Near owner maintenance

By establishing an encrypted connection between wireless devices and accessories and using a key rotation mechanism, the wireless attachment positioning problem that cannot communicate with the WAN is solved, and efficient and low-power device tracking and positioning are achieved.

CN120302294APending Publication Date: 2025-07-11APPLE INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510656265.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2021-02-05
Filing Date
2021-08-19
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The location of wireless accessories that cannot communicate with the wide area network cannot be effectively maintained in the prior art, resulting in the inability to be located when lost or stolen.

Method used

By establishing an encrypted wireless connection between the wireless device and the accessory, using the key rotation and timeout counter mechanism, the wireless device is periodically maintained with nearby owner devices, and the connection status is managed through the status field indicator and counter of the ad packet type, avoiding repeated maintenance operations.

Benefits of technology

Effective positioning and tracking of wireless accessories is achieved, power consumption is reduced, battery exhaustion is avoided due to multiple attempts to connect to wireless devices, and positioning accuracy of the device within the owner-wide range.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120302294A_ABST
    Figure CN120302294A_ABST
Patent Text Reader

Abstract

The invention relates to near owner maintenance. The presence of a wireless device and / or accessory that cannot maintain an independent network connection may be detected by a network-connected wireless device, and the detected location of the device and / or accessory may be reported to a device location service. Because the wireless device and / or accessory does not have a separate network connection, periodic maintenance is performed on the devices by nearby owner devices with which the wireless device and / or accessory is paired or associated. Systems, methods, and associated devices are described herein for maintaining a positionable wireless device by a set of multiple owner devices for the wireless device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the patent application for invention titled "Proximity to Owner Maintenance" with the application date of August 19, 2021, application number 202180053288.7.

[0002] Cross-reference

[0003] This patent application claims the benefit of the priority of U.S. Provisional Application No. 63 / 071,988, filed on August 28, 2020, and U.S. Patent Application No. 17 / 169,036, filed on February 5, 2021, and each of the above patent applications is hereby incorporated by reference in its entirety. Technical Field

[0004] The embodiments described herein generally relate to systems and methods for locating wireless devices and accessories. More specifically, the embodiments relate to the periodic maintenance of wireless devices and accessories via a secure wireless connection. Background Art

[0005] Current security features in handheld and portable products allow the location of the product to be identified upon user request, such as in the case where the product is lost or stolen. If a wireless device includes location technology, the device can be configured to report its last known location to a server computer, which is displayed on a map presented to the user via a service. Typically, wireless devices are used with wireless accessory devices that cannot determine their own location and cannot communicate with a remote tracking service over a wide area network. These accessory devices can include, for example, wireless earbuds, earphones, headphones, and other wearable devices (e.g., smartwatches, fitness bands, optical head-mounted displays) that communicate directly with the wireless device using peer-to-peer communication. When a wireless accessory device that cannot determine its location and cannot communicate with a remote tracking service is lost or stolen, those devices cannot be tracked via the service. However, the presence of those devices can be detected based on the wireless signals broadcast by those devices. Summary of the Invention

[0006] The embodiments described herein provide a technique for arbitrating the maintenance of a wireless accessory among multiple owner devices. The presence of a wireless device and / or accessory that cannot maintain an independent network connection can be detected by a network-connected wireless device, and the location of the detected device and / or accessory can be reported to a device location service. Since the wireless device and / or accessory does not have an independent network connection, periodic maintenance is performed on these devices by nearby owner devices paired with or associated with the wireless device and / or accessory. In the absence of an arbitration mechanism, various owner devices may continuously attempt to perform maintenance operations on nearby wireless accessories. Systems, methods, and associated devices for maintaining a wireless device by a plurality of owner devices for a locatable wireless device are described herein.

[0007] One embodiment provides a method performed on a wireless device. The method includes establishing a first encrypted wireless connection with a first electronic device, wherein the first encrypted wireless connection is established using cryptographic material associated with a first key rotation period. The method additionally includes setting an indicator in a status field of a first wireless advertisement packet type. The first wireless advertisement packet type is associated with a first broadcast mode, and the indicator indicates that the wireless device has been maintained during the first key rotation period. The method performed on the wireless device additionally includes: broadcasting a wireless beacon having the first advertisement packet type; and in response to disconnecting from the encrypted wireless connection, starting a counter associated with a timeout period. The timeout triggers the wireless device to transition to a second broadcast mode. The wireless device will cyclically transition to a new cryptographic key for establishing an encrypted connection with the device. During a transition from the first key rotation period to a second key rotation period, the wireless device may reset the indicator in the status field of the first wireless advertisement packet type. In response to establishing a second encrypted wireless connection with a second electronic device, the electronic device may reset the counter associated with the timeout period.

[0008] One embodiment provides a data processing system on a wireless device. The data processing system includes: a memory device; and one or more processors configured to execute instructions stored in the memory device, wherein the instructions cause the one or more processors to perform operations to establish a first encrypted wireless connection with a first electronic device, and in response to the establishment of the first encrypted wireless connection: set an indicator in a status field of a first wireless advertisement packet type, wherein the indicator indicates that a maintenance operation has been performed on the wireless device during a first key rotation period; and broadcast a wireless beacon having the first wireless advertisement packet type. In response to disconnecting from the first encrypted wireless connection, the data processing system may start a counter associated with a timeout period. Expiration of the timeout period may trigger the wireless device to transition from a first broadcast mode to a second broadcast mode. The data processing system may then establish a second encrypted wireless connection with a second electronic device. The second electronic device may be associated with an account shared with the first electronic device. The data processing system may then reset the counter associated with the timeout period after establishing the second encrypted wireless connection.

[0009] One embodiment provides a non-transitory machine-readable medium storing instructions that cause one or more processors of a wireless device to perform operations including establishing a first encrypted wireless connection with a first electronic device, wherein the first encrypted wireless connection is established using cryptographic material associated with a first key rotation period. The operations additionally include setting an indicator in a status field of a first wireless advertisement packet type. The first wireless advertisement packet type is associated with a first broadcast mode, and the indicator indicates that the wireless device has been maintained during the first key rotation period. The operations additionally include: broadcasting a wireless beacon having the first advertisement packet type; and in response to disconnecting from the encrypted wireless connection, starting a counter associated with a timeout period. The timeout triggers the wireless device to transition to a second broadcast mode. The wireless device will cyclically rotate to a new cryptographic key for establishing an encrypted connection with the device. During a transition from the first key rotation period to a second key rotation period, the wireless device may reset the indicator in the status field of the first wireless advertisement packet type. In response to establishing a second encrypted wireless connection with a second electronic device, the electronic device may reset the counter associated with the timeout period.

[0010] The foregoing summary does not include an exhaustive list of all embodiments of the present disclosure. All systems and methods may be practiced in accordance with all suitable combinations of the various aspects and embodiments outlined above and those disclosed in the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] The invention is illustrated by way of example and is not limited to the figures of the drawings, in which like reference numerals indicate like elements and in which:

[0012] Figure 1 is a block diagram of a network operating environment for a mobile device according to an embodiment;

[0013] Figure 2 illustrates a system for locating a wireless accessory that cannot access a wide area network according to an embodiment;

[0014] Figure 3 illustrates a system for pairing and locating a wireless accessory according to an embodiment described herein;

[0015] Figure 4 is a flowchart of a process for entering a near-owner state to perform near-owner maintenance at a secondary device;

[0016] Figure 5 illustrates an advertising beacon packet for a wireless accessory;

[0017] Figure 6 illustrates an operating method for transitioning from a near-owner advertising mode to a field advertising mode on a wireless accessory;

[0018] Figure 7 illustrates a system enabling the use of multiple devices to implement near-owner maintenance;

[0019] Figures 8A to 8B illustrates a state and connection timing diagram of multiple owner devices and a wireless accessory;

[0020] Figures 9A to 9B illustrates a state and connection timing diagram of multiple owner devices and a wireless accessory according to an additional embodiment;

[0021] Figure 10 illustrates a state and connection timing diagram of multiple owner devices and a wireless accessory using a synchronization maintenance timer;

[0022] Figure 11 illustrates a state and connection timing diagram of multiple owner devices and a wireless accessory using a dual maintenance timer and / or a dual mode timer;

[0023] Figure 12 illustrates an electronic device including hardware and software logic to implement multi-device near-owner maintenance of a wireless accessory;

[0024] Figure 13 illustrates a method performed by an electronic device to implement multi-device near-owner maintenance of a wireless accessory;

[0025] Figure 14 is a block diagram of a device architecture for a mobile or embedded device according to an embodiment; and

[0026] Figure 15 is a block diagram of a computing system according to an embodiment. DETAILED DESCRIPTION

[0027] The embodiments described herein provide techniques for enabling a secure crowdsourcing locator service for lost or misplaced devices that are unable to communicate with a wide area network. The various embodiments and aspects will be described with reference to the details discussed below, and the drawings will illustrate the various embodiments. The following specification and drawings are illustrative and should not be construed as restrictive. Many specific details are described to provide a thorough understanding of the respective embodiments. However, in some instances, well-known or conventional details are not described in order to provide a concise discussion of the embodiments.

[0028] The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used in the specification of the present invention and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. It will also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. It will also be understood that the term "comprises" and / or "comprising", when used in this specification, specifies the presence of the stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0029] In the following discussion, a computing device including a touch-sensitive display is described. However, it should be understood that the computing device may include one or more other physical user interface devices. The various applications that may be executed on the device may use at least one shared physical user interface device, such as a touch-sensitive surface. One or more functions of the touch-sensitive surface and the corresponding information displayed on the device may be adjusted and / or varied from one application to the next, and / or within the respective application. Thus, the shared physical architecture of the device, such as the touch-sensitive surface, may support the various applications with an intuitive and transparent user interface.

[0030] Some processes are described below in terms of a sequence of operations. However, it should be understood that some of the operations may be performed in a different order. In addition, some operations may be performed in parallel rather than sequentially.

[0031] Overview of the operating environment

[0032] Figure 1is a block diagram of a network operating environment 100 for a mobile device according to an embodiment. The network operating environment 100 includes a plurality of mobile devices, such as mobile device 102A and mobile device 102B. Mobile devices 102A to 102B can each be any electronic device capable of communicating with a wireless network and one or more wireless accessory devices. Some exemplary mobile devices include, but are not limited to, smart phones, tablet computers, notebook computers or laptop computers, wearable computers (e.g., smart watches or other wearable computing accessories), mobile media players, personal digital assistants, and other similar devices. Each of mobile device 102A and mobile device 102B includes a user interface, such as user interface 104 of mobile device 102B. Mobile devices 102A and 102B can communicate through one or more wired and / or wireless networks 110 to perform data communication. For example, wireless network 112 (e.g., cellular network, Wi-Fi network) can communicate with a wide area network 114 (such as the Internet) by using gateway 116. Similarly, an access device 118, such as a mobile hotspot wireless access device, can provide communication access to the wide area network 114. Then, gateway 116 and access device 118 can communicate with the wide area network 114 through a combination of wired and / or wireless networks.

