Time-Limited Access Code Generation for Building Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic access control systems for buildings face security risks due to the use of static general system codes and the need for frequent changes in access permissions, especially for temporary access, which can be compromised by data connections used for updates.
Innovation Solution
A method where a user rights management system generates a first test feature by transforming an identifier and validity period using a first algorithm, which is transmitted to the user and then compared with a second test feature generated by the control device using the same algorithm and current time, ensuring secure temporary access without exposing the validity period.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static general system codes are used for long periods, then system operation is simplified, but security risk increases when access permissions need to change
Solution Approach 1:
The patent transforms static system codes into dynamic time-limited access codes. The control device generates different access codes based on the current time, ensuring that codes expire automatically after a validity period. This resolves the contradiction by making the system both easy to operate (automatic code generation) and secure (time-based expiration prevents unauthorized long-term access).
Solution Approach 2:
The patent changes the parameter of code validity from permanent to time-limited. By incorporating a validity period into the access code structure, the system automatically renders codes obsolete after a set time, eliminating the security risk of长期使用 static codes while maintaining operational simplicity through automated code management.
2Reliability
If access codes are updated frequently to maintain security, then security is improved, but system complexity and update requirements increase
Solution Approach 1:
The control device automatically generates and manages time-limited access codes without requiring external updates or interventions. The system uses its internal timekeeping function to automatically expire codes, eliminating the need for manual code updates while maintaining high security through automatic code rotation and expiration.
3Ease of operation
If data connections are used to update access codes remotely, then ease of updates is improved, but security weakens due to additional attack vectors
Solution Approach 1:
The patent extracts the code update function from external data connections and implements it locally within the control device. By using the device's internal timekeeping function to generate and expire codes automatically, the system eliminates the need for external data connections for code updates, thereby removing the security vulnerability while maintaining ease of code management.
4Reliability
If one-way functions are used to prevent code decryption, then security is improved, but the control device must calculate multiple codes increasing processing time
Solution Approach 1:
The patent implements preliminary action by pre-calculating and storing multiple time-based code variants in the control device during system setup. When authentication is required, the device simply compares the entered code against pre-computed codes for the current time period, eliminating the need for real-time calculation while maintaining security through one-way functions. This resolves the contradiction by shifting the computational burden from runtime to setup time.
Data Source
Figure 1
Figure 2
Figure 3a~3c
AI summary
The method involves transforming identification and validity period of first inspection characteristics by user rights management using first algorithm. The first test item is isolated from the access code and is compared with the second inspection characteristic. The object is accessed totally or partly by comparing time limit of access code with time information associated with time-measuring instrument. An access code is generated such that first test item is added with time restriction and is transmitted to a user by a controller. The identification and current time associated with the time-measuring instrument are transformed by first algorithm. An independent claim is included for an access control system for object.