CRYPTOGRAPHIC SEPARATION OF USERS
    54.
    发明申请

    公开(公告)号:US20170357830A1

    公开(公告)日:2017-12-14

    申请号:US15275273

    申请日:2016-09-23

    Applicant: Apple Inc.

    Abstract: Techniques are disclosed relating to securely storing data in a computing device. In one embodiment, a computing device includes a secure circuit configured to maintain key bags for a plurality of users, each associated with a respective one of the plurality of users and including a first set of keys usable to decrypt a second set of encrypted keys for decrypting data associated with the respective user. The secure circuit is configured to receive an indication that an encrypted file of a first of the plurality of users is to be accessed and use a key in a key bag associated with the first user to decrypt an encrypted key of the second set of encrypted keys. The secure circuit is further configured to convey the decrypted key to a memory controller configured to decrypt the encrypted file upon retrieval from a memory.

    Baseband secure boot with remote storage
    57.
    发明授权
    Baseband secure boot with remote storage 有权
    带有远程存储的基带安全引导

    公开(公告)号:US09563765B2

    公开(公告)日:2017-02-07

    申请号:US14632917

    申请日:2015-02-26

    Applicant: Apple Inc.

    Abstract: In order to simplify and reduce the cost of an electronic device, the size of a first non-volatile memory associated with an integrated circuit is significantly reduced. Instead of using the first non-volatile memory, a second non-volatile memory associated with a processor in the electronic device is used to store an embedded operating system of the integrated circuit, as well as associated data and a configuration of the integrated circuit. To reduce the security risks associated with using this remote second non-volatile memory, the first non-volatile memory may store authorization information and anti-replay information. During a secure boot of the integrated circuit, the authorization information is used to verify that the embedded operating system, the data and the configuration are authorized. In addition, the anti-replay information is used to determine that the embedded operating system, the data and the configuration are different than previously received versions of these items.

    Abstract translation: 为了简化和降低电子设备的成本,与集成电路相关联的第一非易失性存储器的尺寸显着降低。 代替使用第一非易失性存储器,与电子设备中的处理器相关联的第二非易失性存储器用于存储集成电路的嵌入式操作系统,以及相关联的数据和集成电路的配置。 为了减少与使用该远程第二非易失性存储器相关联的安全风险,第一非易失性存储器可以存储授权信息和反重放信息。 在集成电路的安全启动期间,授权信息用于验证嵌入式操作系统,数据和配置是否被授权。 此外,反重放信息用于确定嵌入式操作系统,数据和配置与先前接收到的这些项目的版本不同。

    Combined Authorization Process
    58.
    发明申请
    Combined Authorization Process 审中-公开
    组合授权流程

    公开(公告)号:US20170012974A1

    公开(公告)日:2017-01-12

    申请号:US15273622

    申请日:2016-09-22

    Applicant: Apple Inc.

    Abstract: Some embodiments provide a method for a first device to join a group of related devices. The method receives input of a password for an account with a centralized entity and a code generated by a second device in the group. When the second device determines that the code input on the first device matches the generated code, the method receives an authentication code from the second device for authorizing the first device with the entity as a valid device for the account. The method uses the password and information regarding the first device to generate an application to the group. After sending the application to the second device, the method receives information from the second device that enables the first device to add itself to the group. The second device verifies the generated application, and the method uses the information received from the second device to join the group.

    Abstract translation: 一些实施例提供了一种用于第一设备加入一组相关设备的方法。 该方法接收到具有集中实体的帐户的密码输入和由组中的第二设备生成的代码。 当第二设备确定在第一设备上输入的代码与生成的代码匹配时,该方法从第二设备接收认证代码,用于授权具有该实体的第一设备作为该帐户的有效设备。 该方法使用密码和有关第一个设备的信息来生成组的应用程序。 在将应用发送到第二设备之后,该方法从第二设备接收使第一设备能够将自身添加到组中的信息。 第二设备验证生成的应用程序,并且该方法使用从第二设备接收的信息加入该组。

    Baseband Caching of SIM Files
    59.
    发明申请
    Baseband Caching of SIM Files 有权
    SIM文件的基带缓存

    公开(公告)号:US20150133196A1

    公开(公告)日:2015-05-14

    申请号:US14501573

    申请日:2014-09-30

    Applicant: Apple Inc.

    CPC classification number: H04W8/183

    Abstract: This disclosure relates to caching SIM files at a baseband processor to reduce cellular bootup time. According to one embodiment, a wireless device may read SIM files from a SIM and store a local copy of each file in a cache of the baseband processor of the wireless device. SIM identification information for the SIM from which the cached files were read may be associated with the cache. Indicator information usable for comparing file versions may also be generated and stored in the cache for each file. Upon a subsequent SIM initialization, the wireless device may read SIM files from the cache instead of from the initialized SIM if the cached version is identical to the SIM version, which may be determined based at least in part on the SIM identification information and the indicator information for such files.

    Abstract translation: 本公开涉及在基带处理器上缓存SIM文件以减少蜂窝启动时间。 根据一个实施例,无线设备可以从SIM读取SIM文件,并将每个文件的本地副本存储在无线设备的基带处理器的高速缓存中。 读取缓存文件的SIM卡的SIM识别信息可以与缓存相关联。 用于比较文件版本的指示符信息也可以被生成并存储在每个文件的高速缓存中。 在随后的SIM初始化中,如果缓存版本与SIM版本相同,则无线设备可以从高速缓存而不是从初始化的SIM读取SIM文件,其可以至少部分地基于SIM识别信息和指示符来确定 这些文件的信息。

Patent Agency Ranking