Tor Sornes (1976)
Designation: Punch-card lock
Inventor: Tor Sornes invented the first electromechanical punch-card lock in 1976, laying the foundation for modern hotel locking technology. The idea was radically new: instead of a physical key coding the lock, a punch card activated electrical or mechanical contacts when inserted, thereby releasing the door. The system was based on:
- A plastic or paper punch card with a defined perforation code.
- A reading mechanism that detected the perforations electrically or mechanically.
- An electromechanical locking mechanism that released the bolt.
- A rapidly replaceable coding principle, changing the card effectively recoded the lock.
For the hotel industry, this was revolutionary: Lost keys no longer posed a major risk, codes could be changed immediately, and guests did not have to carry metal keys. Sornes thus laid the foundation for today’s magnetic-stripe, chip and RFID hotel locks.
Current locks of this type
Traditional punch-card locks based on Sornes’ design are now rarely manufactured, but their successor technologies are used worldwide:
- Magnetic-stripe hotel locks
- Chip cards / smart cards
- RFID cards
- Electronic access-control systems with interchangeable coded media
- NFC and smartphone-based systems Many manufacturers, including VingCard, which later became part of ASSA ABLOY, built directly on Sornes’ principle.
Lockpicking
• Exploiting manufacturing tolerances
Early punch-card readers exhibited typical production variations:
- Uneven sensor activation
- Variations in contact-spring tension
- Minor deviations in the position of the reading pins
- Slight displacement caused by mechanical wear
These tolerances could result in slightly bent or imprecisely punched cards still being recognised as valid, increasing the potential for misuse.
• Mechanical feedback Because the card guide was mechanical, a certain amount of feedback was present:
- A perceptible click when the card was inserted
- Slight movement in individual reading contacts
- Audible differences between worn contact pins
Trained individuals could theoretically use this information to determine the location of active reading contacts, making it easier to reproduce a functioning card.
• Wear during use Continuous use, particularly in hotels, caused typical signs of wear:
- Worn contact pins
- Reduced spring tension
- Corroded electrical contacts
- Worn card slots
This wear could lead to incorrect interpretation of the code, making the lock more susceptible to imprecise or manipulated cards.
Risk/security
Highest risk: Destructive attacks: Forcing the door or mortise-lock case Levering attacks against the door frame Mechanical force against the card reader
Medium risk: Targeted, partially destructive attacks: Drilling or forcing open the reader head Short-circuiting or manipulating the electromechanical mechanism Removing the card-slot cover
Low risk: Fine manipulation: Analysing the card through mechanical feedback, Reproducing a functioning punch card, Decoding caused by tolerances using test cards.
Findings
Tor Sornes revolutionised the access-control market with his punch-card lock in 1976. For the first time, access was governed not by a metal mechanism but by variably codable data carriers. The system was pioneering, even though, from today’s perspective, it was susceptible to wear, tolerances and electromechanical manipulation. Its greatest strength: Immediate recoding, a decisive advantage over conventional key systems. Sornes’ invention forms the historical foundation of modern hotel locking and access-control systems, making it a milestone in the development of locking technology.
Charles Walton (1983)
Designation: Electronic RFID lock
Inventor: Charles Walton is regarded as the inventor of the RFID principle for security-related applications. In 1983, he filed a patent that described the contactless identification of an authorised credential, such as a transponder or card, for access control. This marked the birth of the modern RFID lock. His system was based on: A passive or active RFID transponder, A reader that generated an electromagnetic field, a coded response signal transmitted only by the authorised transponder, and an electronic control unit that released the bolt following successful identification. Walton’s approach was revolutionary because it introduced contactless identification into security-related applications. This laid an important foundation for modern hotel doors, company locking systems, access-control systems and smart locks.
Current locks of this type
RFID is now one of the world’s most important access-control technologies. Direct successors can be found in:
- Hotel card locks using MIFARE, LEGIC, HID and similar technologies
- Access systems for companies and public authorities
- Car parks and barriers
- Smart-home door locks
- Industrial and laboratory access systems
RFID has evolved through several technological generations:
- LF RFID at 125 kHz, used in early systems
- HF RFID at 13.56 MHz, including MIFARE and NFC
- UHF RFID for industrial access and longer reading ranges
- Latest-generation RFID keys with cryptographic protection
Walton’s principle is now found almost everywhere and forms the basis of most modern contactless access-control systems.
