Remote Access Control Programming via Encrypted Mobile Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional access control systems face challenges in managing encryption keys and configuring locks remotely, especially in hotel locking systems, where synchronization between different systems for indicating access rights is required, and the use of physical key cards with mobile devices is not seamlessly integrated.
Innovation Solution
The proposed solution involves a credential service that generates an encrypted programming credential, which is communicated to an installer mobile application on a mobile device. This application then interacts with a credential module in the access control system to decrypt, validate, and extract programming data, allowing for remote programming of lock encryption keys and virtual card data management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional encryption key management methods are used with physical programming devices, then security is maintained through established cryptographic protocols, but the complexity of key distribution and system configuration increases significantly
Solution Approach 1:
The patent creates a digital copy of the programming credential stored on a physical key card and transmits it electronically to the mobile device. This electronic credential copy enables remote programming without requiring physical presence or complex key distribution infrastructure, thereby reducing system complexity while maintaining security through cryptographic protection of the credential data.
Solution Approach 2:
The patent replaces the mechanical/physical system of key card encoding and manual programming device connection with an electronic wireless transmission system. The mobile device communicates with the access control system via electronic credentials transmitted through wireless protocols, eliminating the need for physical programming devices and reducing operational complexity.
2Adaptability or versatility
If separate systems are used for physical key cards and mobile devices to indicate access rights, then each system can be optimized independently, but synchronization between systems becomes complex and error-prone
Solution Approach 1:
The patent merges the credential systems by allowing both physical key cards and mobile devices to use the same credential format and authentication protocol. The access control system processes both card-based and mobile-based credentials through a unified authentication pathway, eliminating the need for separate synchronization mechanisms while maintaining flexibility in access methods.
Solution Approach 2:
The patent creates a universal credential system where a single credential format can be used across multiple access methods (physical key cards, mobile devices, NFC, Bluetooth). This multi-functional approach allows the same credential infrastructure to support diverse access scenarios without requiring separate systems, thereby reducing synchronization complexity while preserving adaptability.
3Loss of time
If encryption keys are pre-loaded in the factory, then initial setup time is reduced, but the ability to remotely rekey and manage keys after deployment is limited
Solution Approach 1:
The patent implements a dynamic key management system where encryption keys can be changed remotely after initial deployment. The mobile device receives updated credentials through wireless communication and transmits them to the access control system, enabling real-time key rotation and rekeying without requiring physical access or factory reconfiguration, thus maintaining both quick setup and flexible ongoing management.
Solution Approach 2:
The patent performs preliminary key establishment through factory pre-loading or initial credential provisioning, but also prepares the system for future key changes by implementing a structured credential update mechanism. The mobile application and access control system are pre-configured to handle credential reception, validation, and installation, enabling seamless remote key management when needed without requiring additional setup infrastructure.
Data Source
AI summary
An access control system includes a credential service operable to generate an encrypted programming credential. A mobile library on a mobile device operable to communicate with the credential service, the mobile library operable to receive the encrypted programming credential from the credential service and a credential module for an access control, the credential module operable to extract programming data from the encrypted programming credential, the programming data usable to program the access control.


