Ephemeral IRK and RPA for Scheduled Electronic Lock Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems for electronic locks often rely on static identity resolving keys (IRKs), which can compromise privacy and security, especially when third-party services need scheduled access.
Innovation Solution
The implementation of scheduled access control using ephemeral identity resolving keys (IRKs) and resolvable private addresses (RPAs), which are valid only during a designated time period, allowing secure and controlled access without revealing static IRKs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static identity resolving keys (IRKs) are used for access control, then access control functionality is provided, but privacy and security are compromised
Solution Approach 1:
The patent applies dynamics by transitioning from static IRKs to dynamic ephemeral IRKs that change over time. The electronic lock generates a new ephemeral IRK for each access session, and the central wireless device obtains the current ephemeral IRK before resolving the RPA. This dynamic key generation and rotation mechanism ensures that even if one ephemeral IRK is compromised, previous and future sessions remain secure, thus improving security while maintaining privacy through frequent key changes.
Solution Approach 2:
The patent applies preliminary action by having the central wireless device obtain the ephemeral IRK in advance before needing to resolve the RPA for access. The system performs key distribution and validation prior to the actual access request, allowing the electronic lock to verify the legitimacy of the access attempt before granting entry. This preliminary key establishment enhances security by ensuring authenticated access while protecting privacy through pre-shared ephemeral credentials.
2Adaptability or versatility
If third-party services are granted access to locations, then service functionality is provided, but unauthorized access risk increases
Solution Approach 1:
The patent applies segmentation by dividing the access control system into distinct components: the electronic lock holds the static IRK and generates ephemeral IRKs, the central wireless device obtains and uses ephemeral IRKs for access, and the RPA acts as a separate identifier. This segmentation allows third-party services to access locations through controlled ephemeral credentials without exposing the master static IRK, thus enabling service versatility while maintaining access security through isolated credential scopes.
Solution Approach 2:
The patent applies the intermediary principle by introducing the ephemeral IRK and RPA mechanism as a mediator between the central wireless device and the electronic lock. Instead of direct static IRK sharing, the system uses ephemeral keys as intermediaries that enable authenticated communication for third-party services. This intermediary layer allows versatile service access while enhancing security by preventing direct exposure of permanent credentials.
3Loss of information
If private addresses change over time for privacy protection, then privacy is enhanced, but access control complexity increases
Solution Approach 1:
The patent applies parameter changes by modifying the temporal validity parameter of IRKs. Ephemeral IRKs are generated with specific time-bound validity periods, allowing the system to enhance privacy through changing identifiers while managing complexity through automated expiration and renewal mechanisms. The electronic lock and central wireless device automatically handle parameter validation, reducing manual intervention despite the dynamic nature of changing addresses.
Data Source
AI summary
Methods and apparatus to support scheduled access control for an electronic lock are described herein. An initiating central wireless device obtains an ephemeral identity resolving key (IRK) to use in resolving an ephemeral resolvable private address (RPA) of a peripheral wireless device. The initiating central wireless device can subsequently connect securely to the peripheral wireless device in order to unlock an electronic lock controlled by the peripheral wireless device to gain access during a scheduled time period. The ephemeral IRK and ephemeral RPA can be used for a limited period of time and/or for a predetermined number of usages during the scheduled time period.