Lockpicking
• Exploiting manufacturing tolerances
Early RFID systems suffered from technical variations: Uneven antenna-coil sensitivity, Varying reading ranges, minor inaccuracies when evaluating weak transponder signals, Incorrect interpretation of interference signals caused by component tolerances. In rare cases, these deviations could result in unauthorised or imprecisely copied RFID tags being accepted, particularly by early systems with weak coding.
• Mechanical feedback
Mechanical feedback played only a minor role in RFID locks. The only perceptible signs were:
- Audible relays or magnetic latches
- Minimal vibration from the bolt motor
- Hardly any perceptible feedback from the reader itself
This provided attackers with no useful points for manipulation because the security-relevant logic was entirely electronic.
• Wear during use Wear mainly affected:
- Buttons or covers on the reader module
- Oxidised contacts in hybrid readers
- Ageing coils or weakening transponder elements
- The bolt mechanism in electromechanically coupled systems
Electronic ageing could increase the likelihood of incorrect readings, but it could rarely be exploited deliberately.
Risk/security
Highest risk: Destructive attacks: Forcing the door frame or lock case Levering tools, chisels and angle grinders Attacking the door leaf or fittings instead of the electronics
Medium risk: Targeted, partially destructive attacks: Drilling or tearing off the reader, Short-circuiting the electronics, Disconnecting cables, depending on the system, Bypassing the electric bolt by gaining direct access to the mechanism.
Low risk: Fine manipulation / electronic attacks: Copying simple RFID tags, with early 125 kHz systems being particularly vulnerable, Reading unencrypted transponders, Replay attacks against very old models, Interference signals intended to cause incorrect interpretation.
Findings
In 1983, Charles Walton created the foundation for an entirely new security concept: contactless identification instead of mechanical keys. His RFID lock fundamentally changed access control and made flexible authorisation systems possible, with permissions that could be changed quickly. The weaknesses of early models were primarily:
- Unencrypted RFID transponders
- Electromechanical components that could be attacked relatively easily
- Destructive attacks against the surrounding door structure
Walton’s RFID lock is now regarded as one of the most important predecessors of modern digital access-control systems with cryptographic protection, and as a milestone in security technology.
Paul E. Szabo (1985)
Designation: Kaba Nova
Inventor: Paul E. Szabo developed the Kaba Nova system in 1985, one of the most advanced developments of the multi-row reversible-key principle. While earlier Kaba systems, including Kaba 8 and Kaba 20, were based on radial pin arrangements, Nova introduced complex multi-channel and multi-row coding, combined with increased protection against unauthorised key duplication and extremely precise manufacturing. The main characteristics of the Kaba Nova system included: Several rows of radial pins coded simultaneously, a highly complex reversible-key profile with an asymmetrical, deeply guided design, additional profile barriers that severely restricted the insertion of foreign tools, a cylinder plug with minimal movement and high precision, and optional mechanical security elements designed to resist picking and unauthorised key duplication. Szabo combined mechanical security, key-copy protection and master-key-system compatibility in a form that had not previously been achieved. Kaba Nova became one of the most robust locking systems of the late 1980s and early 1990s.
Current locks of this type
The original Kaba Nova series is no longer manufactured in this form. However: The technology continues in several successor systems, including:
- Kaba quattro
- Kaba quattro plus
- Kaba experT / experT plus
- Kaba pextra / pextra+
- Modern dormakaba high-security cylinders
All these systems are based on Szabo’s design philosophy: Radially operating pin rows, the reversible-key principle, Complex profile barriers, High manufacturing precision, Certifiable master-key technology. Nova can therefore be regarded as a direct predecessor of many current high-security key profiles.
Lockpicking
• Exploiting manufacturing tolerances
The Nova system also has natural tolerances, although these are considerably smaller:
- Minimal differences in the positions of individual pin chambers
- Slight radial or axial play
- Variations in spring force in heavily used cylinders
- Differences in the microgeometry of the key
In rare cases, these minute manufacturing variations could provide minimal feedback, although only to highly experienced specialists.
• Mechanical feedback Nova was specifically designed to provide as little feedback as possible. Nevertheless, a small amount of theoretically usable residual feedback exists:
- Barely perceptible setting points in the radial pins
- Minimal differences in torque as the correct height is approached
- Slight variations in friction in worn cylinders
Compared with conventional pin-tumbler systems, the feedback is extremely subdued.
