IP Library › Granted Patent US 12,470,551
Granted Patent B2
US 12,470,551 · App. 18/674,271 · Granted Nov 11, 2025

Structure-based access control

Inventors: Mark Spates, IV (San Francisco, CA); Vincent Mo (Sunnyvale, CA); Zhenguo Guan (Cupertino, CA); David Roy Schairer (San Jose, CA)
Assignee: GOOGLE LLC
H04L63/0853G06F16/2379
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,551
App. No.
18/674,271
Granted
Nov 11, 2025
Kind
B2
Abstract

The present disclosure provides systems and methods that perform structure-based access control. In particular, rather than relying upon a user-specific credential scheme, which can require manual sharing of user-specific credentials and/or switching between the multiple accounts to access the particular devices, applications, or services associated with such accounts, the systems and methods of the present disclosure facilitate user credentials to be inherited by or otherwise assigned to a structure identifier associated with a structure (e.g., a home in which the user resides), thereby generating a set of structure credentials. This enables other users in the structure, who may be part of a collaborative user group, to access devices, applications, and/or services using the structure credentials.

Claims (58)

1 . A computer-implemented method, comprising:

receiving, from a first user, a first set of user credentials for accessing one or more of: a first computing device physically located within a physical structure, a first application, or a first web service;

assigning the first set of user credentials to a structure identifier of the physical structure to generate a first set of structure credentials, wherein the first set of structure credentials are distinct from the first set of user credentials;

receiving, from the first user, a setting that indicates whether a second user is authenticated to access or use the first computing device, the first application, or the first web service;

receiving, from the second user, a request to control the first computing device, the first application, or the first web service; and

in response to receiving the request from the second user:

determining, based on the setting, whether to use the first set of structure credentials to enable the second user to, without sharing the first set of user credentials with the second user, access the first computing device, the first application, or the first web service.

2 . The method of claim 1 , wherein the setting received from the first user enables any user to control the first computing device, the first application, or the first web service.

3 . The method of claim 2 , further comprising:

in response to receiving the request from the second user, fulfilling the request from the second user using the first set of structure credentials.

4 . The method of claim 2 , wherein the first set of user credentials is associated with a first user account of the first user for the first application, the first application being a music streaming application.

5 . The method of claim 1 , wherein the setting received from the first user enables only one or more authenticated users to control the first computing device, the first application, or the first web service.

6 . The method of claim 5 , further comprising:

in response to receiving the request from the second user and in response to determining that the second user is one of the one or more authenticated users, fulfilling the request from the second user using the first set of structure credentials.

7 . The method of claim 5 , further comprising:

in response to receiving the request from the second user and in response to determining that the second user is not any of the one or more authenticated users, not making available the first set of structure credentials to access or use the first computing device, the first application, or the first web service.

8 . The method of claim 5 , wherein the first set of user credentials is associated with a first user account of the first user for the first application, the first application being a calendar application.

9 . The method of claim 1 , wherein assigning the first set of user credentials to the structure identifier comprises:

using the first set of user credentials to obtain an authentication token from a web server; and

storing the authentication token at the first computing device.

10 . A computer-implemented method, comprising:

determining that a first user is assigned as an owner of a physical structure,

wherein the first user is assigned as the owner of the physical structure by a different user, and

wherein the different user is assigned as an additional owner of the physical structure;

receiving, from the first user, a first set of user credentials for accessing one or more of: a first computing device physically located within the physical structure, a first application, or a first web service,

wherein the first set of user credentials is associated with a user account of the first user; and

in response to receiving the first set of user credentials from the first user and based on the first user being assigned as the owner of the physical structure, assigning the first set of user credentials to a structure identifier of the physical structure to generate a first set of structure credentials,

wherein the first set of structure credentials are distinct from the first set of user credentials;

receiving, from the different user, a second set of user credentials for accessing one or more of: a second computing device physically located within the physical structure, a second application, or a second web service;

in response to receiving the second set of user credentials from the second user and based on the second user being the additional owner of the physical structure, assigning the second set of user credentials to the structure identifier of the physical structure to generate a second set of structure credentials,

wherein the second set of structure credentials are distinct from the first set of user credentials;

receiving a command from the first user to control the second computing device, the second application, or the second web service,

wherein the second computing device is the same as the first computing device, the second application is the same as the first application, and the second web service is the same as the first web service; and

in response to receiving the command from the first user and based on the first user being the owner of the structure, determining whether to use the first set of structure credentials or the second set of structure credentials to control the second computing device, the second application, or the second web service.

11 . The method of claim 10 wherein the command from the first user is to control the second computing device; and

wherein, in response to receiving the command from the first user and based on the first user being the owner of the structure, the second computing device is controlled using the second set of structure credentials.

12 . The method of claim 10 wherein the command from the first user is to control the second application; and

wherein, in response to receiving the command from the first user and based on the first user being the owner of the structure, the second application is controlled using the second set of structure credentials.

13 . The method of claim 10 wherein the command from the first user is to control the second web service; and

wherein, in response to receiving the command from the first user and based on the first user being the owner of the structure the second web service is accessed using the second set of structure credentials.

14 . The method of claim 10 , wherein the second set of user credentials is associated with a user account of the second user.

15 . The method of claim 10 , wherein the first set of user credentials is received via a voice command of the first user.

