Secure Element Token Sharing for Remote Property Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for granting access to electronically-secured property, such as physical keys, secret codes, or biometric data, are inconvenient and insecure, especially when sharing access with others, as they require physical transfer or insecure communication, limiting feasibility and security.

Innovation Solution

A system using secure elements in electronic devices to issue and manage sharing tokens, which are encrypted and verified through a token server or peer-to-peer communication, allowing secure access without the need for physical presence or insecure data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical keys or fobs are used for access control, then access can be granted to another individual, but the owner must physically deliver and retrieve the key, which is inconvenient and allows malicious entities to gain access if lost or stolen

Engineering Contradiction:
Improveconvenience of granting accessVSAvoidsecurity of access control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces physical mechanical keys with electronic sharing tokens that are generated, stored, and verified through cryptographic mechanisms. The secure element stores the token in a tamper-resistant manner, and access is granted through electronic verification rather than physical key insertion, eliminating the need for physical delivery while maintaining security through cryptographic protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a sharing token as an intermediary that mediates between the owner and the friend. The token is generated by the owner's secure element and transferred through a token server or peer-to-peer communication to the friend's device. This intermediary mechanism allows secure access sharing without requiring physical presence or direct key transfer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If secret data such as passwords or PINs are used for access control, then access can be shared without physical transfer, but the communication of secret data must be secure or a third party can observe it, and the secret data must be changed after the individual is finished with access

Engineering Contradiction:
Improveconvenience of sharing accessVSAvoidrisk of secret data observation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent creates a copy of the access credential in the form of a sharing token that is stored in the friend's secure element. This token is a cryptographic copy that allows access without exposing the owner's original credentials or secret data. The token can be independently verified by the access control system without requiring the owner's continued involvement.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces secret data communication with cryptographic token transfer. Instead of communicating passwords or PINs through potentially insecure channels, the system uses secure element-based token generation and transfer mechanisms with cryptographic protection, eliminating the risk of observation while maintaining ease of sharing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If biometric data is used to secure the system, then access control is secure, but the system generally cannot be accessed by the individual without the owner being present

Engineering Contradiction:
Improvesecurity of access controlVSAvoidconvenience of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the access control system into two parts: the owner's biometric data for token generation and the friend's token for access. The secure element divides the authentication process into token generation (requiring owner's biometric) and token verification (allowing friend's independent access). This segmentation maintains security through biometric protection while enabling convenient independent access for authorized individuals.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11777936B2Friend key sharing
Publication Date: 2023.10.03 APPLE INC
  • US11777936B2 patent drawing
  • US11777936B2 patent drawing
  • US11777936B2 patent drawing

AI summary

Techniques are disclosed relating to sharing access to electronically-secured property. In some embodiments, a first computing device having a first secure element receives, from a second computing device associated with an owner of the electronically-secured property, an indication that the second computing device has transmitted a token to server computing system, the token permitting a user of the first computing device access to the electronically-secured property. Based on the received indication, the first computing device sends a request for the transmitted token to the server computing system and, in response to receiving the requested token, securely stores the received token in the first secure element of the first computing device. The first computing device subsequently transmits the stored token from the first secure element of the first device to the electronically-secured property to obtain access to the electronically-secured property based on the token.