-
公开(公告)号:WO2019118203A1
公开(公告)日:2019-06-20
申请号:PCT/US2018/063229
申请日:2018-11-30
Applicant: APPLE INC.
Inventor: BENSON, Wade , SMITH, Michael J. , DE CESARE, Joshua P.
IPC: G06F21/72 , G06F21/74 , G06F15/167 , G06F12/14
Abstract: Techniques are disclosed relating to data storage. In various embodiments, a computing device includes first and second processors and memory having stored therein a first encrypted operating system executable by the first processor and a second encrypted operating system executable by the second processor. The computing device also includes a secure circuit configured to receive, via a first mailbox mechanism of the secure circuit, a first request from the first processor for a first cryptographic key usable to decrypt the first operating system. The secure circuit is further configured to receive, via a second mailbox mechanism of the secure circuit, a second request from the second processor for a second cryptographic key usable to decrypt the second operating system, and to provide the first and second cryptographic keys.
-
2.
公开(公告)号:WO2017218208A1
公开(公告)日:2017-12-21
申请号:PCT/US2017/035601
申请日:2017-06-02
Applicant: APPLE INC.
Inventor: BENSON, Wade , KROCHMAL, Marc, J. , LEDWITH, Alexander, R. , IAROCCI, John , HAUCK, Jerrold, V. , BROUWER, Michael , ADLER, Mitchell, D. , SIERRA, Yannick, L.
IPC: H04L29/06
Abstract: Some embodiments of the invention provide a method for a trusted (or originator) device to modify the security state of a target device (e.g., unlocking the device) based on a securing ranging operation (e.g., determining a distance, proximity, etc.). The method of some embodiments exchanges messages as a part of a ranging operation in order to to determine whether the trusted and target devices are within a specified range of each other before allowing the trusted device to modify the security state of the target device. In some embodiments, the messages are derived by both devices based on a shared secret and are used to verify the source of ranging signals used for the ranging operation. In some embodiments, the method is performed using multiple different frequency bands.
Abstract translation: 本发明的一些实施例提供一种用于可信任(或发起者)设备基于安全测距操作来修改目标设备的安全状态(例如,解锁设备)的方法(例如,确定 距离,接近度等)。 一些实施例的方法交换消息作为测距操作的一部分,以便在允许可信设备修改目标设备的安全状态之前确定可信设备和目标设备是否在彼此的指定范围内。 在一些实施例中,消息是由两个设备基于共享秘密导出的并且被用于验证用于测距操作的测距信号源。 在一些实施例中,该方法使用多个不同的频带来执行。 p>
-
公开(公告)号:WO2020214833A1
公开(公告)日:2020-10-22
申请号:PCT/US2020/028549
申请日:2020-04-16
Applicant: APPLE INC.
Inventor: LEDWITH, Alexander R. , BENSON, Wade , KROCHMAL, Marc J. , IAROCCI, John J. , HAUCK, Jerrold V. , BROUWER, Michael , ADLER, Mitchell D. , SIERRA, Yannick L. , SYKORA, Libor , MARGARITOV, Jiri
Abstract: In some embodiments, a first device performs ranging operations to allow a user to perform one or more operations on the first device without providing device-access credentials. For example, when a second device is within a first distance of the first device, the first device determines that the second device is associated with a first user account that is authorized to perform operations on the first device. In response to the determination, the first device enables at least one substitute interaction (e.g., a password-less UI interaction) to allow the operations to be performed on the first device to be accessed without receiving access credentials through a user interface. In response to detecting an occurrence of the substitute interaction, the operation is authorized on the first device.
-
公开(公告)号:WO2022197822A1
公开(公告)日:2022-09-22
申请号:PCT/US2022/020581
申请日:2022-03-16
Applicant: APPLE INC.
Inventor: BROGLE, Kyle C. , BENSON, Wade , DEVLIN, Sean P. , KUCEROVA, Lucie , MENSCH, Thomas , SIERRA, Yannick L. , SUCHAN, Tomislav
Abstract: Embodiments described herein provided techniques to enable peripherals configured to provide secure functionality. A secure circuit on a peripheral device can be paired with a secure circuit on a host device outside of a factory environment without compromising security by verifying silicon keys that are embedded within the secure circuit during manufacturing.
