IP Library Granted Patent US 12,724,868
Granted Patent B2
US 12,724,868 · App. 18/069,395 · Granted Sep 1, 2026

Method and system for starting up or managing an offline control device

Inventors: Trong-Nghia Cheng (Freiburg, DE); Reinhard Eggert (Schallstadt, DE); Pascal Bodechon (Ettenheim, DE)
Assignee: Sphinx Electronics GmbH & Co KG
G06F21/44G06F21/45G06F21/64H04L9/3234H04L9/3236H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,724,868
App. No.
18/069,395
Granted
Sep 1, 2026
Kind
B2
Abstract

A method of starting up and managing an offline control device with a management control unit and a terminal, includes: implementing of a multi-factor/ID authentication algorithm in the terminal; delivering the terminal and a first storage medium having a storage medium ID and a first security code to a customer; delivering of a second security code generated using the first security code, to a second storage medium of the customer; positioning, by a user, of the first and second storage mediums at the terminal and reading of the storage medium ID and the first and second security codes, and offline checking by the algorithm of the terminal, whether the read first and second security codes are valid with one another; after a positive multi-factor authentication check, storing the storage medium ID as the authorization ID and the first security code in the terminal; and terminating the initial start-up mode.

Claims (38)

1 . A method for starting up and managing an offline access control device, by a multi-factor and ID authentication, wherein the offline access control device comprises a management control unit and a terminal which activates the management control unit, the method has having the following method steps for initial start-up of the offline access control device in an initial start-up mode and then having the following method steps for a management mode comprising:

implementing the multi-factor and ID authentication algorithm in the terminal;

generating, exclusively by a terminal manufacturer, a first security code and a second security code;

delivering the terminal, in a factory state as a new system delivered from the terminal manufacturer to a customer;

delivering a first storage medium, in which a storage medium ID and the first security code are stored in the first storage medium in a forgery-proof copy/clone and manipulation protection known only to the terminal manufacturer, to the customer;

delivering the second security code generated using the first security code, to a second storage medium of the customer;

positioning, by the customer, the first and the second storage medium at the location of the terminal, and reading, by the terminal, of the storage medium ID and the first and the second security code, and offline checking whether the read first and second security code match one another;

after the terminal has matched the first and the second security codes, storing the storage medium ID as an authorization ID and the first security code in the terminal, and subsequently activating the management control unit by means of the terminal for the management of the management control unit by the customer; and

terminating the initial start-up mode; and

wherein on completion of the initial start-up of the offline access control device, the following method steps for managing the management control unit in the management mode comprises:

positioning, by the customer, the first storage medium and the second storage media at the location of the terminal and reading, by the terminal, of the storage medium ID and the first security code of the first storage medium and the second security code of the second storage medium, and offline checking whether the read storage medium ID and the read first security code of the first storage medium match the authorization ID stored in the terminal and the first security code stored in the terminal, and offline checking whether the read first security codes matches the read second security code;

after the terminal has matched the read first security code with the read second security code, activating the management control unit by means of the terminal for the management of the management control unit by the customer; and

terminating the management mode.

2 . The method as claimed in claim 1 , wherein the multi-factor authentication check is performed in the management mode only after the terminal has matched the first and the second security codes.

3 . The method as claimed in claim 1 , wherein the transmission to the terminal of the storage medium ID, the first security code, or the second security code is performed offline in a wireless or wired manner.

4 . The method as claimed in claim 1 , wherein the first storage medium is a transponder which is delivered to the customer.

5 . The method as claimed in claim 1 , wherein the first security code is a binary code.

6 . The method as claimed in claim 1 , wherein the second security code is supplied as a digital signature of the first security code to the second storage medium and is stored there.

7 . The method as claimed in claim 1 , wherein the second security code is encrypted by means of a private key and in that the validity of the encrypted second security code is verified by the multi-factor authentication algorithm of the terminal by a public key.

8 . The method as claimed in claim 7 , wherein a hash value of the first security code is defined by means of a cryptographic hash function which is applied to the first security code, and in that the private key is applied to this hash value of the first security code in order to generate the second security code in the form of a digital signature of the first security code.

9 . The method as claimed in claim 1 , wherein, in the case of a mobile terminal of the customer which forms the second storage medium, an app of the provider activated by means of the second security code is installed on the mobile terminal in order to manage the management control unit.

