-
公开(公告)号:US12074865B1
公开(公告)日:2024-08-27
申请号:US16252515
申请日:2019-01-18
Applicant: Apple Inc.
Inventor: Max M. Gunther , Onar Vikingstad , Ramiro Calvo , Isabella M. Funke , Eric D. Friedman , Hervé Sibert , David P. Remahl , Yannick L. Sierra , Frank B. Dancs , Sudhakar N. Mambakkam
CPC classification number: H04L63/0838 , G06F21/71 , G06K7/1417 , G06K19/06037 , H04L9/0869 , H04L9/3213 , H04L9/3228 , H04L63/0428 , H04L63/061 , H04L63/0853 , H04L63/0861 , H04L63/102 , H04L63/108 , H04L63/18 , H04L65/1069
Abstract: This application relates to establishing a communication session between a host device and a trusted client device. A host device generates a one-time secret (OTS) and transmits the OTS to a trusted client device via an out-of-band communication channel. The trusted client device verifies an identity of a user of the trusted client device utilizing one or more sensors of the trusted client device. Responsive to verifying the identity of the user, the trusted client device negotiates an encryption key with the host device based on the OTS. The trusted client device then establishes a communication session with the host device utilizing the encryption key. The communication session can be utilized to pass credentials in a protected manner from the trusted client device to the host device that enable the host device to access a user account associated with a service.
-
公开(公告)号:US20220382838A1
公开(公告)日:2022-12-01
申请号:US17804814
申请日:2022-05-31
Applicant: Apple Inc.
Inventor: Fabio Sozzani , Isabella M. Funke , Frederic Jacobs , Brandon J. Van Ryswyk
IPC: G06F21/31
Abstract: Techniques are disclosed relating to computing security and privacy. In some embodiments, a computing device provides, to a service computing system, a service request that identifies an action and includes an anonymous identifier for a user of the computing device. The computing device receives, from the service computing system, a score request for a trustworthiness score indicative of the user's trustworthiness. In response to receiving the score request from the service computing system, the computing device provides information indicative of the user's identity to a scoring computing system and receives the trustworthiness score and a corresponding score signature from the scoring computing system. In response to receiving the score and the score signature from the scoring computing system, the computing device provides the score to the service computing system.
-