Controlling access to an access object

    公开(公告)号:US11763618B2

    公开(公告)日:2023-09-19

    申请号:US17234321

    申请日:2021-04-19

    申请人: ASSA ABLOY AB

    摘要: It is presented a method for controlling access to an access object. The method is performed in an access control device and comprises the steps of: receiving a user input to reset the access control device; generating a new identifier for the access control device, and discarding any previously used identifier for the access control device; communicating with an electronic key to obtain an identity of the electronic key; obtaining a plurality of delegations, wherein each delegation is a delegation from a delegator to a receiver; and granting access to the access object only when the plurality of delegations comprise a sequence of delegations covering a delegation path from the access control device, identified using the new identifier, to the electronic key such that, in the sequence of delegations, the delegator of the first delegation is the access control device, and the receiver of the last delegation is the electronic key.

    Co-signing delegations
    3.
    发明授权

    公开(公告)号:US11869292B2

    公开(公告)日:2024-01-09

    申请号:US18101823

    申请日:2023-01-26

    申请人: ASSA ABLOY AB

    发明人: Frans Lundberg

    IPC分类号: G07C9/20 G07C9/00 H04L9/32

    摘要: It is provided a method for controlling access to a physical space using a co-sign delegation. The method is performed in a lock device and comprises the steps of: receiving an access request from an electronic key; obtaining a plurality of delegations, wherein each delegation is a delegation from a delegator to a delegatee, the plurality of delegations collectively forming a chain of delegations; determining that a delegation is a co-sign delegation, indicating that all further delegations need to be cryptographically signed by both the delegator of the respective delegation and by an access controller; and granting access to the physical space when the chain of delegations start in an owner of the lock device and ends in the electronic key; and when all delegations in the chain of delegations after the co-sign delegation are cryptographically signed by both the delegator of the respective delegation and by the access controller.

    Co-signing delegations
    4.
    发明授权

    公开(公告)号:US11580806B2

    公开(公告)日:2023-02-14

    申请号:US17413077

    申请日:2019-12-18

    申请人: ASSA ABLOY AB

    发明人: Frans Lundberg

    IPC分类号: G07C9/20 G07C9/00 H04L9/32

    摘要: It is provided a method for controlling access to a physical space using a co-sign delegation. The method is performed in a lock device and comprises the steps of: receiving an access request from an electronic key; obtaining a plurality of delegations, wherein each delegation is a delegation from a delegator to a delegatee, the plurality of delegations collectively forming a chain of delegations; determining that a delegation is a co-sign delegation, indicating that all further delegations need to be cryptographically signed by both the delegator of the respective delegation and by an access controller; and granting access to the physical space when the chain of delegations start in an owner of the lock device and ends in the electronic key; and when all delegations in the chain of delegations after the co-sign delegation are cryptographically signed by both the delegator of the respective delegation and by the access controller.

    HANDLING ACCESS RIGHTS FOR ACCESS TO A PHYSICAL SPACE

    公开(公告)号:US20240321029A1

    公开(公告)日:2024-09-26

    申请号:US18547017

    申请日:2022-02-17

    申请人: ASSA ABLOY AB

    IPC分类号: G07C9/27

    CPC分类号: G07C9/27

    摘要: It is provided a method for handling access rights for access to a physical space (16a-g), comprising: communicating (40) with a credential (2) of a user (5), based on short-range wireless communication; determining (42) that the credential (2) does not currently have access rights to access the physical space (16a-g); finding (44) a communication address to a superior (6) to the user (5); generating (46) an increased-access request message, comprising a link that, when activated, adds a first access role to the user (5); sending (48) the increased-access request message to the address of the superior (6); receiving (50) an indication that the superior has activated the link, adding the first access role to the user (5); and granting (52) access for the user (5) to the physical space (16a-g).

