Secure Circuit For Encryption Key Generation
Abstract
Techniques are disclosed relating to relating to a public key infrastructure (PKI). In one embodiment, an integrated circuit is disclosed that includes at least one processor and a secure circuit isolated from access by the processor except through a mailbox mechanism. The secure circuit is configured to generate a key pair having a public key and a private key, and to issue, to a certificate authority (CA), a certificate signing request (CSR) for a certificate corresponding to the key pair. In some embodiments, the secure circuit may be configured to receive, via the mailbox mechanism, a first request from an application executing on the processor to issue a certificate to the application. The secure circuit may also be configured to perform, in response to a second request, a cryptographic operation using a public key circuit included in the secure circuit.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A non-transitory computer readable medium having program instructions stored therein that are executable by a device to perform operations comprising:
sending, by an application, a key creation request for a secure circuit of the device to create a cryptographic key associated with the application and protected by a biometric authentication performed by the secure circuit for the application; sending, by the application, a use request for the secure circuit to perform a cryptographic service using the protected cryptographic key; and receiving, by the application, a result of the cryptographic service in response to a successful biometric authentication.
22 . The computer readable medium of claim 21 , wherein the key creation request specifies usage criteria that restrict how the protected cryptographic key is used; and
wherein one of the usage criteria is the secure circuit verifying biometric information from a biosensor before performing a requested service using the protected cryptographic key.
23 . The computer readable medium of claim 21 , wherein the key creation request is a request for a certified public key pair, and wherein the operations further comprise:
receiving, by the application, a certificate obtained by the secure circuit for the certified public key pair and from a certificate authority, wherein the certificate includes a public key of the pair, and wherein the protected cryptographic key is a private key of the pair.
24 . The computer readable medium of claim 23 , wherein the certificate includes an application identifier of the application.
25 . The computer readable medium of claim 23 , wherein the certificate indicates an ability to perform the biometric authentication.
26 . The computer readable medium of claim 21 , wherein the operations further comprise:
prior to sending the key creation request:
performing an authentication using a user name and password of a user;
receiving an indication of a user preference to perform a different type of authentication, wherein the key creation request is sent in response to the received indication; and
performing a subsequent authentication for the user that includes:
the application sending the use request of the cryptographic service; and
the application providing the received result of the cryptographic service to an external entity in lieu of the user name and password.
27 . The computer readable medium of claim 21 , wherein the operations further comprise:
providing the result of the cryptographic service to another device to unlock functionality of the other device.
28 . The computer readable medium of claim 21 , wherein the cryptographic service includes signing a payload provided by the application and using the protected cryptographic key.
29 . The computer readable medium of claim 21 , wherein the cryptographic service includes an encryption or a decryption performed by the secure circuit using the protected cryptographic key.
30 . The computer readable medium of claim 21 , wherein the requests are sent via an application programing interface (API) supported by an operating system of the device.
31 . The computer readable medium of claim 21 , wherein the requests are sent to a mailbox circuit of the secure circuit.
32 . A method, comprising:
sending, by an application executing on a device, a key creation request for a secure circuit of the device to create a cryptographic key associated with the application and protected by a biometric authentication performed by the secure circuit for the application; sending, by the application, a use request for the secure circuit to perform a cryptographic service using the protected cryptographic key; and receiving, by the application, a result of the cryptographic service in response to a successful biometric authentication.
33 . The method of claim 32 , wherein the key creation request includes usage criteria specified by the application to restrict how the protected cryptographic key is used including a requirement to perform the biometric authentication before using the protected cryptographic key.
34 . The method of claim 32 , further comprising:
in response to the key creation request, receiving, by the application, a certificate obtained by the secure circuit for a certified public key pair, wherein the certificate includes a public key of the pair, and wherein the protected cryptographic key is a private key of the pair.
35 . The method of claim 32 , further comprising:
prior to sending the key creation request:
performing, by the application, an authentication for a user using a user credential supplied by the user;
receiving, by the application, an indication of a preference of the user to perform a different type of authentication, wherein the key creation request is sent in response to the received indication; and
performing a subsequent authentication for the user that includes:
the application sending the use request of the cryptographic service; and
the application providing the received result of the cryptographic service to an external entity.
36 . The method of claim 32 , wherein the use request is a request to sign data provided by the application and using the protected cryptographic key.
37 . The method of claim 32 , wherein the use request is a request to encrypt or decrypt data provided by the application and using the protected cryptographic key.
38 . A non-transitory computer readable medium having program instructions stored therein that are executable by a device to implement an application programing interface (API) that performs operations comprising:
receiving, from an application, a key creation request for a secure circuit of the device to create a cryptographic key associated with the application and protected by a biometric authentication performed by the secure circuit for the application; receiving, by the application, a use request for the secure circuit to perform a cryptographic service using the protected cryptographic key; and sending, to the application, a result of the cryptographic service in response to a successful biometric authentication.
39 . The computer readable medium of claim 38 , wherein the operations further comprise:
providing the requests to a mailbox circuit of the secure circuit.
40 . The computer readable medium of claim 38 , wherein the application programing interface (API) is implemented by an operating system of the device.Join the waitlist — get patent alerts
Track US2024039714A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.