• Wear during use Use causes typical signs of wear:
- Worn pin tips, slight but perceptible
- Increased plug movement after many years
- Slightly worn key grooves
- Fatigued springs in the multi-row arrangement
Depending on the age of the cylinder, these factors increase its mechanical readability, although the security level remains considerably higher than that of many conventional systems.
Risk/security
Highest risk: Destructive attacks: Breaking, drilling or milling out the cylinder Angle grinders and impact tools Bypass attacks against the door or frame rather than the cylinder
Medium risk: Targeted, partially destructive attacks: Drilling individual pin chambers, historically possible in versions without carbide inserts, Pulling the cylinder where no security fitting is installed, Milling the front plate, Forcing open the keyway.
Low risk: Fine manipulation: Setting individual radial pins using minimal torsional pressure, Decoding through rare manufacturing or wear-related tolerances, Manipulation requiring extremely sophisticated tools and considerable expertise.
Findings
Paul E. Szabo’s Kaba Nova was a milestone in the development of modern high-security cylinders. It combined radial multi-row systems, an asymmetrical key profile and extreme precision in a way that made manipulation considerably more difficult. As with all high-quality cylinders, its weaknesses lay less in the mechanism itself and more in:
- Destructive attacks
- Missing security fittings
- Age-related wear
Nova became the foundation for many later dormakaba systems and remains an important technical development in the history of modern reversible-key technology.
Klaus Abend, Dieter Wienert, Johannes Filthaut (1987)
Designation: Electronic Winkhaus lock
Inventors: In 1987, Abend, Wienert and Filthaut presented a complete electronic locking system for Winkhaus. It was one of the early solutions to combine electronic identification, access control and mechanical locking in a coherent system. The system was based on: An electronically coded key using early transponder or chip technology, An electronic reader inside the cylinder, An electronic control unit that verified whether the key was authorised, and a mechanical locking mechanism that was released only after successful identification. This resulted in one of Europe’s first true mechatronic cylinders. Winkhaus was among the pioneers exploring the combination of mechanical locking technology and electronic access control, long before smart locks became a mass-market product. The system was particularly suitable for:
- Master-key systems with changing access permissions
- Companies and public authorities
- Large residential complexes
- Areas requiring protection against lost keys, where a missing key could be blocked immediately
Current locks of this type
The 1987 Winkhaus system is regarded as a direct predecessor of modern mechatronic cylinders. Successor systems are now used worldwide:
- Winkhaus blueChip
- Winkhaus X-tra systems
- Modern transponder and chip cylinders
- Hybrid mechanical and electronic master-key systems
- Time-controlled access profiles in companies and public authorities
The basic principle of mechanical locking combined with electronic authorisation is now standard in modern access control. The electronic Winkhaus lock was one of the most important European steps towards intelligent door systems.
Lockpicking
• Exploiting manufacturing tolerances
As with early electronic systems, certain production variations were present: Differences in the sensitivity of contact points or reader coils, Minimal variations in the key insertion path, Slight differences in the positioning of electronic components, Different response times in the control electronics. These tolerances occasionally caused reading errors, but could only rarely be used as a basis for manipulation.
• Mechanical feedback Because the security-relevant verification process was electronic, the lock itself provided: Almost no usable mechanical feedback, Only an audible click from the release motor or solenoid, Minimal changes in torque during release. There were therefore few points of attack for conventional mechanical manipulation. Only the subsequent mechanical locking element could be manipulated at all, and then only following successful electronic identification.
• Wear during use Wear primarily affected: Electrical contacts, Insertion channels inside the cylinder, Key surfaces in hybrid key types, Motor or magnetic locking components under intensive use. Wear could cause malfunctions, but could only rarely be exploited deliberately.
Risk/security
Highest risk: Destructive attacks: Forcing the security fitting or door frame, Angle grinders, breaking tools and chisels, Attacking the door material instead of the lock.
Medium risk: Targeted, partially destructive attacks: Drilling or breaking out the electronic module, Manipulating the release motor through direct physical access, Milling the cylinder where insufficient mechanical protection is present.
Low risk: Fine manipulation / electronic attacks: Signal analysis, possible in early unencrypted systems, Replay attacks, relevant only to very early prototypes, Exploiting communication errors or interference signals.
