Wireless Lock Authentication via Server-Mediated Challenge-Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communications with electronic locks are often insecure, increasing the risk of unauthorized access.
Innovation Solution
A method and system for wireless key management using a server-based authentication scheme with two keys: a secret key stored on the electronic locking device and an access key stored on both the device and the user's mobile device, ensuring secure communication through encryption and verification processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless communication is used to control electronic locks, then ease of operation is improved, but security is worsened due to unauthorized access risks
Solution Approach 1:
The authentication system is segmented into multiple independent components: device identifiers, cryptographic keys, challenge-response protocols, and encrypted data channels. This segmentation allows each component to perform a specific security function, collectively providing robust protection while maintaining wireless operation convenience.
Solution Approach 2:
A server acts as an intermediary between the mobile device and the electronic lock, facilitating secure authentication. The server verifies device identifiers, manages cryptographic keys, and validates challenge-response exchanges, enabling secure wireless control without requiring direct trust between the mobile device and lock.
2Ease of operation
If simple authentication is used for wireless access, then ease of operation is improved, but security is worsened
Solution Approach 1:
Authentication credentials including device identifiers and cryptographic keys are pre-configured in both the mobile device and the electronic lock during manufacturing or initial setup. This preliminary action enables rapid authentication without requiring complex real-time key exchange, maintaining both simplicity and security.
Solution Approach 2:
The challenge-response protocol provides cryptographic feedback verification: the server generates a challenge, the mobile device computes a response using its cryptographic keys, and the server verifies the response. This feedback mechanism confirms authentication validity without requiring complex user interaction, balancing simplicity and security.
Data Source
AI summary
Disclosed are methods, systems, and computer-readable media for wireless key management for authentication. Authentication includes transmitting a request to a locking device, transmitting a security challenge to the mobile device, and transmitting a response to the challenge and an encrypted user profile for the locking device. The response includes data generated with an access key that is stored by both the mobile device and the locking device, and the user profile is encrypted by a server using a secret key that is stored by the server and the locking device. Authentication further includes verifying the response to the challenge, where the response is verified using the access key, and validating additional data from the mobile device. An action of the locking device may be initiated as specified by the request.


