Electronic device and method by which electronic device manages object

The electronic device and method address the challenge of managing personal content inheritance by generating and managing access information to securely and legally transfer access rights to external users, ensuring secure and compliant content access.

WO2025127401A1PCT designated stage expired Publication Date: 2025-06-19SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/017005
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-27
Filing Date
2024-11-01
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

As IT technology advances and personal content storage on electronic devices increases, there is a growing need for managing personal content inheritance, particularly in regards to legal requirements and access rights after a user's death or incapacitation.

Method used

An electronic device and method for generating and managing access information, including access conditions and rights, to allow external users, such as heirs, to access stored objects. This involves encrypting objects based on verified access rights and information of external users, and transmitting access information to a server for confirmation and execution of access functions.

Benefits of technology

Enables secure and controlled access to personal content stored on electronic devices, ensuring compliance with legal requirements regarding inheritance and access rights, while maintaining the security and integrity of the content until authorized access is granted.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024017005_19062025_PF_FP_ABST
    Figure KR2024017005_19062025_PF_FP_ABST
Patent Text Reader

Abstract

An electronic device according to an embodiment of the present invention comprises: a display; a communication circuit; at least one processor; and a memory storing instructions. The instructions according to an embodiment, when executed by the at least one processor, may be set to cause the electronic device to: generate access information including an access condition for allowing an external user to access at least one object stored in the electronic device, and an access authority set to the at least one object; transmit the access information to a server via the communication circuit; enter an access mode when an instruction for executing an access function is received from the server that has confirmed satisfaction with the access condition; when, in the instruction, a first instruction for executing a first access function is included, identify, in the first instruction, information about the external user and an encryption key corresponding to the information about the external user; identify a first object able to access the information about the external user among objects for which the access authorities are set for access; and encrypt the first object with the encryption key. Other embodiments may be included.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic devices and methods for managing objects in electronic devices

[0001] The present disclosure relates to an electronic device and a method for managing objects in the electronic device.

[0002] With the widespread adoption of IT technology, the amount of personal content stored on electronic devices is rapidly increasing, and there is a growing interest in the property rights of such personal content and legal requirements related to inheritance.

[0003] As legal requirements regarding property interests and inheritance of personal content increase, service providers are providing services that allow users to send links to download content stored on servers operated by the service provider to people designated by the user in advance when a dormant condition set by the user (e.g., no access record for 3 months) occurs, or that allow the designated people to have limited access to content stored on the server.

[0004] An object stored in an electronic device can be accessed by an external user (e.g., an heir) and the access rights of the external user can be specified, and when a condition for allowing access to the object is satisfied, the object can be independently encrypted so that the object can be accessed (inherited) by each external user according to the access rights.

[0005] If the condition for allowing access to the object is the death of the user of the electronic device, the object stored in the electronic device can be maintained until the time of death.

[0006] An electronic device according to an embodiment may include a display, a communication circuit, at least one processor, and a memory storing instructions. The instructions according to an embodiment, when executed by the at least one processor, may cause the electronic device to generate access information including an access condition for allowing an external user to access at least one object stored in the electronic device and an access right set for the at least one object. The instructions according to an embodiment, when executed by the at least one processor, may cause the electronic device to transmit the access information to a server via the communication circuit. The instructions according to an embodiment, when executed by the at least one processor, may cause the electronic device to enter an access mode when receiving a command for executing an access function from the server that has confirmed satisfaction of the access condition. The commands according to one embodiment, when executed by the at least one processor, cause the electronic device to, if the commands include a first command for executing a first access function, verify information of an external user and a cryptographic key corresponding to the information of the external user in the first command. The commands according to one embodiment, when executed by the at least one processor, cause the electronic device to verify a first object that can access information of the external user among objects for which the access right is set to access. The commands according to one embodiment, when executed by the at least one processor, cause the electronic device to encrypt the first object with the cryptographic key.

[0007] According to one embodiment, a method for managing objects in an electronic device may include an operation of generating access information including an access condition for allowing an external user to access at least one object stored in the electronic device and an access right set for the at least one object. According to one embodiment, the method may include an operation of transmitting the access information to a server via the communication circuit. According to one embodiment, the method may include an operation of entering an access mode when a command for executing an access function is received from the server that has confirmed satisfaction of the access condition. According to one embodiment, the method may include an operation of checking information of an external user and an encryption key corresponding to the information of the external user in the first command if the command includes a first command for executing a first access function. According to one embodiment, the method may include an operation of checking a first object that can be accessed using information of the external user among objects for which the access right is set to access. According to one embodiment, the method may include an operation of encrypting the first object with the encryption key.

[0008] In one embodiment, a non-volatile storage medium storing commands is provided, wherein the commands, when executed by an electronic device, are configured to cause the electronic device to perform at least one operation, wherein the at least one operation may include an operation of generating access information including an access condition for allowing an external user to access at least one object stored in the electronic device and an access right set for the at least one object. The at least one operation according to one embodiment may include an operation of transmitting the access information to a server via the communication circuit. The at least one operation according to one embodiment may include an operation of entering an access mode when a command for executing an access function is received from the server that has confirmed satisfaction of a pre-existing access condition. The at least one operation according to one embodiment may include an operation of verifying information of an external user and an encryption key corresponding to the information of the external user in the first command when the command includes a first command for executing a first access function. The at least one operation according to one embodiment may include an operation of verifying a first object, among objects for which the access right is set to access, that can be accessed with information of the external user. In one embodiment, the at least one operation may include encrypting the first object with the encryption key.

[0009] FIG. 1 is a block diagram of an electronic device within a network environment according to one embodiment.

[0010] FIG. 2 is a drawing for explaining an operation of managing an object in an electronic device according to one embodiment.

[0011] Figure 3 is a block diagram of an electronic device according to one embodiment.

[0012] FIGS. 4A, 4B, 4C, and 4D are diagrams illustrating access of an object in an electronic device according to one embodiment.

[0013] FIGS. 5A and 5B are flowcharts for explaining operations for managing objects in an electronic device according to an embodiment.

[0014] FIG. 6 is a flowchart for explaining an operation of managing an object in an electronic device according to an embodiment.

[0015] FIG. 1 is a block diagram of an electronic device (101) within a network environment (100) according to an embodiment. Referring to FIG. 1, in the network environment (100), the electronic device (101) may communicate with the electronic device (102) via a first network (198) (e.g., a short-range wireless communication network), or may communicate with at least one of the electronic device (104) or the server (108) via a second network (199) (e.g., a long-range wireless communication network). According to an embodiment, the electronic device (101) may communicate with the electronic device (104) via the server (108). According to one embodiment, the electronic device (101) may include a processor (120), a memory (130), an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a connection terminal (178), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197). In some embodiments, the electronic device (101) may omit at least one of these components (e.g., the connection terminal (178)), or may have one or more other components added. In some embodiments, some of these components (e.g., the sensor module (176), the camera module (180), or the antenna module (197)) may be integrated into one component (e.g., the display module (160)).