Findings
The electronic Winkhaus lock of 1987 was an important milestone in access technology. By combining electronic identification with mechanical locking, Abend, Wienert and Filthaut created one of Europe’s first mechatronic cylinder systems. Its strengths included:
- Flexible allocation of access permissions
- Effective protection against lost keys
- Minimal feedback that could be used for manipulation
Its weaknesses were primarily:
- Destructive attacks
- Early electronic modules without sufficient physical protection
- Age-related electronic malfunctions
The system laid the foundation for many modern access solutions and remains one of the important innovations in 1980s locking technology.
Volker Ziegler (1988)
Designation: CES alpha electronic locking system
Inventor: Volker Ziegler developed CES alpha for CES in 1988, one of the first complete electronic locking systems in cylinder form. It was among the earliest systems to combine electronic identification and mechanical locking within the compact dimensions of a profile cylinder, making it a genuine innovation of the 1980s. The system was based on: An electronically coded key using early chip or transponder technology, An electronic reader module located directly inside the cylinder, An intelligent control unit that checked the authorisation, a mechanical locking core that was released only after successful identification, The ability to block lost keys through software without replacing the cylinder. CES alpha was therefore one of the first digitally managed master-key systems, long before electronic access control became standard in buildings.
Current locks of this type
CES alpha is no longer manufactured in its original form, but the principle continues in modern CES systems. Current successors include:
- CES OMEGA FLEX
- CES OMEGA ACTIVE
- CES eCLIQ / electronic CLIQ systems, developed in cooperation
- Mechatronic and fully electronic cylinders with online and offline management
The central elements, an electronic key, electronic authentication and mechanical locking, can be traced directly to the 1988 alpha concept. CES alpha is now regarded as a predecessor of modern mechatronic and electronic locking technology in Europe.
Lockpicking
• Exploiting manufacturing tolerances
As with early electronic cylinders, certain production variations were present: Variations in the sensitivity of the reading contacts, Different ranges of the identification field, Differences in the positioning of electronic components, Minor mechanical tolerances where the electronic and mechanical components interacted. These tolerances occasionally caused incorrect readings or recognition problems, but offered very little scope for useful manipulation.
• Mechanical feedback Because CES alpha primarily operated electronically, mechanical feedback was minimal: An audible click from the release element, A slight change in torque when the plug was released, No usable sequential feedback of the kind found in mechanical cylinders. There was very little that could be felt by someone attempting manipulation because the security-relevant logic was located entirely within the electronics. • Wear during use Wear affected both the electronic and mechanical components: Contact wear between the key and reader unit in hybrid-key systems, Ageing electronic components, Fatigue in the electromechanical release module, Wear in the mechanical core. Ageing components could cause malfunctions, but could rarely be exploited deliberately.
Risk/security
Highest risk: Destructive attacks: Breaking or drilling out the door fitting Angle grinders, chisels and crowbars Attacking the door or frame instead of the cylinder
Medium risk: Targeted, partially destructive attacks: Physically drilling the electronic or mechanical unit, Tearing off the front electronic modules, Milling the cylinder where no security fitting is installed, Directly manipulating the release mechanism by gaining access through force.
Low risk: Fine manipulation / electronic attacks: Reading old, unencrypted chips, primarily relevant to early prototypes, Replay attacks against weak authentication protocols, Disrupting the electronics through targeted manipulation of the electromagnetic field.
Findings
The electronic CES alpha system was a visionary step in locking technology in 1988. Volker Ziegler created one of Europe’s first electronic profile cylinders, combining identification, access management and mechanical locking in a format that remains standard today. Its strengths: Immediate blocking of lost keys, Flexible management of access permissions, High resistance to conventional picking methods. Its weaknesses: Electronic modules susceptible to physical destruction, Limited protection against brute force, Early chip technology without modern cryptography. CES alpha is one of the most important milestones on the path towards today’s high-end mechatronic cylinders.
Mijodrag Makivic (1992)
Designation: EVVA EMZY electronic motorised cylinder
Inventor: Mijodrag Makivic developed the EMZY for EVVA in 1992. It was one of the first fully motorised locking cylinders and did more than combine mechanical and electronic components, it actively powered the entire locking process. The EMZY was not simply an electronic version of a mechanical system, but an entirely new approach: An integrated electric motor that turned the cylinder plug independently, an electronic identification unit, such as a transponder, chip or higher-level access-control system, a set of sensors that monitored the key status, position and rotational state, Automatic locking and unlocking governed by the electronics, with optional event logging and connection to building-management systems. The EMZY is regarded as a milestone in mechatronics: It transferred responsibility for the locking process from the person to the system, an important step towards today’s automated access solutions.
