Predefined access control for electronic locks

CN115348569BActive Publication Date: 2026-09-11APPLE INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210451570.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-04-25
Filing Date
2022-04-26
Publication Date
2026-09-11
Estimated Expiration
2042-04-26

Smart Images

  • Figure CN115348569B_ABST
    Figure CN115348569B_ABST
Patent Text Reader

Abstract

The present disclosure relates to scheduled access control for electronic locks. Methods and apparatuses are described herein that support scheduled access control for electronic locks. An initiating central wireless device obtains a temporary identity resolution key (IRK) for resolving a temporary resolvable private address (RPA) of a peripheral wireless device. The initiating central wireless device can then securely connect to the peripheral wireless device in order to unlock an electronic lock controlled by the peripheral wireless device to gain access during a scheduled time period. The temporary IRK and the temporary RPA can be used for a limited time period and / or a predetermined number of times during the scheduled time period.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The described implementation scheme relates generally to wireless communication, including methods and apparatus for supporting predetermined access control for electronic locks. An initiating central wireless device can obtain a temporary identity resolution key (IRK) to resolve the temporary resolvable private address (RPA) of a peripheral wireless device. The initiating central wireless device can then securely connect to the peripheral wireless device to unlock the electronic lock controlled by the peripheral wireless device, thereby accessing, for example, an accessible location during a predetermined time period. Background Technology

[0002] Recent technological advancements have integrated various Radio Access Technologies (RATs) into single, multi-functional wireless devices. Dedicated, single-function wireless devices are being replaced and / or supplemented by multi-functional wireless devices capable of using various RAT communications. Furthermore, wireless communication capabilities are being integrated into a variety of systems, including those using traditional mechanical functions, such as access control for accessible locations or vehicles. Users can pair a central wireless device (e.g., a smartphone) with a peripheral wireless device (e.g., an electronic lock) to control the electronic lock's functions, such as unlocking to authorize access to the location and locking to restrict access. Paired central wireless devices and electronic locks can allow automatic unlocking and / or locking based on the proximity of the paired central wireless device to the electronic lock. Third-party services (such as delivery, cleaning, maintenance, or care services) may be unable to access the location without knowing the private key used to resolve the private address of the electronic lock, where the private address changes over time to provide privacy. Summary of the Invention

[0003] The described implementation scheme relates generally to wireless communication, including methods and apparatus for supporting predetermined access control for electronic locks. An initiating central wireless device can obtain a temporary identity resolution key (IRK) to resolve a temporary resolvable private address (RPA) of a peripheral wireless device, the temporary RPA being based on the temporary IRK. The initiating central wireless device can then securely connect to the peripheral wireless device to unlock an electronic lock controlled by the peripheral wireless device, thereby accessing, for example, an accessible location during a predetermined time period. In this specification, the electronic lock can be any form of lock or access control (including electric, electronic, electromechanical, software-controlled, alarm-based, etc.) used to limit or otherwise restrict / control access to resources (e.g., locations, areas, equipment, goods, etc.).

[0004] This document describes methods, apparatus, and devices for arranging access control for an access control mechanism (e.g., an electronic lock) embedded in a peripheral wireless device to allow a central wireless device to be authorized for access control by the peripheral wireless device. The access control mechanism can be installed in an access port, such as a door to an accessible location (e.g., a room, home, garage, storage room, etc.). During and / or after the installation of the access control mechanism, a user can pair their central wireless device with the peripheral wireless device, for example, based on a Bluetooth Low Energy (BLE) pairing process, to allow enabling (e.g., locking the lock) and disabling (e.g., unlocking the lock) the access control mechanism. The BLE pairing process may include establishing a static shared key (e.g., an Identity Resolution Key (IRK)) and exchanging authentication keys between the central wireless device and the peripheral wireless device to allow proximity-based automatic control of the access control mechanism. Unlike a static IRK, the peripheral wireless device obtains a temporary IRK, which can be used by one or more designated third parties for a specified predetermined time period. The temporary IRK may be generated by the peripheral wireless device or provided to the peripheral wireless device by an external entity. A temporary IRK can be provided to the central wireless device for use by a service representative seeking access to a predetermined service, such as an accessible location, during a predetermined time period. The temporary IRK may be valid during the predetermined time period and may be invalid before and / or after the predetermined time period. The peripheral wireless device broadcasts an announcement packet including a Temporary Resolvable Private Address (RPA) based on the temporary IRK for the predetermined time period. The service representative's central wireless device can resolve the temporary RPA based on knowledge of the temporary IRK. The service representative's central wireless device can then establish a secure BLE connection with the peripheral wireless device. In some implementations, the central and peripheral wireless devices may perform secure ranging settings to allow secure proximity detection between the service representative's central wireless device and the peripheral wireless device. The peripheral wireless device may authorize access, for example, by responding to a request from the service representative's central wireless device after a successful establishment of a secure BLE connection and / or by disabling access control mechanisms on the access port based on determining the proximity of the service representative's central wireless device to the peripheral wireless device after establishing a secure BLE connection. In some implementations, the ephemeral IRK and associated ephemeral RPA are only valid for a limited time period, e.g., during a predetermined time period but not before or after the predetermined time period. In some implementations, the ephemeral IRK and associated ephemeral RPA are only valid for a limited number of secure BLE connections established during the predetermined time period. In some implementations, the ephemeral IRK and associated ephemeral RPA are only valid for disabling a limited number of access control mechanisms during the predetermined time period.In some implementations, peripheral wireless devices generate temporary IRKs and securely provide them to the central wireless device of the service representative, for example, via a secure Internet Protocol (IP) connection to a network-based server associated with the central wireless device of the service representative. In some implementations, a network-based server associated with the central wireless device of the service representative generates temporary IRKs and provides them to both the central wireless device and the peripheral wireless devices. In some implementations, temporary IRKs are provided to multiple central wireless devices used by different service representatives, for example, a central wireless device associated with a public service seeking access during a predetermined time period, or a central wireless device associated with different services seeking access during a predetermined time period (or in non-overlapping or partially overlapping predetermined time periods). In some implementations, different temporary IRKs are provided to different central wireless devices used by the same service or by different services, and the peripheral wireless devices broadcast different announcement packets including temporary RPAs based on the respective temporary IRKs for the corresponding predetermined time period associated with each of the different temporary IRKs.