[0016] The processor (120) may control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) by executing, for example, software (e.g., a program (140)), and may perform various data processing or calculations. According to one embodiment, as at least a part of the data processing or calculation, the processor (120) may store a command or data received from another component (e.g., a sensor module (176) or a communication module (190)) in a volatile memory (132), process the command or data stored in the volatile memory (132), and store the resulting data in a non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or a secondary processor (123) (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor) that can operate independently or together therewith. For example, if the electronic device (101) includes a main processor (121) and a secondary processor (123), the secondary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a specified function. The secondary processor (123) may be implemented separately from the main processor (121) or as a part thereof.

[0017] The auxiliary processor (123) may control at least a part of functions or states associated with at least one component (e.g., a display module (160), a sensor module (176), or a communication module (190)) of the electronic device (101), for example, on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (123) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (180) or a communication module (190)). In one embodiment, the auxiliary processor (123) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, on the electronic device (101) itself where the artificial intelligence model is executed, or can be performed through a separate server (e.g., server (108)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include multiple artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.

[0018] The memory (130) can store various data used by at least one component (e.g., processor (120) or sensor module (176)) of the electronic device (101). The data can include, for example, software (e.g., program (140)) and input data or output data for commands related thereto. The memory (130) can include volatile memory (132) or non-volatile memory (134).

[0019] The program (140) may be stored as software in the memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0020] The input module (150) can receive commands or data to be used in a component of the electronic device (101) (e.g., a processor (120)) from an external source (e.g., a user) of the electronic device (101). The input module (150) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).

[0021] The audio output module (155) can output audio signals to the outside of the electronic device (101). The audio output module (155) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. According to one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.

[0022] The display module (160) can visually provide information to an external party (e.g., a user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. According to one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.

[0023] The audio module (170) can convert sound into an electrical signal, or vice versa, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150), output sound through the sound output module (155), or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (101).

[0024] The sensor module (176) can detect the operating status (e.g., power or temperature) of the electronic device (101) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (176) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0025] The interface (177) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (101) with an external electronic device (e.g., the electronic device (102)). In one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0026] The connection terminal (178) may include a connector through which the electronic device (101) may be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0027] A haptic module (179) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. According to one embodiment, the haptic module (179) can include, for example, a motor, a piezoelectric element, or an electrical stimulation device.

[0028] The camera module (180) can capture still images and videos. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0029] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented as, for example, at least a part of a power management integrated circuit (PMIC).

[0030] A battery (189) may power at least one component of the electronic device (101). In one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0031] The communication module (190) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may operate independently from the processor (120) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Among these communication modules, the corresponding communication module can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules can be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can verify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) by using subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (196).

[0032] The wireless communication module (192) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in a high-frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), an external electronic device (e.g., the electronic device (104)), or a network system (e.g., the second network (199)). According to one embodiment, the wireless communication module (192) may support a peak data rate (e.g., 20 Gbps or more) for eMBB realization, a loss coverage (e.g., 164 dB or less) for mMTC realization, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for URLLC realization.

[0033] The antenna module (197) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). According to one embodiment, the antenna module (197) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). According to one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (198) or the second network (199), may be selected from the plurality of antennas, for example, by the communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device via the selected at least one antenna. According to some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (197).

[0034] In one embodiment, the antenna module (197) may form a mmWave antenna module. In one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high frequency band.

[0035] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).

[0036] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) via a server (108) connected to a second network (199). Each of the external electronic devices (102 or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations executed in the electronic device (101) may be executed in one or more of the external electronic devices (102, 104, or 108). For example, when the electronic device (101) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (101) may, instead of or in addition to executing the function or service itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (101) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server utilizing machine learning and / or a neural network. According to one embodiment, the external electronic device (104) or the server (108) may be included in the second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.

[0037] FIG. 2 is a drawing for explaining an operation of managing an object in an electronic device according to one embodiment.

[0038] Referring to the above FIG. 2, an electronic device (301) according to one embodiment can generate access information that sets access conditions for an external user to access at least one object stored in the electronic device (301) and access rights for the at least one object, and transmit the generated access information to a server (401).

[0039] The electronic device (301) according to one embodiment may include an electronic device owned by an individual user or an electronic device having a personal account.

[0040] An electronic device (301) according to one embodiment can generate the access information when, in a setting mode of an access function (e.g., an inheritance setting mode), the setting of an access function (e.g., an inheritance function) is activated by a user's selection, and the access conditions (e.g., an inheritance condition) and access rights (e.g., an inheritance right) selected (set) by the user are confirmed.

[0041] The access conditions according to one embodiment may include changes in the health or personal circumstances of the user of the electronic device (301), a designated period for access, and / or a designated date for access.

[0042] The access rights according to one embodiment may include at least one of access (e.g., inheritance) to allow external users to access the specified object, non-access (e.g., non-inheritance) to prevent external users from accessing the specified object, and / or deletion to delete the object.

[0043] According to an embodiment, the electronic device (301), when the access right is set to access, may generate the access information including object information set to access (e.g., type of object and / or name of object) and information of an external user (e.g., heir) who can access the object. According to an embodiment, the electronic device (301) may confirm information of an external user input (selected) by a user of the electronic device (e.g., phone number, email address, account information of a server where the electronic device of the external user is registered, and / or name and resident registration number, etc.).

[0044] According to an embodiment, the electronic device (301) may generate access information including object information (e.g., type and / or name of the object) set to non-access when the access right is set to non-access. According to an embodiment, the electronic device (301) may generate access information including object information set to deletion when the access right is set to deletion.

[0045] The electronic device (301) according to one embodiment may generate the access information and transmit it to the server (401) periodically or whenever the access conditions and / or access rights are changed.

[0046] At least one object stored in the electronic device (301) according to one embodiment may include content, files and / or folders.

[0047] According to one embodiment, when an electronic device (301) receives a command for executing an access function from a server (401) that has confirmed satisfaction of an access condition, the electronic device (301) switches to an access mode and executes an access function (e.g., access, non-access, and / or deletion) according to an access right set for at least one object stored in the electronic device (301) in the access mode.

[0048] According to an embodiment, the electronic device (301), if the command includes a first command for executing a first access function, may verify information of an external user included in the first command and an encryption key corresponding to the information of the external user, verify an object whose access right is set to access among at least one object stored in the electronic device (301), verify a first object to which information of the external user can access among the at least one object set to access, and encrypt the first object with the encryption key.

[0049] According to one embodiment, the electronic device (301) can, in the access mode, decrypt the encrypted first object and display the decrypted first object when it verifies information of the external user who can access the first object based on the input authentication information.

