IP Library › Granted Patent US 12,493,458
Granted Patent B2
US 12,493,458 · App. 18/515,689 · Granted Dec 9, 2025

Secure delivery of assets to a trusted device

Inventors: Dallas B. De Atley (San Francisco, CA); Bailey E. Basile (Cupertino, CA); Venkat V. Memula (Livermore, CA); Thomas P. Mensch (Sunnyvale, CA); Robert M. Marini (San Francisco, CA); David P. Remahl (Woodside, CA); Kelsey J. Skillman (Mountain View, CA); Edward E. Thomas (Cupertino, CA)
Assignee: Apple Inc.
G06F8/65G06F21/602H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,493,458
App. No.
18/515,689
Granted
Dec 9, 2025
Kind
B2
Abstract

Embodiments described herein provide a system and method for secure delivery of assets to a trusted device. Multiple levels of verification are implemented to enable components of a software update and asset delivery system to verify other components within the system. Furthermore, updates are provided only to client devices that are authorized to receive such updates. In one embodiment, the specific assets provided to a client device during a software update can be tailored to the client device, such that individual client devices can receive updated versions of software asset at a faster or slower rate than mass market devices. For example, developer or beta tester devices can receive pre-release assets, while enterprise devices can receive updates at a slower rate relative to mass market devices.

Claims (35)

1 . A method performed by an asset server for managing a software update, the method comprising:

receiving an asset request from a client device, the asset request including a cryptographic identifier of the client device, wherein the cryptographic identifier includes one or more hardware keys derived from or stored within a secure memory of the client device, the one or more hardware keys indicating whether the client device is a trusted client device;

in response to receipt of the asset request, verifying the client device based, at least in part, on the cryptographic identifier; and

upon verification of the client device, providing a response signed by the asset server to the client device, wherein the signed response includes information associated with an asset.

2 . The method according to claim 1 , wherein the signed response further comprises a signed asset receipt, wherein the signed asset receipt is a receipt registered for the asset at the asset server.

3 . The method according to claim 1 , wherein the verifying the client device based, at least in part, on the cryptographic identifier, comprises:

sending, by the asset server, an attestation request to an attestation server; and

receiving, by the asset server, a response from the attestation server that the client device is authentic.

4 . The method according to claim 1 , wherein the client device comprises a consumer electronic device.

5 . The method according to claim 1 , wherein the client device is authentic if the client device is manufactured by and registered with a device vendor of the client device.

6 . The method according to claim 1 , wherein the signed response includes a storage location for the asset.

7 . The method according to claim 1 , further comprising determining whether the client device is associated with a special asset list, a registry or a database.

8 . The method according to claim 7 , wherein the special asset list, the registry or the database comprise assets associated with client device in an enterprise managed update system.

9 . The method according to claim 7 , further comprising determining whether the client device is a special client device based on the special asset list, the registry or the database, wherein the special client device is a client device for which software updates are delayed.

10 . The method according to claim 7 , further comprising determining whether the client device is a special client device based on the special asset list, the registry or the database, wherein the special client device is a client device for which software updates are accelerated.

11 . A system for managing a software update for an electronic device, the system comprising one or more processors configured to:

receiving, by an asset server, an asset request from a client device, the asset request including a cryptographic identifier of the client device, wherein the cryptographic identifier includes one or more hardware keys derived from or stored within secure memory of the client device, the one or more hardware keys indicating whether the client device is a trusted client device;

in response to receipt of the asset request, verifying the client device based, at least in part, on the cryptographic identifier; and

upon verification of the client device, providing a response signed by the asset server to the client device, wherein the signed response includes information associated with an asset.

12 . The system according to claim 11 , wherein the signed response further comprises a signed asset receipt, wherein the signed asset receipt is a receipt registered for the asset at the asset server.

13 . The system according to claim 11 , wherein the verifying the client device based, at least in part, on the cryptographic identifier, comprises:

sending, by the asset server, an attestation request to an attestation server; and

receiving, by the asset server, a response from the attestation server that the client device is authentic.