    CO-SIGNING DELEGATIONS
    6.
    发明公开

    公开(公告)号:US20240021035A1

    公开(公告)日:2024-01-18

    申请号:US18476732

    申请日:2023-09-28

    申请人: ASSA ABLOY AB

    发明人: Frans Lundberg

    IPC分类号: G07C9/20 G07C9/00 H04L9/32

    摘要: It is provided a method for controlling access to a physical space using a co-sign delegation. The method is performed in a lock device and comprises the steps of: receiving an access request from an electronic key; obtaining a plurality of delegations, wherein each delegation is a delegation from a delegator to a delegatee, the plurality of delegations collectively forming a chain of delegations; determining that a delegation is a co-sign delegation, indicating that all further delegations need to be cryptographically signed by both the delegator of the respective delegation and by an access controller; and granting access to the physical space when the chain of delegations start in an owner of the lock device and ends in the electronic key; and when all delegations in the chain of delegations after the co-sign delegation are cryptographically signed by both the delegator of the respective delegation and by the access controller.

    Managing central secret keys of a plurality of user devices associated with a single public key

    公开(公告)号:US11870887B2

    公开(公告)日:2024-01-09

    申请号:US17057802

    申请日:2019-06-27

    申请人: ASSA ABLOY AB

    IPC分类号: H04L9/08

    摘要: It is provided a method for managing central secret keys of a plurality of user devices associated with a single public key. The method is performed in a key manager and comprises the steps of: receiving, from a first user device, transformation data and an identifier of a second user device; obtaining a first central secret key associated with the first user device; generating a second central secret key by applying the transformation data to the first central secret key, wherein the transformation data is applied in reverse to how the same transformation data is applied by the first user device to a device secret key of the first user device; and storing the second central secret key in association with the second user device.

    Delegation and auxiliary condition for physical access

    公开(公告)号:US11263840B2

    公开(公告)日:2022-03-01

    申请号:US16487163

    申请日:2018-02-23

    申请人: ASSA ABLOY AB

    摘要: It is provided a method for controlling access to a physical space. The method is performed in an access control device and comprises the steps of: communicating with an electronic key to obtain an identity of the electronic key; obtaining a plurality of delegations; determining, from one of the delegations, that there is an auxiliary condition, wherein the auxiliary condition is that access is approved for the electronic key by an auxiliary party, authenticated by a digital signature by the auxiliary party; and granting access to the physical space when the plurality of delegations comprises a sequence of delegations covering a delegation path from the access control device to the electronic key such that, in the sequence of delegations, the delegator of the first delegation is the access control device, the receiver of the last delegation is the electronic key, and the auxiliary condition is fulfilled.

    PRIVACY-ENHANCED DELEGATION OF ACCESS RIGHT
    9.
    发明公开

    公开(公告)号:US20240296704A1

    公开(公告)日:2024-09-05

    申请号:US18547953

    申请日:2022-02-22

    申请人: ASSA ABLOY AB

    发明人: Frans Lundberg

    摘要: It is provided a method for providing a privacy-enhanced delegated access right to unlock a physical lock. The method comprises: obtaining a derivation scalar; receiving a cryptographically signed delegation from the delegator device, the delegation being a data object comprising a public key of the delegator device, a public key of the physical lock, and a derived public key for the delegatee device, and wherein the delegation is cryptographically signed using a secret key that is paired with the public key of the delegator device; obtaining a source secret key for the delegatee device, the source secret key being paired with the source public key; calculating a derived secret key for the delegatee device using the source secret key for the delegatee device and the derivation scalar; providing the delegation to the physical lock; and authenticating the delegatee device with the physical lock using the derived secret key.

    Emergency delegation
    10.
    发明授权

    公开(公告)号:US11790717B2

    公开(公告)日:2023-10-17

    申请号:US17298259

    申请日:2019-12-17

    申请人: ASSA ABLOY AB

    摘要: It is provided a method for controlling access to a physical space using an emergency delegation. The method is performed in a lock device and comprises the steps of: receiving an access request from an electronic key; obtaining a plurality of delegations, wherein each delegation is a delegation from a delegator to a delegatee, the plurality of delegations collectively forming a chain of delegations wherein when two delegations are chained together, the delegatee of one delegation is the delegator of the next delegation; determining that a delegation in the chain of delegations is an emergency delegation, the emergency delegation indicating that access should only be granted when an emergency situation occurs; determining when an emergency situation occurs; and granting access to the physical space when the chain of delegations starts in the lock device and ends in the electronic key; and when the emergency situation occurs.