IP Library › Granted Patent US 10,452,859
Granted Patent B2
US 10,452,859 · App. 15/275,289 · Granted Oct 22, 2019

File system metadata protection

Inventors: Eric B. Tamura (Sunnyvale, CA); Wade Benson (San Jose, CA); John Garvey (Victoria, CA)
Assignee: Apple Inc.
G06F21/6218G06F21/31G06F21/602H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,452,859
App. No.
15/275,289
Filed
Sep 23, 2016
Granted
Oct 22, 2019
Kind
B2
Art Unit
2498
USPC
713/193
Abstract

Techniques are disclosed relating to securely storing file system metadata in a computing device. In one embodiment, a computing device includes a processor, memory, and a secure circuit. The memory has a file system stored therein that includes metadata for accessing a plurality of files in the memory. The metadata is encrypted with a metadata encryption key that is stored in an encrypted form. The secure circuit is configured to receive a request from the processor to access the file system. In response to the request, the secure circuit is configured to decrypt the encrypted form of the metadata encryption key. In some embodiments, the computing device includes a memory controller configured to receive the metadata encryption key from the secure circuit, retrieve the encrypted metadata from the memory, and decrypt the encrypted metadata prior to providing the metadata to the processor.

Claims (29)

1. A computing device, comprising:

a processor;

memory having a first file system stored therein, wherein the first file system includes metadata for accessing a plurality of files in the memory, wherein the metadata includes directory records of the first file system, and wherein the metadata is encrypted with a metadata encryption key that is stored in an encrypted form; and

a secure circuit having cryptographic circuitry isolated from direct access by the processor, wherein the secure circuit is configured to:

receive a request from the processor to access the first file system; and

in response to the request, decrypt, via the cryptographic circuitry, the encrypted form of the metadata encryption key; and

a memory controller circuit coupled to the memory, wherein the memory controller circuit is configured to:

receive the metadata encryption key from the secure circuit;

retrieve the encrypted metadata from the memory; and

decrypt the encrypted metadata prior to providing the decrypted metadata to the processor.

2. The computing device of claim 1 , wherein the secure circuit is further configured to:

prior to providing the metadata encryption key to the memory controller circuit, encrypt the metadata encryption key with a shared encryption key known to the memory controller circuit.

3. The computing device of claim 1 , wherein the memory controller circuit is further configured to:

receive a request from the processor to write new metadata of the first file system to the memory;

encrypt the new metadata with the metadata encryption key received from the secure circuit; and

send the encrypted new metadata to the memory for storage.

4. The computing device of claim 3 , wherein the new metadata includes a record for a directory, wherein the record identifies names for a plurality of files stored in the directory.

5. The computing device of claim 1 , wherein the secure circuit is further configured to:

receive a credential supplied by a user of the computing device; and

based on the credential, derive a decryption key for decrypting the encrypted form of the metadata encryption key.

6. The computing device of claim 5 , further comprising:

a touch screen configured to:

receive a passcode from the user; and

provide the passcode to the secure circuit as the credential.

7. The computing device of claim 5 , wherein the secure circuit is further configured to:

store a unique identifier indicative of the computing device; and

derive the decryption key based on the supplied credential and the stored unique identifier.

8. The computing device of claim 1 , wherein the memory has a first partition and a second partition stored therein, wherein the first partition includes encrypted metadata of a first system that is encrypted with a first metadata encryption key, and wherein the second partition includes encrypted metadata of a second file system that is encrypted with a second metadata encryption key.

9. The computing device of claim 1 , wherein the secure circuit is further configured to communicate with the processor via a mailbox mechanism configured to isolate circuitry of the secure circuit from being accessed by the processor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2016
From: TAMURA, ERIC B.; BENSON, WADE; GARVEY, JOHN
To: APPLE INC.
Reel/Frame 040664/0888 →
Continuity (2)
Provisional Application 62348617 · Jun 10, 2016
Related Publication 20170357817A1 · Dec 14, 2017
Cited By (3)
US 12,206,799 US 12,314,408 US 12,712,744