IP Library › Granted Patent US 11,863,671
Granted Patent B1
US 11,863,671 · App. 16/848,591 · Granted Jan 2, 2024

Accessory assisted account recovery

Inventors: Yannick L. Sierra (San Francisco, CA); Lucia E. Ballard (San Francisco, CA); Kyle C. Brogle (San Francisco, CA); DJ Capelis (San Francisco, CA)
Assignee: Apple Inc.
H04L9/0894H04L9/083H04L9/0822H04L9/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,863,671
App. No.
16/848,591
Granted
Jan 2, 2024
Kind
B1
Abstract

Embodiments described herein enable a user to bypass the use of one-time keys or account recovery codes by providing techniques for accessory assisted account recovery. In various embodiments, accessory assisted account recovery makes use of an accessory device of a user, where the accessory device can be any device having a secure processor, cryptographic engine, public key accelerator, or is otherwise able to accelerate cryptographic operations or perform cryptographic operations in a secure execution environment. An account recovery key can be split into multiple portions. At least one portion of the recovery key is then encrypted. The accessory device is then configured to be uniquely capable of decrypting the encrypted portion of an account recovery key.

Claims (62)

1. An electronic device, comprising:

a memory to store instructions; and

at least one application processor coupled with the memory, the at least one application processor to execute instructions stored in the memory, wherein the at least

one application processor is to:

split an account recovery key into multiple key portions, wherein the account recovery key is to enable recovery of an account associated with the electronic device;

receive an encryption key from an accessory device associated with the electronic device, wherein the encryption key is signed with an attestation key;

verify authenticity of the accessory device with the signed encryption key;

encrypt a portion of the account recovery key using cryptographic material derived from the encryption key, wherein encrypting the portion of the account recovery key includes to:

generate an ephemeral key pair;

compute a first portion of the cryptographic material based in part on a first key of the ephemeral key pair and the encryption key;

compute a second portion of the cryptographic material based in part on a second key of the ephemeral key pair and the first portion of the cryptographic material; and

encrypt the portion of the account recovery key using the second portion

of the cryptographic material; and

provide an encrypted portion of the account recovery key to a server associated with a user account associated with the electronic device.

2. The electronic device as in claim 1 , wherein the encrypted portion of the account recovery key provided to the server is to be used to recover credentials associated with the user account.

3. The electronic device as in claim 1 , wherein the encryption key received from the accessory device is a public key derived by the accessory device.

4. The electronic device as in claim 3 , the at least one application processor to provide randomized data to the accessory device to enable the accessory device to derive the public key.

5. The electronic device as in claim 1 , wherein the multiple key portions of the account recovery key include a first key portion and a second key portion and the at least one application processor is to encrypt the first key portion.

6. The electronic device as in claim 5 , wherein to encrypt the portion of the account recovery key includes to perform an encryption operation on the first key portion.

7. The electronic device as in claim 1 , wherein to provide the encrypted portion of the account recovery key to the server associated with the user account includes to store the encrypted portion of the account recovery key to the encrypted cloud storage container that is synced with the server via a network interface.

8. The electronic device as in claim 7 , wherein the server is capable of decrypting the encrypted cloud storage container.

9. The electronic device as in claim 7 , the at least one application processor is additionally to provide a second portion of the multiple key portions to the server.

10. A non-transitory machine-readable medium storing instructions to cause one or more processors on an electronic device to perform operations comprising:

receiving, at an accessory device, an encrypted portion of an account recovery key, wherein the encrypted portion of the account recovery key is a first portion of the account recovery key;

transmitting, to a primary device, the first portion of the account recovery key from the accessory device, the first portion of the account recovery key having been decrypted from the encrypted portion of the account recovery key, wherein decrypting the first portion of the account recovery key includes:

computing a first portion of the cryptographic material based in part on a first key of an ephemeral key pair and the encryption key;

computing a second portion of the cryptographic material based in part on a second key of the ephemeral key pair and the first portion of the cryptographic material; and

encrypting the portion of the account recovery key using the second portion of the cryptographic material.

11. The non-transitory machine-readable medium as in claim 10 , the operations additionally comprising receiving the encrypted portion of the account recovery key and the second portion of the account recovery key from a server, wherein the server is associated with an account having credentials or data which the account recovery key is used to recover.