-
公开(公告)号:WO2021262545A1
公开(公告)日:2021-12-30
申请号:PCT/US2021/038039
申请日:2021-06-18
Applicant: APPLE INC.
Inventor: KOVAH, Xeno S. , SCHLEJ, Nikolaj , MENSCH, Thomas P. , BENSON, Wade , HAUCK, Jerrold V. , DE CESARE, Josh P. , JENNINGS, Austin G. , DONG, John J. , GRAHAM, Robert C. , FORTIER, Jacques
IPC: G06F21/57 , H04L29/06 , H04L9/32 , G06F21/575 , G06F21/72 , G06F21/73 , G06F2221/034 , G06F9/4406 , H04L63/0823 , H04L63/123 , H04L63/126 , H04L9/0897 , H04L9/3226 , H04L9/3236 , H04L9/3247 , H04L9/3263 , H04L9/3268
Abstract: Techniques are disclosed relating to securing computing devices during boot. In various embodiments, a secure circuit of a computing device generates for a public key pair and signs, using a private key of the public key pair, configuration settings for an operating system of the computing device. A bootloader of the computing device receives a certificate for the public key pair from a certificate authority and initiates a boot sequence to load the operating system. The boot sequence includes the bootloader verifying the signed configuration settings using a public key included in the certificate and the public key pair. In some embodiments, the secure circuit cryptographically protects the private key based on a passcode of a user, the passcode being usable by the user to authenticate to the computing device.
-
公开(公告)号:EP3925254A1
公开(公告)日:2021-12-22
申请号:EP20724335.3
申请日:2020-04-16
Applicant: Apple Inc.
-
公开(公告)号:EP4284046A3
公开(公告)日:2024-01-17
申请号:EP23202648.4
申请日:2017-06-02
Applicant: Apple Inc.
Inventor: BENSON, Wade , KROCHMAL, Marc J. , LEDWITH, Alexander R. , IAROCCI, John , HAUCK, Jerrold V. , BROUWER, Michael , ADLER, Mitchell D. , SIERRA, Yannick L.
IPC: H04W8/00 , H04W12/086 , H04W12/06 , H04W12/0431 , H04W12/041 , H04L9/40
Abstract: There is provided a method comprising announcing, by a proxy device (830), an availability of a trusted device (520); in response to the announced availability, receiving, by the proxy device (830), a first request (850) from a target device (510); and upon receiving the first request from the target device (510), sending, by the proxy device (830), a second request to the trusted device (520), wherein the second request (855) comprises a request for the trusted device (520) to announce its availability directly to the target device (510) from which the first request was received, and the trusted device (520) establishes a communication connection with the target device (510) based on the second request.
-
公开(公告)号:EP4284046A2
公开(公告)日:2023-11-29
申请号:EP23202648.4
申请日:2017-06-02
Applicant: Apple Inc.
Inventor: BENSON, Wade , KROCHMAL, Marc J. , LEDWITH, Alexander R. , IAROCCI, John , HAUCK, Jerrold V. , BROUWER, Michael , ADLER, Mitchell D. , SIERRA, Yannick L.
IPC: H04W12/086
Abstract: There is provided a method comprising announcing, by a proxy device (830), an availability of a trusted device (520); in response to the announced availability, receiving, by the proxy device (830), a first request (850) from a target device (510); and upon receiving the first request from the target device (510), sending, by the proxy device (830), a second request to the trusted device (520), wherein the second request (855) comprises a request for the trusted device (520) to announce its availability directly to the target device (510) from which the first request was received, and the trusted device (520) establishes a communication connection with the target device (510) based on the second request.
-
公开(公告)号:EP4291998A1
公开(公告)日:2023-12-20
申请号:EP22715256.8
申请日:2022-03-16
Applicant: Apple Inc.
Inventor: BROGLE, Kyle C. , BENSON, Wade , DEVLIN, Sean P. , KUCEROVA, Lucie , MENSCH, Thomas , SIERRA, Yannick L. , SUCHAN, Tomislav
-
公开(公告)号:EP4168913A1
公开(公告)日:2023-04-26
申请号:EP21740398.9
申请日:2021-06-18
Applicant: Apple Inc.
-
-
-
-
-
-
-
-
-