[0033] In some specific embodiments, both voice communication and data communication can be established through wireless network 112 and / or access device 118. For example, mobile device 102A can make and receive phone calls (e.g., using VoIP protocol), send and receive email messages (e.g., using POP3 protocol), and retrieve electronic documents and / or streams, such as web pages, photos, and videos, through wireless network 112, gateway 116, and wide area network 114 (e.g., using TCP / IP or UDP protocol). In some specific embodiments, mobile device 102A can make and receive phone calls, send and receive email messages, and retrieve electronic documents through access device 118 and wide area network 114. In some specific embodiments, mobile device 102A or mobile device 102B can be physically connected to access device 118 using one or more cables. For example, where access device 118 is a personal computer. In this configuration, mobile device 102A or mobile device 102B can be referred to as a "tethered" device. In one embodiment, mobile device 102A can communicate with mobile device 102B via a wireless peer-to-peer connection 120. The wireless peer-to-peer connection 120 can be used to synchronize data between devices.

[0034] Mobile device 102A or mobile device 102B can communicate with one or more services via one or more wired and / or wireless networks 110, such as telephone service 130, instant messaging service 140, media service 150, storage service 160, and device locator service 170. For example, telephone service 130 can enable telephone communication between mobile device 102A and mobile device 102B or between a mobile device and a wired telephone device. Telephone service 130 can route IP-based voice (VoIP) calls via a wide area network 114 or can access a cellular voice network (e.g., wireless network 112). Instant messaging service 140 can provide, for example, email and / or other instant messaging services. Media service 150 can provide access to media files, such as song files, audiobooks, movie files, video clips, and other media data. Storage service 160 can provide network storage capabilities to mobile device 102A and mobile device 102B to store documents and media files. Device locator service 170 can enable a user to locate a lost or misplaced device that is at least at some point connected to one or more wired and / or wireless networks 110. For example, mobile device 102A can perform a location query on mobile device 102B. Device locator service 170 can also implement location queries for devices that do not have a network connection via a network using a detector device, as shown below in Figures 2 to 3 as shown. Other services can also be provided, including a software update service for updating the operating system software or client software on the mobile device. In one embodiment, instant messaging service 140, media service 150, storage service 160, and device locator service 170 can each be associated with a cloud service provider. Then, various services can be facilitated via a cloud service account associated with mobile devices 102A - 102B. In one embodiment, storage server 160 can be used to synchronize password materials for connecting to or identifying attachments shared between mobile devices 102A - 102B.

[0035] Figure 2Shown is a system 200 for locating a wireless accessory 201 that cannot access a wide area network. The system 200 can also be used to locate a device that cannot access a WAN or LAN and thus cannot transmit its device location. In one embodiment, the wireless accessory 201 includes one or more wireless transceivers and can communicate directly or indirectly (e.g., through another device or computer) with an accompanying device via a wireless network or a peer-to-peer communication link. The accompanying device is an electronic device (e.g., mobile device 102) with which the wireless accessory 201 is paired or cryptographically associated. Some examples of wireless accessory devices include, but are not limited to, wireless earbuds, earphones, headphones, and other wearable devices (e.g., smartwatches, fitness bands, optical head-mounted displays). The wireless accessory 201 can also include other wireless devices such as game controllers or remote controls. In one embodiment, the wireless accessory 201 also includes a smartphone, a tablet computer, a laptop computer, a smart speaker device, a television, or a television set-top box that is at least temporarily unable to access a wide area network such as the Internet (e.g., the wide area network 114 as Figure 1 shown). The wireless accessory can also be any other wireless device that includes a wireless beacon peripheral or a locator tag that can be attached to other devices or items to enable tracking or locating of those devices or items. In one embodiment, the wireless accessory 201 can use a wireless technology standard (such as, but not limited to, Bluetooth) to pair with the mobile device 102. The wireless accessory 201 can also communicate with the mobile device 102 via wireless technologies such as Wi-Fi Direct, Zigbee, or AirPlay. Although the accompanying device with which the wireless accessory 201 is paired is commonly referred to as the mobile device 102, the accompanying device is not limited to mobile devices. In some embodiments, the companion device can also include a laptop or a desktop device and can also include some wearable accessories such as, but not limited to, smartwatch devices or wearable displays.

[0036] In one embodiment, the wireless accessory 201 can periodically transmit a wireless beacon signal. The wireless accessory 201 can use one of various wireless technologies (e.g., Bluetooth, Wi-Fi, Z-Wave, Zigbee, etc.) to transmit the beacon signal and can also use ultra-wideband (UWB) radio technology to send the beacon in one embodiment. The beacon signal can be transmitted using a single wireless technology, one of multiple alternative wireless technologies, or multiple simultaneous wireless technologies. The beacon signal can transmit a beacon identifier that includes information specifically identifying the wireless accessory 201. In one embodiment, the beacon identifier is a public encryption key associated with the device.

[0037] The beacon signal may also convey information about the wireless accessory 201, such as beacon type, device classification, battery level. In one embodiment, the beacon signal may also convey device status, such as lost status, alert status, or near-owner status. The beacon signal may also include information specifying battery life, charge status, and / or other status information. The lost status may indicate that the wireless accessory 201 has determined that it has been lost or has been placed in a lost state by the owner of the device. The alert status may indicate that the wireless accessory 201 is in a state where the device should trigger an alert if it moves from its current location. The near-owner status may indicate that the wireless accessory 201 has detected the presence of the mobile device 102 associated with the owner of the accessory in the vicinity.

[0038] The beacon signal may be detected by a detector device 202 that is locally proximate to the wireless accessory 201. The detector device 202 may be a device similar to the mobile device 102 and may receive and transmit data over the wide area network 114, and the receiving and transmitting is performed using a wireless technology similar to that of the wireless accessory 201 (e.g., Bluetooth, etc.). Specifically, the detector device 202 may use a wireless protocol to receive data, through which the beacon signal is transmitted. The detector device 202 may use one or more location and / or positioning services to determine its location, and the location and / or positioning services include but are not limited to satellite positioning services 206 or a terrestrial positioning system that uses RF signals received from wireless base stations 205 such as Wi-Fi access points or cellular towers of a cellular telephone network. In one embodiment, the detector device 202 periodically stores its location determined based on one or more location and / or positioning services. The stored location may be associated with a timestamp for which the location was determined. When the detector device 202 receives a beacon signal from the wireless accessory 201, the detector device 202 may transmit the location of the detector device over the wide area network 114 to the device locator server 203. The timestamp of the location of the detector device 202 used for determination may be associated with the timestamp when the beacon signal was received to associate the geographical location with the received beacon signal. In one embodiment, the wireless accessory 201 includes location determination capabilities via an integrated satellite positioning service (e.g., GPS) receiver. If the wireless accessory is unable to access a network to send its location to the device locator server 203, the wireless accessory may encode encrypted location data within the beacon signal 301. Then, the detector device 202 may relay the encrypted location data to the device locator server 203.

[0039] In the case where the wireless accessory 201 provides a public key within the beacon signal, the detector device 202 may encrypt the determined location data and transmit the encrypted location data to the device locator server 203 via the wide area network 114. In one embodiment, additional data may be encrypted and transmitted together with the location data, or transmitted to the device locator server 203 without encryption. For example, the received signal strength indication (RSSI) of the beacon signal may be transmitted together with the location data. Then, the RSSI data can be used to determine the distance of the wireless accessory 201 from the detector device 202 and assist in triangulation on the owner device. In the case where the RSSI data is transmitted in an unencrypted state, in one embodiment, if there are other stronger signals, the server may use the RSSI information to reduce noise by discarding very weak signals. In one embodiment, UWB ranging data may also be provided, where such data is available.

[0040] In one embodiment, the detector device 202 may behave differently when receiving a beacon signal from the wireless accessory 201 according to the device state communicated by the wireless accessory 201. For a standard beacon signal, the detector device 202 may queue the encrypted location data and transmit the location data to the device locator server 203 during a periodic transmission window. However, if the wireless accessory 201 is indicating an alarm state, the detector device 202 may immediately transmit the location data to the device locator server 203. Additionally, if the beacon signal of the wireless accessory 201 indicates that the accessory is close to the owner of the accessory, the detector device 202 may not transmit the location data to the device locator server 203. Alternatively, the detector device 202 may delay the transmission of the encrypted location data. The device state may also indicate whether near-owner maintenance has been performed on the wireless accessory 201. If the owner device (e.g., the mobile device 102) detects that the wireless accessory is broadcasting a status bit indicating that it has not been maintained recently, the owner device may connect to the wireless accessory 201 and perform maintenance operations such as synchronizing timers, setting or resetting internal counters, checking error or crash logs, or other operations that are periodically performed on the wireless accessory 201.

[0041] If the owner of the wireless accessory 201 wishes to locate the wireless accessory, the owner can access the device locator user interface (e.g., device locator UI 204) on the mobile device 102. The device locator UI 204 can be associated with a device locator application that is used to locate electronic devices and accessories registered to the user's online account (such as a cloud service account or another type of online account). The device owner can use the device locator UI 204 to query the device locator server 203 for location data that may have been transmitted to the device locator server by the detector device 202 of the wireless accessory 201. In one embodiment, the mobile device 102 can transmit a public encryption key associated with the wireless accessory 201 to the device locator server 203. Then, the device locator server 203 can return any stored location data corresponding to the public encryption key. The location data returned to the mobile device 102 can be encrypted data that was encrypted by the detector device 202 using the public encryption key. The mobile device 102 can use the associated private key to decrypt the encrypted location data. Then, the decrypted location data is processed by the mobile device 102 to determine the most likely location of the wireless accessory 201. In various embodiments, the most likely location of the wireless accessory 201 can be determined by triangulation from multiple received locations and using other data (such as beacon signal RSSI associated with each location and timestamp or UWB ranging data included within the location data).