[0005] Other aspects and advantages of this disclosure will become apparent from the following detailed description taken in conjunction with the accompanying drawings, which illustrate by way of example the principles of the described embodiments.

[0006] The content of this invention is provided merely to outline some exemplary embodiments in order to provide a basic understanding of some aspects of the subject matter described herein. Therefore, it should be understood that the above features are merely illustrative and should not be construed as narrowing the scope of the subject matter described herein in any way. Other features, aspects, and advantages of the subject matter described herein will become apparent from the following detailed description, the accompanying drawings, and the claims. Attached Figure Description

[0007] This disclosure will be more readily understood from the following detailed description taken in conjunction with the accompanying drawings, wherein similar reference numerals denote similar structural elements.

[0008] Figure 1 An exemplary central wireless device, which can be configured to communicate using a variety of radio access technologies according to some implementations, is shown.

[0009] Figure 2 An exemplary wireless personal area network (WPAN) system according to some implementations is shown, which includes a central wireless device and peripheral wireless devices housed in an access port in an accessible location.

[0010] Figure 3 An example of a Bluetooth Low Energy (BLE) pairing process according to some implementation schemes is shown.

[0011] Figure 4 An exemplary sequence of messages is shown, according to some implementations, for establishing a secure BLE connection between a central wireless device and a peripheral wireless device to allow access to the vehicle using the owner's static identity resolution key (IRK).

[0012] Figure 5A , Figure 5B and Figure 5C An exemplary sequence of messages for establishing a secure BLE connection between a central wireless device and a peripheral wireless device for temporary IRK-authorized access, according to some implementation schemes, is shown.

[0013] Figure 6 An exemplary method for obtaining access using a temporary IRK, performed by a central wireless device according to some implementation schemes, is shown.

[0014] Figure 7 Exemplary apparatus for implementing the embodiments disclosed herein is shown according to some embodiments. Detailed Implementation

[0015] This section describes representative applications of the methods and apparatus according to this application. These examples are provided only to add context and aid in understanding the described embodiments. Therefore, it will be apparent to those skilled in the art that the described embodiments can be practiced without some or all of these specific details. In other instances, well-known processing steps have not been described in detail to avoid unnecessarily obscuring the embodiments. Other applications are possible, such that the following examples should not be considered limiting.

[0016] In the following detailed description, reference is made to the accompanying drawings, which form part of this specification, and specific embodiments according to the described embodiments are illustrated by way of example. While these embodiments are described in sufficient detail to enable those skilled in the art to practice them, it should be understood that these examples are not limiting; other embodiments can be used, and modifications can be made without departing from the spirit and scope of the described embodiments.

[0017] The described implementation scheme relates generally to wireless communication, including methods and apparatus for supporting predetermined access control for access mechanisms such as electronic locks. An initiating central wireless device can obtain a temporary identity resolution key (IRK) to resolve the temporary resolvable private address (RPA) of a peripheral wireless device. The initiating central wireless device can then securely connect to the peripheral wireless device to unlock the electronic lock controlled by the peripheral wireless device, thereby accessing, for example, an accessible location during a predetermined time period.

[0018] This document describes methods, apparatus, and devices for arranging access control for an access control mechanism (e.g., an electronic lock) embedded in a peripheral wireless device to allow a central wireless device to be authorized for access control by the peripheral wireless device. The access control mechanism can be installed in an access port, such as a door to an accessible location (e.g., a room, home, garage, storage room, etc.). During and / or after the installation of the access control mechanism, including the embedded peripheral wireless device, a user can pair their central wireless device with the peripheral wireless device, for example, based on a Bluetooth Low Energy (BLE) pairing process. After completing the BLE pairing process, the user's central wireless device can enable (e.g., by locking the lock) and disable (e.g., by unlocking the lock) the access control mechanism. The BLE pairing process may include establishing a static key, such as an Identity Resolution Key (IRK), shared between the user's central wireless device and the peripheral wireless device of the access control mechanism. The BLE pairing process may also include the exchange of authentication keys between the user's central wireless device and the peripheral wireless device to allow proximity-based automatic control (e.g., locking and unlocking) of the access control mechanism.

[0019] Users may also seek to share access managed by the access control mechanism of the peripheral wireless device with one or more third parties (e.g., with a service representative of a scheduled service that attempts to access it during a predetermined time period). Users will not share a static IRK with the scheduled service to maintain control over access based on the static IRK. Instead, users obtain and use a temporary IRK used by one or more third parties designated by the user during the predetermined time period. The peripheral wireless device obtains a temporary IRK by generating it or receiving it from another device via a secure communication channel; this temporary IRK can be used during the specified predetermined time period. The temporary IRK can be provided to the central wireless device of the service representative seeking access to, for example, an accessible location of the scheduled service during the predetermined time period. In some embodiments, the peripheral wireless device generates the temporary IRK and securely provides it to the central wireless device of the service representative, for example, via a secure Internet Protocol (IP) connection to a network-based server associated with the central wireless device of the service representative. In some embodiments, a network-based server associated with the central wireless device of the service representative generates the temporary IRK and provides it to both the central wireless device and the peripheral wireless device of the service representative. In some implementations, a third-party device, such as a user's central wireless device, generates a temporary IRK and provides it to the service representative's central and peripheral wireless devices. In various implementations, the temporary IRK can be generated and / or provided before and / or during a predetermined time period. In some implementations, the predetermined time period can be adjusted. The temporary IRK may be valid during the predetermined time period.

[0020] Peripheral wireless devices may broadcast one or more advertisement packets including a Temporarily Resolvable Private Address (RPA) based on a temporary IRK for a predetermined time period. Peripheral wireless devices may also broadcast one or more advertisement packets including a separate RPA based on a static IRK for a predetermined time period. The central wireless device of the service representative cannot resolve a separate RPA based on a static IRK because the representative's central wireless device lacks knowledge of the static IRK. The central wireless device of the service representative can resolve the temporary RPA based on knowledge of the temporary IRK. The central wireless device of the service representative can then establish a secure BLE connection with the peripheral wireless device based on the resolution of the temporary RPA. In some implementations, the central wireless device and the peripheral wireless device may perform secure ranging settings to allow secure proximity detection between the central wireless device of the service representative and the peripheral wireless device. The peripheral wireless device may authorize access, for example, by responding to a request from the central wireless device of the service representative after a successful establishment of a secure BLE connection and / or by disabling access control mechanisms on the access port after determining the proximity of the central wireless device of the service representative to the peripheral wireless device after establishing a secure BLE connection.

