IP Library Granted Patent US 12,430,965
Granted Patent B2
US 12,430,965 · App. 18/330,822 · Granted Sep 30, 2025

Access control architecture for detecting secure data copied between devices

Inventors: Aaron Schlicht (Golden, CO); Joseph W. Baumgarte (Carmel, IN)
Assignee: Schlage Lock Company LLC
G07C9/00309G07C2009/00388
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,430,965
App. No.
18/330,822
Granted
Sep 30, 2025
Kind
B2
Abstract

A method for leveraging an access control architecture for detecting secure data copied between devices according to an embodiment includes, by a credential system, generating an authentication diversified key based on a master key and a first key diversification input, generating an encryption diversified key based on the master key and a second key diversification input, generating a credential blob including an encrypted credential for a mobile device and a portion of the second key diversification input, and transmitting the credential blob to the mobile device, and by a reader device, receiving credential data from the mobile device including an encrypted version of the credential blob, generating the encryption diversified key based on the master key and the second key diversification input, validating the credential data based on the encryption diversified key, and extracting the credential for use in an access control decision.

Claims (42)

1. A method for leveraging an access control architecture for detecting secure data copied between devices in an access control system that includes a credential system, a mobile device, and a reader device, the method comprising:

generating, by the credential system, an authentication diversified key based on a master key and a first key diversification input, wherein the master key is securely stored at the credential system and at the reader device;

generating, by the credential system, an encryption diversified key based on the master key and a second key diversification input, wherein the second key diversification input is a function of the first key diversification input;

generating, by the credential system, a credential blob including an encrypted credential for the mobile device and a portion of the second key diversification input;

transmitting, by the credential system, the credential blob to the mobile device;

performing, by the reader device in response to the mobile device being presented to the reader device, mutual authentication with the mobile device to generate a session key, wherein performing the mutual authentication involves using the authentication diversified key;

receiving, by the reader device, credential data from the mobile device, wherein the credential data includes an encrypted version of the credential blob;

generating, by the reader device, the encryption diversified key based on the master key and the second key diversification input, wherein the second key diversification input is determined based on the portion of the second key diversification input of the credential blob and the first key diversification input;

validating, by the reader device, the credential data based on the encryption diversified key; and

extracting, by the reader device, the credential for use in an access control decision.

2. The method of claim 1 , wherein the first key diversification input comprises a random number.

3. The method of claim 2 , wherein the second key diversification input is based on the first key diversification input and a second random number different from the first random number.

4. The method of claim 3 , wherein the second random number comprises the portion of the second key diversification input.

5. The method of claim 1 , wherein generating the authentication diversified key comprises generating a first cipher-based message authentication code (CMAC) of the first key diversification input using the master key.

6. The method of claim 5 , wherein generating the encryption diversified key comprises generating a second CMAC of the second key diversification input using the master key.

7. The method of claim 1 , further comprising storing, by the mobile device, the authentication diversified key in a secure key storage separate from the first key diversification input.

8. The method of claim 7 , further comprising storing, by the mobile device, the first key diversification input in an encrypted file, wherein the file is encrypted by a file key stored in the secure key storage.

9. The method of claim 1 , further comprising transmitting, by the reader device, instructions to a lock device to perform an access control action based on the extracted credential.

10. The method of claim 1 , wherein receiving the credential data from the mobile device comprises receiving credential data encrypted with the session key; and

wherein generating the encryption diversified key comprises generating the encryption diversified key in response to decrypting the encrypted credential data using the session key.

11. An access control system for leveraging an access control architecture for detecting secure data copied between devices of the access control system, the access control system comprising:

at least one processor; and

at least one memory comprising a plurality of instructions stored thereon that, in response to execution by the at least one processor, causes the access control system to:

generate, by a credential system of the access control system, an authentication diversified key based on a master key and a first key diversification input, wherein the master key is securely stored at the credential system and at a reader device of the access control system;

generate, by the credential system, an encryption diversified key based on the master key and a second key diversification input, wherein the second key diversification input is a function of the first key diversification input;

generate, by the credential system, a credential blob including an encrypted credential for the mobile device and a portion of the second key diversification input;