[0042] Figure 3Shown is a system 300 for pairing and locating a wireless accessory according to an embodiment described herein. In one embodiment, a mobile device 102 of a user of a wireless accessory 201 may present an accessory pairing UI 302 through which the user may pair the mobile device 102 with the wireless accessory 201. During an initial pairing (305) between the mobile device 102 and the wireless accessory, a public key exchange (310) may be performed between the mobile device 102 and the wireless accessory 201. In one embodiment, the initial pairing 305 is performed within a secure wireless communication session that includes additional security above and beyond the security provided by the wireless protocol. In one embodiment, during the public key exchange (310), the mobile device 102 and the wireless accessory exchange the public keys in the public key pairs generated by the device and the accessory. In one embodiment, the public key exchange (310) is a one-way transfer in which the mobile device 102 transmits the public key in the public / private key pair to the wireless accessory 201. Additionally or alternatively, the public key exchange (310) may be a Diffie-Hellman key exchange in which the device and the accessory establish a shared secret between the two parties. In one embodiment, the public key exchange (310) additionally uses elliptic curve cryptography to establish the shared secret. For example, Elliptic Curve Diffie-Hellman (ECDH) may be used to implement the establishment of the public key pair and one or more shared secrets. In one embodiment, one or more of the shared secrets include an anti-tracking secret that may be used by the wireless accessory 201 to periodically derive additional public keys. In one embodiment, the public key exchange (310) is performed as part of a collaborative key generation process, where the public key exchange is performed by the mobile device 102 and the wireless accessory. In one embodiment, identity-based encryption is used at least in part. With identity-based encryption, the public key is or is derived from some unique element of information about the user's identity, such as an email address. The entity that wants to decrypt the encrypted information may obtain the decryption key from a trusted central authority.

[0043] After the wireless accessory 201 has been paired with the mobile device 102, the wireless accessory 201 may periodically broadcast a beacon signal 301 that includes device status information and a beacon identifier. In one embodiment, the beacon identifier is a public key derived from a shared secret established during public key exchange (310). Additionally, the wireless accessory 201 may periodically perform public key derivation (315) to generate a new public key and begin broadcasting the new public key as the beacon identifier. Alternatively, a large number of keys may be derived based on the public key and rotated periodically. The beacon identifier is a K-byte key, where a new K-byte key is generated or rotated every M minutes. The values of K and M may vary between embodiments. In one embodiment, a K value of 28 bytes is used. In one embodiment, a K value of 27 bytes is used. The value of K may be determined at least in part based on the beacon length associated with the wireless protocol used to transmit the beacon signal 301. In one embodiment, the beacon signal may transmit a variant of a beacon advertisement packet associated with a low-power radio protocol such as Bluetooth Low Energy.

[0044] In one embodiment, the value of M is 15 minutes such that a new K-byte key is selected every 15 minutes. The new K-byte key may be deterministically pre-generated with a batch of keys and selected during the key rotation period. Using different keys over time prevents a long-term association of a particular key with a particular device. The keys may be derived based on a shared secret known only to the mobile device 102 and the wireless accessory 201, allowing the mobile device 102 to determine which public key the wireless accessory 201 will broadcast at any given timestamp.

[0045] In one embodiment, the wireless accessory 201 may transmit the beacon signal 301 every two seconds, but other beacon rates may be used and the beacon rate may vary in some cases. For example, when in a near-owner state, the wireless accessory 201 may reduce the beacon rate. The beacon rate may also vary based on accelerometer-triggered events. For example, when in an alert state, the wireless accessory 201 may increase the beacon rate, which may be triggered by an accelerometer on the wireless accessory 201. The beacon rate may also increase when the wireless accessory 201 is in motion and decrease when the wireless accessory 201 is stationary.

[0046] The wireless accessory 201 can enter an alert state upon receiving a message from the mobile device 102 indicating that the wireless accessory 201 should enter an alert state. While in the alert state, the wireless accessory can initially enter an armed state in which the wireless accessory 201 can reduce or stop transmitting locator beacon signals, but other types of wireless signaling can continue to exist. The wireless accessory 201 can remain in the armed state until the mobile device 102 deactivates the state or an alarm is triggered. In one embodiment, the alarm can be triggered when movement is detected, for example, via an accelerometer within the wireless accessory 201. In one embodiment, the alarm can also be triggered when it is detected that the wireless accessory has moved out of range of the mobile device and is no longer in a near owner state. When the alarm is triggered, the rate of the beacon signal 301 can increase to increase the speed at which the wireless accessory 201 can be located.

[0047] The beacon signal 301 transmitted by the wireless accessory 201 can be detected by a set of detector devices 303, which are other electronic devices that can receive the beacon signal transmitted by the wireless accessory and transmit the location and other data associated with the beacon signal 301 to the device locator server 203 via the wide area network 114. In one embodiment, the set of detector devices 303 includes a variation of the mobile device 102, or can be other types of electronic devices. The set of detector devices 303 may include Figure 2 The detector device 202 of the embodiment of the present invention may be a variant of the detector device 202 and may determine similar location determination techniques. For example, the detector device may perform operations (320) to associate a beacon signal 301 received from the wireless accessory 201 with a device location associated with the detector device. Figure 2 The device location may be determined via a satellite positioning service or a ground positioning system using RF signals received from a wireless base station (e.g., a Wi-Fi access point or a cellular tower transmitter). In one embodiment, the group of detector devices 303 may also include fixed devices that can receive beacon signals 301, such as smart speaker devices, televisions, or television set-top boxes.

[0048] The set of detector devices 303 may encrypt the location data using the beacon identifier (e.g., a public key) received within the beacon signal 301 and send the location data (325) to the device locator server 203. The data sent by the set of detector devices 303 is sent anonymously, and identification information of the detector devices is not stored with the data sent by the detector devices.

[0049] The device locator server 203 can store encrypted location data in the data repository 304, which in one embodiment can be a distributed database with multiple nodes. The hash of the beacon identifier / public key of the attachment can be sent along with the encrypted location data. The encrypted location data can be stored in the database nodes based on the hash of the beacon identifier. The encrypted location data can be indexed by the device locator server 203 using the hash of the beacon identifier. Sending the hash of the beacon identifier instead of the full beacon identifier can prevent the full beacon identifier from being stored on the server. Other information can also be sent and stored with the location data in encrypted or unencrypted form. Other information can include the timestamp when the beacon signal 301 was received, the RSSI information of the received beacon, and / or ranging information determined via UWB ranging, for example.

[0050] When the user or owner of the wireless attachment 201 wishes to locate the attachment, the user or owner can access the device locator UI 204 on the mobile device 102. The device locator UI 204 can be associated with the device locator application or feature of the mobile device 102. The device locator UI 204 can also have a web-based interface that can be accessed from the mobile device 102 or another type of electronic device, such as a laptop or desktop device. When the device locator UI 204 is loaded, the mobile device 102 can send a request (330) for location data to the device locator server 203. The request 330 can include a set of public key hashes of beacon identifiers that can be used as beacon data. The mobile device 102 can generate this set of public keys based on the secret information held by the mobile device 102 and the wireless attachment 201 and the timestamp at which the mobile device 102 wishes to receive location data. In one embodiment, the set of public keys is based on the public key sequence P i , which is generated based on a tracking-resistant secret. The public key sequence P i corresponds to the matching private key sequence d i . The mobile device 102 can generate the public key sequence and the corresponding private key sequence d i , where i is a counter or timestamp. In one embodiment, the mobile device 102 can generate and send the hash of the public keys for the previous 24 hours within the request 330. If no data for the 24-hour public keys is found, the mobile device 102 can send the hashed keys for an earlier time period, back to a pre-determined location data retention limit.

[0051] Store and index encrypted location data based on the hash of the public key rather than the public key to prevent providers of location service data from storing data that can be used to bind encrypted location data to a specific device and thus to a specific user or user account. The detector device sends the hash of the public key broadcast within beacon signal 301 associated with the observed location. The owner of the device can use the hash of the public key determined for the query time period to query the device locator server 203.

[0052] In some embodiments, if a location query is to be performed via a web-based interface from an electronic device such as a laptop or desktop device, a key may need to be sent to the electronic device to enable decryption of the location data. In one embodiment, the decryption key for the location data can be sent to a server that provides a web-based interface so that the server can decrypt the location data at least when viewing the location data through the web-based interface. Before presenting the location data via the web-based interface, a notification can be presented to inform the user that the location decryption key is being temporarily shared with the web-based interface server to enable decryption and presentation of the location data. In one embodiment, sharing of the location decryption key can be performed via automatic and temporary authorization of the location query privilege of a proxy account associated with the web-based interface.

[0053] In one embodiment, the wireless accessory 201 can be placed in a lost light mode. In the lost light mode, a set of future public keys can be generated for the wireless accessory and the hashes of those public keys can be transmitted to the device locator server 203. Then, if any location data corresponding to the keys in this set of future public keys is received, the device locator server 203 can notify the mobile device 102. In one embodiment, the detector device that sends the location of the wireless accessory in the lost light mode can be directed by the device locator server 203 to relay a message to the wireless accessory 201 that notifies the wireless accessory that it is in the lost light mode. A similar mechanism can also be used to relay a message to the wireless accessory 201 that places the accessory in an explicit lost mode. The user can enable the explicit lost mode via the device locator UI 204. In the explicit lost mode, the wireless accessory 201 cannot be paired with another device unless it is unlocked by the owner.

[0054] Proximity owner maintenance

[0055] In one embodiment, to establish a secure session with the wireless accessory 201, the accessory is placed in the near-owner mode. During the secure session with the owner device and for a certain period of time after disconnecting from the secure session, the wireless accessory 201 will send beacons in the near-owner mode. When the wireless accessory 201 has not been connected to the owner device for more than a threshold period of time, the wireless accessory 201 can broadcast in the wild mode. When in the wild mode, the wireless accessory 201 can be more easily located by the detector device 303. However, transmitting beacons in the wild mode consumes a greater amount of power compared to transmitting beacons in the near-owner mode. In addition, the location of the accessory can be detected by nearby devices and uploaded to the device locator server 203. Detecting the wireless accessory in the wild mode is beneficial when the location of the accessory may be unknown. However, when the accessory is in a known location and within the range of one or more owner devices, the network resources, server resources, processor cycles, and power consumed by uploading the location data of the wireless accessory are wasted. Therefore, it is beneficial to continuously maintain the wireless accessory in the near-owner mode when it is within the wireless range of the owner device.

[0056] Near-owner maintenance can be performed by any one of a plurality of owner devices paired with the wireless accessory. Since a user or user account can be associated with multiple mobile devices, for the purpose of reporting to location services, a single device can be designated as the user's primary location device. When reporting the location of a user associated with a device to family members or other users with an account authorized to receive the user's location, the location of the primary location device is reported to the locator service. In one embodiment, the maintenance is performed by the device designated as the user's primary location device, even if other devices may exist. As described herein, near-owner maintenance refers to maintenance operations (such as synchronizing timers, setting or resetting internal counters, checking error or crash logs, or other operations periodically performed on the wireless accessory), and periodically establishing a short connection with the wireless accessory for the purpose of preventing a wild mode transition.

