IP Library Granted Patent US 12683950
Granted Patent B2
US 12683950 · App. 18/533,600 · Granted Jul 14, 2026

Sharing system access using a device

Inventors: Matthias Lerch (San Francisco, CA); Sven J. Hofmann (Cupertino, CA)
Assignee: Apple Inc.
H04L63/0823H04L63/062H04L63/107H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12683950
App. No.
18/533,600
Granted
Jul 14, 2026
Kind
B2
Abstract

Techniques are disclosed relating to sharing an access credential. In various embodiments, sharee device receives an access credential shared by a sharer device to obtain access to a system. The sharee device determines a policy based on a server-based device (SBxD) certificate included in the access credential and performs an action in accordance with the determined policy. In some embodiments, the policy specifies a restricted set of access rights for the system. The sharee device presents, in accordance with the policy, the access credential to the system. In some embodiments, the action includes the sharee device providing information to a remote server. In some embodiments, the sharee device identifies an access credential class defined by class information included in the access credential and performs an action in accordance with the determined policy and the identified access credential class.

Claims (58)

1 . A non-transitory computer readable medium having program instructions stored therein that are executable by a sharee device to perform operations comprising:

receiving an access credential shared by a sharer device to obtain access to a system;

determining a policy based on a server-based device (SBD) certificate included in the access credential, wherein the SBD certificate identifies the sharer device as being a server and certifies a public key pair corresponding to an identity of the server, and wherein the policy defines one or more criteria restricting a set of actions permissible using the shared access credential, wherein the SBD certificate is one of:

a server-based owner device (SBOD) certificate that identifies the sharer device as a device belonging to an owner of the system; and

a server-based friend device (SBFD) certificate that identifies the sharer device as a device belonging to an entity granted authority by the owner; and

performing an action in accordance with the determined policy.

2 . The computer readable medium of claim 1 , wherein the action includes:

presenting a particular user interface in accordance with the policy.

3 . The computer readable medium of claim 1 , wherein the policy specifies a restriction for a particular geographic region; and

wherein the action includes:

determining whether to accept the access credential based on whether the access credential is associated with the particular geographic region.

4 . The computer readable medium of claim 1 , wherein the policy specifies whether the sharee device is permitted to share the access credential with another device; and

wherein the action includes:

sharing the access credential based on the policy.

5 . The computer readable medium of claim 1 , wherein the policy specifies a restricted set of access rights for the system; and

wherein the action includes:

presenting, in accordance with the policy, the access credential to the system.

6 . The computer readable medium of claim 1 , wherein the action includes providing information to a remote server.

7 . The computer readable medium of claim 6 , wherein the provided information includes an identity associated with the sharer device.

8 . The computer readable medium of claim 6 , wherein the provided information includes information about an access event using the shared access credential.

9 . The computer readable medium of claim 6 , wherein the provided information includes information associated with the sharee device.

10 . The computer readable medium of claim 6 , wherein the action further includes:

sharing the access credential with another device, wherein the provided information includes information associated with the other device.

11 . A method, comprising:

receiving, by a sharee device, an access credential shared by a sharer device to obtain access to a system;

determining, by the sharee device, a policy based on a server-based device (SBD) certificate included in the access credential, wherein the SBD certificate identifies the sharer device as being a server and certifies a public key pair corresponding to an identity of the server, and wherein the policy defines one or more criteria restricting a set of actions permissible using the shared access credential, wherein the SBD certificate is one of:

a server-based owner device (SBOD) certificate that identifies the sharer device as a device belonging to an owner of the system; and

a server-based friend device (SBFD) certificate that identifies the sharer device as a device belonging to an entity granted authority by the owner; and

performing, by the sharee device, an action in accordance with the determined policy.

12 . The method of claim 11 , further comprising:

identifying, by the sharee device, an access credential class defined by class information included in the access credential; and

wherein performing an action in accordance with the determined policy includes:

performing an action in accordance with the determined policy and the identified access credential class.

13 . The method of claim 12 , wherein the access credential class is associated with a rental provider access credential; and

wherein the action is an action associated with usage of a system managed by the rental provider.

14 . The method of claim 11 , wherein the SBD certificate includes an identity of the sharer device indicative that the sharer device is a delegate server authorized by an owner device of the system to grant limited access to the system; and

wherein determining the policy includes:

based on the included identity in the SBD certificate, determining a policy associated with the delegate server.

15 . The method of claim 11 , wherein the access credential includes a signed attestation package for a public key pair associated with the sharee device;

wherein the attestation package is signed by the sharer device using a private key corresponding to a public key included in the SBD certificate; and

wherein the performed action includes:

using the public key pair associated with the sharee device, the signed attestation package, and the SBD certificate to authenticate the sharee device to the system.

16 . The method of claim 15 , further comprising:

generating, by the sharee device, the public key pair associated with the sharee device; and

submitting, by the sharee device, a public key of the public key pair in an attestation signing request to the sharer device to obtain the signed attestation package.

17 . A sharee device, comprising:

one or more processors; and

memory having program instructions stored therein that are executable by the one or more processors to cause the sharee device to perform operations including:

receiving an access credential shared by a sharer device to obtain access to a system;

determining a policy based on a server-based device (SBD) certificate included in the access credential, wherein the SBD certificate identifies the sharer device as being a server and certifies a public key pair corresponding to an identity of the server, and wherein the policy defines one or more criteria restricting a set of actions permissible using the shared access credential, wherein the SBD certificate is one of:

a server-based owner device (SBOD) certificate that identifies the sharer device as a device belonging to an owner of the system; and

a server-based friend device (SBFD) certificate that identifies the sharer device as a device belonging to an entity granted authority by the owner; and

performing an action in accordance with the determined policy.

18 . The sharee device of claim 17 , wherein the action includes:

performing, with the system, a challenge response exchange that includes using a private key of the access credential to sign a challenge issued by the system.

19 . The sharee device of claim 18 , wherein the operations further comprise:

storing the access credential in a secure element configured to use the private key to generate a signature of the issued challenge.

20 . The sharee device of claim 17 , wherein the system is a vehicle.