Secure Wireless Firmware Updates for Electronic Locks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communications with electronic locks are often insecure, increasing the risk of unauthorized access due to lack of robust authentication and encryption methods.
Innovation Solution
A method and device for wireless key management using a server-based authentication and encryption scheme with two keys, where one key is stored on the electronic locking device and the other on the user device, ensuring secure communication and authentication through a challenge-response process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless communication is used to control electronic locks, then ease of operation is improved, but security is worsened due to lack of robust authentication and encryption
Solution Approach 1:
The authentication system is segmented into multiple independent components: device identifiers, cryptographic keys, authentication tokens, and encrypted command structures. Each component serves a specific security function, collectively providing robust authentication while maintaining wireless operation convenience.
Solution Approach 2:
A server acts as an intermediary between the mobile device and electronic lock, facilitating secure authentication by verifying device identifiers, managing cryptographic keys, and validating authentication tokens without requiring direct trust between the lock and mobile device.
2Reliability
If encryption and authentication protocols are implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
Complex cryptographic operations and authentication logic are extracted from the electronic lock and relocated to the mobile device and server. The lock retains only essential functions: storing device identifiers, verifying authentication tokens, and executing validated commands, thereby reducing its complexity.
Solution Approach 2:
Authentication credentials, cryptographic keys, and device identifiers are pre-configured in the mobile device and server before wireless communication begins. This preliminary setup enables streamlined authentication during operation without requiring complex real-time key generation or exchange protocols in the lock.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
Disclosed are methods and devices for securely updating firmware of locking devices. One method includes receiving a lock identifier from a locking device; determining that the lock identifier is associated with a user profile by comparing the lock identifier to a set of lock identifiers; receiving a firmware update packet from a server, wherein the firmware packet is encrypted by a lock key; transmitting the firmware update packet to the lock; decrypting the firmware update using the lock key; validating the encrypted firmware update; and installing the firmware update.