12. The non-transitory machine-readable medium as in claim 10 , the operations additionally comprising transmitting a confirmation to the accessory device after recovering the account on the electronic device.

13. The method comprising:

splitting an account recovery key into multiple key portions, wherein the account recovery key is to enable recovery of an account associated with the electronic device;

receiving an encryption key from an accessory device associated with the electronic device, wherein the encryption key is signed with an attestation key;

verifying authenticity of the accessory device with the signed encryption key;

encrypting a portion of the account recovery key using cryptographic material derived from the encryption key, wherein the encrypting the portion of the account recovery key includes to:

generating an ephemeral key pair;

computing a first portion of the cryptographic material based in part on a first key of the ephemeral key pair and the encryption key;

computing a second portion of the cryptographic material based in part on a second key of the ephemeral key pair and the first portion of the cryptographic material; and

encrypting the portion of the account recovery key using the second portion of the cryptographic material; and

providing an encrypted portion of the account recovery key to a server associated with a user account associated with the electronic device.

14. The method as in claim 13 , wherein the encrypted portion of the account recovery key provided to the server is to be used to recover credentials associated with the user account.

15. The method as in claim 13 , wherein the encryption key received from the accessory device is a public key derived by the accessory device.

16. The method as in claim 15 , the at least one application processor to provide randomized data to the accessory device to enable the accessory device to derive the public key.

17. The method as in claim 13 , wherein the multiple key portions of the account recovery key include a first key portion and a second key portion and the at least one application processor is to encrypt the first key portion.

18. The method as in claim 17 , wherein to encrypt the portion of the account recovery key includes to perform an encryption operation on the first key portion.

19. The method as in claim 13 , wherein to provide the encrypted portion of the account recovery key to the server associated with the user account includes to store the encrypted portion of the account recovery key to the encrypted cloud storage container that is synced with the server via a network interface.

20. The method as in claim 19 , wherein the server is capable of decrypting the encrypted cloud storage container.

21. The method as in claim 19 , the at least one application processor is additionally to provide a second portion of the multiple key portions to the server.

22. A non-transitory machine-readable medium storing instructions to cause one or more processors on an electronic device to perform operations comprising:

splitting an account recovery key into multiple key portions, wherein the account recovery key is to enable recovery of an account associated with the electronic device;

receiving an encryption key from an accessory device associated with the electronic device, wherein the encryption key is signed with an attestation key;

verifying authenticity of the accessory device with the signed encryption key;

encrypting a portion of the account recovery key using cryptographic material derived from the encryption key, wherein the encrypting the portion of the account recovery key includes to:

generating an ephemeral key pair;

computing a first portion of the cryptographic material based in part on a first key of the ephemeral key pair and the encryption key;

computing a second portion of the cryptographic material based in part on a second key of the ephemeral key pair and the first portion of the cryptographic material; and

encrypting the portion of the account recovery key using the second portion of the cryptographic material; and

providing an encrypted portion of the account recovery key to a server associated with a user account associated with the electronic device.

23. The non-transitory machine-readable medium as in claim 22 , wherein the encrypted portion of the account recovery key provided to the server is to be used to recover credentials associated with the user account.

24. The non-transitory machine-readable medium as in claim 22 , wherein the encryption key received from the accessory device is a public key derived by the accessory device.

25. The non-transitory machine-readable medium as in claim 22 , the at least one application processor to provide randomized data to the accessory device to enable the accessory device to derive the public key.

26. The non-transitory machine-readable medium as in claim 22 , wherein the multiple key portions of the account recovery key include a first key portion and a second key portion and the at least one application processor is to encrypt the first key portion.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2020
From: SIERRA, YANNICK L.; BALLARD, LUCIA E.; BROGLE, KYLE C.; CAPELIS, DJ
To: APPLE INC.
Reel/Frame 053802/0391 →
Continuity (1)
Provisional Application 62835234 · Apr 17, 2019
Cited By (12)
US 12,262,278 US 12,279,227 US 12,381,728 US 12,431,002 US 12,445,273 US 12,483,858 US 12,488,664 US 12,495,353 US 12,550,214 US 12,581,268 US 12,677,111 US 12,749,389