When you want to revoke a key, you re-issue a new set with a higher revision number. When the guest checks out, you issue the next revision number to the next guest, effectively disabling the previous set.
You do all this as a fallback when the network fails. This way, you can still disable keys in real-time when people checkout of their room.
Assuming it does use asymmetric keys to prevent someone from creating counterfeit access cards, there would still be a window (if the network is unavailable) where the old key would continue to work until a new key is scanned the first time on the door lock?
There are definitely multiple solutions that don't depend on a server to authenticate every unlock.
It needs to work in a way where the key is saved to your phone so it can be accessed quickly and offline.
I know other locks use Bluetooth from an app which isn’t supported by Apple Wallet.
<Grant access to KEY_ID>
<Revoke access from KEY_ID>
And it would keep track internally so that if the central system went down it could still function with already issued keys until it is fixed.
I agree, thats why I figured if you can get away with fooling around with a lock, some wires and a laptop in the hallway, you can probably pick the backup key more discreetly.