IP Library Granted Patent US 12,494,913
Granted Patent B2
US 12,494,913 · App. 17/655,147 · Granted Dec 9, 2025

Pairing protocol for peripherals with a secure function

Inventors: Kyle C. Brogle (San Francisco, CA); Wade Benson (San Jose, CA); Sean P. Devlin (New York, NY); Lucie Kucerova (Chodoun, CZ); Thomas P. Mensch (Sunnyvale, CA); Yannick L. Sierra (San Francisco, CA); Tomislav Suchan (San Jose, CA)
Assignee: Apple Inc.
H04L9/3231G06F21/44H04W12/03
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,494,913
App. No.
17/655,147
Granted
Dec 9, 2025
Kind
B2
Abstract

Embodiments described herein provided techniques to enable peripherals configured to provide secure functionality. A secure circuit on a peripheral device can be paired with a secure circuit on a host device outside of a factory environment without compromising security by verifying silicon keys that are embedded within the secure circuit during manufacturing.

Claims (33)

1 . A peripheral device comprising:

a wireless data interface;

a biometric sensor;

a memory device; and

a processor including a first secure circuit, the processor coupled with the wireless data interface and the memory device, the processor configured to execute instructions from the memory device to:

establish a first encrypted local wireless data connection with a host device via the wireless data interface, the first encrypted local wireless data connection established via first cryptographic material derived using a public key generated by the first secure circuit;

via the first encrypted local wireless data connection, establish a second encrypted local wireless data connection between the first secure circuit and a second secure circuit on the host device using second cryptographic material, the second cryptographic material derived using at least one key from the first secure circuit and at least one key from the second secure circuit, the second cryptographic material unknown to an application processor of the host device;

construct, from biometric data captured from the biometric sensor and using the first secure circuit, a biometric image for validation by biometric authentication logic in the second secure circuit; and

transmit, in response to the construction, the biometric image or features extracted from the biometric image from the first secure circuit to the second secure circuit via the second encrypted local wireless data connection using the second cryptographic material so that the biometric image is unknown to the application processor of the host device.

2 . The peripheral device as in claim 1 , wherein the second encrypted local wireless data connection is encapsulated within the first encrypted local wireless data connection and wherein the first encrypted local wireless data connection is a Bluetooth connection.

3 . The peripheral device as in claim 1 , wherein the processor is configured to receive the biometric data from the biometric sensor and transmit a request to authenticate the biometric data to the host device over the wireless data interface via the second encrypted local wireless data connection.

4 . The peripheral device as in claim 3 , wherein the first secure circuit is to read a biometric sensor key that identifies the biometric sensor and validate the biometric sensor based on the biometric sensor key.

5 . The peripheral device as in claim 1 , wherein the processor is configured to validate authenticity of the host device via a first attestation key, the first attestation key used to verify a portion of the first cryptographic material that is received from the host device.

6 . The peripheral device as in claim 5 , wherein the first secure circuit is configured to validate authenticity of the second secure circuit via a second attestation key that differs from the first attestation key, the second attestation key used to verify a portion of the second cryptographic material that is received from the second secure circuit.

7 . The peripheral device as in claim 1 , wherein the processor is configured to:

after the second encrypted local wireless data connection is established, establish a pairing between the first secure circuit and the second secure circuit.

8 . The peripheral device as in claim 7 , wherein the processor is configured to:

store pairing information for the pairing between the first secure circuit and the second secure circuit to a non-volatile memory device of the peripheral device, wherein the pairing information includes hardware identifiers of the first secure circuit and the second secure circuit.

9 . The peripheral device as in claim 8 , wherein the processor is configured to:

encrypt the pairing information via third cryptographic material, wherein the third cryptographic material is cryptographically related to a hardware key stored within the second secure circuit.

10 . A method comprising:

establishing, by a peripheral device including a biometric sensor and a first secure circuit, a first encrypted local wireless data connection with a host device using first cryptographic material derived using a public key generated by the first secure circuit;

establishing a second encrypted local wireless data connection between the first secure circuit on the peripheral device and a second secure circuit on the host device using second cryptographic material derived using at least one key from the first secure circuit and at least one key from the second secure circuit, the second encrypted local wireless data connection established via the first encrypted local wireless data connection, the second cryptographic material unknown to an application processor of the host device;

constructing, from biometric data captured from the biometric sensor and using the first secure circuit, a biometric image for validation by biometric authentication logic in the second secure circuit; and

transmitting, in response to the construction, the biometric image or features extracted from the biometric image from the first secure circuit to the second secure circuit via the second encrypted local wireless data connection using the second cryptographic material so that the biometric image is unknown to the application processor of the host device.