Current locks of this type
The EMZY itself and its successors remain in use. Modernised versions include: - Different generations of EVVA EMZY - Electronic motorised cylinders in master-key systems - Motor-controlled panic and access systems - Integrated solutions in modern building-management architectures Other manufacturers later adopted similar approaches, but EVVA remains one of the reference companies in this category.
Lockpicking
• Exploiting manufacturing tolerances Early EMZY models also exhibited tolerances in:
- Motor mounting
- Sensor positions
- Locking travel
- Transmission of force between the motor shaft and cylinder plug
In the worst case, these tolerances could cause incorrect interpretations, for example the system reporting that the door was closed when it remained slightly open. However, they offered little value for manipulation because the motor and electronics strictly governed the locking process.
• Mechanical feedback Because the EMZY was not operated like a conventional mechanical cylinder, almost all picking feedback was eliminated. Only minimal feedback could be perceived:
- A quiet motor sound
- A change in torque when the plug was moved automatically
These signals were irrelevant for manipulation. Without electronic authorisation, the cylinder remained mechanically rigid.
• Wear during use The EMZY exhibited typical electromechanical ageing:
- Motor wear
- Wear in the gear stages
- Ageing sensors or electronic contacts
- Wear in the mechanical coupling
As the system aged, malfunctions could occur, such as the motor becoming blocked or key states being recognised incorrectly. However, this had little relevance to deliberate manipulation.
Risk/security
Highest risk: Destructive attacks: Attacking the fitting or door frame, Breaking out the cylinder, Angle grinders, crowbars and impact tools, Drilling the mechanical locking mechanism.
Medium risk: Targeted, partially destructive attacks: Drilling the motor or electronic components, Milling the cylinder face, Removing the electronic module by force, Accessing the mechanical coupling after destroying the security fitting.
Low risk: Fine manipulation / electronic attacks: Picking and decoding attacks are largely irrelevant because the plug cannot move without authorisation. Electronic attacks, such as protocol analysis, were theoretically possible against early EMZY models, but extremely difficult. Interference signals could cause malfunctions, but rarely resulted in the lock opening.
Findings
With the EMZY in 1992, Mijodrag Makivic created one of the first fully motorised locking cylinders, a system that used the key solely for identification and left the actual locking process to the electronics. Its strengths: High resistance to manipulation, Flexible connection to access-control systems, Automated locking, Integrated mechatronics. Its weaknesses: Destructive attacks against the door or fitting, Physical attacks against the motor and cylinder body, Electronic ageing after many years of operation. The EMZY remains an important milestone in motorised access technology and has influenced almost all modern smart-lock architectures.
Günter Uhlmann (1996)
Designation: Electronic locking cylinder with transponder
Inventor: Günter Uhlmann developed an electronic locking cylinder with an integrated transponder reader in 1996. It combined mechanical and electronic locking technology in a compact format suitable for the mass market. While earlier systems often required external readers, motors or additional modules, Uhlmann integrated:
- A transponder reader directly into the cylinder head
- Electronics that checked and authorised the transponder
- An electromechanical release unit that disengaged the plug only after successful identification
- A conventional mechanical locking core, allowing the door to be operated normally with a key, but only after electronic authorisation.
This created a true mechatronic cylinder whose shape, dimensions and installation largely corresponded to those of a conventional profile cylinder. The transponder-based approach was particularly attractive for:
- Residential complexes
- Companies
- Master-key systems with dynamic access permissions
- Users who required electronic management without a complicated infrastructure
Current locks of this type
The basic principle behind Uhlmann’s development is now widely used and forms the basis of many modern mechatronic systems. Successors and further developments include:
- CES OMEGA ACTIVE / ACTIVE 2
- EVVA AirKey and AirKey hybrid systems
- Winkhaus blueChip
- dormakaba mechatronic cylinders
- eCLIQ / electronic CLIQ systems
- Numerous modern transponder locking cylinders
The principle of electronic transponder authorisation combined with mechanical locking remains one of the dominant concepts in the electronic locking market.