[0021] In some implementations, the temporary IRK and associated temporary RPA are valid only for a limited time period, e.g., during a predetermined time period but not before or after the predetermined time period. In some implementations, the temporary IRK and associated temporary RPA are valid only for a limited number of secure BLE connections during the predetermined time period. In some implementations, the temporary IRK and associated temporary RPA are valid only for disabling a limited number of access control mechanisms during the predetermined time period. In some implementations, the temporary IRK becomes invalid, and peripheral wireless devices are authorized to access it. In some implementations, before and / or during the predetermined time period, the central wireless device representing the service obtains an updated temporary IRK and replaces the temporary key with the updated temporary IRK before parsing the temporary RPA broadcast by the peripheral wireless device.

[0022] In some implementations, temporary IRKs are provided to multiple central wireless devices that can be used by different service representatives. These temporary IRKs may be associated with a public service seeking access during a predetermined time period, or with different services each seeking access during one or more predetermined time periods. In some implementations, the same temporary IRK is provided to multiple central wireless devices used by different service representatives during different predetermined time periods, which may be time-non-overlapping or overlapping. During the respective predetermined time periods, peripheral wireless devices broadcast temporary RPAs based on the temporary IRKs associated with their respective predetermined time periods. Peripheral wireless devices may broadcast announcement packets that repeatedly cycle through multiple temporary RPAs associated with multiple temporary IRKs to allow the service representative's central wireless device to receive announcement packets including temporary RPAs associated with temporary IRKs previously provided to the service representative's central wireless device. In some implementations, different temporary IRKs are provided to different central wireless devices used by the same service or by different services, and peripheral wireless devices broadcast announcement packets including temporary RPAs based on the temporary IRKs associated with the respective predetermined time periods of each of the different temporary IRKs. In some implementations, each of the different temporary IRKs is valid for the same predetermined time period, while in other implementations, each of the different temporary IRKs is valid for different, possibly overlapping, predetermined time periods. In some implementations, the use of the same or different temporary IRKs may depend on the service for which access is pre-assigned. In some implementations, the use of the same or different temporary IRKs depends on the battery level of the access control mechanism. In some implementations, the peripheral wireless device broadcasts fewer different temporary RPAs based on different temporary IRKs (potentially including a single temporary RPA based on a single temporary IRK) for lower battery levels (e.g., below a predetermined power threshold level) during one or more predetermined time periods. For example, when the peripheral wireless device's battery level is below a predetermined power threshold level, the peripheral wireless device may offer a single temporary IRK to one or more services and broadcast an advertisement packet including a single temporary RPA based on the single temporary IRK during the predetermined time period for each of the one or more services. This allows for the broadcasting of fewer different advertisement packets during the predetermined time period, which can conserve the peripheral wireless device's battery power. In some implementations, peripheral wireless devices are configured to allow the broadcasting of a larger number of different temporary RPAs based on different temporary IRKs for higher battery levels (e.g., above a predetermined power threshold level) during one or more predetermined time periods. This allows for greater privacy and security because each service is associated with a different temporary IRK with limited use during the predetermined time period.

[0023] The following is for reference. Figures 1 to 7 These and other embodiments will be discussed here; however, those skilled in the art will readily understand that the detailed descriptions given herein with respect to the accompanying drawings are for illustrative purposes only and should not be construed as limiting.

[0024] Figure 1 Illustration 100 shows an exemplary group of overlapping wireless networks for wireless device 102. Wireless device 102 can include a combination of hardware and software to provide wireless connectivity individually, separately, or in combination, such as via the group of overlapping networks, using one or more different wireless networks. Wireless device 102 can represent a device with wireless communication capabilities, such as a smartphone (e.g., ), tablet devices (e.g., Wearable computing devices (e.g., Apple Watch) TM ), portable media players (e.g., ), laptop computers (e.g. Desktop computers (e.g.) ), digital media servers / extenders (e.g., Apple) ) and other possible equipment.

[0025] Wireless device 102 may include a combination of hardware, software, and / or firmware to provide communication using a Wireless Personal Area Network (WPAN) 104, which provides power-efficient connectivity while operating over a limited range. WPAN 104 connectivity typically enables wireless device 102 to connect to peripheral and associated wireless devices, such as headphones, handsets, supplemental display devices, and supplemental input / output devices. A typical WPAN 104 can operate according to communication protocols specified by the Bluetooth Special Interest Group (SIG) standards organization (e.g., classic). It operates using Bluetooth Low Energy (BLE) and / or communication protocols specified by Apple Inc., such as Apple Wireless Direct Link (AWDL).

[0026] Wireless device 102 may also include a combination of hardware, software, and / or firmware to provide communication using WLAN 106, which offers higher data rates and a wider operating range compared to WPAN 104. Wireless device 102 may include separate and / or shared hardware, software, and / or firmware components for WPAN 104 and WLAN 106. Both WPAN 104 and WLAN 106 can operate as a "local area" wireless network. A representative WLAN 106 can operate according to communication protocols specified by the Institute of Electrical and Electronics Engineers (IEEE) standards organization (such as the IEEE 802.11 wireless standard family, which may also be referred to in some versions as...). Use it to operate.

[0027] Wireless device 102 may also include additional hardware, software, and / or firmware to provide the capabilities of a wireless wide area network (WWAN) 108, such as interconnection with one or more cellular wireless networks. Wireless device 102 is able to provide a wide range of services using one or more connections through its wireless networking capabilities.