[0050] According to one embodiment, the electronic device (301), if the command includes a second command for executing a second access function, can verify an encryption key for non-access included in the second command, verify an object whose access right is set to non-access among at least one object stored in the electronic device, and encrypt the object set to non-access with the encryption key for non-access.

[0051] According to an embodiment, the electronic device (301) can, if the command includes a third command for executing a third access function, check for an object whose access right is set to delete among at least one object stored in the electronic device, and delete the object set to delete.

[0052] According to one embodiment, when a server (401) receives access information including access conditions and access rights from an electronic device (301), the server (401) can register the access information by matching it with user information of the electronic device (e.g., phone number and / or account information of a server to which the electronic device is registered).

[0053] According to one embodiment, the server (401) may be a server of a service provider that manages access to at least one object stored in the electronic device (301). For example, the server (401) may be an inheritance service provider that manages inheritance of at least one object stored in the electronic device (301).

[0054] According to one embodiment, the server (401) can confirm satisfaction of access conditions based on a physical document that can confirm a change in health or personal condition of a user of the electronic device (301) presented by an external user (e.g., an heir).

[0055] According to one embodiment, the server (401) can confirm satisfaction of the access condition by confirming the current date as the start date of a specified period set as the access condition or as a specified date.

[0056] According to an embodiment, the server (401), when it confirms that the access condition is satisfied, may transmit to the electronic device (301) a command for executing an access function, including at least one command among a first command including information of an external user for accessing an object set to access and an encryption key corresponding to the information of the external user, a second command including an encryption key for non-access for encrypting an object set to non-access, or a third command for deleting an object set to delete, based on the access right.

[0057] According to an embodiment, the server (401) may, based on the access right, verify information of an external user (e.g., an heir) who can access an object set to access, and transmit authentication information for accessing the object from the electronic device (301) to the electronic device (201a) of the external user. According to an embodiment, the server (401) may, based on information of the external user included in the access information (e.g., a phone number, an email address, account information of a server where the electronic device of the external user is registered, and / or a name and resident registration number, etc.), verify information of an external user who can access an object set to access.

[0058] According to an embodiment, the server (401) may transmit the authentication information via the external user's email address or message. According to an embodiment, the server (401) may generate an ID and password as authentication information and transmit them to the external electronic device (201a). According to an embodiment, the server (401) may transmit an encryption key corresponding to the external user's information transmitted to the electronic device (301) to encrypt an object to the external electronic device (201) as a decryption key.

[0059] According to one embodiment, the server (401) may store at least one object stored in the electronic device received from the electronic device (301), an access condition for executing an access function for the at least one object, and an access right set for the at least one object.

[0060] According to an embodiment, the server (401), when at least one object stored in the electronic device is stored in the server, and if the access condition is satisfied, the object set to be accessible according to the access right can be displayed or transmitted through the electronic device (201a) of the external user who has accessed the server (401) based on information of the external user who can access the object. According to an embodiment, the server (401) can identify the object set to be inaccessible according to the access right as an inaccessible object. According to an embodiment, the server (401) can delete the object set to be deleted according to the access right.

[0061] According to one embodiment, an electronic device (201a) of an external user that can access some objects (e.g., a first object) among at least one object stored in an electronic device (301) of at least one external user can receive authentication information (e.g., an ID and a password or a decryption key) from a server (401) that can access the object stored in the electronic device (301).

[0062] Figure 3 is a block diagram of an electronic device according to one embodiment.

[0063] Referring to the above drawing 3, the electronic device (301) may include a processor (320), a memory (330), a display (360), and a communication circuit (390).

[0064] According to one embodiment, the processor (320) may perform overall control operations of the electronic device (301). The processor (320) according to one embodiment may execute software (e.g., the program (140) of FIG. 1) to control at least one other component (e.g., a hardware or software component) of the electronic device (301) connected to the processor (320), and may perform data processing or calculations based on instructions. Instructions according to one embodiment may include instructions configured in a machine language that can be processed by the electronic device (301) or the processor (320). For example, the instructions may include instructions corresponding to operation instructions used in the program.

[0065] According to one embodiment, the processor (320) activates the setting of the access function (e.g., inheritance function) based on a selection by a user of the electronic device (301) in a setting mode of the access function (e.g., inheritance setting mode), and when checking the access condition (e.g., inheritance condition) and access right (e.g., inheritance right) selected by the user, the processor (320) can generate access information including the access condition and the access right.

[0066] According to one embodiment, the processor (320) can, in the setting mode of the access function, check the access conditions under which an external user (e.g., an heir) selected by the user can access at least one object stored in the electronic device (301).

[0067] According to an embodiment, the access condition may include at least one of a change in the health of the electronic device (301), a change in the person's condition, a designated period of time, and / or a designated date. For example, the change in the person's condition may include death, brain death, and / or severe dementia, and the change in the person's condition may include disappearance. For example, if the user of the electronic device (301) is unable to use the electronic device (301) for a designated period of time, such as due to military enlistment and / or overseas travel, the designated period selected by the user may be confirmed as the access condition.

[0068] According to one embodiment, the processor (320) may set access conditions differently based on the user's selection, by type of at least one object stored in the memory (330), by information of an external user who can access the at least one object, and / or by access authority.

[0069] According to one embodiment, an object may represent an object stored in an electronic device (301) that can set access conditions and access rights based on a user's selection. According to one embodiment, the object may represent a digital asset that an heir of the electronic device can inherit (access) to an heir corresponding to an external user in an inheritance mode of the electronic device. According to one embodiment, the object may include at least one of content, files, and / or folders stored in the electronic device (301). For example, the object may include a photo, a video, an address book, contacts, a memo, a voice recording, an anniversary, an important schedule, a text message, and / or a call history.

[0070] According to one embodiment, the processor (320) may provide a user interface that can set the access conditions by type of content, file unit, or folder unit in order to set the access conditions by type of object.

[0071] According to one embodiment, the processor (320) may include at least one of a phone number, an email address of the external user, account information of a server where the electronic device of the external user is registered, or a name and resident registration number.

[0072] According to one embodiment, the processor (320) may provide a user interface that can set the access condition for each of a plurality of external user information (e.g., phone number) in order to set the access condition for each external user information.

[0073] The access rights according to one embodiment may include at least one of access to allow an external user (e.g., an heir) to access the specified object, non-access to prevent an external user from accessing the specified object, and / or deletion to delete the object.

[0074] According to an embodiment, the processor (320) may check an object whose access right is set (selected) to access among at least one object stored in the electronic device (301), and input (select) information of an external user who can access the object set to access, and may match information of the object set to access (e.g., type of object and / or name of object), access right information of the object set to access, and information of the external user (e.g., phone number, email address, account information of the server where the electronic device of the external user is registered, and / or name and resident registration number, etc.) as related information and store them in a memory (330), and generate access information including information of the object set to access, access right information of the object set to access, and information of the external user (e.g., phone number, email address, account information of the server where the electronic device of the external user is registered, and / or name and resident registration number, etc.).

