Remote Key Device Certificate Exchange for Locking Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current remote control systems for properties require physical interconnection of key and locking devices for pairing and do not allow for flexible allocation of operational rights or changes in control relationships between locking devices, limiting remote access and efficiency.

Innovation Solution

A method where the key device's certificate is transferred over a data network, signed with a valid private PKI key, to establish trusted relationships and alter operational rights between locking devices, enabling remote access and virtual private network establishment between locking devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical interconnection is required for pairing key device and locking device, then security is improved, but ease of operation deteriorates due to the need for physical connection

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical pairing process (physical connection between key device and locking device) with an electronic/cryptographic process. The key device and locking device establish trust through certificate exchange and digital signatures over a network connection, eliminating the need for physical USB connection while maintaining security through cryptographic verification of device identities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical connection is required for adding new key devices, then security is maintained, but productivity deteriorates due to travel requirements

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent eliminates the mechanical travel requirement by implementing a remote pairing mechanism. The new key device can be paired with the locking device through network communication without requiring the user to physically travel to the property. The cryptographic certificate exchange process occurs remotely over the network, maintaining security while enabling rapid deployment of new key devices anywhere in the world.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Stability of the object's composition

If fixed control relationships between locking devices are enforced, then system stability is improved, but adaptability deteriorates

Engineering Contradiction:
Improvesystem stabilityVSAvoidadaptability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic control relationships by allowing the master-slave configuration between locking devices to be changed remotely. The system transitions from a static, fixed hierarchy to a dynamic one where operational rights can be reassigned. The key device can send reconfiguration commands over the network to alter which locking device serves as master and which serves as slave, enabling the system to adapt to changing operational requirements while maintaining overall system stability through controlled authorization changes.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2834938B1Secure method for remote grant of operating rights
Publication Date: 2017.05.31 TOSIBOX
  • EP2834938B1 patent drawingFigure 1
  • EP2834938B1 patent drawingFigure 2
  • EP2834938B1 patent drawingFigure 3

AI summary

In the method and system of establishing a trusted relationship, first a virtual private network is established between a key device and at least one locking device. Thereafter, in order to establish a trusted relationship the key device sends a message encrypted with its private cryptographic key to at least one locking device. The message comprises the certificate of the trusted key device and the certificate of some other device, with which the locking device that received the message shall establish a new trusted relationship. By using the established trusted relationship either a trusted relationship between the locking device and a new key device or a trusted relationship between two or more locking devices is established, whereby a virtual private network can be established between the locking devices.