[0028] Figure 2 Figure 200 illustrates an exemplary WPAN 104 system including a central wireless device 102, which can communicate with peripheral wireless devices 202 housed in an access port 204 at an accessible location 206. The central wireless device 102 may also be referred to as a wireless device, a first wireless device, a requesting wireless device, an initiating wireless device, etc. The peripheral wireless device 202 may also be referred to as a wireless device, a second wireless device, another wireless device, a responding wireless device, etc. The central wireless device 102 and the peripheral wireless device 202 can establish a secure connection via the WPAN 104, for example, after a successful Bluetooth Low Energy (BLE) pairing process. The peripheral wireless device 202 can control an access control mechanism (e.g., an electronic lock) for the access port 204 (e.g., a door), which allows access to the accessible location 206 (e.g., a room, home, garage, storage room, etc.). Access is permitted when the central wireless device 102 is within proximity of the peripheral wireless device 202 and can successfully resolve the resolvable private address (RPA) included in the announcement packet broadcast by the peripheral wireless device 202. A user of the peripheral wireless device 202, controlling access to the accessible location 206, can pair their own central wireless device 102 with the peripheral wireless device 202 and establish a shared key, such as a static identity resolution key (IRK), and an exchanged encryption key for authentication and / or secure connection establishment. The peripheral wireless device 202 can broadcast the RPA based on the static IRK, and the central wireless device 102 can resolve the RPA using the static IRK shared by the peripheral wireless device 202. The user's central wireless device 102 can identify the peripheral wireless device 202 without an additional BLE pairing process. BLE supports a privacy feature that reduces device identity tracking over a period of time by frequently changing the RPA. RPA can be based on a static IRK known to the central wireless device 102 according to the previous BLE pairing, and the peripheral wireless device 202 can authorize access to the accessible location 206 via the access entry port 204 based on the proximity of the user's central wireless device 102 and the peripheral wireless device 202.

[0029] For different central wireless devices 102 not owned by users associated with peripheral wireless device 202, such as central wireless device 102 for a service representative using a subscription service, users can avoid sharing a static IRK to maintain its confidentiality. Instead, as discussed further herein, peripheral wireless device 202 can share a temporary (temporary) IRK with the service representative's central wireless device 102 via secure out-of-band communication (i.e., via communication different from that via WPAN 104). For example, peripheral wireless device 202 can provide the temporary IRK to a backend server 208 associated with the subscription service via secure Internet Protocol (IP) communication (not shown). The service representative's central wireless device 102 can obtain the shared temporary IRK from the backend server 208, for example, via WWAN 108, via WLAN 106, or via another secure communication link (not shown).

[0030] Figure 3 Figure 300 illustrates the stages of an exemplary Bluetooth Low Energy (BLE) pairing process between two wireless devices (e.g., between a central wireless device 102 and a peripheral wireless device 202). During the discovery stage 302 of the BLE pairing process, the central wireless device 102 and the peripheral wireless device 202 discover each other's presence based on the transmission and reception of announcement packets broadcast by the respective wireless devices. During the capability exchange stage 304, the central wireless device 102 and the peripheral wireless device 202 exchange capability information about their respective device capabilities and preferences for communication. During the key generation and secure connection establishment stage 306, the central wireless device 102 and the peripheral wireless device 202 generate encryption keys for establishing a secure connection and for authentication purposes. During the optional key distribution and bonding stage 308, the central wireless device 102 and the peripheral wireless device 202 may exchange encryption keys for establishing a long-term automatic connection.

[0031] Figure 4Figure 400 illustrates an exemplary secure Bluetooth Low Energy (BLE) connection process that uses the vehicle owner's static IRK to allow a partner of the vehicle owner access to vehicle 406 for a predetermined time period. Prior to this predetermined time period, at 408, the vehicle owner's central wireless device 402-1 may share the static IRK and other digital key payload information with the partner's central wireless device 402-2, for example, to allow the partner access to the vehicle during the predetermined time period. At 408, the vehicle owner's central wireless device 402-1 may share the static IRK and other digital key payload information with the partner's central wireless device 402-2 via a secure connection to one or more network-based backend servers. During a predetermined time period, at 410, the peripheral radio device 404 of vehicle 406 may transmit a Bluetooth Low Energy (BLE) announcement packet. This BLE announcement packet includes a resolvable private address (RPA) of the peripheral radio device 404 of vehicle 406, based on a static IRK of the vehicle owner previously shared with the partner's central radio device 402-2. The static IRK can be used by the partner's central radio device 402-2 to resolve the resolvable private address (RPA) included in one or more announcement packets broadcast by the peripheral radio device 404 of vehicle 406 during the BLE discovery phase 302. Both the vehicle owner's central radio device 402-1 and the partner's central radio device 402-2, who are aware of the static IRK, can resolve the RPA in the Bluetooth BLE announcement packet, for example, at 412 for the vehicle owner's central radio device 402-1, or at 414 for the partner's central radio device 402-2. The Bluetooth address of the peripheral wireless device 404 derived from the RPA can be used by the partner's central wireless device 402-2 to establish a Bluetooth connection with the peripheral wireless device 404 at 416 during a predetermined time period. The partner's central wireless device 402-2 can then perform a secure ranging setup process at 418 to allow proximity detection, such as distance and angle of arrival, between the partner's central wireless device 402-2 and the peripheral wireless device 404. When the peripheral wireless device 404 is included in the digital key locking mechanism of the vehicle 406, after the secure ranging setup at 418 and the establishment of the BLE secure connection at 416, the partner's central wireless device 402-2 can communicate with the peripheral wireless device 404 to disable the locks on the vehicle 406 to provide access to the vehicle 406. However... Figure 4 The process illustrated is susceptible to privacy and security issues, such as being performed by malicious third-party scanning devices to obtain and / or use knowledge of the vehicle owner's static IRK. Therefore, providing access using a static IRK for a predetermined period of time is not preferred; instead, a temporary IRK will be used as discussed further herein.