[0057] Figure 4 is a flowchart of a process for entering the near-owner state to perform near-owner maintenance at a secondary device. In one embodiment, when the primary device 402 detects the presence of a secondary device 404 nearby, the primary device 402 can place the secondary device 404 in the near-owner state. The primary device 402 can be an owner device (e.g., the mobile device 102), or an equivalent device as described herein. The secondary device 404 can be, for example, the wireless accessory 201 or an equivalent device as described herein. In one embodiment, before a specific command can be issued, the secondary device 404 is placed in the near-owner state to perform maintenance operations and / or maintain the near-owner state of the secondary device 404.

[0058] In one embodiment, the primary device 402 and the secondary device 404 may perform operations 411A - 411B to enter a new privacy window and rotate key material. The primary device 402 and the secondary device 404 may each calculate the new key material for privacy window i based on key P and SK, where P is a private key, SK is a secret key, and P and SK are collaboratively generated by the primary device 402 and the secondary device 404. A token derived in part based on the command key CK i and the diversified public key P i places the secondary device 404 in the near - owner state.

[0059] The primary device 402 may perform operation 412 to update the radio controller lookup table with the expected broadcast address. The desired broadcast address may be based on a derived key that is a reduced - bit representation of the diversified public key P i . The secondary device 404 may perform operation 413 to update the broadcast address based on the derived key. The primary device 402 and the secondary device 404 may each derive the derived key based on the calculated key material of the privacy window. The broadcast address of the secondary device 404 is updated by encoding the bytes of the derived key into the hardware address of the secondary device, e.g., by setting the most significant byte group of the hardware address to the corresponding bytes of the derived key. Then, the primary device 402 may update the radio controller (e.g., Bluetooth controller) lookup table to look up the updated hardware address.

[0060] The primary device 402 may perform operation 414 to detect nearby secondary devices based on the expected broadcast address. Then, the primary device 402 may perform operation 415 to derive additional key material, which may include a near - owner authorization token. In one embodiment, there is a 1:1 mapping between the diversified public key P i and the corresponding near - owner authorization token, allowing tokens to be pre - calculated for multiple privacy windows. In such embodiments, the near - owner authorization token for a privacy window may be derived as:

[0061] NearOwnerAuthToken i = MostSignificant6Bytes(MAC(CK i ,x(P i ))||“NearOwnerAuthToken”)

[0062] The primary device 402 performs an operation 416 to send a message as a source address along with a proximity owner authorization token. In one embodiment, the message is a Bluetooth network packet that is sent as a Bluetooth source hardware address along with the proximity owner authorization token. Then, the secondary device 404 may perform an operation 417 to enter the proximity owner mode in response to receiving the message as a source address along with the proximity owner authorization token. When the secondary device 404 enters the proximity owner mode, the proximity owner timeout is reset. When the primary device 402 disconnects from the secondary device 404, a countdown to enter the wild mode begins.

[0063] The primary device 402 and the secondary device 404 may each be associated with a common user account. The cryptographic material used by the primary device 402 to connect to the secondary device 404 may be shared with other devices associated with the common user account. Those other devices may also perform proximity owner maintenance on the secondary device 404. However, to prevent multiple devices from attempting to maintain, the secondary device 404 may set an indicator in a status field indicating whether the device has been maintained recently. When the maintenance status is set, the owner device will not attempt to maintain the secondary device 404.

[0064] Figure 5 An advertising beacon packet 500 for a wireless accessory is shown. The advertising packet broadcast by the wireless accessory may vary based on whether the accessory is in the proximity owner mode or in the wild mode. In one embodiment, the advertising packet may be a Bluetooth Low Energy advertising packet. However, the embodiment is not limited thereto. Additionally, the packet format may be different from the standard wireless protocol advertising packet.

[0065] In one embodiment, the proximity owner advertising packet 501 includes a first public key portion (PubKey1 / 2) used as an advertising address. The first key portion may include the first six bytes of the current public key of the wireless accessory. In one embodiment, the most significant bit of the advertising address is constrained to the value 0b11, which specifies a static device address. In contrast, if the wireless accessory is a wireless beacon tag, the actual address bits are stored in the EK (extra key) field together with the bits defining the tag type of the wireless accessory. The proximity owner packet may additionally include fields L1, T1, CID, T2, L2, and S1. L1 is the length of the advertising type field, T1 is the advertising type field, CID is the companion ID field, T2 is the payload type (e.g., object discovery), L2 is the length of the object discovery field, and S1 is the status flag field. The length of the object discovery payload may vary depending on whether the wireless accessory is in the proximity owner mode or in the wild mode. The status flag field may include, for example, the battery status and additional device type flags, such as whether the wireless accessory is a wireless beacon tag.

[0066] The out-of-proximity advertisement packet 502 may include fields similar to the near-owner advertisement packet 501. The out-of-proximity advertisement packet 502 may additionally include a second public key portion (PubKey2 / 2), which includes additional bits of the public key. In one embodiment, the additional bits of the public key or combined public keys (PubKey1 / 2, PubKey2 / 2, EK) may be used as a static identifier for the wireless accessory, which allows suppression of unwanted tracking notifications. In one embodiment, the combined public key may also be used by the detector device as an encryption key to encrypt the observed location of the wireless beacon when uploading the observation to the device locator server.

[0067] In one embodiment, the status flag field S1 of the near-owner advertisement packet 501 includes a maintenance bit 503. The maintenance bit 503 indicates whether near-owner maintenance has been performed during a given key rotation period. During each key rotation, the maintenance bit 503 may be cleared to indicate that the device is in an unmaintained near-owner mode, available for near-owner maintenance connections, and will soon transition to out-of-proximity mode if not maintained. The maintenance bit can be used to facilitate near-owner maintenance by multiple owner devices.

[0068] Multiple device proximity owner maintenance

[0069] As described above, when there is a single owner device associated with an online account, that device is responsible for performing near-owner maintenance on the wireless accessories to prevent those accessories from transitioning to out-of-proximity mode when the owner device is present. The owner device may configure a near-owner timeout for the wireless accessory during a secure connection with the accessory. Upon disconnection, the accessory will start counting down from the configured timeout and will transition to out-of-proximity mode when the countdown reaches zero. The owner device may reconnect to the wireless accessory before the countdown reaches zero to prevent the transition to out-of-proximity mode.

[0070] When the user has multiple devices associated with an online account, any one of those devices may be configured to perform near-owner maintenance. This functionality is useful when the user leaves home with a smart phone device and the wireless accessories are left at home with, for example, a tablet computer device. Additionally, in the case of sharing a wireless accessory between users, the password material may be shared between those users' accounts so that the receiving device of the shared accessory can connect to the accessory. Then, when the accessory is within wireless range, the receiver of the shared accessory may perform near-owner maintenance on the accessory.

[0071] An arbitration system among multiple devices capable of performing near-owner maintenance is used to prevent battery depletion that would accompany repeated maintenance connections from multiple devices within the same time period. Refer to Figure 5For the advertisement beacon packet 500, the maintenance bit 503 of the status field S1 of the near-owner advertisement packet 501 is used to indicate when the wireless accessory receives a maintenance connection during the key rotation period. The maintenance bit can be cleared at the start of each key rotation period.

[0072] Figure 6 An operation method 600 for transitioning from the near-owner advertisement mode to the wild advertisement mode on a wireless accessory is shown. The method 600 can be executed by any wireless device, wireless accessory, or wireless accessory device as described herein. In one embodiment, the wireless device can receive a connection from the owner device to perform a maintenance operation (block 601). Then, the wireless device can set the maintenance bit in the status field of the advertisement beacon (block 602). The maintenance bit can be set by the owner device during the duration of the connection and for a certain period of time after the connection is disconnected. After disconnection, the wireless device can use the near-owner advertisement packet to send a beacon in the near-owner mode (block 603).

[0073] The wireless device can clear the maintenance bit during the next key roll on the wireless device (block 604). Clearing the maintenance bit indicates to nearby owner devices that the device will soon transition to the wild mode (unless near-owner maintenance is performed), and indicates to any nearby owner devices that a maintenance operation can be performed to prevent the wild mode transition.

[0074] If the near-owner timeout is reached and the owner device does not connect to perform maintenance (block 605, yes), then the wireless device can enter the wild mode and start sending beacons in the wild mode using the wild mode advertisement packet (block 606). When in the wild mode, the wireless device broadcasts wild mode advertisement packets that can be discovered by detector devices within the wireless range of the wireless accessory. The beacon rate of the wireless device can be increased relative to the beacon rate when in the near-owner mode. Upon detecting a wild mode advertisement, nearby detector devices can attempt to determine or estimate the location of the wireless device relative to the detector device and upload the determined or estimated location to a device location server, where the determined or estimated location is indexed on the device location server by a hash of the wild mode address broadcast by the wireless device.

[0075] Figure 7A system 700 enabling near-owner maintenance using multiple devices is shown. The system 700 includes a plurality of mobile devices 102A - 102B, each of which stores cryptographic material enabling the device to establish a secure connection with a wireless accessory. Each mobile device 102A - 102B includes at least one timer 702A - 702B that is periodically triggered on the device. When the timers 702A - 702B trigger, the device can scan for beacon signals 301 broadcast by the wireless accessory. The device can also check a scan buffer or scan cache to determine if any advertisement packets associated with the beacon signal 301 were received during a period of time prior to the triggering of the timers 702A - 702B. For example, mobile device 102A can detect an advertisement packet broadcast by wireless accessory 201 and check a maintenance bit (712) in the status field of the advertisement packet. If the maintenance bit indicates that the wireless accessory has not been recently maintained (e.g., within the current key rotation period), then mobile device 102A can connect (714) to wireless accessory 201 and perform one or more maintenance operations, such as performing error checking operations, synchronizing timers, resetting counters, and other operations to be periodically performed on wireless accessory 201. When the timer 702B at mobile device 102B expires, mobile device 102B can also perform a wireless scan and / or check the scan buffer or scan cache. When a wireless advertisement packet is detected, mobile device 102B can check the maintenance bit (716). If the wireless accessory has been recently maintained based on the maintenance bit in the advertisement packet of beacon signal 301, then mobile device 102B can skip establishing a connection (718).

[0076] In various embodiments, multiple instances of timers 702A - 702B can be used on each of mobile devices 102A - 102B. For example, the device can use an opportunistic timer that can trigger opportunistically before or after the timer deadline to take advantage of other timers or wake events that occur or are scheduled to occur near the timer deadline. Leveraging opportunistic events avoids waking a separate device or processor from a low-power state solely to service the opportunistic timer, thereby reducing the total number of wake events. The device can pair the opportunistic timer with a precise timer that fires at a set time interval precisely as a fallback for the opportunistic timer.

