Server-Mediated Access Control for Shared Device Location
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device locator services face challenges in limiting access to location information for shared accessory devices, as direct sharing of encryption keys with the sharee device complicates access control.
Innovation Solution
A server-mediated system that manages access to location services by using a delegate server to handle cryptographic keys and metadata, ensuring that only authorized sharee devices receive the necessary keys and information based on predefined conditions, thereby controlling access to location information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If encryption keys are transferred directly between owner device and sharee device, then the sharee device can access location information for the accessory device, but access control and limiting access to location information becomes challenging
Solution Approach 1:
The patent introduces a server as an intermediary that holds and manages the encryption keys. Instead of direct key transfer between owner and sharee devices, the server mediates the authentication process by verifying credentials against stored keys and returning authentication results. This intermediary architecture enables fine-grained access control policies to be enforced centrally while allowing flexible sharing arrangements, resolving the contradiction between ease of access and reliability of access control.
2Reliability
If a server-mediated system is introduced to manage cryptographic keys and access policies, then access control to location services is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal server-mediated authentication system that handles multiple sharing scenarios through a single centralized architecture. The same server infrastructure supports different access control policies, credential types, and sharee configurations without requiring separate systems for each case. This multi-functional approach consolidates complexity into a single manageable component rather than distributing it across multiple specialized systems, thereby improving access control reliability while controlling overall system complexity.
Data Source
AI summary
Methods, non-transitory machine-readable mediums, and system to provide that a delegate server receives authentication credentials from a first sharee electronic device, determines at least one cryptographic key and metadata accessible to a first sharee corresponding to the received authentication credentials, the metadata defines a set of conditions for a share of location information for an accessory device, evaluates the metadata to determine if the set of conditions are satisfied, upon determination that the set of conditions are satisfied, sends the metadata and the at least one cryptographic key to the first sharee electronic device, receives an indication that a second sharee electronic device is joining the share of location information for the accessory device, and sends at least one update for the cryptographic key and the metadata.


