US2023289787A1PendingUtilityA1

Authentication using a secure circuit

Assignee: APPLE INCPriority: Jun 12, 2016Filed: Feb 24, 2023Published: Sep 14, 2023
Est. expiryJun 12, 2036(~9.9 yrs left)· nominal 20-yr term from priority
G06Q 20/3829H04L 63/08H04L 63/0823H04L 63/126G06Q 20/12G06Q 20/3223G06Q 20/3227G06Q 20/385G06Q 20/40145H04L 63/0861H04L 63/083H04L 9/3268G06Q 20/3825H04L 2209/56H04L 2209/80G06Q 2220/00H04W 12/069
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques are disclosed relating to authentication using public key encryption. In one embodiment, a computing device includes a secure circuit, a processor, and memory. The secure circuit is configured to generate a public key pair usable to authenticate a user of the computing device. The memory has program instructions stored therein that are executable by the processor to cause the computing device to perform operations including authenticating the user with a server system by sending authentication information supplied by the user. The operations further include, in response to the server system verifying the authentication information, receiving a first token usable to register the public key pair with the server system and sending, to the server system, a request to register the public key pair for authenticating the user. In such an embodiment, the request includes the first token and identifies a public key of the public key pair.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A computing device, comprising:
 a processor; and   memory having program instructions stored therein that are executable by the processor to cause the computing device to perform operations including:
 as part of a first exchange with a server system to facilitate a particular type of operation for a user:
 receiving a first token from the server system in response to providing valid user-supplied authentication information to the server system, wherein the first token enables registering of a public key of a public key pair so that the server system can subsequently authenticate the user without the valid user-supplied authentication information; and 
 receiving a second token from the server system as part of registering the public key with the server system using the first token; and 
 
 as part of a second exchange with the server system to facilitate the particular type of operation for the user:
 using a private key of the public key pair to generate a digital signature; and 
 sending the second token and the digital signature to the server system to enable authentication of the user without sending the valid user-supplied authentication information, wherein the second token enables the server system to verify the digital signature. 
 
   
     
     
         22 . The computing device of  claim 21 , further comprising a secure circuit configured to generate the public key pair, wherein the operations further comprise:
 as part of the second exchange:
 receiving a challenge from the server system; and 
 requesting that the secure circuit generate, with the private key, the digital signature for the challenge. 
   
     
     
         23 . The computing device of  claim 22 , wherein the operations further comprise:
 in response to receiving the first token, requesting that the secure circuit generate the public key pair; and   providing the first token and the public key to the server system to register the public key with the server system.   
     
     
         24 . The computing device of  claim 23 , wherein the requesting that the secure circuit generate the public key pair includes issuing a request to a mailbox mechanism of the secure circuit, wherein the mailbox mechanism is configured to isolate circuitry in the secure circuit from being accessed by the processor. 
     
     
         25 . The computing device of  claim 21 , further comprising a biosensor configured to detect biometric data from the user, wherein the operations further comprise:
 causing a biometric authentication of the user to be performed using the biosensor, wherein the digital signature is generated in response to the user providing valid biometric data.   
     
     
         26 . The computing device of  claim 25 , wherein the operations further comprise:
 in response to receiving a user request to discontinue using the biosensor to authenticate as part of an exchange with the server system to facilitate the particular type of operation, issuing a cancellation request to the server system to unregister the public key.   
     
     
         27 . The computing device of  claim 25 , further comprising a secure circuit configured to perform at least a portion of the biometric authentication, wherein the secure circuit and the biosensor are configured to encrypt communications between each other using a shared key. 
     
     
         28 . The computing device of  claim 21 , wherein the first token includes at least a portion, signed by the server system, of the valid user-supplied authentication information. 
     
     
         29 . A non-transitory computer-readable medium having program instructions stored thereon that are executable by a computer system to perform operations comprising:
 as part of a first exchange with a server system to facilitate a particular type of operation for a user:
 receiving a first token from the server system in response to providing valid user-supplied authentication information to the server system, wherein the first token enables registering of a public key of a public key pair so that the server system can subsequently authenticate the user without the valid user-supplied authentication information; and 
 receiving a second token from the server system as part of registering the public key with the server system using the first token; and 
   as part of a second exchange with the server system to facilitate the particular type of operation for the user:
 using a private key of the public key pair to generate a digital signature; and 
 sending the second token and the digital signature to the server system to enable authentication of the user without sending the valid user-supplied authentication information, wherein the second token enables the server system to verify the digital signature. 
   
     
     
         30 . The non-transitory computer-readable medium of  claim 29 , wherein the operations further comprise:
 before the using of the private key to generate the digital signature, requesting that the user provide valid biometric data.   
     
     
         31 . The non-transitory computer-readable medium of  claim 29 , wherein the operations further comprise:
 before the using of the private key to generate the digital signature, receiving a challenge from the server system, wherein the digital signature is generated based on the challenge.   
     
     
         32 . The non-transitory computer-readable medium of  claim 29 , wherein the operations further comprise:
 in response to receiving a user request to discontinue using biometric data to authenticate as part of an exchange with the server system to facilitate the particular type of operation, issuing a cancellation request to the server system to unregister the public key.   
     
     
         33 . The non-transitory computer-readable medium of  claim 29 , wherein the operations further comprise:
 deriving a value from a username and password of the user; and   sending the value as the valid user-supplied authentication information to the server system as part of the first exchange.   
     
     
         34 . A method, comprising:
 as part of a first exchange with a server system to facilitate a particular type of operation for a user, a computing device:
 receiving a first token from the server system in response to providing valid user-supplied authentication information, wherein the first token enables registering of a public key of a public key pair so that the server system can subsequently authenticate the user without the valid user-supplied authentication information; and 
 receiving a second token from the server system as part of registering the public key with the server system using the first token; and 
   as part of a second exchange with the server system to facilitate the particular type of operation for the user, the computing device:
 using a private key of the public key pair to generate a digital signature; and 
 sending the second token and the digital signature to the server system to enable authentication of the user without sending the valid user-supplied authentication information, wherein the second token enables the server system to verify the digital signature. 
   
     
     
         35 . The method of  claim 34 , further comprising:
 storing, by the computing device and in association with the private key, usage criteria that indicates that the private key cannot be used to generate a digital signature without performing a biometric authentication of the user.   
     
     
         36 . The method of  claim 35 , further comprising:
 updating, by the computing device, a setting of a client application that is used in the first exchange to indicate that biometric authentication is to be used for subsequent exchanges with the server system to perform the particular type of operation.   
     
     
         37 . The method of  claim 34 , further comprising:
 performing, by the computing device, a biometric authentication of the user, wherein the digital signature is generated in response to the user providing valid biometric data.   
     
     
         38 . The method of  claim 34 , further comprising:
 in response to receiving the first token, the computing device causing the public key pair to be generated; and   sending, by the computing device, a registration request to the server system to register the public key with the server system, wherein the registration request includes a machine identifier that identifies the computing device.   
     
     
         39 . The method of  claim 38 , wherein the second token identifies the machine identifier and an expiration date of a registration of the public key. 
     
     
         40 . The method of  claim 34 , wherein the second exchange with the server system is performed after a restart of the computing device.

Join the waitlist — get patent alerts

Track US2023289787A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.