[0077] In various embodiments, the duration of the near-owner timeout and the number, type, and configuration of the timers may vary, but are typically set to complementary values. Every M minutes, a new K-byte key is selected to be used as the beacon identifier broadcast by the wireless accessory or to enable the derivation of the beacon identifier. The near-owner timeout period may be configured for M+I minutes after the encryption communication session between the owner device and the connection is disconnected. In various embodiments, the value of I may be set to be between one minute and five minutes, but is not limited to any specific value.

[0078] In one embodiment, a 15-minute near-owner timeout is used with a keep-alive timer set for 14 minutes. In one embodiment, a 20-minute near-owner timer is used with a keep-alive timer set for 18 or 19 minutes. In some embodiments, the timers are synchronized across devices that can perform near-owner keep-alive.

[0079] Figures 8A to 8B A state and connection timing diagram of multiple owner devices and wireless accessories according to one embodiment is shown. Mobile devices 102A - 102B may operate as owner devices. However, the owner device is not limited to any specific type of electronic device. The techniques performed by the wireless accessory 201 may be performed by any wireless device or wireless accessory described herein. The wireless accessory 201 is configured with a 15-minute key rotation period and a 15-minute near-owner timeout. The mobile devices 102A - 102B are configured with a 14-minute opportunity timer. The top portion of the timeline of the wireless accessory 201 indicates the status of the keep-alive bit 503 broadcast in the status field S1 of the near-owner advertisement packet 501 broadcast by the wireless accessory 201.

[0080] As Figure 8A shown, the mobile device 102A may connect (802) at the two-minute mark. If the wireless accessory 201 is in the field mode, the mobile device 102A may put the wireless accessory 201 into the near-owner mode to establish a connection. During the duration of the connection and for 15 minutes after the disconnection, the wireless accessory 201 will remain in the near-owner mode. During the duration of the connection and until the next key rotation, the wireless accessory will set the keep-alive bit in the status field of the advertisement packet. When a timer event occurs at 14 minutes on the mobile device 102B, the mobile device 102B does not perform a connection (804) because the keep-alive bit is set in the near-owner advertisement.

[0081] At the 15-minute mark, the wireless accessory 201 will rotate to a new key and start broadcasting a new beacon identifier based on the new key. During key rotation, the hold bit in the status field is cleared. At the 15-minute mark, the mobile devices 102A - 102B also rotate the key used to connect to the wireless accessory 201 and will use the new key to connect to the wireless accessory 201. When the opportunistic timer on mobile device 102B fires at 16.9 minutes, mobile device 102B will use the new key to connect to the wireless accessory (806). Establishing the connection causes the wireless accessory 201 to set the hold bit and reset the near owner timeout. When the connection is terminated, the countdown to the near owner timeout begins. Subsequent opportunistic timer events occurring at 17.1 minutes (808) and 29.3 minutes (810) on mobile device 102A will not result in a connection to the wireless accessory 201 due to the presence of the hold bit in the status field of the near owner advertisement packet. Then during key rotation on the wireless accessory 201, the hold bit is cleared at the 30-minute mark. Mobile device 102 detects that the wireless accessory 201 was not held during the opportunistic timer event at 32 minutes and establishes a connection to the wireless accessory 201 (812). In response to the timer event at 42 minutes, mobile device 102A does not establish a connection (814).

[0082] Since the opportunistic timers on mobile devices 102A - 102B can fire earlier or later, it is possible for timer events to occur twice during the same key rotation period. For example, two timer events occur between the 15-minute mark and the 30-minute mark on mobile device 102A. If it were not for the timer event at 32 minutes occurring on mobile device 102B, the wireless accessory 201 would have transitioned to the field mode. In the case of a 15-minute near owner timeout, depending on the duration of the connection (806) established at 16.9 minutes, a field mode transition may still occur during a short period before the connection (812) made by mobile device 102B at 32 minutes.

[0083] Figure 8BIllustrates how multiple timer firings during a key rotation period can cause a transition to the wild mode. Mobile device 102A may connect (822) to wireless accessory 201 at the one-minute mark and connect again (826) at the 15.5-minute mark. Mobile device 102B will not connect (824) at the 14.0-minute mark because the hold bit is set by wireless accessory 201. Mobile device 102B will not connect (828) at the 28-minute mark because the hold bit is set. However, due to an early opportunistic wake-up, mobile device 102A will also not connect (830) at the 29.3-minute mark. A dual hold timer event during the same key rotation period can cause a longer period of time to elapse before the next event fires at either mobile device 102A or mobile device 102B, causing a near-owner timeout to occur on wireless accessory 201. The near-owner timeout occurs within 15 minutes after the termination of the last secure connection. Wireless accessory 201 will then begin to broadcast in the wild mode 840 and become visible to detector devices, even if wireless accessory 201 is actually near the associated owner device. In one scenario, wireless accessory 201 will remain in the wild mode until it returns to the near-owner mode for a connection (832) made by mobile device 102B at 42 minutes. When the next timer event occurs at 43 minutes, mobile device 102 will not connect (834) to mobile device 102 because the hold bit is set and mobile device 102B causes wireless accessory 201 to return to the near-owner mode one minute earlier.

[0084] Various solutions can be applied to prevent wireless accessory 201 from broadcasting in the wild mode 840 or to reduce the duration for which wireless accessory 201 is in the wild mode. In one embodiment, if either mobile device 102A or mobile device 102B detects a wild mode packet that matches wireless accessory 201, the device can immediately connect to wireless accessory 201 to place it back in the near-owner mode. In one embodiment, the near-owner timeout and opportunistic timer settings can be adjusted to reduce the likelihood of dual timer events during the same key rotation period.

[0085] Figures 9A to 9B Illustrates a state and connection timing diagram of multiple owner devices and wireless accessories according to an additional embodiment. In one embodiment, a 20-minute near-owner timeout is used along with an 18-minute opportunistic timer. This timer configuration significantly reduces the likelihood of two hold timer firings occurring within a single 15-minute key rotation period. Additionally, if an entire key rotation period is missed, the timer is likely to fire before wireless accessory 201 transitions to the wild mode.

[0086] In Figures 9A to 9BIn this case, the upper portion of the timeline of the wireless accessory 201 indicates the state of the hold bit, while the lower portion indicates whether the wireless accessory 201 is in the near-owner mode. As Figure 9A shown, under an 18-minute opportunity timer, a 20-minute near-owner timeout enables the wireless accessory 201 to be consistently held in the near-owner mode by the mobile devices 102A - 102B. The mobile device 102A can make connections (902, 906, 910) at 1 minute, 10 minutes, and 37 minutes respectively. No connection is made at 55 minutes (914) because the mobile device 102B holds the wireless accessory 201 through a connection (912) made at 46 minutes. The mobile device 102B does not establish a hold connection (904, 908) at 8 minutes and 27 minutes because the mobile device 102A pre-holds the wireless accessory 201 during the corresponding key rotation period.

[0087] Figure 9A The timer configuration of does not address the scenario where the device commonly used to perform holding leaves the wireless range of the wireless accessory 201. As Figure 9B shown, if the mobile device 102A leaves the range of the wireless accessory 201 within a certain period of time after the connection (906) made by the mobile device 102A at the 19-minute mark, the wireless accessory 201 can transition to the wild mode at approximately the 39-minute mark and can remain in the wild mode until the mobile device 102B places the wireless accessory back into the near-owner mode through a connection (912) made by the mobile device 102B at the 46-minute mark. One mitigation option is to configure the mobile devices 102A - 102B to connect to the accessory immediately upon detecting a wild-mode advertisement packet resolved to the wireless accessory 201. In one embodiment, the wild-mode transition can be completely avoided by synchronizing the hold timers of the mobile devices 102A - 102B.

[0088] Figure 10 shows the state and connection timing diagrams of multiple owner devices and a wireless accessory using synchronized hold timers. In one embodiment, once the mobile devices 102A - 102B determine that they are each holding the wireless accessory 201, the hold timers can be synchronized. The mobile device 102A can make a connection (1002) at the one-minute mark and place the mobile device 102 in the near-owner mode. The mobile device 102B will not make a connection (1004) in response to a timer event at eight minutes because the hold bit is set by the wireless accessory 201. Then, the mobile devices 102A - 102B can synchronize their timers with each trigger within 2 - 3 minutes after the key rotation, where a random variation is added to each timer so that the two devices do not attempt to hold the wireless accessory 201 simultaneously.

[0089] Once synchronized, mobile device 102B can make a connection at the 17.1-minute mark (1006) before the near-owner timeout occurs at 21 minutes. Due to the presence of a sustain bit in the status field broadcast by wireless accessory 201, mobile device 102A does not make a connection (1008) in response to a sustain timer event at 17.2 minutes. Mobile device 102A can make a connection (1010) in response to a timer event at 32 minutes before the near-owner timeout at 37.1 minutes. In response to a timer event that occurs at 32.2 minutes on mobile device 102B, no connection needs to be established (1012). If mobile device 102A goes out of range, mobile device 102B can maintain wireless accessory 201 at the same rhythm as mobile device 102A. When mobile device 102A is out of range before the near-owner timeout at 52 minutes, mobile device 102B can make a connection (1014) in response to a timer event at 47.4 minutes. When mobile device 102B is out of range, mobile device 102A can make a connection (1016) in response to a timer event at 62.1 minutes before the near-owner timeout at 67.4 minutes.

[0090] The synchronization sustain timer can be an exact timer or an opportunistic timer. The exact timer will fire on schedule but can result in an increased number of system wakes, which can increase the total power consumption of the device. However, depending on the specific implementation of the opportunistic timer, it may be difficult to constrain the time period during which the opportunistic timer will fire in some systems. In one embodiment, a dual-sustain timer system can be used, which includes a combination of an opportunistic timer and an exact timer. The exact timer serves as a backup timer for the opportunistic timer. If an opportunistic timer event occurs within the range of the expected firing time, the next exact timer can be canceled and no additional wakes will be required. If the opportunistic timer fires outside the threshold of the expected time, the exact timer can be maintained.

[0091] In some embodiments, the dual-sustain timer system can be implemented by a dual-mode timer that has the characteristics of both an exact timer and an opportunistic timer. In such embodiments, a dual-mode timer can be defined that will not fire later than a specified time but can fire opportunistically as early as the time defined by a specified early firing percentage. For example, the dual-mode timer can be defined to have a specified time of 15 minutes and an early firing percentage of 90 percent of the timer value (13.5 minutes). In such examples, it is guaranteed that the dual-mode timer fires at some point between 13.5 minutes and 15 minutes, thus firing opportunistically at any time between 13.5 minutes and 15 minutes to merge with another wake event or firing at 15 minutes if the opportunistic firing does not occur.

