Electronic credential management system
A system and method for the management of electronic credentials stored on mobile devices. The system may encrypt information that is provided to a lock device and an access control system using diversification keys. The diversification keys may be generated by supplying a master key and a component identifier such as, for example, a mobile device identifier, to a diversification algorithm. The mobile device may be a conduit for the communication of information between the access control system and the lock device. The mobile device may be unable to decrypt information that has been encrypted by a diversification key. Embodiments also provide for enrolling administrative mobile devices with the access control system, the distribution and revocation of credential identifiers for user mobile device, and removing administrative mobile devices that are enrolled with lock devices.
1. A method for credential management, comprising:
inputting a master key and an administrative mobile device identifier into a diversification algorithm to generate a diversification key, the administrative mobile device identifier including information that identifies a first administrative mobile device;
encrypting, with the diversification key, a control system payload that includes at least one or more unique credential identifiers;
communicating, by an access control system, the encrypted control system payload to the first administrative mobile device;
receiving, by a lock device, the encrypted control system payload from the first administrative mobile device;
retrieving, by the lock device, the master key from a memory of the lock device;
decrypting, by the lock device, the encrypted control system payload using the retrieved master key and the administrative mobile device identifier;
encrypting, by the lock device and using the diversification key, a lock device payload that includes at least one lock device identifier and a field device reset identifier;
communicating, by the lock device, the encrypted lock device payload to the first administrative mobile device;
receiving, by the access control system, the encrypted lock device payload from the first administrative mobile device; and
decrypting, by the access control system, the encrypted lock device payload using the master key and the administrative mobile device identifier.
2. The method of claim 1 , further comprising recording, by the access control system, at least a portion of the information extracted from the encrypted lock device payload in association with at least one of a user account or the lock device.
3. The method of claim 1 , further comprising placing the lock device in an enrollment mode in response to the first administrative mobile device receiving the encrypted control system payload and prior to the lock device receiving the encrypted control system payload.
4. A method for managing a system, comprising:
receiving, by an access control system, a mobile device identifier from a mobile device;
applying the mobile device identifier and a master key to a diversification algorithm to generate a diversification key;
encrypting, by the access control system and using the diversification key, a mobile device payload that includes a credential identifier and a field device reset identifier, the credential identifier including information regarding a permission level of the mobile device;
communicating, by the access control system, the encrypted mobile device payload to the mobile device;
receiving, by a lock device, the encrypted mobile device payload from the mobile device;
decrypting, by the lock device, the encrypted mobile device payload;
extracting, by the lock device, the credential identifier from the decrypted encrypted mobile device payload;
identifying, by the lock device, the permission level of the mobile device using the extracted credential identifier; and
determining, by the lock device and based on the identified permission level, whether the mobile device has authority to complete an action.
5. The method of claim 4 , further comprising:
communicating, from the access control system, an invitation to the mobile device to join the system; and
communicating, from the access control system, in response to the acceptance of the invitation to join the system, an application for installation on the mobile device.
6. The method of claim 4 , further comprising:
extracting, by the lock device, the field device reset identifier from the decrypted encrypted mobile device payload;
comparing, by the lock device, the extracted field device reset identifier to a field device reset identifier stored by the lock device; and
terminating a connection between the mobile device and the lock device if the comparing indicates that the extracted field device reset identifier does not correspond with the field device reset identifier stored by the lock device.
7. The method of claim 4 , further comprising:
receiving, by a lock device, an encrypted revocation response payload, the encrypted revocation response payload identifying the credential identifier of the mobile device that is to be revoked;
decrypting, by the lock device, the encrypted revocation response payload;
extracting, by the lock device, the credential identifier of the mobile device that is to be revoked from the decrypted encrypted revocation response payload;
identifying, by the lock device, the extracted credential identifier of the mobile device that is to be revoked as being a revoked identifier;
receiving, by the lock device, a subsequent communication from the mobile device that includes a credential identifier; and
identifying, by the lock device, whether the received credential identifier included in the subsequent communication is the revoked identifier.
8. The method of claim 7 , further comprising terminating, by the lock device, a connection between the lock device and the mobile device if the identifying step indicates that the credential identifier included in the subsequent communication is the revoked identifier.
9. The method of claim 7 , further comprising communicating, by the lock device, a demand that the mobile device remove the revoked identifier.
10. The method of claim 7 , further comprising:
identifying to the access control system the mobile device for which the credential identifier is to be revoked, and
communicating, by the access control system, a revocation request to the mobile device, the revocation request requesting that the credential identifier be removed from the mobile device.
11. The method of claim 4 , further comprising:
communicating, by the access control system, a revocation request to the mobile device, the revocation request requesting that the credential identifier be removed from the mobile device; and
receiving, by the access control system, a notification that the credential identifier has been removed from the mobile device.
12. The method of claim 1 , further comprising:
notifying an access control system that the first administrative mobile device is being removed from the access control system;
enrolling a replacement administrative mobile device with the access control system;
performing a field device reset on the lock device to automatically modify the field device reset identifier stored on the lock device and to remove all credential identifiers stored on the lock device;
receiving, by the access control system, a second encrypted lock device payload, the second encrypted lock device payload including a replacement field device reset identifier;
extracting, by the access control system, from the second encrypted lock device payload the replacement field device reset identifier; and
communicating, from the access control system, the extracted replacement field device reset identifier to one or more user mobile devices that are to be used with the lock device.
13. The method of claim 12 , further comprising:
generating, by the access control system, a replacement administrative mobile device payload, the replacement administrative mobile device payload including a replacement administrative mobile device identifier;
encrypting the replacement administrative mobile device payload using a replacement administrative mobile device diversification key, the replacement administrative mobile device diversification key being generated using a master key, the replacement administrative mobile device identifier, and the diversification algorithm; and
receiving, by the enrolled lock device, the encrypted replacement administrative mobile device payload.
14. The method of claim 13 , further comprising one of:
decrypting, by the lock device, the encrypted replacement administrative mobile device payload using at least the master key and the replacement administrative mobile device identifier; and
terminating a connection between the lock device and the replacement administrative mobile device if the lock device is unable to decrypt the encrypted replacement administrative mobile device payload using at least the master key and the replacement administrative mobile device identifier.
15. The method of claim 1 , further comprising registering, by the access control system, the field device reset identifier in association with the lock device in response to decrypting the encrypted lock device payload.
16. The method of claim 4 , further comprising performing a field device reset on the lock device to automatically modify the field device reset identifier stored on the lock device and to remove all credential identifiers stored on the lock device; and
wherein the lock device is inoperable with the mobile device using the field device reset identifier extracted from the mobile device payload in response to performing the field device reset on the lock device.
17. The method of claim 12 , wherein performing the field device reset on the lock device comprises performing the field device reset on the lock device to automatically modify the field device reset identifier stored on the lock device and to remove all credential identifiers stored on the lock device without interacting with the first administrative mobile device.
18. The method of claim 12 , wherein performing the field device reset on the lock device comprises performing the field device reset on the lock device to automatically modify the field device reset identifier stored on the lock device and to remove all credential identifiers stored on the lock device in response to a determination that the first administrative mobile device has been lost or stolen.
19. The method of claim 3 , wherein placing the lock device in the enrollment mode comprises processing, by the lock device, an enrollment credential received by a card reader associated with the lock device.
20. The method of claim 3 , wherein placing the lock device in the enrollment mode comprises processing, by the lock device, a code entered into a keypad associated with the lock device.