Synchronization and verification groups among related devices

    公开(公告)号:US10747435B2

    公开(公告)日:2020-08-18

    申请号:US16250890

    申请日:2019-01-17

    Applicant: Apple Inc.

    Abstract: Some embodiments provide a method for a first device to synchronize a set of data items with a second device. The method receives a request to synchronize the set of data items stored on the first device with the second device. The method determines a subset of the synchronization data items stored on the first device that belong to at least one synchronization sub-group in which the second device participates. Participation in at least one of the synchronization sub-groups is defined based on membership in at least one verification sub-group. The first and second devices are part of a set of related devices with several different verification sub-groups. The method sends only the subset of the synchronization data items that belong to at least one synchronization sub-group in which the second device participates to the second device using a secure channel.

    Privacy enhancements for wireless devices

    公开(公告)号:US10587654B2

    公开(公告)日:2020-03-10

    申请号:US16048934

    申请日:2018-07-30

    Applicant: Apple Inc.

    Abstract: A wireless device can obtain a network information record from another device operating as a credential source. The network information record can include network access information for a wireless network (e.g., SSID and password) and a usage policy specifying conditions under which the wireless device should search for the wireless network (e.g., temporal and/or spatial conditions). The wireless device can implement the usage policy by searching for the wireless network only when the conditions are satisfied. In some instances, the network access information can include instructions for dynamically generating time-varying network access information, and the wireless device can use the instructions to generate network access information during a search for wireless networks.

    AUTOMATIC IDENTIFICATION OF INVALID PARTICIPANTS IN A SECURE SYNCHRONIZATION SYSTEM
    5.
    发明申请
    AUTOMATIC IDENTIFICATION OF INVALID PARTICIPANTS IN A SECURE SYNCHRONIZATION SYSTEM 审中-公开
    在安全同步系统中自动识别无效参与者

    公开(公告)号:US20160359965A1

    公开(公告)日:2016-12-08

    申请号:US14871210

    申请日:2015-09-30

    Applicant: Apple Inc.

    Abstract: A method of identifying invalid participants in a synchronization group. The method generates a device synchronization group identifier (DSGI) for a first device from a device-specific key of the first device. The method joins the first device in the synchronization group by using the DSGI of the first device. Prior to the joining of the first device, the synchronization group stores a set of DSGIs of a set of devices that have joined the synchronization group. The method determines that a particular DSGI stored in the synchronization group is the same as the DSGI of the first device. The method identifies the particular DSGI stored in the synchronization group as a DSGI of an invalid participant of the synchronization group.

    Abstract translation: 识别同步组中的无效参与者的方法。 该方法从第一设备的设备专用密钥生成第一设备的设备同步组标识符(DSGI)。 该方法通过使用第一个设备的DSGI连接同步组中的第一个设备。 在加入第一设备之前,同步组存储已经加入同步组的一组设备的DSGI集合。 该方法确定存储在同步组中的特定DSGI与第一设备的DSGI相同。 该方法将同步组中存储的特定DSGI标识为同步组的无效参与者的DSGI。

    SECURING IN-APP PURCHASES
    6.
    发明申请
    SECURING IN-APP PURCHASES 审中-公开
    安全入场购买

    公开(公告)号:US20140025521A1

    公开(公告)日:2014-01-23

    申请号:US13668109

    申请日:2012-11-02

    Applicant: APPLE INC.

    Abstract: In one embodiment, a unique (or quasi unique) identifier can be received by an application store, or other on-line store, and the store can create a signed receipt that includes data desired from the unique identifier. This signed receipt is then transmitted to a device that is running the application obtained from the on-line store and the device can verify the receipt by deriving the unique (or quasi-unique) identifier from the signed receipt and comparing the derived identifier with the device identifier stored on the device, or the vendor identifier assigned to the application vendor.

    Abstract translation: 在一个实施例中,唯一的(或准唯一的)标识符可以由应用商店或其他在线商店接收,并且商店可以创建包括从唯一标识符所期望的数据的签名收据。 然后将该签名的收据发送到运行从在线商店获取的应用的设备,并且设备可以通过从签名的收据导出唯一(或准唯一)标识符来验证收据,并将导出的标识符与 存储在设备上的设备标识符或分配给应用供应商的供应商标识符。

    Silicon key attestation
    9.
    发明授权

    公开(公告)号:US10536271B1

    公开(公告)日:2020-01-14

    申请号:US15435229

    申请日:2017-02-16

    Applicant: Apple Inc.

    Abstract: Systems and methods are disclosed for generating one or more hardware reference keys (HRK) on a computing device, and for attesting to the validity of the hardware reference keys. An initial hardware reference key can be a silicon attestation key (SIK) generated during manufacture of a computing system, such as a system-on-a-chip. The SIK can comprise an asymmetric key pair based at least in part on an identifier of the processing system type and a unique identifier of the processing system. The SIK can be signed by the computing system and stored thereon. The SIK can be used to generate further HRKs on the computing device that can attest to the processing system type of the computing device and an operating system version that was running when the HRK was generated. The computing device can generate an HRK attestation (HRKA) for each HRK generated on the computing system.

Patent Agency Ranking