11 . The method as in claim 10 , wherein the second encrypted local wireless data connection is encapsulated within the first encrypted local wireless data connection and wherein the first encrypted local wireless data connection is a Bluetooth connection.

12 . The method as in claim 10 , further comprising capturing the biometric data via the biometric sensor and transmitting a request to authenticate the biometric data to the host device via the second encrypted local wireless data connection.

13 . The method as in claim 12 , further comprising reading, by the first secure circuit, a biometric sensor key that identifies the biometric sensor and validating the biometric sensor based on the biometric sensor key.

14 . The method as in claim 10 , further comprising validating authenticity of the host device via a first attestation key, the first attestation key used to verify a portion of the first cryptographic material that is received from the host device.

15 . The method as in claim 14 , further comprising validating authenticity of the second secure circuit via a second attestation key that differs from the first attestation key, the second attestation key used to verify a portion of the second cryptographic material that is received from the second secure circuit.

16 . The method as in claim 10 , further comprising, after the second encrypted local wireless data connection is established, establishing a pairing between the first secure circuit and the second secure circuit.

17 . The method as in claim 16 , further comprising storing pairing information for the pairing between the first secure circuit and the second secure circuit to a non-volatile memory device of the peripheral device, wherein the pairing information includes hardware identifiers of the first secure circuit and the second secure circuit.

18 . The method as in claim 17 , further comprising encrypting the pairing information via third cryptographic material, wherein the third cryptographic material is cryptographically related to a hardware key stored within the second secure circuit.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2022
From: BROGLE, KYLE C.; SIERRA, YANNICK L; MENSCH, THOMAS P; DEVLIN, SEAN P; SUCHAN, TOMISLAV; BENSON, WADE; KUCEROVA, LUCIE
To: APPLE INC.
Reel/Frame 059287/0374 →
Continuity (2)
Provisional Application 63162323 · Mar 17, 2021
Related Publication 20220303137A1 · Sep 22, 2022
References Cited (25)
US 12143483B2 · Subert et al. · 2024 [cited by applicant]
US 20020095587A1 · Doyle et al. · 2002 [cited by applicant]
US 20020174348A1 · Ting et al. · 2002 [cited by applicant]
US 20080263363A1 · Jueneman · 2008 [cited by examiner]
US 20120102332A1 · Mullin · 2012 [cited by applicant]
US 20150071502A1 · Breznicky · 2015 [cited by applicant]
US 20160308855A1 · Lacey · 2016 [cited by examiner]
US 20170093853A1 · Boivie · 2017 [cited by examiner]
US 20170126672A1 · Jang · 2017 [cited by applicant]
US 20170185762A1 · Chang et al. · 2017 [cited by applicant]
US 20170238172A1 · Benoit et al. · 2017 [cited by applicant]
US 20170249451A1 · Andreeva · 2017 [cited by applicant]
US 20170373844A1 · Sykora et al. · 2017 [cited by applicant]
US 20190207752A1 · Mandal et al. · 2019 [cited by applicant]
US 20200228341A1 · Mohassel et al. · 2020 [cited by applicant]
US 20200313890A1 · Mondello · 2020 [cited by examiner]
CN 206322182 · 2017 [cited by applicant]
McCune et al., “Bump in the Ether: A Framework for Securing Sensitive User Input”, Proceedings of the 2006 USENIX Annual Technical Conference, Available Online at: https://www.usenix.org/legacy/event/usenix06/tech/full_… [cited by applicant]
International Search Report and Written Opinion issued in PCT Application No. PCT/US2022/020581, dated Jun. 28, 2022 in 13 pages. [cited by applicant]
The International Application No. PCT/US2022/020581, “International Preliminary Report on Patentability”, mailed Sep. 28, 2023, 9 pages. [cited by applicant]
U.S. Appl. No. 17/654,964 , “Non-Final Office Action”, Jan. 18, 2024, 17 pages. [cited by applicant]
U.S. Appl. No. 17/654,964 , “Notice of Allowance”, Jul. 16, 2024, 14 pages. [cited by applicant]
Bouazzouni et al., “Trusted Mobile Computing: An Overview of Existing Solutions”, Future Generation Computer Systems, vol. 80, Mar. 31, 2018, 17 pages. [cited by applicant]
International Patent Application No. PCT/US2022/020547 , “International Preliminary Report on Patentability”, Sep. 28, 2023, 7 pages. [cited by applicant]
International Patent Application No. PCT/US2022/020547 , “International Search Report and Written Opinion”, Jun. 30, 2022, 11 pages. [cited by applicant]