[0092] Figure 11 Shows the status and connection timing diagrams of multiple owner devices and wireless accessories using a dual-maintenance timer and / or a dual-mode timer. The near-owner maintenance state is shown above the timeline of the wireless accessory 201, while the near-owner state is shown below the timeline. In the illustrated embodiment, the opportunistic maintenance timer is set for 15 minutes, with a 16-minute near-owner timeout, and a 15-minute key rotation period.

[0093] In one scenario, the mobile device 102A may connect (1102) to the wireless accessory 201 and place the wireless accessory 201 in the near-owner mode. The wireless accessory 201 will set the maintenance bit in the near-owner advertisement status field. The opportunistic timer of the mobile device 102A may be configured to fire at 15 minutes, but may opportunistically fire at 13.5 minutes to merge with another wake event. Due to the early firing of the opportunistic timer, the maintenance bit remains set by the wireless accessory and no connection is established (1104). To prevent a field mode transition at the wireless accessory 201, the backup timer may fire shortly after the start of the new key rotation period (e.g., 15.5 minutes) and connect (1106) to the wireless accessory 201 to prevent the wireless accessory 201 from transitioning to the field mode within 17 minutes after the termination of the previous encrypted connection. When the opportunistic timer event occurs on the mobile device 102A within a threshold of the expected time, the backup timer may be canceled. For example, if the maintenance timer on the mobile device 102A is expected to fire shortly after the new key rotation period starts at the 30-minute mark and fires at 30.2 minutes, the mobile device 102A may connect (1108) to the wireless accessory 201 to perform near-owner maintenance and prevent the wireless accessory 201 from entering the field mode at 31.5 minutes (which is 16 minutes after the most recent connection to the wireless accessory 201). The mobile device 102A may then cancel (1110) the backup timer scheduled to fire at 30.5, which may prevent an additional wake event from occurring on the mobile device 102A (if the device would be in a low-power state when the backup timer event is scheduled to occur).

[0094] Wake mitigation may be applied to the dual-timer system to further reduce the number of increased wakes that may occur due to the use of the backup timer. In one embodiment, the backup timer may be configured as a non-wake timer. Instead of waking the application processor of the mobile device 102A, a low-power processor (such as a wireless processor) may check the scan cache where advertisement packets may be stored when the mobile device 102A is in a low-power state. If the stored packets indicate that any nearby wireless accessories have been maintained, the wake event may be avoided.

[0095] In one embodiment, when within the wireless range of the wireless accessory 201, a similar timer event may occur for the mobile device 102B. In another embodiment, the mobile device 102B may be configured to use a dual-mode timer that opportunistically triggers during an early trigger period 1112 that may span between time T1 and time T2. If the dual-mode timer does not opportunistically trigger during the early trigger period 1112, the dual-mode timer will trigger at time T2. When the dual-mode timer triggers, the mobile device 102B may check the status of the sustain bit in the status field of the advertisement packet broadcast by the wireless accessory 201 to determine whether to perform a sustain operation on the wireless accessory 201. If the status field indicates that the accessory has not been recently sustained, the mobile device 102B will connect to the wireless accessory 201.

[0096] In various embodiments, a mobile device may be configured to use any of the timer systems described herein to sustain a wireless accessory. All mobile devices may be configured to use the same timer system. Alternatively, different mobile devices may be configured to use different timer systems. The timer system may be configured based on the type of mobile device, or may vary based on the software, hardware, or firmware version of the mobile device and / or wireless accessory.

[0097] Figure 12 An electronic device 1200 is shown that includes hardware and software logic to implement multi-device near-owner sustainment of a wireless accessory. The electronic device 1200 can be any electronic device configured to perform near-owner sustainment. The electronic device 1200 includes a processing system 1204 having multiple types of processors. The electronic device 1200 also includes one or more memory devices configured as a system memory 1210. The processing system 1204 includes an application processor 1205, a sensor processor 1206, a security processor 1207, and a wireless processor 1208. The application processor 1205 can be a multi-core processor, where different cores have different performance and / or efficiency levels. The electronic device also includes one or more speaker devices 1201 to enable playback of the audio portion of media, alerts, warnings, notifications, and / or phone calls.

[0098] The network interface 1202 is coupled to the wireless processor 1208 and includes a set of wireless radio components 1203A - 1203B. The network interface 1202 can enable support for wireless networking protocols such as, but not limited to, Bluetooth, Wi-Fi, Near Field Communication (NFC), and / or other wireless networking technologies. In some specific implementations, the network interface 1202 can also support a wired network connection. In one embodiment, the network interface 1202 and the wireless processor 1208 include hardware and / or software logic to optimize the coexistence of different wireless protocols communicating in the same or similar frequency bands. For example, the duty cycle of Bluetooth transmissions can be reduced during heavy use of Wi-Fi in the 2.4 GHz band. The duty cycle that can be reduced performs scans for Bluetooth advertisement packets or connection attempts to wireless accessories over a longer period of time to avoid interfering with Wi-Fi transmissions. When heavy 2.4 GHz Wi-Fi use stops, scanning or connection can resume at a higher duty cycle.

[0099] The wireless processor 1208 includes on-chip memory or a memory device attached that can be used as a scan cache 1218. The scan cache 1218 can store advertisement packets received via one or more of the wireless radio components 1203A - 1203B when the application processor 1205 is in a low power state. When the application processor 1205 wakes up due to user use of the electronic device 1200 or in response to a timer wake event, the application processor 1205 can check the scan cache for the received advertisement packets before performing a discovery scan. In some scenarios, the discovery scan can be bypassed. For example, if the scan cache 1218 includes a near owner advertisement packet from the current key rotation period indicating that a wireless accessory has been maintained, the discovery scan for that wireless accessory can be skipped.

[0100] The electronic device 1200 also includes a set of sensor devices 1209. The sensor devices 1209 include various sensors, including but not limited to motion sensors, light sensors, proximity sensors, biometric sensors, audio sensors (e.g., microphones), and image sensors (e.g., cameras). The sensor devices 1209 can also include accelerometers, gyroscopes, or other motion sensors that can detect and analyze the movement of the electronic device 1200. The sensor processor 1206 can implement low power monitoring of the always-on sensors within the suite of sensor devices 1209.

[0101] The system memory 1210 can be a system virtual memory having an address space that includes volatile and non-volatile memory. The system memory 1210 can store instructions for software logic executed by the processing system 1204. The software logic includes system logic such as accessory maintenance logic 1212, opportunistic timer logic 1214, and backup timer logic 1216.

[0102] The accessory maintenance logic 1212 enables the electronic device 1200 to perform a near-owner maintenance operation. The near-owner maintenance operation includes detecting a field mode advertisement packet from a known wireless accessory and determining the maintenance status of the wireless accessory. If the detected wireless accessory is in the field mode or does not maintain the near-owner mode, the accessory maintenance logic can determine or contribute to determining a key for placing the wireless accessory in the near-owner mode and for connecting to the wireless accessory. Once connected to the wireless accessory, the accessory maintenance logic 1212 can determine the operational status of the wireless accessory, including collecting error and / or crash logs. The accessory maintenance logic 1212 can also synchronize and / or reset timers and counters on the wireless accessory.

[0103] The opportunistic timer logic 1214 can configure an opportunistic timer on the electronic device 1200. The timer allows process scheduling of delayed or periodic actions. The timer waits until a specific interval has elapsed and then fires to perform a specific action such as checking the scan cache 1218 or performing a wireless discovery scan. When the application processor 1205 and other systems wake up from their low-power idle state, waking the system from the idle state incurs an energy cost. Thus, reducing the number of wake-ups by performing some delayed tasks earlier or later during another wake-up can reduce the total power consumption of the electronic device 1200. In one embodiment, a dual-mode timer that utilizes both the opportunistic timer logic 1214 and the backup timer logic 1216 can be configured.

[0104] Figure 13 A method 1300 performed by an electronic device to implement multi-device near-owner maintenance of a wireless accessory is shown. The method 1300 can be executed by the hardware and software logic of the electronic devices described herein (e.g., Figure 12 the electronic device 1200, the mobile devices 102A - 102B).

[0105] The operating system on the electronic device can receive a timer event based on a maintenance timer (block 1301). The maintenance timer can be a periodic timer that enables the electronic device to periodically check for nearby unmaintained wireless accessories (block 1302) according to the advertisement packet type and the maintenance bit in the status field of the advertisement packet. The unmaintained wireless accessory is an accessory in an unmaintained near-owner mode. The timer can be an opportunistic timer or a precise timer (e.g., a backup timer). The check for unmaintained accessories can include reading the scan buffer to determine whether an advertisement packet for the wireless accessory has been received. The status fields of these packets can be checked to determine the maintenance status of these accessories. The electronic device can also perform a wireless discovery scan to collect a current survey of nearby wireless devices and accessories to determine whether any of these accessories can be maintained.

[0106] If any unmaintained accessory is detected (block 1303, yes), the electronic device may connect to the unmaintained accessory to reset the near-owner timeout (block 1304). In this case, the connection to the accessory is an encrypted wireless connection. In response to receiving the encrypted wireless connection, the wireless accessory will set the maintained bit in the status field of the near-owner advertisement packet until the end of the current key rotation period. The connection also causes the accessory to reset its near-owner timeout. The electronic device may then perform any necessary maintenance activities on the wireless accessory (block 1307). Maintenance activities may include, but are not limited to, synchronizing timers, setting or resetting internal counters, and checking error or crash logs.

[0107] If no accessory in the unmaintained near-owner mode is detected (block 1303, no), the electronic device may determine whether any known accessory is transmitting a beacon in the wild mode (block 1305). A wild mode accessory may be detected based on the type field in the packet header and / or based on the structure of the advertisement packet. Wild mode accessories belonging to other users may be logged for processing, and other logic on the electronic device may transmit a location estimate for the accessory to a device locator server. When detected, a known (e.g., owned or shared with a user account on the electronic device) wild mode accessory will be placed in the near-owner mode. If no known accessory is detected as transmitting a beacon in the wild mode (block 1305, no), the electronic device may continue with other activities or return to a low-power state. If a known accessory is detected as being in the wild mode (block 1305, yes), the electronic device may connect to the accessory to place the accessory in the near-owner mode (block 1306). The electronic device may then perform any necessary maintenance activities on the wireless accessory (block 1307). In one implementation, the electronic device may connect to known wild mode accessories even when not during a maintenance period, as long as those accessories are detected. In one implementation, a primary location service device associated with a user may periodically connect to the wireless accessory even if the accessory indicates that it has been maintained. In one implementation, when the application processor is in a low-power state, the electronic device may perform at least a portion of the operations of method 1300.