16 . The method of claim 10 , wherein:

the structure identifier is entered by the first user,

the structure identifier is programmed into the first computing device by a manufacturer, or

the structure identifier is assigned to the physical structure when the first computing device is deployed in the physical structure.

17 . A system comprising:

a processor, a computer-readable memory, one or more computer-readable storage media, and program instructions collectively stored on the one or more computer-readable storage media, the program instructions executable to:

receive, from a first user, a first set of user credentials for accessing one or more of: a first computing device physically located within a physical structure, a first application, or a first web service;

assign the first set of user credentials to a structure identifier of the physical structure to generate a first set of structure credentials, wherein the first set of structure credentials are distinct from the first set of user credentials;

receive, from the first user, a setting that indicates whether a second user is authenticated to access or use the first computing device, the first application, or the first web service;

receive, from the second user, a request to control the first computing device, the first application, or the first web service; and

in response to receiving the request from the second user:

determine, based on the setting, whether to use the first set of structure credentials to enable the second user to, without sharing the first set of user credentials with the second user, access the first computing device, the first application, or the first web service.

18 . The system of claim 17 , wherein the setting received from the first user enables any user to control the first computing device, the first application, or the first web service.

19 . The system according to claim 18 , the program instructions further being executable to:

in response to receiving the request from the second user, fulfill the request from the second user using the first set of structure credentials.

20 . The system of claim 18 , wherein the first set of user credentials is associated with a first user account of the first user for the first application, the first application being a music streaming application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2024
From: SPATES, MARK, IV; MO, VINCENT YANTON; GUAN, ZHENGUO; SCHAIRER, DAVID ROY
To: GOOGLE LLC
Reel/Frame 067743/0115 →
Continuity (5)
Continuation 18214217 · Jun 26, 2023
Continuation 17962769 · Oct 10, 2022
Continuation 16609569
Provisional Application 62591934 · Nov 29, 2017
Related Publication 20240314120A1 · Sep 19, 2024
References Cited (33)
US 9191382B1 · Homung et al. · 2015 [cited by applicant]
US 9674187B1 · Ngo et al. · 2017 [cited by applicant]
US 10523441B2 · Lingappa · 2019 [cited by applicant]
US 11470078B2 · Spates, IV et al. · 2022 [cited by applicant]
US 11722483B2 · Spates, IV et al. · 2023 [cited by applicant]
US 20140143826A1 · Sharp · 2014 [cited by applicant]
US 20150213355A1 · Sharma · 2015 [cited by examiner]
US 20170024378A1 · Sharma et al. · 2017 [cited by applicant]
US 20170132909A1 · Rabb et al. · 2017 [cited by applicant]
US 20170142124A1 · Mukhin et al. · 2017 [cited by applicant]
US 20170318075A1 · Liensberger et al. · 2017 [cited by applicant]
US 20180018373A1 · Yazdian · 2018 [cited by examiner]
US 20190020636A1 · Gehring · 2019 [cited by applicant]
US 20190122001A1 · Bradley · 2019 [cited by examiner]
US 20200067916A1 · Spates, IV et al. · 2020 [cited by applicant]
US 20230030076A1 · Spates, IV et al. · 2023 [cited by applicant]
US 20230336544A1 · Spates, IV et al. · 2023 [cited by applicant]
CN 105812140 · 2016 [cited by applicant]
CN 106412083 · 2017 [cited by applicant]
CN 106685978 · 2017 [cited by applicant]
CN 106992989 · 2017 [cited by applicant]
CN 106992989B · 2020 [cited by examiner]
WO 2019108648 · 2019 [cited by applicant]
Sampemane, G. et al.; Access control for Active Spaces; 18th Annual Computer Security Applications Conference; Proceedings, Las Vegas ; pp. 343-352; dated 2002. [cited by applicant]
Armac, I. et al.; Privacy-Friendly Smart Environments; 2009 Third International Conference on Next Generation Mobile Applications, Services and Technologies; Cardiff, UK; pp. 425 431; dated 2009. [cited by applicant]
European Patent Office; Intention to Grant issued in Application No. 18829546.3, 42 pages, dated Oct. 24, 2022. [cited by applicant]
China National Intellecutal Property Administration; Notice of Grant issued for Application No. 201880076605.5, 6 pages, dated Jul. 20, 2022. [cited by applicant]
Ma Guojun et al.; An End-to-End Security Scheme of the Internet of Things; Information Network Security; 9 pages; dated Oct. 10, 2017. [cited by applicant]
European Patent Office; Intemational Search Report and Written Opinion of Ser. No. PCT/US2018/062841; 14 pages; dated Feb. 11, 2019. [cited by applicant]
European Patent Office; Communication Pursuant to Article 94(3) for European Application No. 18829546.3; 6 pages; dated Jul. 29, 2020. [cited by applicant]
European Patent Office; Communication Pursuant to Article 94(3) EPC issued in Application No. 18829546.3; 7 pages; dated Jun. 17, 2021. [cited by applicant]
China National Intellectual Property Administration; Notification of First Office Action issued in Application No. 201880076605.5; 23 pages; dated Oct. 19, 2021. [cited by applicant]
China National Intellectual Property Administration; Second Office Action issued for Application No. 201880076605.5; 6 pages; dated Apr. 6, 2022. [cited by applicant]