IP Library Granted Patent US 12,445,289
Granted Patent B2
US 12,445,289 · App. 17/591,430 · Granted Oct 14, 2025

Systems and methods for shared device access control

Inventors: Chu Ly Tran (San Jose, CA); Xun Chen (Freemont, CA)
Assignee: Samsung Electronics Co., Ltd.
H04L9/3236H04L9/0833H04L63/0861H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,289
App. No.
17/591,430
Granted
Oct 14, 2025
Kind
B2
Abstract

A method includes receiving, at an electronic device and from a second electronic device, a second root identifier, wherein the second root identifier is associated with a second profile tree maintained at the second electronic device and determining that a first root identifier does not match the second root identifier, wherein the first root identifier is based on a first profile tree maintained at the electronic device. The method further includes sending, to the second electronic device, the first profile tree, wherein the first profile tree comprises representation of currently maintained user profiles at the electronic device, receiving, from the second electronic device, user profile update information, and updating a subset of the currently maintained user profiles based on the user profile update information.

Claims (70)

1. A method, comprising:

receiving, at a first electronic device associated with a first root identifier, a second root identifier from a second electronic device, wherein the first root identifier is based on a first profile tree maintained at the first electronic device, and wherein the second root identifier is associated with a second profile tree maintained at the second electronic device;

determining that the first root identifier does not match the second root identifier;

sending, to the second electronic device, the first profile tree, wherein the first profile tree comprises a representation of currently-maintained user profiles at the first electronic device;

receiving, from the second electronic device, user profile update information, wherein the user profile update information corresponds to user profile information maintained at the second electronic device and determined to be more recent than corresponding user profile information at the first electronic device; and

updating a subset of the currently-maintained user profiles based on the user profile update information.

2. The method of claim 1 , further comprising:

responsive to updating the subset of the currently-maintained user profiles, updating the first profile tree; and

generating an updated first root identifier based on the updated first profile tree.

3. The method of claim 1 , wherein the first profile tree comprises a Merkle tree generated from one or more hash tables of user profile data.

4. The method of claim 3 , wherein the first root identifier comprises a Merkle root of the first profile tree.

5. The method of claim 1 , further comprising:

detecting the second electronic device;

authenticating the second electronic device as a peer device of a shared device group; and

establishing a trusted connection with the second electronic device.

6. The method of claim 5 , wherein detecting the second electronic device comprises:

receiving an advertising message from the second electronic device,

wherein the advertising message comprises an identifier of the shared device group and at least a portion of the second root identifier.

7. The method of claim 5 , wherein establishing the trusted connection with the second electronic device comprises:

receiving, from the second electronic device, a group key for the shared device group; and

confirming that the group key for the shared device group received from the second electronic device matches a group key for the shared device group maintained at the first electronic device.

8. The method of claim 7 , further comprising:

responsive to confirming that the group key for the shared device group received from the second electronic device matches the group key for the shared device group maintained at the first electronic device, decrypting a biometric authentication profile for a user with the group key;

receiving, through a biometric sensor of the first electronic device, biometric information of the user;

authenticating the user by comparing the biometric information of the user against the biometric authentication profile for the user; and

sending a logoff message for the user to the second electronic device.

9. The method of claim 1 , further comprising:

receiving, at the first electronic device from a third electronic device, a third root identifier, wherein the third root identifier is associated with a third profile tree maintained at the third electronic device;

determining that the first root identifier does not match the third root identifier;

sending, to the third electronic device, the first profile tree;

receiving, from the third electronic device, second user profile update information; and

updating a second subset of the currently-maintained user profiles at the first electronic device based on the second user profile update information.

10. The method of claim 1 , further comprising:

subsequent to updating the subset of the currently-maintained user profiles based on the user profile update information, sending a report to a remote management console, wherein the report comprises at least one of per-profile metadata of the currently-maintained user profiles or per-device metadata based on the currently-maintained user profiles.

11. An electronic device associated with a first root identifier, the first root identifier based on a first profile tree maintained at the electronic device, the electronic device comprising:

at least one communication interface; and

at least one processor configured to:

receive, via the at least one communication interface, a second root identifier from a second electronic device, wherein the second root identifier is associated with a second profile tree maintained at the second electronic device,

determine that the first root identifier does not match the second root identifier,

send, to the second electronic device, the first profile tree, wherein the first profile tree comprises a representation of currently-maintained user profiles at the electronic device,

receive, from the second electronic device, user profile update information, wherein the user profile update information corresponds to user profile information maintained at the second electronic device and determined to be more recent than corresponding user profile information at the electronic device; and

update a subset of the currently-maintained user profiles based on the user profile update information.