[0075] According to an embodiment, when the processor (320) identifies an object whose access rights are set (selected) to non-access among at least one object stored in the electronic device (301), it matches information of the object set to non-access (e.g., type of object and / or name of object) and access rights information of the object set to non-access as related information and stores them in a memory (330), and generates access information including information of the object set to non-access and access rights information of the object set to non-access.

[0076] According to an embodiment, when the processor (320) identifies an object whose access rights are set (selected) to be deleted among at least one object stored in the electronic device (301), it matches information of the object set to be deleted (e.g., type of object and / or name of object) and access rights information of the object set to be deleted as related information and stores them in the memory (330), and generates access information including information of the object set to be deleted and access rights information of the object set to be deleted.

[0077] According to one embodiment, the processor (320) may, upon confirming selection (input) of a period of time during which access to an object for which the access right is set to access is permitted, generate the period as access period information and include the access period information in the access information. According to one embodiment, the processor (320) may provide a user interface that can set access rights by content type, file unit, or folder unit in order to set the access right differently for each type of object.

[0078] According to one embodiment, the processor (320) may transmit the access information to a server (e.g., server (401) of FIG. 2) through a communication circuit (390).

[0079] According to one embodiment, when a processor (320) receives a command for executing an access function from a server (e.g., server (401) of FIG. 2) that has confirmed satisfaction of an access condition through a communication circuit (390), the processor (320) may enter an access mode (e.g., inheritance mode) and execute an access function (e.g., access, non-access, and / or deletion) for at least one object stored in the electronic device (301) according to access rights.

[0080] According to an embodiment, the processor (320) may, if the command received from the server includes a first command for executing a first access function, verify information of an external user and an encryption key corresponding to the information of the external user in the first command. According to an embodiment, the processor (320) may, based on the information of the external user verified in the first command, verify an object whose access right is set to access among at least one object stored in the memory (330), and verify a first object that can be accessed with the information of the external user among the objects whose access right is set to access. According to an embodiment, the processor (320) may encrypt the first object with an encryption key corresponding to the information of the external user. In one embodiment, an operation of encrypting an object according to information of an external user is described as an example, but an encryption key corresponding to object information (e.g., type of object) may be received from the server so that encryption can be performed differently depending on the type of the object set to the access.

[0081] According to an embodiment, the processor (320) may, in the access mode (e.g., inheritance mode), if the command includes a second command for executing a second access function, identify an encryption key for non-access in the second command. According to an embodiment, the processor (320) may identify an object whose access right is set to non-access among at least one object stored in the memory (330). According to an embodiment, the processor (320) may encrypt the object identified as non-accessible with the encryption key for non-access.

[0082] According to one embodiment, the processor (320) may, in the access mode (e.g., inheritance mode), if the command includes a third command for executing a third access function, identify an object whose access right is set to delete among at least one object stored in the memory (330). According to one embodiment, the processor (320) may delete the object whose access right is set to delete.

[0083] According to one embodiment, the processor (320) may include at least one command among the first command, the second command, or the third command in the command.

[0084] According to an embodiment, the processor (320) may, in the access mode (e.g., inheritance mode), set the screen of the electronic device (301) to a lock screen and display an indicator notifying the execution of an access function (e.g., inheritance function) on the lock screen. According to an embodiment, the processor (320) may request input of authentication information based on selection of the indicator and verify information of an external user based on the input authentication information.

[0085] According to an embodiment, the processor (320), when it is confirmed that the screen of the electronic device (301) is set to a lock screen in the access mode (e.g., inheritance mode), may additionally display an indicator notifying the execution of an access function (e.g., inheritance function) on the lock screen. According to an embodiment, the processor (320) may request input of authentication information based on selection of the indicator, and may confirm information of an external user based on the input authentication information.

[0086] According to one embodiment, the processor (320) may verify the input of authentication information including an ID and a password, and, upon verifying information of an external user based on the authentication information, may decrypt an object accessible to the information of the external user using a corresponding encryption key of the external user as a decryption key, and may display the decrypted object through a display (360). According to one embodiment, the processor (320) may verify the ID and password in the information of the external user included in the first command received from the server.

[0087] According to one embodiment, the processor (320) verifies the input of authentication information including a decryption key, verifies information of an external user based on the authentication information, uses the authentication information as a decryption key to decrypt an object that can be accessed as information of the external user, and displays the decrypted object through a display (360).

[0088] According to one embodiment, the processor (320) can check access period information that sets a period for accessing the at least one object in the access mode, and, if the expiration of the access period is confirmed, can deactivate (release) the access mode.

[0089] According to one embodiment, the processor (320) may deactivate the access mode (e.g., inheritance mode) of the electronic device (301), decrypt all encryption of objects stored in the electronic device (301), and set the screen of the electronic device (301) to an unlock screen when the setting of the access function (e.g., inheritance function) is disabled based on a user's selection in the setting mode of the access function (e.g., inheritance function).

[0090] The memory (330) according to one embodiment may be implemented substantially identically or similarly to the memory (130) of FIG. 1.

[0091] According to one embodiment, the memory (330) may store access rights set for at least one object in the memory (330) and access conditions that allow an access function (e.g., access, non-access, and / or deletion) to be executed for the at least one object according to the access rights.

[0092] According to one embodiment, the memory (330) may store at least one of information on the object, access rights set for the object, and / or information on an external user who can access the object.

[0093] A display (360) according to one embodiment may be implemented substantially identically or similarly to the display module (160) of FIG. 1.

[0094] According to one embodiment, the display (360) may display the screen of the electronic device as a lock screen in an access mode in which an access function (e.g., an inheritance function) is executed, and an indicator notifying execution of the access function (e.g., an inheritance function) may be displayed on the lock screen.

[0095] A communication circuit (390) according to one embodiment may be implemented substantially identically or similarly to the communication circuit (190) of FIG. 1.

[0096] According to one embodiment, the communication circuit (390) may include at least one of a wireless LAN circuit (not shown) and a short-range communication circuit (not shown).

[0097] The communication circuit (390) according to one embodiment may include an NFC communication circuit, a BLE communication circuit, and / or a UWB communication circuit capable of transmitting and receiving a UWB signal with an external device using a plurality of antennas, a Wi-Fi communication circuit, and / or a Bluetooth legacy communication circuit.

[0098] FIGS. 4A, 4B, 4C, and 4D are drawings illustrating access of an object in an electronic device according to one embodiment.