[0108] Additional exemplary electronic devices

[0109] Figure 14 is a block diagram of a device architecture 1400 for a mobile or embedded device according to an implementation. The device architecture 1400 includes a memory interface 1402, a processing system 1404 including one or more data processors, an image processor and / or a graphics processing unit, and a peripheral device interface 1406. The various components may be coupled by one or more communication buses or signal lines. The various components may be separate logical components or devices or may be integrated in one or more integrated circuits, such as a system-on-chip integrated circuit.

[0110] The memory interface 1402 can be coupled to a memory 1450, which may include high-speed random access memory such as static random access memory (SRAM) or dynamic random access memory (DRAM) and / or non-volatile memory, such as but not limited to flash memory (e.g., NAND flash, NOR flash, etc.).

[0111] Sensors, devices, and subsystems can be coupled to the peripheral device interface 1406 to facilitate multiple functions. For example, a motion sensor 1410, a range sensor 1411, a light sensor 1412, and a proximity sensor 1414 can be coupled to the peripheral device interface 1406 to facilitate mobile device functions. The motion sensor 1410 can include an inertial measurement unit (IMU), which is a multi-axis sensor that measures and reports specific forces, angular velocities, and / or magnetic fields experienced by the device. The range sensor 1411 can include an ultra-wideband radio transceiver that enables peer-to-peer ranging with other similarly equipped devices.

[0112] There may also be one or more biometric sensors 1415, such as a fingerprint scanner for fingerprint recognition or an image sensor for face recognition. Other sensors 1416 can also be connected to the peripheral device interface 1406, such as a positioning system (e.g., a global positioning sensor (GPS) receiver), a temperature sensor, or other sensing devices to facilitate related functions. A camera subsystem 1420 and an optical sensor 1422 (such as a charge-coupled device (CCD) or a complementary metal-oxide semiconductor (CMOS) optical sensor) can be utilized to facilitate camera functions, such as taking photos and video clips.

[0113] Communication functions can be facilitated by one or more wireless communication subsystems 1424, which may include radio frequency receivers and transmitters and / or optical (e.g., infrared) receivers and transmitters. The specific design and implementation of the wireless communication subsystem 1424 can depend on the communication network through which the mobile device is intended to operate. For example, a mobile device including the illustrated device architecture 1400 can include a wireless communication subsystem 1424 designed to operate over a GSM network, a CDMA network, an LTE network, a Wi-Fi network, a Bluetooth network, or any other wireless network. Specifically, the wireless communication subsystem 1424 can provide a communication mechanism in which a media playback application can retrieve resources from a remote media server or retrieve scheduling events from a remote calendar or event server.

[0114] The audio subsystem 1426 can be coupled to a speaker 1428 and a microphone 1430 to facilitate voice-enabled functions such as speech recognition, speech reproduction, digital recording, and telephone functionality. In the intelligent media device described herein, the audio subsystem 1426 can be a high-quality audio system including support for virtual surround sound.

[0115] The I / O subsystem 1440 can include a touchscreen controller 1442 and / or other input controllers 1445. For a computing device including a display device, the touchscreen controller 1442 can be coupled to a touch-sensitive display system 1446 (e.g., a touchscreen). The touch-sensitive display system 1446 and the touchscreen controller 1442 can detect contact, movement, and / or pressure, for example, using any of a variety of touch and pressure sensing technologies, including but not limited to capacitive, resistive, infrared, and surface acoustic wave technologies, as well as other proximity sensor arrays or other elements for determining one or more points of contact with the touch-sensitive display system 1446. The display output of the touch-sensitive display system 1446 can be generated by a display controller 1443. In one embodiment, the display controller 1443 can provide frame data to the touch-sensitive display system 1446 at a variable frame rate.

[0116] In one embodiment, a sensor controller 1444 is included to monitor, control, and / or process data received from one or more of the motion sensor 1410, the light sensor 1412, the proximity sensor 1414, or other sensors 1416. The sensor controller 1444 can include logic to interpret the sensor data to determine the occurrence of one or more of a motion event or activity by analyzing the sensor data from the sensors.

[0117] In one embodiment, the I / O subsystem 1440 includes other input controllers 1445, which can be coupled to other input / control devices 1448, such as one or more buttons, rocker switches, thumb wheels, infrared ports, USB ports, and / or pointer devices such as a stylus, or up / down buttons for controlling the volume of control devices such as the speaker 1428 and / or the microphone 1430.

[0118] In one embodiment, a memory 1450 coupled to the memory interface 1402 can store instructions for an operating system 1452, including portable operating system interface (POSIX)-compatible and -incompatible operating systems or embedded operating systems. The operating system 1452 can include instructions for handling basic system services and for performing hardware-related tasks. In some implementations, the operating system 1452 can be a kernel.

[0119] The memory 1450 may also store communication instructions 1454 to facilitate communication with one or more additional devices, one or more computers, and / or one or more servers, such as retrieving network resources from a remote network server. The memory 1450 may also include user interface instructions 1456, including graphical user interface instructions that facilitate graphical user interface processing.

[0120] In addition, the memory 1450 may store sensor processing instructions 1458 that facilitate sensor-related processing and functions; telephone instructions 1460 that facilitate telephone-related processes and functions; instant messaging instructions 1462 that facilitate processes and functions related to electronic messaging; web browser instructions 1464 that facilitate processes and functions related to web browsing; media processing instructions 1466 that facilitate processes and functions related to media processing; location service instructions including GPS and / or navigation instructions 1468 and Wi-Fi-based location instructions that facilitate location-based functions; camera instructions 1470 that facilitate processes and functions related to a camera; and / or other software instructions 1472 that facilitate other processes and functions such as security processes and functions and system-related processes and functions. The memory 1450 may also store other software instructions, such as web video instructions that facilitate processes and functions related to web video; and / or web shopping instructions that facilitate processes and functions related to web shopping. In some specific implementations, the media processing instructions 1466 are divided into audio processing instructions and video processing instructions to respectively facilitate processes and functions related to audio processing and processes and functions related to video processing. A mobile device identifier, such as an International Mobile Equipment Identity (IMEI) 1474 or a similar hardware identifier, may also be stored in the memory 1450.

[0121] Each of the instructions and applications identified above may correspond to an instruction set for performing one or more of the functions described above. These instructions need not be implemented as separate software programs, processes, or modules. The memory 1450 may include additional instructions or fewer instructions. In addition, various functions may be performed in hardware and / or software, including in one or more signal processing and / or application specific integrated circuits.

[0122] Figure 15FIG. 1500 is a block diagram of a computing system 1500 according to an embodiment. The illustrated computer system 1500 is intended to represent a family of computing systems (wired or wireless), including, for example, one or more specific implementations of a desktop computer system, a laptop computer system, a tablet computer system, a cellular phone, a personal digital assistant (PDA) including a cellular-enabled PDA, a set-top box, an entertainment system or other consumer electronic device, a smart appliance device, or a smart media playback device. Alternative computing systems may include more, fewer, and / or different components. The computing system 1500 may be used to provide a computing device and / or a server device to which the computing device may be connected.

[0123] The computing system 1500 includes a bus 1535 or other communication device for conveying information, and a processor 1510 coupled to the bus 1535 that can process information. Although the computing system 1500 is illustrated as having a single processor, the computing system 1500 may include multiple processors and / or co-processors. The computing system 1500 may also include a memory 1520 in the form of a random access memory (RAM) or other dynamic storage device coupled to the bus 1535. The memory 1520 may store information and instructions executable by the processor 1510. During execution of instructions by the processor 1510, the memory 1520 may also be a main memory for storing temporary variables or other intermediate information.

[0124] The computing system 1500 may also include a read only memory (ROM) 1530 and / or another data storage device 1540 coupled to the bus 1535 that can store information and instructions for the processor 1510. The data storage device 1540 may be or include a variety of storage devices, such as a flash memory device, a magnetic disk, or an optical disk, and may be coupled to the computing system 1500 via the bus 1535 or via a remote peripheral interface.

[0125] The computing system 1500 may also be coupled to a display device 1550 via the bus 1535 to display information to a user. The computing system 1500 may also include an alphanumeric input device 1560 that includes alphanumeric keys and other keys that may be coupled to the bus 1535 to convey information and command selections to the processor 1510. Another type of user input device includes a cursor control 1570 device, such as a touchpad, a mouse, a trackball, or cursor direction keys, for conveying direction information and command selections to the processor 1510 and for controlling cursor movement on the display device 1550. The computing system 1500 may also receive user input from a remotely coupled device communicatively coupled via one or more network interfaces 1580.

[0126] The computing system 1500 may also include one or more network interfaces 1580 to provide access to a network such as a local area network. The network interface 1580 may include, for example, a wireless network interface having an antenna 1585, which may represent one or more antennas. The computing system 1500 may include multiple wireless network interfaces, such as a combination of Wi-Fi, near field communication (NFC) and / or cellular phone interfaces. The network interface 1580 may also include, for example, a wired network interface to communicate with a remote device via a network cable 1587, which may be, for example, an Ethernet cable, a coaxial cable, an optical fiber cable, a serial cable, or a parallel cable.

[0127] In one embodiment, the network interface 1580 may provide access to a local area network, for example, by conforming to the IEEE 802.11 wireless standard, and / or the wireless network interface may provide access to a personal area network, for example, by conforming to the Bluetooth standard. Other wireless network interfaces and / or protocols may also be supported. As a supplement or alternative to communicating via a wireless LAN standard, the network interface 1580 may use, for example, a time division multiple access (TDMA) protocol, a global system for mobile communications (GSM) protocol, a code division multiple access (CDMA) protocol, a long term evolution (LTE) protocol, a fifth generation (5G) communication protocol, and / or any other type of wireless communication protocol to provide wireless communication.

[0128] The computing system 1500 may also include one or more energy sources 1505 and one or more energy measurement systems 1545. The energy source 1505 may include an AC / DC adapter coupled to an external power source, one or more batteries, one or more charge storage devices, a USB charger, or other energy sources. The energy measurement system includes at least one voltage or current measurement device that may measure the energy consumed by the computing system 1500 during a predetermined period of time. In addition, one or more energy measurement systems may measure, for example, the energy consumed by a display device, a cooling subsystem, a Wi-Fi subsystem, or other commonly used or high-energy consumption subsystems.

[0129] References to "an embodiment" or "embodiments" in this specification mean that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the invention. The phrase "in an embodiment" appearing in various places in this specification does not necessarily refer to the same embodiment. The processes depicted in the following figures may be executed by processing logic that includes hardware (e.g., circuits, dedicated logic), software (as instructions on a non-transitory machine-readable storage medium), or a combination of hardware and software. Reference will now be made in detail to various embodiments, examples of which are illustrated in the figures. Numerous specific details are given in the following detailed description in order to provide a thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention may be practiced without these specific details. In other instances, well-known methods, procedures, components, circuits, and networks have not been described in detail so as not to unnecessarily obscure aspects of the embodiments.