12. The electronic device of claim 11 , wherein the at least one processor is further configured to:

responsive to updating the subset of the currently-maintained user profiles, update the first profile tree, and

generate an updated first root identifier based on the updated first profile tree.

13. The electronic device of claim 11 , wherein the first profile tree comprises a Merkle tree generated from one or more hash tables of user profile data.

14. The electronic device of claim 13 , wherein the first root identifier comprises a Merkle root of the first profile tree.

15. The electronic device of claim 11 , wherein the at least one processor is further configured to:

detect the second electronic device,

authenticate the second electronic device as a peer device of a shared device group, and

establish a trusted connection with the second electronic device.

16. The electronic device of claim 15 , wherein:

to detect the second electronic device, the at least one processor is configured to receive an advertising message from the second electronic device, and

the advertising message comprises an identifier of the shared device group and at least a portion of the second root identifier.

17. The electronic device of claim 16 , wherein, to establish the trusted connection with the second electronic device, the at least one processor is configured to:

receive, from the second electronic device, a group key for the shared device group, and

confirm that the group key for the shared device group received from the second electronic device matches a group key for the shared device group maintained at the electronic device.

18. The electronic device of claim 17 , wherein the at least one processor is further configured to:

responsive to confirming that the group key for the shared device group received from the second electronic device matches the group key for the shared device group maintained at the electronic device, decrypt a biometric authentication profile for a user with the group key,

receive, through a biometric sensor of the electronic device, biometric information of the user,

authenticate the user by comparing the biometric information of the user against the biometric authentication profile for the user, and

send a logoff message for the user to the second electronic device via the at least one communication interface.

19. The electronic device of claim 11 , wherein the at least one processor is further configured to:

receive, via the at least one communication interface from a third electronic device, a third root identifier, wherein the third root identifier is associated with a third profile tree maintained at the third electronic device,

determine that the first root identifier does not match the third root identifier,

send, to the third electronic device, the first profile tree,

receive, from the third electronic device, second user profile update information, and

update a second subset of the currently-maintained user profiles at the electronic device based on the second user profile update information.

20. The electronic device of claim 11 , wherein the at least one processor is further configured to:

subsequent to updating the subset of the currently-maintained user profiles based on the user profile update information, send a report to a remote management console, wherein the report comprises at least one of per-profile metadata of the currently-maintained user profiles or per-device metadata based on the currently-maintained user profiles.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2022
From: TRAN, CHU LY; CHEN, XUN
To: SAMSUNG ELECTRONICS CO., LTD
Reel/Frame 058867/0320 →
Continuity (2)
Provisional Application 63210219 · Jun 14, 2021
Related Publication 20220400012A1 · Dec 15, 2022
References Cited (29)
US 9171268B1 · Penilla · 2015 [cited by examiner]
US 10447681B2 · Sajja et al. · 2019 [cited by applicant]
US 10855686B2 · Shah · 2020 [cited by applicant]
US 20020166119A1 · Cristofalo · 2002 [cited by examiner]
US 20030125057A1 · Pesola · 2003 [cited by applicant]
US 20050226224A1 · Lee · 2005 [cited by examiner]
US 20060161783A1 · Aiken et al. · 2006 [cited by applicant]
US 20060256734A1 · Erhart et al. · 2006 [cited by applicant]
US 20090133069A1 · Conness · 2009 [cited by examiner]
US 20090210898A1 · Childress · 2009 [cited by examiner]
US 20120023157A1 · Roth et al. · 2012 [cited by applicant]
US 20120177067A1 · Cho et al. · 2012 [cited by applicant]
US 20150082024A1 · Smith · 2015 [cited by applicant]
US 20150120837A1 · Chi · 2015 [cited by applicant]
US 20160344550A1 · Anton · 2016 [cited by examiner]
US 20170374548A1 · Mason · 2017 [cited by examiner]
US 20180285463A1 · Choi · 2018 [cited by examiner]
US 20190334724A1 · Anton · 2019 [cited by examiner]
US 20200050796A1 · Lacey et al. · 2020 [cited by applicant]
US 20200403808A1 · Smith et al. · 2020 [cited by applicant]
US 20210014670A1 · Li · 2021 [cited by examiner]
US 20210103449A1 · Terpstra · 2021 [cited by examiner]
US 20210136193A1 · Mun et al. · 2021 [cited by applicant]
JP 2019165474A · 2016 [cited by applicant]
KR 1020120080410A · 2012 [cited by applicant]
WO 2018038914A1 · 2018 [cited by applicant]
WO 2021031130A1 · 2021 [cited by applicant]
Supplementary European Search Report dated Jul. 4, 2024 in connection with European Patent Application No. 22825144.3, 10 pages. [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority regarding International Patent Application No. PCT/KR2022/00547 dated Jul. 28, 2022, 8 pages. [cited by applicant]