transmit, by the credential system, the credential blob to a mobile device of the access control system;

perform, by the reader device in response to the mobile device being presented to the reader device, mutual authentication with the mobile device to generate a session key, wherein to perform the mutual authentication involves using the authentication diversified key;

receive, by the reader device, credential data from the mobile device, wherein the credential data includes an encrypted version of the credential blob;

generate, by the reader device, the encryption diversified key based on the master key and the second key diversification input, wherein the second key diversification input is determined based on the portion of the second key diversification input of the credential blob and the first key diversification input;

validate, by the reader device, the credential data based on the encryption diversified key; and

extract, by the reader device, the credential for use in an access control decision.

12. The access control system of claim 11 , wherein the first key diversification input comprises a random number.

13. The access control system of claim 12 , wherein the second key diversification input is based on the first key diversification input and a second random number different from the first random number.

14. The access control system of claim 13 , wherein the second random number comprises the portion of the second key diversification input.

15. The access control system of claim 11 , wherein to generate the authentication diversified key comprises to generate a first cipher-based message authentication code (CMAC) of the first key diversification input using the master key.

16. The access control system of claim 15 , wherein to generate the encryption diversified key comprises to generate a second CMAC of the second key diversification input using the master key.

17. The access control system of claim 11 , wherein the plurality of instructions further causes the access control system to store the authentication diversified key in a secure key storage of the mobile device separate from the first key diversification input.

18. The access control system of claim 17 , wherein the plurality of instructions further causes the access control system to store the first key diversification input in an encrypted file of the mobile device, wherein the file is encrypted by a file key stored in the secure key storage of the mobile device.

19. The access control system of claim 11 , wherein the plurality of instructions further causes the access control system to transmit, by the reader device, instructions to a lock device of the access control system to perform an access control action based on the extracted credential.

20. The access control system of claim 11 , wherein to receive the credential data from the mobile device comprises to receive credential data encrypted with the session key; and

wherein to generate the encryption diversified key comprises to generate the encryption diversified key in response to decryption of the encrypted credential data using the session key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2023
From: SCHLICHT, AARON; BAUMGARTE, JOSEPH W.
To: SCHLAGE LOCK COMPANY LLC
Reel/Frame 063918/0642 →
Continuity (2)
Provisional Application 63349663 · Jun 7, 2022
Related Publication 20230394897A1 · Dec 7, 2023
References Cited (21)
US 8559642B2 · Wurm · 2013 [cited by applicant]
US 10237063B2 · Brands · 2019 [cited by applicant]
US 10505732B2 · Doliwa · 2019 [cited by applicant]
US 10706649B2 · Kuenzi et al. · 2020 [cited by applicant]
US 10925102B2 · Neafsey et al. · 2021 [cited by applicant]
US 11023875B2 · Eberwine et al. · 2021 [cited by applicant]
US 20180241561A1 · Albertson et al. · 2018 [cited by applicant]
US 20190218826A1 · Allen et al. · 2019 [cited by applicant]
US 20200026835A1 · Mitchell et al. · 2020 [cited by applicant]
US 20200050779A1 · Prokop et al. · 2020 [cited by applicant]
US 20200100108A1 · Everson · 2020 [cited by examiner]
US 20200104826A1 · Rule et al. · 2020 [cited by applicant]
US 20200106615A1 · Rule · 2020 [cited by examiner]
US 20200106617A1 · Rule · 2020 [cited by examiner]
US 20230083785A1 · Maiman · 2023 [cited by examiner]
EP 2442204B1 · 2013 [cited by applicant]
EP 3529437B1 · 2020 [cited by applicant]
NXP; AN10922: Symmetric Key Diversifications; Jul. 2, 2019, 26 pages. [cited by applicant]
International Search Report; International Searching Authority; International Application No. PCT/US2023/068055; Sep. 13, 2023; 2 pages. [cited by applicant]
Written Opinion of the International Searching Authority; International Searching Authority; International Application No. PCT/US2023/068055; Sep. 13, 2023; 6 pages. [cited by applicant]
Extended European Search Report; European Patent Office; European Patent Application No. 23820611.4; Jul. 7, 2025; 11 pages. [cited by applicant]