14 . The system according to claim 11 , further comprising determining whether the client device is associated with a special asset list, a registry or a database.

15 . The system according to claim 14 , wherein the special asset list, the registry or the database comprise assets associated with client device in an enterprise managed update system.

16 . A non-transitory computer-readable medium storing instructions executable by one or more processors for managing a software update for an electronic device, the instructions comprising:

receiving, by an asset server, an asset request from a client device, the asset request including a cryptographic identifier of the client device, wherein the cryptographic identifier includes one or more hardware keys derived from or stored within secure memory of the client device, the one or more hardware keys indicating whether the client device is a trusted client device;

in response to receipt of the asset request, verifying the client device based, at least in part, on the cryptographic identifier; and

upon verification of the client device, providing a response signed by the asset server to the client device, wherein the signed response includes information associated with an asset.

17 . The non-transitory computer-readable medium according to claim 16 , wherein the signed response further comprises a signed asset receipt, wherein the signed asset receipt is a receipt registered for the asset at the asset server.

18 . The non-transitory computer-readable medium according to claim 16 , wherein the verifying the client device based, at least in part, on the cryptographic identifier, comprises:

sending, by the asset server, an attestation request to an attestation server; and

receiving, by the asset server, a response from the attestation server that the client device is authentic.

19 . The non-transitory computer-readable medium according to claim 16 , further comprising determining whether the client device is associated with a special asset list, a registry or a database.

20 . The non-transitory computer-readable medium according to claim 19 , wherein the special asset list, the registry or the database comprise assets associated with client device in an enterprise managed update system.

Continuity (4)
Continuation 17495699 · Oct 6, 2021
Division 16147295 · Sep 28, 2018
Provisional Application 62620450 · Jan 22, 2018
Related Publication 20240103840A1 · Mar 28, 2024
References Cited (21)
US 11144297B2 · De Atley · 2021 [cited by examiner]
US 20080207168A1 · Forsberg · 2008 [cited by examiner]
US 20110289499A1 · Haubold et al. · 2011 [cited by applicant]
US 20120297175A1 · Ekberg · 2012 [cited by applicant]
US 20150128126A1 · Brunet et al. · 2015 [cited by applicant]
US 20150242198A1 · Tobolski · 2015 [cited by examiner]
US 20150339113A1 · Dorman et al. · 2015 [cited by applicant]
US 20160037149A1 · Nishikawa · 2016 [cited by applicant]
US 20160266889A1 · Gross et al. · 2016 [cited by applicant]
US 20180198629A1 · Deymonnaz et al. · 2018 [cited by applicant]
US 20180217828A1 · Madrid et al. · 2018 [cited by applicant]
US 20180336024A1 · Klische · 2018 [cited by applicant]
US 20190250899A1 · Riedl · 2019 [cited by examiner]
U.S. Appl. No. 16/147,295 , “Advisory Action”, filed May 7, 2021, 3 pages. [cited by applicant]
U.S. Appl. No. 16/147,295 , “Final Office Action”, filed Feb. 18, 2021, 10 pages. [cited by applicant]
U.S. Appl. No. 16/147,295 , “Non-Final Office Action”, filed Aug. 28, 2020, 8 pages. [cited by applicant]
U.S. Appl. No. 16/147,295 , “Notice of Allowance”, filed May 28, 2021, 10 pages. [cited by applicant]
U.S. Appl. No. 16/147,295 , “Restriction Requirement”, filed Jun. 19, 2020, 6 pages. [cited by applicant]
U.S. Appl. No. 17/495,699 , “Final Office Action”, filed May 18, 2023, 11 pages. [cited by applicant]
U.S. Appl. No. 17/495,699 , “Non-Final Office Action”, filed Feb. 6, 2023, 9 pages. [cited by applicant]
U.S. Appl. No. 17/495,699 , “Notice of Allowance”, filed Aug. 17, 2023, 9 pages. [cited by applicant]