IP Library › Granted Patent US 11,263,306
Granted Patent B2
US 11,263,306 · App. 16/927,934 · Granted Mar 1, 2022

Authentication and control of encryption keys

Inventors: Timothy R. Paaske (Cupertino, CA); Weihua Mao (Monte Sereno, CA); Shu-Yi Yu (Sunnyvale, CA)
Assignee: Apple Inc.
G06F21/46G06F21/44G06F21/602G06F21/606G06F21/85H04L9/088G06F2221/2137
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,263,306
App. No.
16/927,934
Granted
Mar 1, 2022
Kind
B2
Abstract

An apparatus, a method, and a system are presented in which the apparatus includes an interface control circuit that may be configured to receive a message including a cryptographic keyword and a policy value. The policy value may include one or more data bits indicative of one or more policies that define allowable usage of the cryptographic keyword. The apparatus also includes a security circuit that may be configured to extract the cryptographic keyword and the policy value from the message, and to apply at least one policy of the one or more policies to usage of the cryptographic keyword in response to a determination that an authentication of the message succeeded.

Claims (55)

1. An apparatus comprising:

a peripheral circuit that includes:

an interface control circuit configured to receive a data packet including a particular cryptographic keyword and a policy value, wherein the policy value includes one or more data bits indicative of one or more policies that define allowable usage of the particular cryptographic keyword; and

a security circuit configured to:

extract the policy value from the data packet;

determine that the policy value includes an indication of a number of bits in the particular cryptographic keyword;

extract the indicated number of bits from a bit field in the data packet that includes the particular cryptographic keyword; and

use the policy value to determine whether the particular cryptographic keyword is valid for use by the peripheral circuit.

2. The apparatus of claim 1 , wherein the security circuit is further configured to:

determine that the policy value indicates that the data packet includes a different cryptographic keyword; and

extract an indicated number of bits from the bit field in the data packet that includes the different cryptographic keyword, wherein the particular cryptographic keyword and the different cryptographic keyword are included in different bits of the bit field.

3. The apparatus of claim 2 , wherein the security circuit is further configured to, using the policy value:

restrict the particular cryptographic keyword for use with encrypting data; and

restrict the different cryptographic keyword for use with decrypting data.

4. The apparatus of claim 1 , wherein the security circuit is further configured to, using the policy value, descramble the particular cryptographic keyword.

5. The apparatus of claim 1 , wherein the security circuit is further configured to:

using the policy value, determine an amount of time to elapse before updating a revocation list, wherein the revocation list includes a list of previously issued cryptographic keywords that are no longer valid; and

discard the particular cryptographic keyword in response to a determination that the particular cryptographic keyword is on the updated revocation list.

6. The apparatus of claim 1 , wherein the security circuit is further configured, in response to the interface control circuit receiving the data packet, to:

authenticate the data packet prior to extracting the policy value; and

extract the policy value in response to a successful authentication of the data packet.

7. The apparatus of claim 1 , wherein the security circuit is further configured, in response to extracting the policy value, to use the policy value to determine one or more additional operations required to unwrap the particular cryptographic keyword from the data packet.

8. An apparatus comprising:

a peripheral circuit including:

an interface control circuit configured to receive a data packet including a first cryptographic keyword, a second cryptographic keyword, and a policy value, wherein the policy value includes one or more data bits indicative of one or more policies that define allowable usage of the first and second cryptographic keywords; and

a security circuit configured to:

extract the first and second cryptographic keywords and the policy value from the data packet;

based on the policy value, combine the first cryptographic keyword with the second cryptographic keyword to generate a third cryptographic keyword; and

use the policy value to determine whether the particular cryptographic keyword is valid for use by the peripheral circuit.

9. The apparatus of claim 8 , wherein to generate the third cryptographic keyword, the security circuit is configured to perform a logic operation using the first and second cryptographic keywords.

10. The apparatus of claim 8 , wherein the security circuit is further configured to:

using the policy value, determine an expiration date and time of day for the first and second cryptographic keywords; and

discard the first and second cryptographic keywords in response to a determination that the expiration date and the time of day have been reached.

11. The apparatus of claim 8 , wherein the policy value includes an indication of a number of bits included in the first and second cryptographic keywords.

12. The apparatus of claim 8 , wherein the security circuit is further configured, in response to the interface control circuit receiving the data packet, to:

authenticate the data packet prior to extracting the first and second cryptographic keywords; and

extract the first and second cryptographic keywords and the policy value in response to a successful authentication of the data packet.

13. The apparatus of claim 8 , wherein the security circuit is further configured, in response to extracting the policy value, to use the policy value to determine one or more additional operations required to unwrap the first and second cryptographic keywords from the data packet.

14. An apparatus comprising:

a peripheral circuit that includes:

an interface control circuit configured to receive a data packet including a particular cryptographic keyword and a policy value, wherein the policy value includes one or more data bits indicative of one or more policies that define allowable usage of the particular cryptographic keyword; and

a security circuit configured to:

extract the particular cryptographic keyword and the policy value from the data packet;

use the policy value to determine if the particular cryptographic keyword is valid for use by the peripheral circuit; and

limit usage of the particular cryptographic keyword to encrypting data in response to a determination that the policy value restricts the particular cryptographic keyword to encryption usage.

15. The apparatus of claim 14 , wherein the security circuit is further configured to determine that the data packet includes a different cryptographic keyword.

16. The apparatus of claim 15 , wherein the security circuit is further configured to limit usage of the different cryptographic keyword to decrypting data in response to a determination that the policy value restricts the different cryptographic keyword to decryption usage.

17. The apparatus of claim 14 , wherein to limit usage of the particular cryptographic keyword to encrypting data, the security circuit is further configured to limit usage of the particular cryptographic keyword to use with a particular encryption algorithm indicated by the policy value.

18. The apparatus of claim 14 , wherein the security circuit is further configured, in response to the interface control circuit receiving the data packet, to:

authenticate the data packet prior to extracting the particular cryptographic keyword; and

extract the particular cryptographic keyword and the policy value in response to a successful authentication of the data packet.

19. The apparatus of claim 18 , wherein to authenticate the data packet, the security circuit is configured to:

perform a hashing function on one or more of bit fields of the data packet to generate a hash value; and

compare the generated hash value to a received hash value included in the data packet.

20. The apparatus of claim 14 , wherein the security circuit is further configured, in response to extracting the particular cryptographic keyword and the policy value, to use the policy value to determine one or more additional operations required to unwrap the particular cryptographic keyword from the data packet.

Continuity (4)
Continuation 16133625 · Sep 17, 2018
Continuation 15678502 · Aug 16, 2017
Continuation 14696581 · Apr 27, 2015
Related Publication 20200342091A1 · Oct 29, 2020
Cited By (1)
US 12,321,443