[0032] Figure 5A Figure 500 illustrates an exemplary sequence of messages for establishing a secure BLE connection between a central wireless device 502 of a service representative and a peripheral wireless device 202 to authorize access to an accessible location 206 for a predetermined time period based on the use of a temporary IRK. The peripheral device 202 may include an access port 204, such as the door to the accessible location 206 (e.g., a room, home, garage, storage room, etc.). The peripheral wireless device 202 may pre-define access control for an access control mechanism (e.g., an electronic lock) embedded in the peripheral wireless device 202 to allow the central wireless device 502 of the service representative to be authorized access to the accessible location 206 controlled by the peripheral wireless device 202. The peripheral wireless device 202 may generate a temporary IRK at 504 before the predetermined shared time period for which access can be authorized. At 506, the peripheral wireless device 202 may share the temporary IRK with the central wireless device 502 of the service representative via a network-based backend server 208. In some implementations, peripheral wireless device 202 forwards a temporary IRK to backend server 208 via a secure Internet Protocol (IP) connection. In some implementations, peripheral wireless device 202 shares the temporary IRK with a separate device (not shown), such as the owner's central wireless device or an internet-connected device like an access point, with which peripheral wireless device 202 can communicate to enable the separate device to forward the temporary IRK to network-based backend server 208. In some implementations, network-based backend server 208 is managed by a service associated with the central wireless device 102 502 of the service representative, and users / owners of accessible location 206 (and peripheral wireless device 202) can request permission for the service representative to be authorized to access accessible location 206 during a predetermined shared time period.

[0033] During a predetermined time period, at point 508, peripheral wireless device 202 may broadcast a Bluetooth Low Energy (BLE) announcement (announcement packet) including a resolvable private address (RPA) of peripheral wireless device 202 based on a static IRK maintained by the owner of peripheral wireless device 202. At point 510, the central wireless device 502 of the service representative may be unable to resolve the RPA based on the owner's static IRK because the central wireless device 502 of the service representative is unaware of the owner's static IRK. This is related to... Figure 4 The process shown in the diagram contrasts with the central wireless device 402-2 of the partner, which is aware of the static IRK. At 512, the peripheral wireless device 202 can broadcast different BLE announcements, which include a temporary RPA of the peripheral wireless device 202 based on a temporary IRK previously provided via a secure out-of-band connection before a predetermined sharing period. Figure 5AAs shown, the peripheral wireless device 202 can broadcast different announcement messages, which include different RPAs at different times during a predetermined shared time period. At 514, the central wireless device 502 of the service representative can resolve the temporary RPA of the peripheral wireless device 202 based on previously acquired knowledge of the temporary IRK. After address resolution, at 516, the central wireless device 502 of the service representative can establish a secure BLE connection with the peripheral wireless device 202. At 518, the central wireless device of the service representative can perform a secure ranging setup procedure to allow proximity detection between the central wireless device 502 of the service representative and the peripheral wireless device 202, such as allowing distance and / or angle of arrival measurement between the central wireless device 502 of the service representative and the peripheral wireless device 202. Due to successful temporary RPA resolution and subsequent secure BLE connection establishment and secure ranging setup, the peripheral wireless device 202 can be authorized to access the accessible location 206 via access entry port 204 (e.g., automatically based on an access request from the central wireless device 502 of the service representative and / or based on proximity detection).

[0034] Figure 5A The process illustrated provides protection against privacy and security attacks from unknown, malicious third-party scanning devices because the ephemeral IRK can be restricted to a limited number of access authorizations during a predetermined time period and / or by the peripheral wireless device 202. The owner's static IRK remains confidential and is not shared with the central wireless device 502 of the service representative. The peripheral wireless device 202 can restrict BLE announcement messages, which include ephemeral RPAs based on the ephemeral IRK, to appear only during the predetermined sharing time period and not before or after it. In some embodiments, the peripheral wireless device 202 stops sending BLE announcement messages including ephemeral RPAs after the central wireless device 502 of the service representative successfully parses the ephemeral RPA. In some embodiments, the peripheral wireless device 202 stops sending BLE announcement messages including ephemeral RPAs after a secure BLE connection is successfully established with the central wireless device 502 of the service representative. In some embodiments, the peripheral wireless device 202 stops sending BLE announcement messages including ephemeral RPAs after a secure BLE connection is successfully established with the central wireless device 502 of the service representative. In some implementations, after secure ranging is established with the central wireless device 502 of the service representative, the peripheral wireless device 202 stops sending BLE advertisement messages including temporary RPA. In some implementations, after authorized access to the central wireless device 502 of the service representative via access ingress port 204, the peripheral wireless device 202 stops sending BLE advertisement messages including temporary RPA.

[0035] In some implementations, a temporary IRK is provided to a central wireless device representing multiple different services used by different services. For each of these different services, the owner of the accessible location 206 seeks authorized access, such as to each of the different services, where each of the different services has a separate, predetermined shared time period that may differ, be the same, or overlap in time. In some implementations, different temporary IRKs are provided to different services for authorized access. In some implementations, the peripheral wireless device 202 broadcasts different BLE announcement messages using different temporary IRKs to authorize access to the central wireless device 502 representing different services; this may occur during common or overlapping predetermined time periods or during different predetermined time periods. In some implementations, the peripheral wireless device 202 may use a common temporary IRK for different services based on configuration or preference to conserve the battery power level of the peripheral wireless device 202, for example, when the peripheral wireless device 202 is operating below a predetermined threshold battery power level. Broadcasting fewer announcement packets using different RPAs based on different IRKs (static and temporary) can conserve the battery power of the peripheral wireless device 202. In some implementations, peripheral wireless device 202 may allow the use of different temporary IRKs for different services based on the battery power level of peripheral wireless device 202, for example, when peripheral wireless device 202 operates at a battery power level above a predetermined threshold. Broadcasting a larger number of advertisement packets using different RPAs based on different IRKs (static and temporary) may require more power from peripheral wireless device 202, but it can also improve security and privacy because each service can be provided with a different, identifiable, and limited-use temporary IRK.

[0036] In some implementations, the peripheral wireless device 202 limits BLE connection establishment and / or access authorization to a predetermined number of uses for a specific temporary IRK, such as a single use only during a predetermined time period. In some implementations, the peripheral wireless device 202 allows multiple different BLE connection establishment and / or access authorizations based on a specific temporary IRK during a predetermined shared time period, for example, allowing the central wireless device 502 of the service representative to obtain more than one access during the predetermined shared time period. In some implementations, the temporary IRK is provided to the central wireless device of the service representative during the predetermined time period, rather than before the predetermined time period. In some implementations, the peripheral wireless device 202 updates the temporary IRK, for example, by providing an updated temporary IRK to the central wireless device 502 of the service representative before and / or during the predetermined time period, in which case the previously provided temporary IRK will no longer be used after the updated temporary IRK is sent. In some implementations, the peripheral wireless device 202 provides the temporary IRK to the backend server 208 before the predetermined shared time period, but the backend server 208 only provides the temporary IRK to the central wireless device 502 of the service representative during the predetermined time period.