Lockpicking
• Exploiting manufacturing tolerances
As with other early mechatronic cylinders, variations in tolerances were present: Differences in the range of the transponder sensor, Minimal deviations in the antenna position, Slight variations in the coupling between the electronics and mechanical core, Tolerances within the mechanical pin system, where one was used. These variations could occasionally cause incorrect readings, but rarely provided a genuine basis for manipulation.
• Mechanical feedback Without a valid transponder, the electronic release system provided: No rotational feedback, No setting points, No mechanical path of attack. Following successful release, the cylinder behaved like a conventional mechanical core, although manipulation would then no longer be relevant.
• Wear during use Combining electronic and mechanical technology meant that both areas were subject to wear: Ageing transponder contacts or antenna elements, Ageing electronic components, Mechanical wear inside the cylinder core, Wear in the coupling mechanism. The decisive point: Wear increased the likelihood of malfunctions, but not the opportunity for manipulation.
Risk/security
Highest risk: Destructive attacks: Forcing the security fitting or door frame, Angle grinders, crowbars and mechanical force, Pulling or breaking off the entire cylinder body.
Medium risk: Targeted, partially destructive attacks: Drilling the electronic modules, Milling the cylinder, Attacking the mechanical coupling after removing the cylinder head, Short-circuiting or physically destroying the release unit.
Low risk: Fine manipulation / electronic attacks: Copying transponders, possible with older unencrypted models, Replay attacks against simple protocols, Manipulating interference signals, for example through shielding, Fine mechanical manipulation is ineffective while the release remains locked.
Findings
Günter Uhlmann’s electronic transponder locking cylinder from 1996 was an important step towards modern mechatronic cylinders. For the first time, it brought together in a compact form:
- Electronic identification
- Mechanical locking
- Modular master-key-system compatibility
Its weaknesses lay less in the mechanical or electronic technology itself and more in: Destructive attacks against the door or fitting, Early unencrypted transponder technologies, And the ageing of electrical components. The basic principle continues in almost all modern access-control systems and forms the basis of many market-leading electronic cylinders.
Ludger Voss and Herbert Meyerle (1997)
Designation: SimonsVoss System 3060 electronic locking cylinder
Inventors: Ludger Voss and Herbert Meyerle developed the SimonsVoss System 3060 in 1997, one of the first fully digital, battery-powered locking systems in the form of a profile cylinder. The system was particularly innovative because the lock: Operated entirely without cables, Integrated the battery power supply into the cylinder knob, Used an RFID credential or transponder as the identification medium, Released an electromechanical coupling after successful authorisation, Could be integrated into digital access-control systems. System 3060 was therefore one of the first locking systems that could be managed both offline and online without cables, a motorised cylinder or an external power supply. Its most important features: Digital management of access permissions Immediate blocking of lost keys Complete event logging, depending on the model A very compact format Modular expansion for large master-key systems The system was adopted very quickly as a standard solution in commercial and public-sector environments.
Current locks of this type
SimonsVoss System 3060 remains one of the world’s most successful digital locking systems. Current or modernised successors include:
- SimonsVoss 3060 in various generations
- SimonsVoss AX system
- Digital SmartHandles
- Integrated online and wireless gateways
- “LDB / WaveNet / SmartIntego” access software
The operating principle, a wireless, battery-powered electronic cylinder, is now an established global standard based on the 3060 architecture.
Lockpicking
• Exploiting manufacturing tolerances
System 3060 also exhibits normal production variations: Slight variations in the range of the RFID antenna, Tolerances in the position of the coupling mechanism, Differences in the spring and magnetic mechanisms inside the knob, Variations in the recognition sensitivity of older transponders. These tolerances primarily result in recognition errors, for example when a key is not recognised, rather than security-relevant openings.
• Mechanical feedback Because the cylinder remains mechanically blocked without electronic authorisation, almost no picking feedback is present: No setting points, No plug movement, No opening signal generated by torsional pressure. The mechanism operates only after electronic authorisation, making conventional manipulation largely irrelevant.
• Wear during use Wear primarily affects: Battery contacts and electronics, The electromagnetic coupling, The knob-control mechanism, The transponder system in older versions. Wear increases the likelihood of malfunctions rather than creating additional opportunities for manipulation.
Risk/security
Highest risk: Destructive attacks: Forcing the security fitting or door frame, Mechanical force against the knob, Angle grinders, chisels and impact tools, Breaking out or completely pulling the cylinder.
