Provision of domains in secure enclave to support multiple users

    公开(公告)号:US11531758B2

    公开(公告)日:2022-12-20

    申请号:US17122771

    申请日:2020-12-15

    Applicant: Apple Inc.

    Abstract: Embodiments described herein provide for a system, method, and apparatus to provision domains in a secure enclave processor to support multiple users. One embodiment provides for an apparatus comprising a first processor to receive a set of credentials associated with one of multiple user accounts on the apparatus and a second processor including a secure circuit to provide a secure enclave, the secure enclave to receive a request from the first processor to authenticate the set of credentials, the request including supplied credentials and an authentication type, where the secure enclave is to block the request from the first processor in response to a determination that the user account has exceeded a threshold number of successive failed authentication attempts for the authentication type.

    Ephemeral Data Storage
    33.
    发明申请

    公开(公告)号:US20220391517A1

    公开(公告)日:2022-12-08

    申请号:US17805329

    申请日:2022-06-03

    Applicant: Apple Inc.

    Abstract: Techniques are disclosed relating to securely storing data in a computing system. In some embodiments, a computing system performs a boot sequence that includes generating ephemeral key data and preventing the generated ephemeral key data from being stored in a non-volatile storage including persisting the generated ephemeral key data in the volatile storage. The boot sequence further includes creating, in the non-volatile storage, an ephemeral data volume and encrypting the ephemeral data volume by using the ephemeral key data persisted in the volatile storage.

    Secure Reduced Power Mode
    34.
    发明申请

    公开(公告)号:US20220129527A1

    公开(公告)日:2022-04-28

    申请号:US17505318

    申请日:2021-10-19

    Applicant: Apple Inc.

    Abstract: Techniques are disclosed relating to maintaining device security associated with reduced power modes. In some embodiments, a computing device receives a request to place the computing device in a reduced power mode in which a first memory of the computing device is powered off. Based on the request, the computing device offloads a memory page from the first memory to a second memory such that the offloading includes encrypting the memory page. Based on a request to resume from the reduced power mode, the computing device restores the memory page from the second memory to the first memory such that the restoring includes decrypting the encrypted memory page. After initiating the restoring, the computing device presents a user authentication prompt asking for a user credential.

    PROVISION OF DOMAINS IN SECURE ENCLAVE TO SUPPORT MULTIPLE USERS

    公开(公告)号:US20210141902A1

    公开(公告)日:2021-05-13

    申请号:US17122771

    申请日:2020-12-15

    Applicant: Apple Inc.

    Abstract: Embodiments described herein provide for a system, method, and apparatus to provision domains in a secure enclave processor to support multiple users. One embodiment provides for an apparatus comprising a first processor to receive a set of credentials associated with one of multiple user accounts on the apparatus and a second processor including a secure circuit to provide a secure enclave, the secure enclave to receive a request from the first processor to authenticate the set of credentials, the request including supplied credentials and an authentication type, where the secure enclave is to block the request from the first processor in response to a determination that the user account has exceeded a threshold number of successive failed authentication attempts for the authentication type.

    FILE SYSTEM METADATA PROTECTION
    39.
    发明申请

    公开(公告)号:US20170357817A1

    公开(公告)日:2017-12-14

    申请号:US15275289

    申请日:2016-09-23

    Applicant: Apple Inc.

    Abstract: Techniques are disclosed relating to securely storing file system metadata in a computing device. In one embodiment, a computing device includes a processor, memory, and a secure circuit. The memory has a file system stored therein that includes metadata for accessing a plurality of files in the memory. The metadata is encrypted with a metadata encryption key that is stored in an encrypted form. The secure circuit is configured to receive a request from the processor to access the file system. In response to the request, the secure circuit is configured to decrypt the encrypted form of the metadata encryption key. In some embodiments, the computing device includes a memory controller configured to receive the metadata encryption key from the secure circuit, retrieve the encrypted metadata from the memory, and decrypt the encrypted metadata prior to providing the metadata to the processor.

    Apparatuses and Methods for Using a Random Authorization Number to Provide Enhanced Security for a Secure Element
    40.
    发明申请
    Apparatuses and Methods for Using a Random Authorization Number to Provide Enhanced Security for a Secure Element 审中-公开
    使用随机授权号码为安全元素提供增强安全性的设备和方法

    公开(公告)号:US20150348022A1

    公开(公告)日:2015-12-03

    申请号:US14475375

    申请日:2014-09-02

    Applicant: Apple Inc.

    CPC classification number: G06Q20/385 G06Q20/3226 G06Q20/354 G06Q20/3829

    Abstract: A system for provisioning credentials onto an electronic device is provided. The system may include a payment network subsystem, a service provider subsystem, and one or more user devices that can be used to perform mobile transactions at a merchant terminal. The user device may communicate with the service provider subsystem in order to obtained commerce credentials from the payment network subsystem. The user device may include a secure element and a corresponding trusted processor. The trusted processor may generate a random authorization number and inject that number into the secure element. Mobile payments should only be completed if the random authorization number on the secure element matches the random authorization number at the trusted processor. The trusted processor may be configured to efface the previous random authorization number and generate a new random authorization number when detecting a potential change in ownership at the user device.

    Abstract translation: 提供了一种用于将凭证提供到电子设备上的系统。 系统可以包括支付网络子系统,服务提供商子系统以及可以用于在商家终端执行移动交易的一个或多个用户设备。 用户设备可以与服务提供商子系统通信,以便从支付网络子系统获得商业凭证。 用户设备可以包括安全元件和相应的可信处理器。 可信处理器可以生成随机授权号,并将该号码注入到安全元件中。 仅当安全元素上的随机授权号码与可信处理器上的随机授权号码匹配时,才应完成移动支付。 信任处理器可以被配置为在检测用户设备的所有权的潜在变化时消除先前的随机授权号码并生成新的随机授权号码。

Patent Agency Ranking