[0037] Figure 5B Figure 520 illustrates an exemplary sequence of messages for establishing a secure BLE connection between a central wireless device 502 of a service representative and a peripheral wireless device 202 to authorize access to, for example, an accessible location 206 for a predetermined time period based on the use of a temporary IRK. At 522, prior to the predetermined shared time period for which authorized access can be granted, a backend server associated with a service seeking authorized access may generate a temporary IRK. At 524, backend server 208 may share the temporary IRK with peripheral wireless device 202, for example, via a secure IP connection. At 526, backend server 208 may further share temporary IRK 522 with the central wireless device 502 of the service representative for use during the predetermined time period. In some embodiments, backend server 208 provides the temporary IRK to peripheral wireless device 202 and / or central wireless device 502 of the service representative during the predetermined time period, rather than prior to the predetermined time period. During the predetermined time period, the peripheral wireless device broadcasts one or more BLE announcement messages including a temporary RPA for the peripheral wireless device based on the temporary IRK provided by backend server 208. and Figure 5A Similarly, the central wireless device 502 of the service representative can resolve the temporary RPA, establish a BLE connection, and perform secure ranging operations to allow access, for example, to accessible location 206 during a predetermined shared time period. Figure 5A The actions involved and the optional variations described also apply to Figure 5B .

[0038] Figure 5C Figure 530 illustrates another exemplary sequence of messages for establishing a secure BLE connection between a central wireless device 502 of a service representative and a peripheral wireless device 202 to authorize access to, for example, an accessible location 206 for a predetermined time period based on the use of a temporary IRK. At 534, prior to the predetermined shared time period for which access can be authorized, an intermediate device 532 associated with the peripheral wireless device 202 may generate a temporary IRK. In some embodiments, the intermediate device 532 may be another wireless device 102 maintained by the owner of the peripheral wireless device 202, such as the owner's central wireless device 102. At 536, the intermediate device 532 may share the temporary IRK with the central wireless device 502 of the service representative, for example, via a secure IP connection through a backend server 208. In some embodiments, the intermediate device 532 provides the temporary IRK to the backend server 208 at a first time, for example, prior to the predetermined shared time period, and the backend server 208 provides the temporary IRK to the central wireless device of the service representative, for example, before or during the predetermined time period. At 538, intermediate device 532 shares a temporary IRK 522 with peripheral wireless device 202 for use during a predetermined time period. In some embodiments, intermediate device 532 provides the temporary IRK to the peripheral wireless device 202 and / or the central wireless device 502 of the service representative during the predetermined time period, rather than before the predetermined time period. During the predetermined time period, the peripheral wireless device broadcasts one or more BLE advertisement messages, which include a temporary RPA for the peripheral wireless device based on the temporary IRK provided by backend server 208. Figure 5A and Figure 5B Similarly, the central wireless device 502 of the service representative can resolve the temporary RPA, establish a secure BLE connection, and perform secure ranging operations to allow access, for example, to accessible location 206 during a predetermined sharing period. Figure 5A The actions involved and the optional variations described also apply to Figure 5C .

[0039] Figure 6A flowchart 600 illustrates an exemplary method performed by a central wireless device 102 to obtain, for example, access to an accessible location 206 using a temporary IRK. At 602, the central wireless device 102 obtains a temporary IRK from an entity other than the central wireless device 102. At 604, the central wireless device 102 receives a Bluetooth Low Energy (BLE) advertisement packet including a Temporarily Resolvable Private Address (RPA) from a peripheral wireless device 202, which includes an access control mechanism, during a predetermined time period. At 606, the central wireless device 102 resolves the temporary RPA, at least based on the temporary IRK. At 608, the central wireless device 102 establishes a secure connection with the peripheral wireless device 202, at least based on the temporary RPA. At 610, the central wireless device 102 transmits an access request to the peripheral wireless device 202 during the predetermined time period, requesting the access control mechanism to authorize, for example, access to the accessible location 206. In some embodiments, access is authorized based on the proximity of the central wireless device 102 to the peripheral wireless device 202, requiring or not requiring the transmission and / or reception of the access request.

[0040] In some implementations, the temporary IRK is valid for a predetermined time period. In some implementations, the temporary IRK is valid for a predetermined number of access control authorizations during the predetermined time period. In some implementations, the predetermined number of access control authorizations allowed during the predetermined time period is one. In some implementations, the temporary IRK becomes invalid after a peripheral wireless device has authorized access based on the temporary IRK. In some implementations: i) the peripheral wireless device includes an electronic lock; ii) the access control mechanism is associated with the electronic lock; and iii) authorizing access includes configuring the electronic lock to an unlocked state. In some implementations, the central wireless device 102 obtains the temporary IRK before the predetermined time period. In some implementations, the central wireless device 102 obtains the temporary IRK during the predetermined time period. In some implementations, the temporary IRK is generated by the peripheral wireless device 202 and provided to the central wireless device 102 via out-of-band communication. In some implementations, the out-of-band communication includes a secure Internet Protocol (IP) connection to a network-based server associated with a predetermined service. In some implementations, the temporary IRK is generated by a network-based server, such as backend server 208, associated with a predetermined service, and the network-based server provides the temporary IRK to both the central wireless device 102 and the peripheral wireless device 202 via separate, secure out-of-band communication. In some implementations, the temporary IRK is generated by an intermediate device 532 associated with the peripheral wireless device 202, and the intermediate device 532 provides the temporary IRK to both the central wireless device 102 and the peripheral wireless device 202 via separate, secure out-of-band communication. In some implementations, the method further includes the central wireless device 102 receiving an updated temporary IRK before a predetermined time period and replacing the temporary IRK with the updated temporary IRK before parsing the temporary RPA.

