Wireless lock
From Wikipedia, the free encyclopedia
Wireless lock is a protection concept for authenticated LAN or WLAN network clients offered from various vendors in various functional shapes and physical designs. In contrast to wireless keys, wireless lock puts emphasis on automatic locking instead of just locking by time-out or unlocking.
The wireless lock concept supports initialising the client with authentication and log-on as electronic key solutions. Beyond that a wireless lock supports automatic log-off after user leaves unlocked network client and independent from time-out conditions. Protection comes into effect, while integrated or galvanically attached and paired receiver/transceiver stays connected with protected client object as soon as wireless token gets separated from client exceeding a set maximum allowed distance, generally the manual reach required for operating keyboard attached to client.
Currently (2011–07) there is no general standard supporting inter-operability of wireless lock concepts.
- Most offered air interface solution is based on ISO/IEC 18000-3 HF (13,56 MHz) passive RFID tags and near field communication (NFC)-like reader specification.
- Most offered authentication procedures make use of IETF public key infrastructure (PKI).
- Comfortable solutions support single sign-on servicing.
- Bluetooth BLE profile proximity is said to support such application.[1]
Applications
The wireless token serves as an independent second authentication factor. Local pairing of token with protected networked client object is the authentication procedure. Personalisation of token with user is a preparative action that may be administered apart from network. Allocated user credentials shall be served from networked authorisation server for allowed access to data and function and from authentication server for allowed access to network and clients.
A wireless communication distance metrics sets the protected object to "locked", as soon as the set distance level between paired transmitter and receiver of a wireless signal transmission is exceeded. The protected object returns to status "unlocked" as soon as the distance gets lesser and the received signal strength level higher than set limit. Transmitters may be worn by the owner of an object, whereas the other receiver item gets attached to the protected object for logically protecting it to usage by the owner only.
Basic electronic gadget is a wireless token that communicates with a counterpart attached to the object to be controlled wirelessly. User guides for mode of operation recommend to bear a very light designed alarm token with a necklace, a wristband or similarly directly bound to the body. Very low transmission power levels secure low electromagnetic interference as well as entirely biologically harmless operation
After setting the object to protect to work and initially pairing the two wireless token devices with each other, the protected object refuses operation when exceeding the set distance between token and protected object.
Advanced solutions offer communications on the basis of standardized communication protocols and based on standardized air interface links.
Simple solutions make use of passive RFID tokens, thus requiring a higher transmission level from a reader attached to the protected object and illuminating the token for response. Chosen frequency band and allowed maximum transmission power level define the possible reach for the response from the token in the vicinity of the protected object.
Application is mainly known PC locking under for authenticated log-in conditions. Protected object controlling works with the token at hands working as a transceiver (RFID passive) or beacon transmitter (RFID active. Currently some similar applications are offered by several no-name vendors and under non-guaranteed specification.
Standardization
Relevant existing standard for such application is Bluetooth V4.0 Low Energy of 2009-12-17 with the profiles Find Me and Proximity.[2]
Security modes
Published concepts for secure key transmission are published in several context.[3] Standardisation in IETF (PKI), W3C (XML), ITU (X.509) is going on. Basically there are different concepts available for implementing a sound security concept:
- Active token sends fixed identity to be read by receiver (not robust against attacks)
- Transceiver sends initial code in challenge–response procedure and active token answers agreed code to prevent from fraudulent attacking
- Transceiver sends with varied power levels to stimulate various response levels from passive tag
- Transceiver and token communicate bi-directional for travel time (time of flight, TOF) estimates
- Beaconing token sends with varied power levels to support RSSI estimation with receiver
Metrics options
The metrics options for detecting separation of protected object and authenticated user have to take into account various physical phenomena and thus offer a variety of signal processing to overcome
- multipath propagation
- indirect and direct paths
- multipath fading
- excess reach of nearby colliding transmitters
- higher populations of transmitters
The safe approach is travel time estimation with ultra-short pulses (e.g. UWB and CSS), the cheap approach is RSSI estimate with just variation of power levels.[citation needed]
Standards based products available
Many current product offers with reference to communication standards are just prototypes. Basic design is proposed e.g. with Texas Instruments sample offer using Bluetooth V4.0 low energy protocol standard[4] and with comparable proposals of other chip foundries.