Wireless Lock Authentication via Server-Mediated Challenge-Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communications with electronic locks are often insecure, increasing the risk of unauthorized access.

Innovation Solution

A method and system for wireless key management using a server-based authentication scheme with two keys: a secret key stored on the electronic locking device and an access key stored on both the device and the user's mobile device, ensuring secure communication through encryption and verification processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless communication is used to control electronic locks, then ease of operation is improved, but security is worsened due to unauthorized access risks

Engineering Contradiction:
Improvewireless control capabilityVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent components: device identifiers, cryptographic keys, challenge-response protocols, and encrypted data channels. This segmentation allows each component to perform a specific security function, collectively providing robust protection while maintaining wireless operation convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A server acts as an intermediary between the mobile device and the electronic lock, facilitating secure authentication. The server verifies device identifiers, manages cryptographic keys, and validates challenge-response exchanges, enabling secure wireless control without requiring direct trust between the mobile device and lock.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If simple authentication is used for wireless access, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveauthentication simplicityVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Authentication credentials including device identifiers and cryptographic keys are pre-configured in both the mobile device and the electronic lock during manufacturing or initial setup. This preliminary action enables rapid authentication without requiring complex real-time key exchange, maintaining both simplicity and security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The challenge-response protocol provides cryptographic feedback verification: the server generates a challenge, the mobile device computes a response using its cryptographic keys, and the server verifies the response. This feedback mechanism confirms authentication validity without requiring complex user interaction, balancing simplicity and security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10262484B2Location tracking for locking device
Publication Date: 2019.04.16 MASTER LOCK CO INC
  • US10262484B2 patent drawing
  • US10262484B2 patent drawing
  • US10262484B2 patent drawing

AI summary

Disclosed are methods, systems, and computer-readable media for wireless key management for authentication. Authentication includes transmitting a request to a locking device, transmitting a security challenge to the mobile device, and transmitting a response to the challenge and an encrypted user profile for the locking device. The response includes data generated with an access key that is stored by both the mobile device and the locking device, and the user profile is encrypted by a server using a secret key that is stored by the server and the locking device. Authentication further includes verifying the response to the challenge, where the response is verified using the access key, and validating additional data from the mobile device. An action of the locking device may be initiated as specified by the request.