IP Library Granted Patent US 11,049,341
Granted Patent B2
US 11,049,341 · App. 16/520,573 · Granted Jun 29, 2021

Secure access to physical resources using asymmetric cryptography

Inventors: Jerod Klink (Kitchener, CA); Herb Little (Waterloo, CA)
Assignee: SERA4 LTD.
G07C9/00309G07C9/00571H04L9/3263H04L9/3268H04L63/0442H04L63/0823H04L63/108H04W12/02H04W12/033H04W12/068H04W12/069H04W12/082H04W12/084G07C2009/00412G07C2009/00793
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,049,341
App. No.
16/520,573
Granted
Jun 29, 2021
Kind
B2
Abstract

Digital certificates are signed by a server's private key and installed at lock controllers that restrict access to physical resources. The server's public key is distributed to lock controllers and to mobile electronic devices operated by users who are given access to the physical resources. Lock-access data is digitally signed by the server's private key and provided to mobile electronic devices to facilitate access. The lock controller validates lock-access data and grants access conditionally based on time, version, and/or identity data provided within lock-access data. The use of certificates reduces the need to rely on a security scheme specific to the network. Lock controllers can also broadcast status notifications, so that updates and log data can be securely communicated with the server using mobile electronic devices as a proxy. The system is highly scalable, as each lock controller need not track the full scope of access permissions.

Claims (63)

1. A wireless mobile device for providing secure access to physical resources, the wireless mobile device comprising:

memory configured to store a public key of a server;

a wireless interface configured for communication with electronic lock controllers in vicinity of the wireless mobile device;

a network interface configured for communication with the server via a computer network; and

a processor configured to use the public key of the server to validate authenticity of public keys of electronic lock controllers received from electronic lock controllers via the wireless interface, the processor further configured to encrypt lock-access data received from the server using public keys of the electronic lock controllers and transmit messages containing encrypted lock-access data to respective authenticated electronic lock controllers via the wireless interface.

2. The wireless mobile device of claim 1 , wherein the processor is further configured to transmit to an electronic lock controller, via the wireless interface, encrypted settings data for updating at least one setting at the electronic lock controller.

3. The wireless mobile device of claim 2 , wherein the at least one setting defines access permission of users to the physical resource, and wherein the access permission of at least one user is updated to be revoked.

4. The wireless mobile device of claim 1 , wherein the processor is further configured to:

when the wireless mobile device is in vicinity of an electronic lock controller, receive from the electronic lock controller, via the wireless interface, a digital certificate containing the public key of the electronic lock controller; and

after receiving the digital certificate, use the public key of the server to validate authenticity of the public key of the electronic lock controller.

5. The wireless mobile device of claim 1 , wherein the processor is further configured to:

receive from an electronic lock controller, via the wireless interface, encrypted log data indicative of past physical access to a physical resource of the electronic lock controller encrypted by the electronic lock controller using the public key of the server; and

transmit the encrypted log data to the server via the network interface.

6. The wireless mobile device of claim 1 , wherein:

the lock-access data includes a unique identifier of an electronic lock controller, a start time defining a beginning of a period of permitted access, an end time defining an end of the period of permitted access, and a user identifier; and

the processor is configured to receive from the server, via the network interface, periodically regenerated lock-access data that is regenerated with updated start and end times to allow for continued access to a physical resource of the electronic lock controller.

7. The wireless mobile device of claim 1 , wherein the processor is further configured to receive, via the wireless interface, the public key of the server distributed by the server.

8. A wireless mobile device for providing secure access to physical resources, the wireless mobile device comprising:

memory configured to store a public key of a server;

a wireless interface configured for communication with electronic lock controllers in vicinity of the wireless mobile device, each respective electronic lock controller loaded with a digital certificate digitally signed by a private key of the server, the digital certificate further having a unique lock controller hardware identifier of the respective electronic lock controller, each respective electronic lock controller operably connectable to a respective physical lock that restricts access to a respective physical resource;

a network interface configured for communication with the server via a computer network; and

a processor configured to:

use the public key of the server to validate authenticity of public keys of electronic lock controllers received from electronic lock controllers via the wireless interface;

encrypt lock-access data received from the server using a public key of an electronic lock controller, the lock-access data having been signed by the server with the private key of the server, the lock-access data defining physical access permission to the physical resources by a user of the wireless mobile device;

provide the encrypted lock-access data in messages for the electronic lock controllers; and

transmit the messages containing the encrypted lock-access data to a respective authenticated electronic lock controller via the wireless interface when the wireless mobile device is in vicinity of the respective electronic lock controller to enable the respective electronic lock controller to:

decrypt the encrypted lock-access data using the private key of the respective electronic lock controller to obtain the lock-access data;

validate authenticity of the lock-access data using the public key of the server; and

unlock the physical lock of the respective electronic lock controller if permitted by the lock-access data to grant the user access to the respective physical resource.

9. The wireless mobile device of claim 8 , wherein the processor is further to establish communications with an electronic lock controller using session encryption parameters containing a randomized or pseudorandomized session identifier.