[0041] In some implementations, a method performed by peripheral wireless device 202 for predetermined access controlled via an access control mechanism associated with peripheral wireless device 202 includes: i) generating a temporary identity resolution key (IRK); ii) generating a temporary resolvable private address (RPA) based on the temporary IRK; iii) transmitting a Bluetooth Low Energy (BLE) announcement packet during a predetermined time period, wherein the BLE announcement packet includes the temporary RPA; and iv) in response to detecting that the requesting wireless device 102 has successfully resolved the temporary RPA: establishing a secure connection with the requesting wireless device 102, and authorizing access during the predetermined time period in response to receiving an access request from the requesting wireless device 102.

[0042] In some implementations, a temporary IRK is valid for a predetermined time period. In some implementations, a temporary IRK is valid for a predetermined number of access control authorizations during a predetermined time period. In some implementations, the temporary IRK becomes invalid after the peripheral wireless device 202 has authorized access based on the temporary IRK. In some implementations, the peripheral wireless device 202 provides the temporary IRK to the requesting wireless device 102 via out-of-band communication. In some implementations, the out-of-band communication includes a Secure Internet Protocol (IP) connection to a network-based server associated with the predetermined service.

[0043] In some embodiments, wireless device 102 includes processing circuitry including a memory storing instructions and one or more processors. When executed by the one or more processors, the instructions cause wireless device 102 to perform actions including: i) obtaining a temporary identity resolution key (IRK) from an entity other than wireless device 102; ii) receiving a Bluetooth Low Energy (BLE) advertisement packet from a second wireless device 202 including an access control mechanism during a predetermined time period, wherein the BLE advertisement packet includes a temporary resolvable private address (RPA); iii) resolving the temporary RPA based at least on the temporary IRK; iv) establishing a secure connection with the second wireless device 202 using the temporary RPA; and v) transmitting an access request to the second wireless device 202 during the predetermined time period, requesting authorization from the access control mechanism, for example, access to an accessible location 206. In some embodiments, after a successful secure BLE connection establishment and secure ranging, access is authorized based on the proximity of wireless device 102 to the second wireless device 202.

[0044] Figure 7 A detailed view of a representative computing device 700, according to some embodiments, that can be used to implement the various methods described herein. Specifically, the detailed view shows various components that can be included in a wireless device 102. Figure 7As shown, computing device 700 may include a processor 702 representing a microprocessor or a controller for controlling the overall operation of computing device 700. Computing device 700 may also include a user input device 708 that allows a user of computing device 700 to interact with it. For example, user input device 708 can take various forms, such as buttons, keypads, dial pads, touchscreens, audio input interfaces, visual / image capture input interfaces, sensor data input sections, etc. Furthermore, computing device 700 may include a display 710 that can be controlled by processor 702 to display information to a user. Data bus 716 facilitates data transfer between at least storage device 740, processor 702, and controller 713. Controller 713 can be used to interact with and control different devices via device control bus 714. Computing device 700 may also include a network / bus interface 711 communicatively coupled to data link 712. In the case of wireless connectivity, network / bus interface 711 may include a wireless transceiver.

[0045] The computing device 700 also includes a storage device 740, which may include a single disk or multiple disks (e.g., a hard disk drive), and includes a storage management module that manages one or more partitions within the storage device 740. In some embodiments, the storage device 740 may include flash memory, semiconductor (solid-state) memory, etc. The computing device 700 may also include random access memory (RAM) 720 and read-only memory (ROM) 722. ROM 722 may store programs, utilities, or processes that will be executed in a non-volatile manner. RAM 720 may provide volatile data storage and store instructions related to the operation of the computing device 700. The computing device 700 may further include a secure element (SE) 750, which may represent a secure storage device, such as a Subscriber Identity Module (SIM) or Electronic SIM, for use by the wireless device 102 to establish a WWAN 108 connection.

[0046] Wireless terminology

[0047] According to the various embodiments described herein, the terms "wireless communication device," "wireless device," "mobile device," "mobile station," and "user equipment (UE)" are used interchangeably herein to describe one or more common consumer electronic devices capable of performing processes associated with the various embodiments of this disclosure. According to various specific embodiments, any of these consumer electronic devices may include: cellular phones or smartphones, tablet computers, laptop computers, notebook computers, personal computers, netbook computers, media player devices, e-book devices, etc. Devices, wearable computing devices, and any other type of electronic computing device with wireless communication capabilities, which may include communication via one or more wireless communication protocols, such as those used for communication on networks including: Wireless Wide Area Network (WWAN), Wireless Metropolitan Area Network (WMAN), Wireless Local Area Network (WLAN), Wireless Personal Area Network (WPAN), Near Field Communication (NFC), Cellular Wireless Network, Fourth Generation (4G) Long Term Evolution (LTE), LTE-A Advanced (LTE-A), and / or Fifth Generation (5G) or other currently or future Next Generation (NG) Advanced Cellular Wireless Networks.

[0048] In some implementations, the wireless communication devices may also operate as part of a wireless communication system, which may include a group of client devices, also referred to as stations, client wireless devices, or client wireless communication devices, interconnected to an access point (AP) as part of a WLAN, and / or interconnected with each other as part of a WPAN and / or a “self-organizing” wireless network. In some implementations, the client devices may be any wireless communication devices capable of communicating via WLAN technology (e.g., according to wireless LAN communication protocols). In some implementations, the WLAN technology may include a Wi-Fi (or more generally, WLAN) wireless communication subsystem or radio component that implements IEEE 802.11 technology, such as one or more of the following: IEEE 802.11a; IEEE 802.11b; IEEE 802.11g; IEEE 802.11-2007; IEEE 802.11n; IEEE 802.11-2012; IEEE 802.11ac; or other currently or future IEEE 802.11 technologies.

[0049] Furthermore, it should be understood that the wireless devices described herein can be configured as multimode wireless communication devices capable of communicating via different third-generation (3G) and / or second-generation (2G) RATs. In these cases, multimode wireless devices can be configured to preferentially attach to LTE networks, which offer faster data rate throughput, compared to other 3G legacy networks that offer lower data rate throughput. For example, in some implementations, multimode wireless devices can be configured to fall back to 3G legacy networks, such as Evolved High-Speed ​​Packet Access (HSPA+) networks or Code Division Multiple Access (CDMA) 2000 Evolution-Data-Only (EV-DO) networks, when LTE and LTE-A networks are unavailable.

