centralized key management while maintaining device-specific security.
Solution Approach 2:
Each user terminal independently generates, stores, and manages its own authentication data without relying on the manufacturer's key management system. This self-service approach to authentication eliminates the security risk of centralized key storage while maintaining strong device-specific security.
3Ease of operation
If traditional access control systems are used, then basic access control is provided, but the system requires separate physical devices like mechanical keys or RFID chips which reduces convenience
Solution Approach 1:
The patent merges the authentication functionality into the user's existing mobile terminal device, eliminating the need for separate physical devices like mechanical keys, RFID chips, or remote controls. The mobile terminal combines communication, encryption, and authentication functions in a single device that users already carry.
Solution Approach 2:
The mobile terminal is utilized for multiple functions: it serves as both the authentication credential and the communication device. The same device used for general communication purposes is also used for secure authentication, eliminating the need for dedicated access control devices.
Data Source
AI summary
The invention relates to a building or enclosure termination opening and/or closing apparatus (10) having communication signed or encrypted by means of a key, and to a method for operating such. To allow simple, convenient and secure use by exclusively authorised users, the apparatus comprises: a first and a second user terminal (14, 30), with secure forwarding of a time-limited key from the first to the second user terminal being possible. According to an alternative, individual keys are generated by a user identification (42) and a secret device key (40).