10 . A system for starting up and managing an offline access control device by means of a multi-factor and ID authentication, comprising:

the offline access control device which comprises a management control unit and a terminal activating the management control unit and having at least one data interface, wherein the multi-factor and ID authentication algorithm is implemented in the terminal and at least one authorization ID and one security code are storable in the terminal;

a mobile first storage medium in which a storage medium ID and a first security code are stored in a forgery-proof copy/clone and manipulation protection known only to the terminal manufacturer;

a mobile second storage medium in which a second security code generated using the first security code is stored;

wherein, in an initial start-up mode, the multi-factor and ID authentication algorithm for the initial start-up of the offline access control device is programmed, in wherein the mobile first storage media and the mobile second storage media are configured to be positioned by a customer at the location of the terminal, to read the storage medium ID and the first security code of the mobile first storage medium and the second security code of the mobile second storage medium by means of the at least one data interface, and to check offline whether the read first and second security codes match one another and, if so, to store the storage medium ID as the at least one authorization ID and the first security code in the terminal and to terminate the initial start-up mode; and

wherein, in a management mode, the multi-factor and ID authentication algorithm for the management of the management control unit is programmed, where the mobile first storage media and the second mobile storage medium are configured to be positioned by a customer at the location of the terminal, to read the storage medium ID and the first security code of the mobile first storage medium and the second security code of the mobile second storage medium by means of the at least one data interface, and to check offline whether the read storage medium ID and the read first security code of the mobile first storage medium match the at least one authorization ID stored in the terminal and the first security code stored in the terminal and to check offline whether the read first security codes matches the read second security code, and, if so, to activate the management control unit for management by the customer, and to terminate the management mode.

11 . The system as claimed in claim 10 , wherein the multi-factor and ID authentication algorithm is programmed to perform the multi-factor authentication check in the management mode only after the terminal has matched the first and the second security codes.

12 . The system as claimed in claim 10 , wherein the multi-factor and ID authentication algorithm is programmed to activate the management control unit for the management of the management control unit by the customer in the initial start-up mode after the storage of the authorization ID.

13 . The system as claimed in claim 10 , wherein the first storage medium is a transponder and in that the terminal includes a data interface for the wireless reading of data stored in the transponder.

14 . The system as claimed in claim 10 , wherein the second storage medium is a mobile terminal of the customer and in that the terminal has a data interface for the wireless reading of data stored in the mobile terminal.

15 . The system as claimed in claim 10 , wherein the first storage medium has a copy/clone, write protection, read protection and manipulation protection.

16 . The system as claimed in claim 10 , wherein an app of the provider activated by means of the second security code is installed on a mobile terminal of the customer in order to manage the management control unit.

17 . The method as claimed in claim 1 , wherein offline checking, whether the read first and second security codes match one another, takes place in the terminal.

18 . The method as claimed in claim 1 , wherein the terminal alone validates the read first and second security codes which are generated exclusively by the terminal manufacturer.

19 . The system as claimed in claim 10 , wherein offline checking, whether the read first and second security codes match one another, takes place in the terminal.

20 . The system as claimed in claim 10 , wherein the terminal alone validates the read first and second security codes which are generated exclusively by the terminal manufacturer.

21 . The system as claimed in claim 15 , wherein the second storage medium includes a manipulation protection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2022
From: CHENG, TRONG-NGHIA; EGGERT, REINHARD
To: SPHINX ELECTRONICS GMBH & CO KG
Reel/Frame 062229/0995 →
Priority Claims (1)
DE 10 2020 117 287.7 · Jul 1, 2020 · national
Continuity (2)
Continuation PCTEP2021067632 · Jun 28, 2021
Related Publication 20230117696A1 · Apr 20, 2023
References Cited (29)
US 7272385B2 · Mirouze et al. · 2007 [cited by applicant]
US 10080133B2 · Ibasco et al. · 2018 [cited by applicant]
US 20040124966A1 · Forrest · 2004 [cited by examiner]
US 20090181644A1 · Humphrey · 2009 [cited by examiner]
US 20150031351A1 · Ibasco · 2015 [cited by examiner]
US 20150154388A1 · Sakamoto · 2015 [cited by examiner]
US 20150381368A1 · Stevens, Jr. · 2015 [cited by examiner]
US 20160140334A1 · Forehand · 2016 [cited by examiner]
US 20160191520A1 · Voice · 2016 [cited by examiner]
US 20170048106A1 · Berry · 2017 [cited by examiner]
US 20170195118A1 · Perretta · 2017 [cited by examiner]
US 20180041341A1 · Gulati · 2018 [cited by examiner]
US 20190007396A1 · Krummel · 2019 [cited by examiner]
US 20190156017A1 · Feng · 2019 [cited by examiner]
US 20200053096A1 · Bendersky · 2020 [cited by examiner]
US 20200104478A1 · Chauhan · 2020 [cited by examiner]
US 20200162455A1 · Lin · 2020 [cited by examiner]
US 20200280855A1 · Avetisov · 2020 [cited by examiner]
CA 2412810A1 · 2002 [cited by applicant]
CN 105915343A · 2016 [cited by examiner]
CN 109271757A · 2019 [cited by examiner]
CN 105915343B · 2019 [cited by applicant]
CN 110737884A · 2020 [cited by examiner]
EP 1564691B1 · 2013 [cited by examiner]
EP 1710760B1 · 2013 [cited by applicant]
EP 3035172A1 · 2016 [cited by applicant]
JP 2013206286A · 2013 [cited by applicant]
RU 2596588C2 · 2016 [cited by applicant]
RU 2628484C2 · 2017 [cited by applicant]