[0130] It will also be understood that although terms such as "first", "second", etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first contact may be named a second contact, and similarly, a second contact may be named a first contact, without departing from the scope of the invention. Both the first contact and the second contact are contacts, but they are not the same contact.

[0131] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of all embodiments. As used in the specification of the present invention and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. It will also be understood that the term "comprises" and / or "comprising" when used in this specification is specifying the presence of the stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0132] As used herein, depending on context, the term "if" can be interpreted to mean "when" or "upon" or "in response to determining" or "in response to detecting". Similarly, depending on context, the phrase "if it is determined that..." or "if [stated condition or event] is detected" can be interpreted to mean "when it is determined that..." or "in response to determining..." or "when [stated condition or event] is detected" or "in response to detecting [stated condition or event]".

[0133] This document describes computing devices, user interfaces for such devices, and associated processes for using such devices. In some embodiments, the computing device is a portable communication device, such as a mobile phone, that also includes other functions such as PDA and / or music player functions. Exemplary portable multifunction devices include, but are not limited to, those from Apple Computer, Inc. (Cupertino, California) and iPod devices. In the descriptions and drawings of this application in which wireless devices, wireless accessories, or wireless accessory devices are described or shown, unless otherwise indicated, the properties described or shown generally apply to any type of wireless device, wireless accessory, wireless accessory device, or other form of electronic device that includes a wireless communication subsystem capable of broadcasting wireless beacons within the electromagnetic spectrum.

[0134] In the foregoing description, exemplary embodiments have been described. It is evident that various modifications can be made thereto without departing from the broader spirit and scope of the disclosure. Accordingly, the specification and drawings are to be regarded in an illustrative rather than a limiting sense. The specific details provided in the description and examples can be used anywhere in one or more embodiments. The various features of different embodiments or examples can be combined differently with some features included and other features excluded to accommodate a variety of different applications. Examples can include a subject matter such as a method, an apparatus for performing acts of the method, at least one machine-readable medium including instructions that, when executed by a machine, cause the machine to perform the acts of the method, or an apparatus or system that performs actions in accordance with the embodiments and examples described herein. Additionally, the various components described herein can be apparatuses for performing the operations or functions described herein.

[0135] The embodiments described herein provide a technique for arbitrating the maintenance of wireless accessories among multiple owner devices. The presence of wireless devices and / or accessories that cannot maintain an independent network connection can be detected by network-connected wireless devices, and the location of the detected devices and / or accessories can be reported to a device location service. Since the wireless device and / or accessory does not have an independent network connection, periodic maintenance is performed on these devices by nearby owner devices paired with or associated with the wireless device and / or accessory. In the absence of an arbitration mechanism, various owner devices may continuously attempt to perform maintenance operations on nearby wireless accessories.

[0136] One embodiment provides a method performed on a wireless device. The method includes establishing a first encrypted wireless connection with a first electronic device, wherein the first encrypted wireless connection is established using cryptographic material associated with a first key rotation period. The method additionally includes setting an indicator in a status field of a first wireless advertisement packet type. The first wireless advertisement packet type is associated with a first broadcast mode, and the indicator indicates that the wireless device has been maintained during the first key rotation period. The method performed on the wireless device additionally includes: broadcasting a wireless beacon having the first advertisement packet type; and in response to disconnecting from the encrypted wireless connection, starting a counter associated with a timeout period. The timeout triggers the wireless device to transition to a second broadcast mode. The wireless device will cyclically transition to a new cryptographic key for establishing an encrypted connection with the device. During the transition from the first key rotation period to a second key rotation period, the wireless device may reset the indicator in the status field of the first wireless advertisement packet type. In response to establishing a second encrypted wireless connection with a second electronic device, the electronic device may reset the counter associated with the timeout period. The second encrypted wireless connection is established using cryptographic material associated with the second key rotation period. The second wireless device is associated with the first electronic device and may receive the cryptographic material from the first electronic device or via a repository shared with the first electronic device.

[0137] One implementation provides a data processing system on a wireless device. The data processing system includes: a memory device; and one or more processors configured to execute instructions stored in the memory device, wherein the instructions cause the one or more processors to perform operations to establish a first encrypted wireless connection with a first electronic device, and in response to the establishment of the first encrypted wireless connection: set an indicator in a status field of a first wireless advertisement packet type, wherein the indicator indicates that a maintenance operation has been performed on the wireless device during a first key rotation period; and broadcast a wireless beacon having the first wireless advertisement packet type. In response to disconnecting from the first encrypted wireless connection, the data processing system may start a counter associated with a timeout period. Expiration of the timeout period may trigger the wireless device to transition from a first broadcast mode to a second broadcast mode. The data processing system may then establish a second encrypted wireless connection with a second electronic device. The second electronic device may be associated with an account shared with the first electronic device. The data processing system may then reset the counter associated with the timeout period after establishing the second encrypted wireless connection.

[0138] One implementation provides a non-transitory machine-readable medium storing instructions that cause one or more processors of a wireless device to perform operations that include establishing a first encrypted wireless connection with a first electronic device, wherein the first encrypted wireless connection is established using cryptographic material associated with a first key rotation period. The operations additionally include setting an indicator in a status field of a first wireless advertisement packet type. The first wireless advertisement packet type is associated with a first broadcast mode, and the indicator indicates that the wireless device has been maintained during the first key rotation period. The operations additionally include: broadcasting a wireless beacon having the first advertisement packet type; and in response to disconnecting from the encrypted wireless connection, starting a counter associated with a timeout period. The timeout triggers the wireless device to transition to a second broadcast mode. The wireless device will cyclically rotate to a new cryptographic key for establishing an encrypted connection with the device. During the transition from the first key rotation period to the second key rotation period, the wireless device may reset the indicator in the status field of the first wireless advertisement packet type. In response to establishing a second encrypted wireless connection with a second electronic device, the electronic device may reset the counter associated with the timeout period.

[0139] From the foregoing description, those skilled in the art will appreciate that the broad techniques of these implementations can be implemented in many forms. Thus, while implementations have been described in connection with specific examples of the implementations, the true scope of the implementations should not be so limited, as other modifications will become apparent to the skilled person after study of the drawings, specification, and appended claims.

Claims

1. A method on an electronic device, the method comprising: Retrieving a wireless advertisement packet that has been received from a wireless device upon expiration of a maintenance timeout period, wherein the maintenance timeout period corresponds to a time period for checking wireless devices that are not maintained; And In response to determining that a status field of the received wireless advertisement packet indicates that a maintenance operation needs to be performed: Establishing a wireless connection with the wireless device; And Sending a request to perform the maintenance operation to the wireless device, wherein the maintenance operation includes resetting a counter associated with a timeout period used by the wireless device to switch a broadcast mode.

2. The method according to claim 1, further comprising: Retrieving the wireless advertisement packet from a scan buffer; And Accessing the status field of the wireless advertisement packet to determine whether the maintenance operation needs to be performed.

3. The method according to claim 1, wherein the wireless advertisement packet type is associated with a first broadcast mode.

4. The method according to claim 1, wherein a wireless connection is established using cryptographic material associated with a key rotation period.

5. The method according to claim 1, further comprising: Resetting a timer at the wireless device; And Checking an error log of the wireless device.

6. The method according to claim 1, further comprising: Transmitting an estimated location of the wireless device.

7. The method according to claim 1, wherein the electronic device is in a low power mode.

8. A data processing system on a wireless device, the data processing system comprising: A storage device; And One or more processors configured to execute instructions stored in the memory device, wherein the instructions cause the one or more processors to perform operations to: Retrieve a wireless advertisement packet that has been received from a wireless device upon expiration of a maintenance timeout period, wherein the maintenance timeout period corresponds to a time period for checking wireless devices that are not maintained; And In response to determining that a status field of the received wireless advertisement packet indicates that a maintenance operation needs to be performed: Establish a wireless connection with the wireless device; And Send a request to perform the maintenance operation to the wireless device, wherein the maintenance operation includes resetting a counter associated with a timeout period used by the wireless device to switch a broadcast mode.

9. The data processing system according to claim 8, the one or more processors configured to perform operations to: Retrieve the wireless advertisement packet from a scan buffer; and Access the status field of the wireless advertisement packet to determine whether the maintenance operation needs to be performed.

10. The data processing system according to claim 8, wherein the wireless advertisement packet type is associated with a first broadcast mode.

11. The data processing system according to claim 8, wherein a wireless connection is established using cryptographic material associated with a key rotation period.

12. The data processing system according to claim 8, the one or more processors configured to perform operations to: Reset a timer at the wireless device; and Check an error log of the wireless device.

13. The data processing system according to claim 8, wherein the one or more processors are configured to perform operations to: Transmit a location estimate of the wireless device.

14. The data processing system according to claim 8, wherein the electronic device is in a low power mode.

15. A non-transitory machine-readable medium storing instructions that cause one or more processors of a wireless device to perform operations including: Upon expiration of the maintenance timeout period, retrieve wireless advertisement packets that have been received from the wireless device, where the maintenance timeout period corresponds to a time period for checking wireless devices that have not been maintained; And In response to determining that a status field of a received wireless advertisement packet indicates that a maintenance operation needs to be performed: Establish a wireless connection with the wireless device; And Send a request to perform the maintenance operation to the wireless device, wherein the maintenance operation includes resetting a counter associated with a timeout period used by the wireless device to switch between broadcast modes.

16. The non-transitory machine-readable medium according to claim 15, wherein the operations further include: Retrieve the wireless advertisement packet from a scan buffer; And Access the status field of the wireless advertisement packet to determine whether the maintenance operation needs to be performed.

17. The non-transitory machine-readable medium according to claim 15, wherein the wireless advertisement packet type is associated with a first broadcast mode.

18. The non-transitory machine-readable medium according to claim 15, wherein the wireless connection is established using cryptographic material associated with a key rotation period.

19. The non-transitory machine-readable medium according to claim 15, wherein the operation further comprises: Transmit a location estimate of the wireless device.

Citation Information

Patent Citations

  • Connecting method between Bluetooth devices and device

    CN103518418A

  • Method achieving bluetooth automatic return connection in Android system

    CN104967971A

  • Communication between host and accessory devices using accessory protocols via wireless transport

    CN105393564A

  • Positioning connection method, device and system, and wearable device

    CN107896283A

  • Method and device for connection of wireless earphone and wireless earphone

    CN109195053A