[0050] As is widely recognized, the use of personally identifiable information should comply with privacy policies and practices that are generally accepted to meet or exceed industry or governmental requirements for protecting user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly explained to users.

[0051] Aspects, embodiments, specific implementations, or features of the described embodiments may be used individually or in any combination. Aspects of the described embodiments may be implemented by software, hardware, or a combination of hardware and software. The embodiments may also be embodied as computer-readable code on a computer-readable medium. A computer-readable medium is any data storage device capable of storing data that can subsequently be read by a computer system. Examples of computer-readable media include read-only memory, random access memory, CD-ROM, HDD, DVD, magnetic tape, and optical data storage devices. Computer-readable media may also be distributed across network-coupled computer systems, such that the computer-readable code is stored and executed in a distributed manner.

[0052] For illustrative purposes, the foregoing description uses specific names to provide a thorough understanding of the described embodiments. However, it will be apparent to those skilled in the art that specific details are not required to practice the described embodiments. Therefore, the foregoing description of specific embodiments is presented for illustrative and descriptive purposes. The foregoing description is not intended to be exhaustive or to limit the described embodiments to the precise forms disclosed. It will be apparent to those skilled in the art that many modifications and variations are possible in light of the teachings above.

Claims

1. A method for pre-booking access via an access control mechanism, the method comprising: From the central wireless equipment: A temporary identity resolution key (IRK) is obtained from an entity other than the central wireless device, and the temporary IRK can be used for a limited period of time; During a predetermined time period, Bluetooth Low Energy (BLE) announcement packets are received from a peripheral wireless device that includes the access control mechanism. The BLE announcement packets include a Temporarily Resolvable Private Address (RPA) based on the temporary IRK. Parse the temporary RPA based at least on the temporary IRK to derive the Bluetooth address of the peripheral wireless device; Establish a secure connection with the peripheral wireless device using the Bluetooth address of the peripheral wireless device derived from the temporary RPA; and During the predetermined time period, an access request is transmitted to the peripheral wireless device requesting the access control mechanism to authorize access. After the access control mechanism authorizes access based on the temporary IRK, the temporary IRK becomes invalid.

2. The method of claim 1, wherein the temporary IRK is valid only during the predetermined time period.

3. The method of claim 1, wherein the temporary IRK is valid for a predetermined number of access control authorizations during the predetermined time period.

4. The method of claim 3, wherein the predetermined number of access control authorizations allowed during the predetermined time period is one.

5. The method according to claim 1, wherein: The peripheral wireless device includes an electronic lock; The access control mechanism is associated with the electronic lock; and Authorized access includes configuring the electronic lock to be in an unlocked state.

6. The method of claim 1, wherein the central wireless device obtains the temporary IRK before the predetermined time period.

7. The method of claim 1, wherein the central wireless device acquires the temporary IRK during the predetermined time period.

8. The method according to claim 1, wherein: The temporary IRK is generated by the peripheral wireless device; and The peripheral wireless device provides the temporary IRK to the central wireless device via out-of-band communication.

9. The method of claim 8, wherein the out-of-band communication includes a secure Internet Protocol (IP) connection to a network-based server associated with a predetermined service.

10. The method of claim 1, wherein: The temporary IRK is generated by a web-based server associated with the scheduled service; and The network-based server provides the temporary IRK to the central wireless device and the peripheral wireless devices via separate and secure out-of-band communication.

11. The method according to claim 1, in: The temporary IRK is generated by an intermediate device associated with the peripheral wireless device; and The intermediate device provides the temporary IRK to the central wireless device and the peripheral wireless devices via separate and secure out-of-band communication.

12. The method according to claim 1, further comprising: The central wireless device receives an updated temporary IRK before the predetermined time period, and Replace the temporary IRK with the updated temporary IRK before parsing the temporary RPA.

13. A method for pre-booking access using an access control mechanism of a peripheral wireless device, the method comprising: From the peripheral wireless device: Generate a temporary identity resolution key (IRK), which can be used for a limited period of time; Generate a temporary resolvable private address (RPA) based at least on the temporary IRK; Transmit Bluetooth Low Energy (BLE) announcement packets during a predetermined time period, the BLE announcement packets including the temporary RPA; and In response to the request, the wireless device detects successful parsing of the temporary RPA to export the Bluetooth address of the peripheral wireless device: Establish a secure connection with the requesting wireless device using the Bluetooth address of the peripheral wireless device derived from the temporary RPA, and Access is authorized in response to receiving an access request from the requesting wireless device during the predetermined time period. Once the peripheral wireless device has authorized access based on the temporary IRK, the temporary IRK becomes invalid.

14. The method of claim 13, wherein the temporary IRK is valid during the predetermined time period.

15. The method of claim 13, wherein the temporary IRK is valid for a predetermined number of access control authorizations during the predetermined time period.

16. The method of claim 13, wherein the peripheral wireless device provides the temporary IRK to the requesting wireless device via out-of-band communication.

17. The method of claim 16, wherein the out-of-band communication includes a secure Internet Protocol (IP) connection to a network-based server associated with a predetermined service.

18. A wireless device, the wireless device comprising: Processing circuitry, comprising one or more processors and a memory storing instructions, the instructions, when executed by the one or more processors, causing the wireless device to perform actions including: Obtain a temporary identity resolution key (IRK) from an entity other than the wireless device, the temporary IRK being usable for a limited time period; During a predetermined time period, a Bluetooth Low Energy (BLE) announcement packet is received from a second wireless device including an access control mechanism, the BLE announcement packet including a Temporarily Resolvable Private Address (RPA) based on the temporary IRK. Parse the temporary RPA based at least on the temporary IRK to derive the Bluetooth address of the second wireless device; Establish a secure connection with the second wireless device using the Bluetooth address of the second wireless device derived from the temporary RPA; as well as During the predetermined time period, an access request is transmitted to the second wireless device requesting the access control mechanism to authorize access. After the access control mechanism authorizes access based on the temporary IRK, the temporary IRK becomes invalid.

Citation Information

Patent Citations

  • System and method for improving bluetooth low energy privacy

    CN103368722A