Ephemeral IRK and RPA for Scheduled Electronic Lock Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for electronic locks often rely on static identity resolving keys (IRKs), which can compromise privacy and security, especially when third-party services need scheduled access.

Innovation Solution

The implementation of scheduled access control using ephemeral identity resolving keys (IRKs) and resolvable private addresses (RPAs), which are valid only during a designated time period, allowing secure and controlled access without revealing static IRKs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static identity resolving keys (IRKs) are used for access control, then access control functionality is provided, but privacy and security are compromised

Engineering Contradiction:
ImprovesecurityVSAvoidprivacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies dynamics by transitioning from static IRKs to dynamic ephemeral IRKs that change over time. The electronic lock generates a new ephemeral IRK for each access session, and the central wireless device obtains the current ephemeral IRK before resolving the RPA. This dynamic key generation and rotation mechanism ensures that even if one ephemeral IRK is compromised, previous and future sessions remain secure, thus improving security while maintaining privacy through frequent key changes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies preliminary action by having the central wireless device obtain the ephemeral IRK in advance before needing to resolve the RPA for access. The system performs key distribution and validation prior to the actual access request, allowing the electronic lock to verify the legitimacy of the access attempt before granting entry. This preliminary key establishment enhances security by ensuring authenticated access while protecting privacy through pre-shared ephemeral credentials.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If third-party services are granted access to locations, then service functionality is provided, but unauthorized access risk increases

Engineering Contradiction:
Improveservice accessVSAvoidaccess security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the access control system into distinct components: the electronic lock holds the static IRK and generates ephemeral IRKs, the central wireless device obtains and uses ephemeral IRKs for access, and the RPA acts as a separate identifier. This segmentation allows third-party services to access locations through controlled ephemeral credentials without exposing the master static IRK, thus enabling service versatility while maintaining access security through isolated credential scopes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies the intermediary principle by introducing the ephemeral IRK and RPA mechanism as a mediator between the central wireless device and the electronic lock. Instead of direct static IRK sharing, the system uses ephemeral keys as intermediaries that enable authenticated communication for third-party services. This intermediary layer allows versatile service access while enhancing security by preventing direct exposure of permanent credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If private addresses change over time for privacy protection, then privacy is enhanced, but access control complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidaccess control mechanism
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by modifying the temporal validity parameter of IRKs. Ephemeral IRKs are generated with specific time-bound validity periods, allowing the system to enhance privacy through changing identifiers while managing complexity through automated expiration and renewal mechanisms. The electronic lock and central wireless device automatically handle parameter validation, reducing manual intervention despite the dynamic nature of changing addresses.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12307841B2Scheduled access control for an electronic lock
Publication Date: 2025.05.20 APPLE INC
  • US12307841B2 patent drawing
  • US12307841B2 patent drawing
  • US12307841B2 patent drawing

AI summary

Methods and apparatus to support scheduled access control for an electronic lock are described herein. An initiating central wireless device obtains an ephemeral identity resolving key (IRK) to use in resolving an ephemeral resolvable private address (RPA) of a peripheral wireless device. The initiating central wireless device can subsequently connect securely to the peripheral wireless device in order to unlock an electronic lock controlled by the peripheral wireless device to gain access during a scheduled time period. The ephemeral IRK and ephemeral RPA can be used for a limited period of time and/or for a predetermined number of usages during the scheduled time period.