An administration entity controls access to an electronic device by
generating credentials and a plurality of corresponding proofs, wherein
no valid proofs are determinable given only the credentials and values
for expired proofs. The electronic device receives the credentials and,
if access is authorized at a particular time, the electronic device
receives a proof corresponding to the particular time and confirms the
proof using the credentials. A single administration entity may generate
the credentials and generate the proofs and/or there may be a first
administration entity that generates the credentials and other
administration entities that generate proofs. The credentials may be a
digital certificate that includes a final value that is a result of
applying a one way function to a first one of the proofs.