IP Library › Granted Patent US 12,321,443
Granted Patent B2
US 12,321,443 · App. 18/593,243 · Granted Jun 3, 2025

Authentication and control of encryption keys

Inventors: Timothy R. Paaske (Cupertino, CA); Weihua Mao (Monte Sereno, CA); Shu-Yi Yu (Sunnyvale, CA)
Assignee: Apple Inc.
G06F21/46G06F21/44G06F21/602G06F21/606G06F21/85H04L9/088G06F2221/2137
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,321,443
App. No.
18/593,243
Granted
Jun 3, 2025
Kind
B2
Abstract

An apparatus, a method, and a system are presented in which the apparatus includes an interface control circuit that may be configured to receive a message including a cryptographic keyword and a policy value. The policy value may include one or more data bits indicative of one or more policies that define allowable usage of the cryptographic keyword. The apparatus also includes a security circuit that may be configured to extract the cryptographic keyword and the policy value from the message, and to apply at least one policy of the one or more policies to usage of the cryptographic keyword in response to a determination that an authentication of the message succeeded.

Claims (55)

1. An apparatus comprising:

an interface control circuit configured to receive a message including a particular cryptographic keyword and a policy value, wherein the policy value includes one or more data bits indicative of a set of policies that define allowable usage of the particular cryptographic keyword; and

a security circuit configured to:

use a hash algorithm to generate a hash value of the message;

compare the hash value to an authentication value included in the message;

based on a determination that the message is valid, extract the particular cryptographic keyword and the policy value from the message;

determine that a particular policy of the set of policies indicates that the particular cryptographic keyword is restricted to decryption usage; and

decrypt encrypted data using the particular cryptographic keyword.

2. The apparatus of claim 1 , wherein the interface control circuit is further configured to receive the message from a security processor.

3. The apparatus of claim 1 , wherein the security circuit is further configured to:

determine that a different policy of the set of policies indicates that the particular cryptographic keyword is restricted to use with a particular decryption algorithm; and

use the particular decryption algorithm to decrypt the encrypted data.

4. The apparatus of claim 1 , wherein the security circuit is further configured to:

determine that the message includes a different cryptographic keyword; and

determine that the policy value includes a different policy for use of the different cryptographic keyword.

5. The apparatus of claim 4 , wherein the security circuit is further configured to:

determine that the different policy indicates that the different cryptographic keyword is encrypted; and

decrypt the different cryptographic keyword using the particular cryptographic keyword.

6. The apparatus of claim 4 , wherein the security circuit is further configured to:

determine that the different policy of the set of policies indicates that the different cryptographic keyword is restricted to encryption usage; and

encrypt unencrypted data using the different cryptographic keyword.

7. The apparatus of claim 4 , wherein the security circuit is further configured to determine that the different policy of the set of policies indicates that the different cryptographic keyword is restricted to use in hashing functions.

8. An apparatus comprising:

one or more peripherals configured to use a respective cryptographic keyword in a cryptographic operation in compliance with one or more policies that define allowable usage of the respective cryptographic keyword; and

a security hardware processor configured to:

generate a plurality of cryptographic keywords;

include the plurality of cryptographic keywords in a bit field having a predetermined number of bits;

determine corresponding sets of policies that define allowable usage of respective ones of the plurality of cryptographic keywords, wherein at least one set of policies includes an indication of a number of bits included in each of the plurality of cryptographic keywords;

generate a policy value based on corresponding sets of policies;

generate a message including the plurality of cryptographic keywords and the policy value; and

send the message to at least a portion of the one or more peripherals.

9. The apparatus of claim 8 , wherein the security hardware processor is further configured to include, in a particular one of the sets of policies, a particular policy that indicates that a subset of the one or more peripherals is allowed to use the respective cryptographic keyword.

10. The apparatus of claim 8 , wherein the security hardware processor is further configured to include, in a particular one of the sets of policies, a particular policy that indicates that two or more of the plurality of cryptographic keywords are to be combined to form a single keyword.

11. The apparatus of claim 10 , wherein the security hardware processor is further configured to include, in the particular policy, an indication of an algorithm for combining the two or more cryptographic keywords.

12. The apparatus of claim 8 , wherein the security hardware processor is further configured to include, in a particular one of the sets of policies, an indication that two of the cryptographic keywords included in the message correspond to a public/private key combination.

13. The apparatus of claim 8 , wherein

at least one of the plurality of cryptographic keywords includes a different number of bits than a different one of the plurality of cryptographic keywords.

14. The apparatus of claim 8 , wherein the security hardware processor is further configured to:

encrypt one or more of the plurality of cryptographic keywords; and

include an indication of one or more additional operations required to be performed on the message to decrypt the encrypted cryptographic keywords.