[0099] Referring to FIGS. 4A to 4D, as in FIG. 4A, when an electronic device (301) (e.g., the electronic device of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) receives a command for executing an access function from a server (e.g., the server (401) of FIG. 2) that has confirmed satisfaction of an access condition, as in FIG. 4B, while the screen of the electronic device is set to a lock screen, the electronic device may enter an access mode and display an indicator (401) that notifies the execution of an access function (e.g., an inheritance function) on the lock screen in the access mode.

[0100] As shown in the above FIG. 4c, the electronic device (301) requests input of authentication information based on the selection of the indicator (361), and when an ID and password (403) are input as the authentication information, and information of an external user who can access an object whose access right is set to access based on the input ID and password is confirmed, the electronic device can decrypt the object by using the corresponding encryption key of the external user as a decryption key.

[0101] As shown in the above drawing 4d, the electronic device (301) can display the decrypted object (405) through the display (360).

[0102] An electronic device (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) according to an embodiment may include a display (e.g., the display (160) of FIG. 1 and / or the display (360) of FIG. 3), a communication circuit (e.g., the communication circuit (190) of FIG. 1 and / or the communication circuit (390) of FIG. 3), at least one processor (e.g., the processor (120) of FIG. 1 and / or the processor (320) of FIG. 3), and a memory (e.g., the memory (130) of FIG. 1 and / or the memory (330) of FIG. 2)) for storing instructions. When the instructions according to an embodiment are executed by the at least one processor, the instructions may cause the electronic device to generate access information including an access condition for allowing an external user to access at least one object stored in the electronic device and an access right set for the at least one object. The instructions according to one embodiment, when executed by the at least one processor, may cause the electronic device to transmit the access information to a server (e.g., server 108 of FIG. 1 and / or server 401 of FIG. 2) via the communication circuit. The instructions according to one embodiment, when executed by the at least one processor, may cause the electronic device to enter an access mode when receiving a command for executing an access function from the server that has confirmed satisfaction of the access condition. The instructions according to one embodiment, when executed by the at least one processor, may cause the electronic device to verify information of an external user and an encryption key corresponding to the information of the external user in the first command, if the command includes a first command for executing a first access function.The commands according to one embodiment, when executed by the at least one processor, may cause the electronic device to identify a first object that can access information of the external user among objects for which the access right is set to access. The commands according to one embodiment, when executed by the at least one processor, may cause the electronic device to encrypt the first object with the encryption key.

[0103] The above instructions according to one embodiment, when executed by the at least one processor, cause the electronic device to, if the instructions include a second instruction for executing a second access function, check an encryption key for non-access in the second instruction, and encrypt an object whose access right is set to non-access with the encryption key.

[0104] The instructions according to one embodiment, when executed by the at least one processor, may cause the electronic device to delete an object for which the access right is set to delete, if the instructions include a third instruction for executing a third access function.

[0105] The instructions according to one embodiment, when executed by the at least one processor, may cause the electronic device to transmit the access information including information of an external user who can access at least one object for which the access right is set to access to the server.

[0106] The instructions according to one embodiment, when executed by the at least one processor, cause the electronic device to decrypt the encrypted first object and display the decrypted first object through the display, upon verifying information of the external user who can access the first object based on authentication information input in the access mode.

[0107] The commands according to one embodiment, when executed by the at least one processor, may cause the electronic device to set the screen of the electronic device as a lock screen in the access mode. The commands according to one embodiment, when executed by the at least one processor, may cause the electronic device to decrypt the at least one encrypted object by using the encryption key as a decryption key when verifying information of the external user who can access the first object based on authentication information input on the lock screen.

[0108] The commands according to one embodiment, when executed by the at least one processor, may cause the electronic device to set the screen of the electronic device as a lock screen in the access mode. The commands according to one embodiment, when executed by the at least one processor, may cause the electronic device to, when verifying information of the external user who can access the first object based on authentication information input on the lock screen, decrypt the at least one encrypted object using the authentication information as a decryption key.

[0109] The instructions according to one embodiment, when executed by the at least one processor, may cause the electronic device to set the access conditions differently for each type of the at least one object based on a selection by a user of the electronic device.

[0110] The instructions according to one embodiment, when executed by the at least one processor, cause the electronic device to, if the access right is set to access, set the access condition differently according to information of an external user who can access an object for which the access right is set to access, based on a selection by a user of the electronic device.

[0111] The access information according to one embodiment may include access period information that sets a period of time during which at least one object can be accessed in the access mode.

[0112] Figures 5a and 5b are flowcharts illustrating operations for managing objects in an electronic device according to an embodiment. The operations for managing objects may include operations 501 to 527. In the following embodiments, the operations may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations may be changed, at least two operations may be performed in parallel, or other operations may be added.

[0113] Referring to the above FIG. 5A, in operation 501, an electronic device (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) may generate access information including access conditions and access rights in a setting mode of an access function.

[0114] According to one embodiment, the electronic device (e.g., the electronic device of the deceased) may, in a setting mode of an access function (e.g., an inheritance setting mode), activate a setting of an access function (e.g., an inheritance function) based on a user selection of the electronic device, and, upon confirming an access condition (e.g., an inheritance condition) and an access right (e.g., an inheritance right) selected by the user, generate access information (e.g., an inheritance information) including the access condition and the access right.

[0115] According to one embodiment, the processor (320) can, in the setting mode of the access function, check the access conditions and access rights that allow an external user (e.g., an heir) selected by the user to access at least one object stored in the electronic device.

[0116] The access condition according to one embodiment may include at least one of a change in the health of the electronic device, a change in the person, a specified period of time, and / or a specified date.

[0117] The access rights according to one embodiment may include at least one of access to allow an external user (e.g., an heir) to access the specified object, non-access to prevent an external user from accessing the specified object, and / or deletion to delete the object.

[0118] According to an embodiment, the electronic device may identify an object whose access rights are set (selected) to access among at least one object stored in a memory of the electronic device (e.g., memory (330) of FIG. 3), and input (select) information of an external user who can access the object set to access, and may match information of the object set to access (e.g., type of object and / or name of object), access rights information of the object set to access, and information of the external user (e.g., phone number, email address, account information of a server where the electronic device of the external user is registered, and / or name and resident registration number, etc.) as related information and store them in the memory (330).

[0119] According to one embodiment, the electronic device may generate access information including information of an object set for access, access authority information of the object set for access, and information of an external user (e.g., a phone number, an email address, account information of a server where the electronic device of the external user is registered, and / or a name and resident registration number, etc.).

[0120] According to an embodiment, the electronic device may, when a period of time for which access to an object for which the access right is set to access is selected, generate the period as access period information and include the access period information in the access information.

