IP Library › Granted Patent US 10,536,271
Granted Patent B1
US 10,536,271 · App. 15/435,229 · Granted Jan 14, 2020

Silicon key attestation

Inventors: Thomas P. Mensch (Sunnyvale, CA); Conrad Sauerwald (Mountain View, CA); Jerrold V. Hauck (Windermere, FL); Timothy R. Paaske (San Jose, CA); Zhimin Chen (San Jose, CA); Andrew R. Whalley (San Francisco, CA)
Assignee: Apple Inc.
H04L9/0866H04L9/0869H04L9/14H04L9/30H04L9/3263G06F21/575G06F21/70G06F21/73H04L9/08H04L9/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,536,271
App. No.
15/435,229
Granted
Jan 14, 2020
Kind
B1
Abstract

Systems and methods are disclosed for generating one or more hardware reference keys (HRK) on a computing device, and for attesting to the validity of the hardware reference keys. An initial hardware reference key can be a silicon attestation key (SIK) generated during manufacture of a computing system, such as a system-on-a-chip. The SIK can comprise an asymmetric key pair based at least in part on an identifier of the processing system type and a unique identifier of the processing system. The SIK can be signed by the computing system and stored thereon. The SIK can be used to generate further HRKs on the computing device that can attest to the processing system type of the computing device and an operating system version that was running when the HRK was generated. The computing device can generate an HRK attestation (HRKA) for each HRK generated on the computing system.

Claims (34)

1. A computer-implemented method, comprising:

receiving, by a computing device, a request from an application to generate a hardware reference key (HRK) pair, wherein the HRK pair is usable with an attestation to attest to a presence of particular hardware in the computing device;

generating, by the computing device, the HRK pair in response to the request, wherein the HRK pair includes a private key and a public key;

using, by the computing device, a hardware identifier embedded in the computing device to generate the attestation for the HRK pair, wherein the hardware identifier is embedded at manufacture to identify a presence of the particular hardware in the computing device, wherein the attestation includes a digest signed using the private key and signed using the hardware identifier, and wherein the digest includes an indication of the particular hardware and the public key; and

publishing, by the computing device, the public key of the HRK pair and the attestation.

2. The method of claim 1 , wherein the HRK pair is generated based on a seed that includes a version of an operating system running on the computing device when the HRK pair is generated.

3. The method of claim 2 , wherein the seed further includes identification information of the application that requested the HRK pair.

4. The method of claim 2 , wherein the seed further includes a random seed portion, and wherein the signed digest identifies the seed.

5. The method of claim 1 , wherein the particular hardware includes a type of processor in the computing device.

6. The method of claim 1 , wherein the publishing is to a certificate authority operable to issue a corresponding certificate.

7. A non-transitory computer readable medium comprising instructions that, are executable by a computing device to cause the computing device to perform operations comprising:

receiving from an application, a request to generate a hardware reference key (HRK) pair that is usable with an attestation to indicate a presence of particular hardware in the computing device;

generating the HRK pair in response to the request wherein the HRK pair includes a private key and a public key;

using a hardware identifier embedded in the computing device to generate the attestation for the HRK pair, wherein the hardware identifier is embedded at manufacture to identify a presence of the particular hardware in the computing device, wherein generating the attestation includes signing a digest that includes an indication of the particular hardware and the public key, wherein the digest is signed using the private key and using the hardware identifier; and

publishing the public key of the HRK pair and the attestation.

8. The non-transitory computer readable medium of claim 7 , wherein the HRK pair is generated based on a seed that includes a version of an operating system running on the computing device when the HRK pair is generated.

9. The non-transitory computer readable medium of claim 8 , wherein the seed further includes identification information of the application that requested the HRK pair.

10. The non-transitory computer readable medium of claim 7 , wherein the particular hardware includes a processor type included in the computing device.

11. The non-transitory computer readable medium of claim 7 , wherein the publishing is to a certificate authority operable to issue a corresponding certificate.

12. The non-transitory computer readable medium of claim 7 , wherein the operations further comprise:

using the HRK pair to generate one or more additional hardware reference keys.

13. A computing device, comprising:

a processing system having at least one hardware processor; and

memory containing instructions by the processing system to cause the computing device to perform operations comprising:

receiving from an application, a request to generate a hardware reference key (HRK) pair that includes a public key and a private key;

generating the HRK pair in response to the request;

using a hardware identifier embedded in the computing device to generate an attestation for the HRK pair, wherein the hardware identifier is embedded at manufacture to identify a presence of particular hardware in the computing device, wherein generating the attestation includes signing a digest that includes an indication of the particular hardware and the public key, wherein the digest is signed using the private key and using the hardware identifier; and

publishing the public key of the HRK pair and the attestation.

14. The computing device of claim 13 , wherein the HRK pair is generated based on a seed that includes a version of an operating system running on the computing device when the HRK pair is generated, and wherein the signed digest includes the seed.

15. The computing device of claim 14 , wherein the seed further includes identification information of the application that requested the HRK pair.

16. The computing device of claim 14 , wherein the seed further include a random seed portion.

17. The computing device of claim 13 , wherein the particular hardware includes a type of the at least hardware processor.

18. The computing device of claim 13 , wherein the public key of the HRK pair and the attestation are published to a certificate authority.

19. The computing device of claim 13 , wherein the operations further comprise: using the HRK pair to certify another hardware reference key pair.

Continuity (2)
Continuation 15274232 · Sep 23, 2016
Provisional Application 62276913 · Jan 10, 2016
Cited By (4)
US 12,206,799 US 12,314,408 US 12,712,744 US 12,726,339