15. An apparatus comprising:

a peripheral circuit that includes:

an interface control circuit configured to receive a message including a plurality of cryptographic keywords and a policy value, wherein the policy value includes an indication that two of the cryptographic keywords included in the message correspond to a public/private key combination; and

a security circuit configured to:

authenticate a validity of the message;

based on a successful authentication, extract the plurality of cryptographic keywords and the policy value from the message; and

use the public/private key combination to perform a cryptographic operation.

16. The apparatus of claim 15 , wherein the plurality of cryptographic keywords includes a third cryptographic keyword, and wherein the policy value includes an indication that the public/private key combination was encrypted using the third cryptographic keyword.

17. The apparatus of claim 16 , wherein the policy value includes an indication of one or more additional operations required to be performed on the message to decrypt the encrypted cryptographic keywords.

18. The apparatus of claim 15 , wherein the interface control circuit is further configured to receive the message from a security processor.

19. The apparatus of claim 15 , wherein the policy value includes an indication of a time period for which the cryptographic keywords are allowed to be used; and

wherein the security circuit is further configured to delete the cryptographic keywords in response to a determination that the time period has elapsed.

20. The apparatus of claim 15 , wherein to authenticate the validity of the message, the security circuit is further configured to:

use a hash algorithm to generate a hash value of the message; and

compare the hash value to an authentication value included in the message.

Continuity (6)
Continuation 17652517 · Feb 25, 2022
Continuation 16927934 · Jul 13, 2020
Continuation 16133625 · Sep 17, 2018
Continuation 15678502 · Aug 16, 2017
Continuation 14696581 · Apr 27, 2015
Related Publication 20240330432A1 · Oct 3, 2024
References Cited (41)
US 6834112B1 · Brickell · 2004 [cited by applicant]
US 6985953B1 · Sandhu et al. · 2006 [cited by applicant]
US 7373500B2 · Ramelson et al. · 2008 [cited by applicant]
US 8332907B2 · Canning et al. · 2012 [cited by applicant]
US 8806607B2 · Archer et al. · 2014 [cited by applicant]
US 9049259B2 · Rathod · 2015 [cited by examiner]
US 9210183B2 · Sadovsky · 2015 [cited by examiner]
US 9317449B2 · Ducharme · 2016 [cited by applicant]
US 11263306B2 · Paaske · 2022 [cited by examiner]
US 20020071552A1 · Rogaway · 2002 [cited by applicant]
US 20040093524A1 · Sakai · 2004 [cited by examiner]
US 20040225650A1 · Cooper · 2004 [cited by examiner]
US 20060069652A1 · Ebihara et al. · 2006 [cited by applicant]
US 20060080321A1 · Horn · 2006 [cited by examiner]
US 20060089970A1 · Pearson et al. · 2006 [cited by applicant]
US 20060092867A1 · Muller et al. · 2006 [cited by applicant]
US 20060209584A1 · Devadas · 2006 [cited by applicant]
US 20060288238A1 · Ray et al. · 2006 [cited by applicant]
US 20070042754A1 · Bajikar et al. · 2007 [cited by applicant]
US 20090319776A1 · Burch et al. · 2009 [cited by applicant]
US 20090319802A1 · Walmsley · 2009 [cited by applicant]
US 20100189262A1 · Ducharme · 2010 [cited by applicant]
US 20100205541A1 · Rapaport · 2010 [cited by examiner]
US 20110116635A1 · Bar-El · 2011 [cited by applicant]
US 20110208822A1 · Rathod · 2011 [cited by examiner]
US 20110276396A1 · Rathod · 2011 [cited by examiner]
US 20110307699A1 · Fielder · 2011 [cited by applicant]
US 20120198241A1 · O'Hare · 2012 [cited by applicant]
US 20130042307A1 · Imamura · 2013 [cited by applicant]
US 20130101114A1 · Kim · 2013 [cited by applicant]
US 20140013406A1 · Tremlet · 2014 [cited by applicant]
US 20140115724A1 · van Brandenburg et al. · 2014 [cited by applicant]
US 20140129942A1 · Rathod · 2014 [cited by examiner]
US 20140136855A1 · Ducharme · 2014 [cited by applicant]
US 20140195807A1 · Bar-El · 2014 [cited by applicant]
US 20140201828A1 · Yoo · 2014 [cited by applicant]
US 20150180894A1 · Sadovsky · 2015 [cited by examiner]
US 20150365393A1 · Shyamsunder · 2015 [cited by examiner]
US 20160154744A1 · Zheng · 2016 [cited by applicant]
US 20180343238A1 · Tola · 2018 [cited by examiner]
US 20190052701A1 · Rathod · 2019 [cited by examiner]