[0121] According to one embodiment, the electronic device, when it identifies an object whose access rights are set (selected) to inaccessibility among at least one object stored in the memory, matches information of the object set to inaccessibility (e.g., type of object and / or name of object) and access rights information of the object set to inaccessibility as related information and stores them in the memory, and generates access information including information of the object set to inaccessibility and access rights information of the object set to inaccessibility.

[0122] According to one embodiment, the electronic device, when it identifies an object whose access rights are set (selected) to be deleted among at least one object stored in the memory, can match information of the object set to be deleted (e.g., type of object and / or name of object) and access rights information of the object set to be deleted as related information and store them in the memory, and can generate access information including information of the object set to be deleted and access rights information of the object set to be deleted.

[0123] In operation 503, an electronic device (e.g., electronic device (101) of FIG. 1 and / or electronic device (301) of FIGS. 2 to 3) may transmit access information to a server (e.g., server (401) of FIG. 2).

[0124] According to one embodiment, the electronic device may transmit access information to the server through a communication circuit of the electronic device (e.g., the communication circuit (390) of FIG. 3).

[0125] According to one embodiment, the electronic device may transmit access information including access conditions and access rights to the server through the communication circuit periodically or whenever access conditions and / or access rights are changed.

[0126] In operation 505, when an electronic device (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) confirms receipt of a command for executing an access function from a server (e.g., the server (401) of FIG. 2), in operation 507, the electronic device may enter an access mode (e.g., an inheritance mode) for executing the access function according to access rights for at least one object stored in the electronic device.

[0127] According to one embodiment, the electronic device may enter the access mode (e.g., inheritance mode) when receiving a command for executing an access function from the server that has confirmed satisfaction of an access condition through a communication circuit of the electronic device (e.g., communication circuit (390) of FIG. 3).

[0128] In operation 509, if the electronic device (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) includes a first command for executing a first access function in the command, in operation 511, the electronic device can encrypt an object whose access right is set to access with an encryption key corresponding to information of an external user.

[0129] In one embodiment, the electronic device, in the access mode (e.g., inheritance mode), if the command includes a first command for executing a first access function, can verify information of an external user and an encryption key corresponding to the information of the external user in the first command.

[0130] According to one embodiment, the electronic device may, based on the information of the external user confirmed in the first command, identify a first object that can be accessed with the information of the external user among objects whose access rights are set to access and stored in a memory (e.g., memory (330) of FIG. 3), and encrypt the first object with an encryption key corresponding to the information of the external user.

[0131] Referring to FIG. 5b, in operation 513, if the electronic device (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) includes a second command for executing a second access function in the command, in operation 515, the electronic device can encrypt an object whose access right is set to inaccessible with an encryption key for inaccessibility.

[0132] In one embodiment, the electronic device, in the access mode (e.g., inheritance mode), if the command includes a second command for executing a second access function, can verify an encryption key for non-access in the second command.

[0133] According to one embodiment, the electronic device can identify an object whose access permission is set to inaccessible among at least one object stored in a memory (e.g., memory (330) of FIG. 3), and encrypt the object identified as inaccessible with an encryption key for inaccessibility.

[0134] In operation 517, if the electronic device (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) includes a third command for executing a third access function in the command, in operation 519, the electronic device can delete an object for which the access right is set to delete.

[0135] According to an embodiment, the electronic device, in the access mode (e.g., inheritance mode), if the command includes a third command for executing a third access function, can identify an object among at least one object stored in a memory (e.g., memory (330) of FIG. 3) with access rights to be deleted, and delete the object identified as deleted.

[0136] In operation 521, the electronic device (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) may display an indicator notifying execution of an access function on the lock screen.

[0137] According to one embodiment, the electronic device may, in the access mode (e.g., inheritance mode), set the screen of the electronic device (301) to a lock screen and display an indicator notifying execution of an access function (e.g., inheritance function) on the lock screen.

[0138] According to one embodiment, when the electronic device (301) is in the access mode (e.g., inheritance mode) and the screen is set to a lock screen, the electronic device may additionally display an indicator notifying execution of an access function (e.g., inheritance function) on the lock screen.

[0139] In operation 523, an electronic device (e.g., electronic device (101) of FIG. 1 and / or electronic device (301) of FIGS. 2 to 3) may request input of authentication information.

[0140] According to one embodiment, the electronic device may request input of authentication information based on selection of the indicator.

[0141] In operation 525, an electronic device (e.g., electronic device (101) of FIG. 1 and / or electronic device (301) of FIGS. 2 to 3) can verify information of an external user based on authentication information.

[0142] According to one embodiment, the electronic device can confirm the input of authentication information including an ID and password, and confirm information of an external user based on the authentication information.

[0143] According to one embodiment, the electronic device can verify the ID and password from the information of an external user included in a first command received from a server (e.g., server (401) of FIG. 4).

[0144] According to one embodiment, the electronic device can verify the input of authentication information including a decryption key and verify information of an external user based on the authentication information.

[0145] In operation 527, an electronic device (e.g., electronic device (101) of FIG. 1 and / or electronic device (301) of FIGS. 2 to 3) can decrypt an encrypted object and display the decrypted object.

[0146] According to one embodiment, the electronic device may decrypt an object accessible to the information of the external user by using the corresponding encryption key of the external user verified based on the authentication information as a decryption key, and display the decrypted object through a display of the electronic device (e.g., display (360) of FIG. 3).

[0147] According to one embodiment, the electronic device can decrypt an object that can be accessed as information of the external user using the authentication information as a decryption key, and display the decrypted object through the display.

[0148] Figure 6 is a flowchart illustrating operations for managing objects in an electronic device according to an embodiment. The operations for managing objects may include operations 601 to 617. In the following embodiments, the operations may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations may be changed, at least two operations may be performed in parallel, or other operations may be added.

[0149] In operation 601, an electronic device (301) (e.g., an electronic device (101) of FIG. 1 and / or an electronic device (301) of FIGS. 2 to 3) may generate access information including access conditions and access rights.

[0150] According to one embodiment, the electronic device (301), in a setting mode of an access function (e.g., an inheritance setting mode), activates a setting of an access function (e.g., an inheritance function) based on a user selection of the electronic device, and upon confirming an access condition (e.g., an inheritance condition) and an access right (e.g., an inheritance right) selected by the user, can generate access information (e.g., an inheritance information) including the access condition and the access right.

[0151] In operation 603, the electronic device (301) (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) may transmit access information to the server (401) (e.g., the server (401) of FIG. 2).

[0152] According to one embodiment, the electronic device (301) can transmit access information to the server (401) through a communication circuit of the electronic device (e.g., a communication circuit (390) of FIG. 3).

[0153] In operation 605, the server (401) (e.g., the server (401) of FIG. 2) can store (register) access information of the electronic device.

[0154] According to one embodiment, when a server (401) receives access information including access conditions and access rights from an electronic device (301), it can register the access information by matching it with user information of the electronic device.