Medium risk: Targeted, partially destructive attacks: Drilling or destroying the electronics inside the knob, Milling the cylinder where no security fitting is installed, Physically accessing the coupling unit after destroying the fitting, Interrupting the power supply by damaging the knob.
Low risk: Fine manipulation / electronic attacks: Copying old generations of unencrypted transponders, theoretically possible but rarely practical, Replay attacks against very early models, Interference signals intended to affect the reader, usually without success, Conventional picking methods are largely irrelevant.
Findings
SimonsVoss System 3060 was one of the most important developments in modern access control in 1997. Voss and Meyerle created a locking system that was:
- Completely wireless
- Battery-powered
- Digitally manageable
- Highly resistant to manipulation
- Mechanically more reliable than many earlier systems
Its weaknesses lie not in the technology itself, but in:
- Destructive attacks
- Insufficient protection of the door or fitting
- Ageing electronic components
System 3060 remains a milestone and forms the technical basis of both modern digital cylinder systems and smart-building architectures around the world.
Kwikset Titan (1998)
Designation: Remote keyless entry system for residential buildings
Manufacturer: Kwikset
In 1998, Kwikset introduced a remote-controlled deadbolt and matching handleset under its Titan product line. In its company history, Kwikset describes this development as a “remote keyless entry deadbolt and handleset”. This made Kwikset one of the early manufacturers to offer keyless, electronically operated access technology specifically for residential buildings.
Kwikset’s publicly available company history does not name an individual inventor. Alberto Loreti must not be identified as the inventor of this system. The previously cited US Patent 6,119,495 describes a mechanically programmable locking cylinder with a master-key function and is unrelated to the remote-entry system introduced by Kwikset in 1998.
The system combined electronic or wireless operation with a mechanical door lock. According to Kwikset, the company expanded the Titan product family in 2000 to include a wireless keypad and a remotely operated lighting unit.
Current systems from this manufacturer
Kwikset subsequently developed several keyless and connected product lines from its early electronic products:
- Powerbolt
- SmartCode
- Kevo
- Halo
- Home Connect
Classification
The 1998 Titan system was an early step towards electronically operated residential door locks. The development is documented in Kwikset’s company history. However, this source does not identify the individual within the company who was responsible for the invention.
Findings
Kwikset demonstrably introduced a remote keyless entry system in 1998. The previous association with Alberto Loreti and US Patent 6,119,495 is factually incorrect and should be removed entirely.
Winkhaus blueChip (from 1998)
Designation: blueChip electronic locking system
Manufacturer: Aug. Winkhaus GmbH & Co. KG
Winkhaus introduced blueChip in the late 1990s. On its current product pages, the company names 1998 as the beginning of blueChip technology. The historical Winkhaus product overview, however, lists its market introduction under 1999. In view of these differing statements, the wording “from 1998” is more accurate than specifying a single definitive year.
blueChip combined contactlessly readable electronic keys with compact electronic cylinders. Authorisation was checked inside the cylinder. The electromechanical coupling was released and the locking process enabled only after an authorised key had been recognised.
The system operated without permanent wiring to each individual door. Access permissions could be managed and lost keys blocked without mechanically replacing the entire master-key system. This made blueChip particularly suitable for companies, public authorities and larger building complexes with frequently changing access permissions.
Inventor
The publicly available Winkhaus sources do not currently provide enough evidence to identify a single individual as the inventor of blueChip. Ludger Henrichmann is named as the inventor in Patent DE 198 23 699 A1. However, this patent concerns a particular locking-cylinder key, described as a mixed-code carrier, rather than the blueChip system as a whole. It therefore does not provide sufficient evidence for identifying Henrichmann as the inventor of the entire blueChip system.
Current systems from this manufacturer
Winkhaus subsequently continued the principle of electronically managed access permissions in other systems:
- blueSmart
- blueCompact
- Electronic profile cylinders
- Electronic door fittings
- Connected access solutions
Classification
blueChip was among the early electronic locking systems that could be installed in existing doors using the dimensions of conventional profile cylinders. Its combination of a contactlessly readable key, electronic authorisation and an electromechanical coupling made the system particularly suitable for larger master-key installations.
Findings
The introduction of blueChip by Winkhaus in the late 1990s is documented. However, a specific individual should only be named as its inventor if an unequivocal product or patent source can be found. The previously cited Patent DE 198 23 699 A1 is not sufficient to support this attribution.