10. The wireless mobile device of claim 8 , wherein the processor is further configured to transmit to an electronic lock controller, via the wireless interface, encrypted settings data for updating at least one setting at the electronic lock controller, and wherein the at least one setting defines access permission of users to a physical resource of the electronic lock controller, and wherein the access permission of at least one user is updated to be revoked.

11. The wireless mobile device of claim 8 , wherein the processor is further configured to:

when the wireless mobile device is in vicinity of an electronic lock controller, receive from the electronic lock controller, via the wireless interface, the public key of the electronic lock controller; and

after receiving the public key of the electronic lock controller, use the public key of the server to validate authenticity of the public key of the electronic lock controller.

12. The wireless mobile device of claim 8 , wherein the processor is further configured to:

receive, via the wireless interface, encrypted log data indicative of past physical access to a physical resource encrypted by an electronic lock controller using the public key of the server; and

transmit the encrypted log data to the server via the network interface.

13. The wireless mobile device of claim 8 , wherein:

the lock-access data includes a unique identifier of an electronic lock controller, a start time defining a beginning of a period of permitted access, an end time defining an end of the period of permitted access, and a user identifier; and

the processor is configured to receive, via the network interface, periodically regenerated lock-access data that is regenerated with updated start and end times to allow for continued access to a physical resource of the electronic lock controller.

14. The wireless mobile device of claim 8 , wherein the processor is further configured to receive, via the wireless interface, the public key of the server distributed by the server.

15. A wireless mobile device for providing secure access to physical resources, the wireless mobile device comprising:

memory configured to store a public key of a server;

a wireless interface configured for communication with electronic lock controllers in vicinity of the wireless mobile device;

a network interface configured for communication with the server via a computer network; and

a processor configured to:

transmit updated version data to an electronic lock controller via the wireless interface for storage at the electronic lock controller;

use the public key of the server to validate authenticity of public keys of electronic lock controllers received from electronic lock controllers via the wireless interface;

encrypt lock-access data received from the server using public keys of the electronic lock controllers, the lock-access data including particular version data for comparison against the updated version data at the electronic lock controller; and

transmit messages containing encrypted lock-access data to respective authenticated electronic lock controllers in vicinity of the wireless mobile device via the wireless interface to obtain access to the physical resource when the particular version data matches the updated version data at the electronic lock controller.

16. The wireless mobile device of claim 15 , wherein the processor is further configured to transmit to an electronic lock controller, via the wireless interface, encrypted settings data for updating at least one setting at the electronic lock controller, and wherein the at least one setting defines access permission of at users to a physical resource of the electronic lock controller, and wherein the access permission of at least one user is updated to be revoked.

17. The wireless mobile device of claim 15 , wherein the lock-access data includes a unique identifier of an electronic lock controller, a start time defining a beginning of a period of permitted access, an end time defining an end of the period of permitted access, and the updated version data.

18. The wireless mobile device of claim 15 , wherein the processor is further configured to:

when the wireless mobile device is in vicinity of an electronic lock controller, receive from the electronic lock controller, via the wireless interface, the public key of the electronic lock controller; and

after receiving the public key of the electronic lock controller, use the public key of the server to validate authenticity of the public key of the electronic lock controller.

19. The wireless mobile device of claim 15 , wherein the processor is further configured to:

receive, via the wireless interface, encrypted log data indicative of past physical access to a physical resource encrypted by an electronic lock controller using the public key of the server; and

transmit the encrypted log data to the server via the network interface.

20. The wireless mobile device of claim 15 , wherein:

the lock-access data includes a unique identifier of an electronic lock controller, a start time defining a beginning of a period of permitted access, and an end time defining an end of the period of permitted access; and

the processor is configured to receive, via the network interface, periodically regenerated lock-access data that is regenerated with updated start and end times to allow for continued access to a physical resource of the electronic lock controller.

21. The wireless mobile device of claim 15 , wherein the processor is further configured to receive, via the wireless interface, the public key of the server distributed by an electronic lock controller.

22. The wireless mobile device of claim 15 , wherein the processor is further to establish communications with an electronic lock controller using session encryption parameters containing a randomized or pseudorandomized session identifier.

Assignments (5)
SECURITY INTEREST Recorded Sep 9, 2025
From: SERA4 LTD.
To: BDC CAPITAL INC.
Reel/Frame 072200/0484 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2019
From: LITTLE, HERB
To: HOCOBO INC.
Reel/Frame 050072/0216 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2019
From: KLINK, JEROD
To: LOCKEDUP LTD.
Reel/Frame 050072/0317 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2019
From: HOCOBO INC.
To: LOCKEDUP LTD.
Reel/Frame 050072/0384 →
CHANGE OF NAME Recorded Aug 16, 2019
From: LOCKEDUP LTD.
To: SERA4 LTD.
Reel/Frame 050082/0179 →
Continuity (3)
Continuation 15990757 · May 28, 2018
Continuation 15332057 · Oct 24, 2016
Related Publication 20190347883A1 · Nov 14, 2019