[0155] According to one embodiment, the server (401) may be a server of a service provider that manages access to at least one object stored in the electronic device (301). For example, the server (401) may be an inheritance service provider that manages inheritance of at least one object stored in the electronic device.

[0156] In operation 607, the server (401) (e.g., server (401) of FIG. 2) can confirm satisfaction of the access condition.

[0157] According to one embodiment, the server (401) can confirm satisfaction of access conditions based on a physical document that can confirm a change in health or personal condition of a user of the electronic device (301) presented by an external user (e.g., an heir).

[0158] According to one embodiment, the server (401) can confirm satisfaction of the access condition by confirming the current date as the start date of a specified period set as the access condition or as a specified date.

[0159] In operation 609, the server (401) (e.g., the server (401) of FIG. 2) may transmit a command for executing an access function to the electronic device.

[0160] According to an embodiment, the server (401), when it confirms that the access condition is satisfied, may transmit to the electronic device (301) a command for executing an access function, including at least one command among a first command including information of an external user for accessing an object set to access and an encryption key corresponding to the information of the external user, a second command including an encryption key for non-access for encrypting an object set to non-access, or a third command for deleting an object set to delete, based on the access right.

[0161] In operation 611, the server (401) (e.g., the server (401) of FIG. 2) can transmit authentication information to an electronic device of an external user.

[0162] According to one embodiment, the server (401) can, based on the access authority, check information of an external user who can access an object set for access, and transmit authentication information for accessing an object stored in the electronic device (301) to the electronic device (201a) of the external user (e.g., the external electronic device (201) of FIG. 2).

[0163] According to one embodiment, the server (401) can verify information of an external user through the external user's phone number, email address, account information of the server where the external user's electronic device is registered and / or name and primary registration number, and transmit the authentication information through the external user's email or message.

[0164] According to one embodiment, the server (401) can generate an ID and password as authentication information and transmit them to the electronic device (201a) of the external user.

[0165] According to one embodiment, the server (401) may transmit an encryption key corresponding to information of an external user transmitted to the electronic device as a decryption key to the electronic device (201a) of the external user in order to encrypt an object set to be accessed by the electronic device.

[0166] In operation 613, the electronic device (301) (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) may enter an access mode (e.g., an inheritance mode).

[0167] According to one embodiment, if the command received from the server includes a first command for executing a first access function, the electronic device (301) may check information of an external user and an encryption key corresponding to the information of the external user in the first command, check an object that can be accessed with the information of the external user among at least one object whose access right is set to access stored in a memory of the electronic device (e.g., a memory (330) of FIG. 3), and encrypt the object confirmed as access with an encryption key corresponding to the information of the external user.

[0168] According to an embodiment, the electronic device (301), if the command includes a second command for executing a second access function, can check an encryption key for non-access in the second command, check an object whose access right is set to non-access among at least one object stored in the memory, and encrypt the object confirmed as non-access with the encryption key for non-access.

[0169] According to an embodiment, the electronic device (301), in the access mode (e.g., inheritance mode), if the command includes a third command for executing a third access function, can check for an object whose access right is set to delete among at least one object stored in the memory, and delete the object checked for deletion.

[0170] In operation 615, the electronic device (301) (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) can verify information of an external user based on authentication information.

[0171] According to one embodiment, the electronic device (301) may, in the access mode (e.g., inheritance mode), set the screen of the electronic device (301) to a lock screen and display an indicator notifying execution of an access function (e.g., inheritance function) on the lock screen.

[0172] According to one embodiment, the electronic device (301), when it is confirmed that the screen of the electronic device (301) is set to a lock screen in the access mode (e.g., inheritance mode), may additionally display an indicator notifying execution of an access function (e.g., inheritance function) on the lock screen.

[0173] According to one embodiment, the electronic device (301) can verify information of an external user using authentication information input based on selection of the indicator.

[0174] According to one embodiment, the electronic device (301) can confirm the input of authentication information including an ID and password, and confirm information of an external user based on the authentication information.

[0175] According to one embodiment, the electronic device (301) can confirm the input of authentication information including a decryption key and confirm information of an external user based on the authentication information.

[0176] In operation 617, the electronic device (301) (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) can decrypt an encrypted object and display the decrypted object.

[0177] According to one embodiment, the electronic device (301) can decrypt an object that can be accessed as information of the external user by using the corresponding encryption key of the external user as a decryption key, and display the decrypted object through a display of the electronic device (e.g., display (360) of FIG. 3).

[0178] According to one embodiment, the electronic device (301) can decrypt an object that can be accessed as information of the external user using the authentication information as a decryption key, and display the decrypted object through the display.

[0179] According to an embodiment, a method for managing an object in an electronic device (e.g., the electronic device (101) of FIG. 1 and / or the electronic device (301) of FIGS. 2 to 3) may include an operation of generating access information including an access condition for allowing an external user to access at least one object stored in the electronic device and an access right set for the at least one object. According to an embodiment, the method may include an operation of transmitting the access information to a server via the communication circuit. According to an embodiment, the method may include an operation of entering an access mode when a command for executing an access function is received from the server that has confirmed satisfaction of the access condition. According to an embodiment, if the command includes a first command for executing a first access function, the method may verify information of an external user and an encryption key corresponding to the information of the external user in the first command. According to an embodiment, the method may include an operation of verifying a first object that can be accessed with information of the external user among objects for which the access right is set to access. The method according to one embodiment may include an operation of encrypting the first object with the encryption key.

[0180] According to one embodiment, the method may include, if the command includes a second command for executing a second access function, an operation of verifying an encryption key for non-provisioning in the second command. According to one embodiment, the method may further include an operation of encrypting an object whose access rights are set to non-accessible using the encryption key.

[0181] The method according to one embodiment may further include an operation of deleting an object for which the access right is set to delete, if the command includes a third command for executing a third access function.

[0182] The method according to one embodiment may further include transmitting, to the server, the access information including information of an external user who can access at least one object for which the access right is set to access.

[0183] According to one embodiment, the method may further include an operation of decrypting the encrypted first object when verifying information of the external user who can access the first object based on authentication information input in the access mode. According to one embodiment, the method may further include an operation of displaying the decrypted first object through a display of the electronic device.

[0184] The method according to one embodiment may further include an operation of setting the screen of the electronic device as a lock screen in the access mode. The method according to one embodiment may further include an operation of decrypting the at least one encrypted object using the encryption key as a decryption key, upon confirming information of the external user who can access the first object based on authentication information input on the lock screen.

[0185] The method according to one embodiment may further include an operation of setting the screen of the electronic device as a lock screen in the access mode. The method according to one embodiment may further include an operation of decrypting the at least one encrypted object using the authentication information as a decryption key when verifying information of the external user who can access the first object based on authentication information input on the lock screen.

