Server-Mediated Access Control for Shared Device Location

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device locator services face challenges in limiting access to location information for shared accessory devices, as direct sharing of encryption keys with the sharee device complicates access control.

Innovation Solution

A server-mediated system that manages access to location services by using a delegate server to handle cryptographic keys and metadata, ensuring that only authorized sharee devices receive the necessary keys and information based on predefined conditions, thereby controlling access to location information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If encryption keys are transferred directly between owner device and sharee device, then the sharee device can access location information for the accessory device, but access control and limiting access to location information becomes challenging

Engineering Contradiction:
Improveaccess to location informationVSAvoidaccess control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a server as an intermediary that holds and manages the encryption keys. Instead of direct key transfer between owner and sharee devices, the server mediates the authentication process by verifying credentials against stored keys and returning authentication results. This intermediary architecture enables fine-grained access control policies to be enforced centrally while allowing flexible sharing arrangements, resolving the contradiction between ease of access and reliability of access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a server-mediated system is introduced to manage cryptographic keys and access policies, then access control to location services is improved, but system complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal server-mediated authentication system that handles multiple sharing scenarios through a single centralized architecture. The same server infrastructure supports different access control policies, credential types, and sharee configurations without requiring separate systems for each case. This multi-functional approach consolidates complexity into a single manageable component rather than distributing it across multiple specialized systems, thereby improving access control reliability while controlling overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240380575A1Server-Mediated Management of Accessory Device Sharing
Publication Date: 2024.11.14 APPLE INC
  • US20240380575A1 patent drawing
  • US20240380575A1 patent drawing
  • US20240380575A1 patent drawing

AI summary

Methods, non-transitory machine-readable mediums, and system to provide that a delegate server receives authentication credentials from a first sharee electronic device, determines at least one cryptographic key and metadata accessible to a first sharee corresponding to the received authentication credentials, the metadata defines a set of conditions for a share of location information for an accessory device, evaluates the metadata to determine if the set of conditions are satisfied, upon determination that the set of conditions are satisfied, sends the metadata and the at least one cryptographic key to the first sharee electronic device, receives an indication that a second sharee electronic device is joining the share of location information for the accessory device, and sends at least one update for the cryptographic key and the metadata.