IP Library › Granted Patent US 9,680,648
Granted Patent B2
US 9,680,648 · App. 15/077,794 · Granted Jun 13, 2017

Securely recovering a computing device

Inventors: Dallas Blake De Atley (San Francisco, CA); Joshua De Cesare (Campbell, CA); Michael Smith (Sunnyvale, CA); Matthew Reda (San Jose, CA); Shantonu Sen (Mountain View, CA); John Andrew Wright (San Francisco, CA)
Assignee: Apple Inc.
H04L9/302G06F11/1417G06F21/51G06F21/572G06F21/575G06F21/64H04L9/14H04L9/3239H04L9/3247H04L9/3249H04L63/06H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,680,648
App. No.
15/077,794
Granted
Jun 13, 2017
Kind
B2
Abstract

A method and an apparatus for establishing an operating environment by certifying a code image received from a host over a communication link are described. The code image may be digitally signed through a central authority server. Certification of the code image may be determined by a fingerprint embedded within a secure storage area such as a read only memory (ROM) of the portable device based on a public key certification process. A certified code image may be assigned a hash signature to be stored in a storage of the portable device. An operating environment of the portable device may be established after executing the certified code.

Claims (58)

1. A method carried out at a computing device, the method comprising:

loading, into a storage of the computing device, a code image that is digitally signed by a signature;

determining whether the code image is certified by verifying the signature using a fingerprint embedded within a read only memory (ROM) of the computing device;

when the code image is certified:

executing the code image to establish an operating environment of the computing device; and

when the code image is not certified:

removing the code image from the storage of the computing device, and

entering a Device Firmware Upgrade (DFU) mode to perform system management tasks for the computing device.

2. The method of claim 1 , wherein the fingerprint is associated with a unique identifier (UID) specific to the computing device.

3. The method of claim 1 , wherein executing the code image comprises:

determining whether the code image matches the signature based on a public key compatible with X.509 standard; and

determining whether the fingerprint matches the public key, wherein the fingerprint is based on a first hash value of the public key.

4. The method of claim 3 , further comprising:

deriving a second hash value based on the code image; and

encrypting the second hash value into a header value based on a key stored in the ROM of the computing device.

5. The method of claim 1 , further comprising, when the code image is certified:

verifying that an operating system component is trusted before executing the operating system component in the storage.

6. The method of claim 1 , wherein the code image is received from an entity that is communication with the computing device.

7. The method of claim 1 , further comprising:

resetting the computing device.

8. A non-transitory computer readable storage medium configured to store instructions that, when executed by a processor included in a computing device, cause the computing device to carry out steps that include:

loading, into a storage of the computing device, a code image that is digitally signed by a signature;

determining whether the code image is certified by verifying the signature using a fingerprint embedded within a read only memory (ROM) of the computing device;

when the code image is certified:

executing the code image to establish an operating environment of the computing device; and

when the code image is not certified:

removing the code image from the storage of the computing device, and

entering a Device Firmware Upgrade (DFU) mode to perform system management tasks for the computing device.

9. The non-transitory computer readable storage medium of claim 8 , wherein the fingerprint is associated with a unique identifier (UID) specific to the computing device.

10. The non-transitory computer readable storage medium of claim 8 , wherein executing the code image comprises:

determining whether the code image matches the signature based on a public key compatible with X.509 standard; and

determining whether the fingerprint matches the public key, wherein the fingerprint is based on a first hash value of the public key.

11. The non-transitory computer readable storage medium of claim 10 , wherein the steps further include:

deriving a second hash value based on the code image; and

encrypting the second hash value into a header value based on a key stored in the ROM of the computing device.

12. The non-transitory computer readable storage medium of claim 8 , wherein the steps further include, when the code image is certified:

verifying that an operating system component is trusted before executing the operating system component in the storage.

13. The non-transitory computer readable storage medium of claim 8 , wherein the code image is received from an entity that is communication with the computing device.

14. The non-transitory computer readable storage medium of claim 8 , wherein the steps further include:

resetting the computing device.

15. A computing device comprising a processor configured to cause the computing device to carry out steps that include:

loading, into a storage of the computing device, a code image that is digitally signed by a signature;

determining whether the code image is certified by verifying the signature using a fingerprint embedded within a read only memory (ROM) of the computing device;

when the code image is certified:

executing the code image to establish an operating environment of the computing device; and

when the code image is not certified:

removing the code image from the storage of the computing device, and

entering a Device Firmware Upgrade (DFU) mode to perform system management tasks for the computing device.

16. The computing device of claim 15 , wherein the fingerprint is associated with a unique identifier (UID) specific to the computing device.

17. The computing device of claim 15 , wherein executing the code image comprises:

determining whether the code image matches the signature based on a public key compatible with X.509 standard; and

determining whether the fingerprint matches the public key, wherein the fingerprint is based on a first hash value of the public key.

18. The computing device of claim 17 , wherein the steps further include:

deriving a second hash value based on the code image; and

encrypting the second hash value into a header value based on a key stored in the ROM of the computing device.

19. The computing device of claim 15 , wherein the steps further include, when the code image is certified:

verifying that an operating system component is trusted before executing the operating system component in the storage.

20. The computing device of claim 15 , wherein the code image is received from an entity that is communication with the computing device.

Continuity (4)
Continuation 14452397 · Aug 5, 2014
Continuation 13566969 · Aug 3, 2012
Continuation 11620697 · Jan 7, 2007
Related Publication 20160277186A1 · Sep 22, 2016