[0186] The method according to one embodiment may further include an operation of setting the access condition differently for each type of the at least one object based on a selection by a user of the electronic device.

[0187] The method according to one embodiment may further include, if the access right is set to access, an operation of differently setting the access condition according to information of an external user who can access an object for which the access right is set to access, based on a selection by a user of the electronic device.

[0188] The access information according to one embodiment may include access period information that sets a period of time during which at least one object can be accessed in the access mode.

[0189] Electronic devices according to embodiments disclosed herein may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to embodiments disclosed herein are not limited to the aforementioned devices.

[0190] The embodiments of this document and the terminology used herein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.

[0191] The term "module" used in one embodiment of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0192] An embodiment of the present document may be implemented as software (e.g., a program (140)) including one or more instructions stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101) or an electronic device (301)). For example, a processor (e.g., a first processor (320)) of the machine (e.g., an electronic device (301)) may call at least one instruction among the one or more instructions stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.

[0193] According to one embodiment, the method according to one embodiment disclosed in the present document may be provided as a computer program product. The computer program product may be traded between sellers and buyers as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or may be provided through an application store (e.g., Play Store). TM ) or directly between two user devices (e.g., smart phones), online distribution (e.g., downloading or uploading). In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily created in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.

[0194] According to one embodiment, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and placed in other components. According to one embodiment, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to one embodiment, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

Claims

1. In an electronic device (101 of FIG. 1; 301 of FIGS. 2 to 3), Display (160 in Fig. 1; 360 in Fig. 3); Communication circuit (190 in Fig. 1; 390 in Fig. 3); At least one processor (120 in FIG. 1; 320 in FIG. 3); and It includes a memory (130 in Fig. 1; 330 in Fig. 2) for storing commands, The above instructions, when executed by the at least one processor, cause the electronic device to: Generate access information including access conditions for allowing external users to access at least one object stored in the electronic device and access rights set for the at least one object, Through the above communication circuit, the access information is transmitted to the server (108 in Fig. 1; 401 in Fig. 2), When a command for executing an access function is received from the server that has confirmed satisfaction of the above access conditions, the server enters access mode. If the above command includes a first command for executing the first access function, the first command verifies the information of the external user and the encryption key corresponding to the information of the external user, and verifies the first object that can be accessed with the information of the external user among the objects for which the access right is set to access, An electronic device set to encrypt the first object with the encryption key.

2. In paragraph 1, The above instructions, when executed by the at least one processor, cause the electronic device to: An electronic device configured to verify an encryption key for non-access in the second command if the above command includes a second command for executing a second access function, and to encrypt an object whose access right is set to non-access with the encryption key.

3. In paragraph 1 or 2, The above instructions, when executed by the at least one processor, cause the electronic device to: An electronic device set to delete an object whose access rights are set to delete, if the above command includes a third command for executing a third access function.

4. In any one of paragraphs 1 to 3, The above instructions, when executed by the at least one processor, cause the electronic device to: An electronic device set to transmit to the server said access information containing information of an external user who can access at least one object for which said access right is set to access.

5. In any one of paragraphs 1 to 4, The above instructions, when executed by the at least one processor, cause the electronic device to: When the information of the external user who can access the first object is verified based on the authentication information entered in the above access mode, the encrypted first object is decrypted, An electronic device set to display the decrypted first object through the display.

6. In any one of paragraphs 1 to 5, The above instructions, when executed by the at least one processor, cause the electronic device to: In the above access mode, set the screen of the electronic device as a lock screen, An electronic device configured to decrypt at least one encrypted object by using the encryption key as a decryption key when verifying information of the external user who can access the first object based on authentication information entered on the lock screen.

7. In any one of paragraphs 1 to 6, The above instructions, when executed by the at least one processor, cause the electronic device to: In the above access mode, set the screen of the electronic device as a lock screen, An electronic device configured to decrypt at least one encrypted object by using the authentication information as a decryption key when verifying information of the external user who can access the first object based on the authentication information entered on the lock screen.

8. In any one of paragraphs 1 to 7, The above instructions, when executed by the at least one processor, cause the electronic device to: An electronic device capable of setting the access conditions differently for each type of at least one object based on a selection made by a user of the electronic device.

9. In any one of paragraphs 1 to 8, The above instructions, when executed by the at least one processor, cause the electronic device to: An electronic device capable of setting the access conditions differently according to information of an external user who can access an object for which the access right is set to access, based on a selection by a user of the electronic device, when the above access right is set to access.

10. In any one of paragraphs 1 to 9, An electronic device including, in the above access information, access period information that sets a period for accessing at least one object in the above access mode.

11. A method for managing objects in an electronic device, An operation of generating access information including access conditions for allowing an external user to access at least one object stored in the electronic device and access rights set for the at least one object; An operation of transmitting the access information to a server through the above communication circuit; An action of entering access mode when receiving a command for executing an access function from the server that has confirmed satisfaction of the above access conditions; If the above command includes a first command for executing a first access function, an operation of verifying information of an external user and an encryption key corresponding to the information of the external user in the first command; An operation for checking a first object that can be accessed with information of the external user among the objects for which the above access rights are set to access; and A method comprising an operation of encrypting the first object using the encryption key.

12. In paragraph 11, If the above command includes a second command for executing a second access function, an operation for verifying a cryptographic key for non-privileged use in the second command; and A method further comprising an action of encrypting an object whose access rights are set to inaccessible using the encryption key.

13. In clause 11 or 12, A method further comprising an action of deleting an object whose access permission is set to delete, if the above command includes a third command for executing a third access function.

14. In any one of paragraphs 11 to 13, A method further comprising the action of transmitting to the server the access information including information of an external user who can access at least one object for which the access right is set to access.

15. In a nonvolatile storage medium storing commands, the commands are set to cause the electronic device to perform at least one operation when executed by the electronic device, the at least one operation being: An operation of generating access information including access conditions for allowing an external user to access at least one object stored in the electronic device and access rights set for the at least one object; An operation of transmitting the access information to a server through the above communication circuit; An action of entering access mode when receiving a command for executing an access function from the server that has confirmed satisfaction of the above access conditions; If the above command includes a first command for executing a first access function, an operation of verifying information of an external user and an encryption key corresponding to the information of the external user in the first command; An operation for checking a first object that can be accessed with information of the external user among the objects for which the above access rights are set to access; and A storage medium including an operation of encrypting the first object using the encryption key.

Citation Information

Patent Citations

  • Stainless steel wall shelf for business and its assembly method

    KR1020220116917A

  • Platform screen door control method, device and system of bus stop

    KR1020230167869A

  • Method and server for managing testament

    KR102139551B1

  • Correlation system for correlating sensory events and legacy system events

    US20200259699A1

  • KR20230115221A