Access control system

US9940768B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9940768-B2
Application numberUS-201615162314-A
CountryUS
Kind codeB2
Filing dateMay 23, 2016
Priority dateDec 5, 2013
Publication dateApr 10, 2018
Grant dateApr 10, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Provided is a method for access control, performed by an access control apparatus, including obtaining access authorization information that is communicated to the access control apparatus having at least one access authorization parameter and first check information; using at least the communicated access authorization parameters, the communicated first check information and a second key from a key pair, which second key is stored in the access control apparatus, to perform a first check on whether the communicated first check information has been produced by performing cryptographic operations by means of access authorization parameters corresponding to the communicated access authorization parameters using at least one first key from the key pair, and deciding whether access can be granted, based on the first check delivers a positive result and it is established that at least one predefined set of the communicated access authorization parameters respectively provides access authorization.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for access control, performed by an access control apparatus, the method comprising: obtaining access authorization information communicated to the access control apparatus and comprising at least one or more access authorization parameters and first check information, first checking, using at least the communicated access authorization parameters, the communicated first check information and a second key of a symmetrical or asymmetrical key pair, said second key being stored in the access control apparatus, as to whether the communicated first check information was generated by performing cryptographic operations on access authorization parameters corresponding to the communicated access authorization parameters using at least a first key of the key pair, deciding whether access is permitted to be granted, wherein necessary conditions for granting access are that the first checking yields a positive result and that it is determined that at least one predefined set of the communicated access authorization parameters, in view of respective pieces of reference information present in the access control apparatus at least at the time of the first checking, respectively authorize for access, wherein the access control apparatus constitutes an access control apparatus from a plurality of access control apparatuses, wherein a second key of a symmetrical or asymmetrical individual key pair is stored in the access control apparatus, said second key being stored on none of the other access control apparatuses of the plurality of access control apparatuses, and wherein the second key of the key pair that is used in the first checking is the second key of the individual key pair, or wherein a second key of a symmetrical or asymmetrical group key pair is, in addition to said second key of said individual key pair, stored in the access control apparatus, said second key of said group key pair being different than the second key of the individual key pair and being stored in all access control apparatuses of a group of access control apparatuses from the plurality of access control apparatuses, wherein said group of access control apparatuses comprises the access control apparatus, and the second key of the key pair that is used in the first checking is either the second key of the individual key pair or the second key of the group key pair. 2. A method for generating access authorization information, the method comprising: generating first check information by performing cryptographic operations on one or more access authorization parameters using at least a first key of a symmetrical or asymmetrical key pair, generating access authorization information comprising at least the one or more access authorization parameters and the first check information, and outputting the access authorization information for storage on an access authorization proving apparatus configured to communicate the access authorization information to at least one access control apparatus in order to enable the latter to decide whether access is permitted to be granted on the basis of the communicated access authorization information, wherein necessary conditions for granting access are that a first checking, using at least the communicated access authorization parameters, the communicated first check information and a second key of the key pair, said second key being stored in the access control apparatus, whether the communicated first check information was generated by performing cryptographic operations on access authorization parameters corresponding to the communicated access authorization parameters using at least the first key of the key pair, yields a positive result and it is determined that at least one predefined set of the communicated access authorization parameters, in view of respective pieces of reference information present in the access control apparatus at least at the time of the first checking, respectively authorize for access, wherein the access control apparatus constitutes an access control apparatus from a plurality of access control apparatuses, wherein a second key of a symmetrical or asymmetrical individual key pair is stored in the access control apparatus, said second key being stored on none of the other access control apparatuses of the plurality of access control apparatuses, and wherein the first key of the key pair that is used in the generating of the first check information is a first key of the individual key pair, or wherein a second key of a symmetrical or asymmetrical group key pair is, in addition to said second key of said individual key pair, stored in the access control apparatus, said second key of said group key pair being different than the second key of the individual key pair and being stored in all access control apparatuses of a group of access control apparatuses from the plurality of access control apparatuses, wherein said group of access control apparatuses comprises the access control apparatus, and the first key of the key pair that is used in the generating of the first check information is either a first key of the individual key pair or a first key of the group key pair. 3. A method for proving an access authorization, performed by an access authorization proving apparatus, the method comprising: communicating access authorization information comprising at least one or more access authorization parameters and first check information to an access control apparatus in order to enable the latter to decide whether access is permitted to be granted on the basis of the communicated access authorization information, wherein necessary conditions for granting access are that a first checking, using at least the communicated access authorization parameters, the communicated first check information and a second key of a symmetrical or asymmetrical key pair, said second key being stored in the access control apparatus, whether the communicated first check information was generated by performing cryptographic operations on access authorization parameters corresponding to the communicated access authorization parameters using at least a first of the key pair, yields a positive result and it is determined that at least one predefined set of the communicated access authorization parameters, in view of respective pieces of reference information present in the access control apparatus at least at the time of the first checking, respectively authorize for access, wherein the access control apparatus constitutes an access control apparatus from a plurality of access control apparatuses, wherein a second key of a symmetrical or asymmetrical individual key pair is stored in the access control apparatus, said second key being stored on none of the other access control apparatuses of the plurality of access control apparatuses, and wherein the first key of the key pair that is used in a generating of the first check information is a first key of the individual key pair, or wherein a second key of a symmetrical or asymmetrical group key pair is, in addition to said second key of said individual key pair, stored in the access control apparatus, said second key of said group key pair being different than the second key of the individual key pair and being stored in all access control apparatuses of a group of access control apparatuses from the plurality of access control apparatuses, wherein said group of access control apparatuses comprises the access control apparatus, and the first key of the key pair that is used in a generating of the first check information is either a first key of the individual key pair or a first key of the group key pair. 4. A non-transitory computer-readable storage medium storing a computer program comprising program instructions that cause a processor to perform and/or control

Assignees

Inventors

Classifications

  • the pass containing active electronic elements, e.g. smartcards · CPC title

  • the pass enabling tracking or indicating presence · CPC title

  • Program-control systems · CPC title

  • Shipping · CPC title

  • Combinations with letter-boxes · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9940768B2 cover?
Provided is a method for access control, performed by an access control apparatus, including obtaining access authorization information that is communicated to the access control apparatus having at least one access authorization parameter and first check information; using at least the communicated access authorization parameters, the communicated first check information and a second key from …
Who is the assignee on this patent?
Carstens Christian, Dautz Christoph, Jansen Jochen, and 5 more
What technology area does this patent fall under?
Primary CPC classification G07C9/00896. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 10 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).