Apple Platform Security
- Welcome
- Intro to Apple platform security
- Hardware security and biometrics
-
System security
- System security overview
-
Secure boot
- Boot process for iPad and iPhone devices
- Memory safe iBoot implementation
- Mac computers with Apple silicon
- Intel-based Mac computers
- Signed system volume security
- Secure software updates
- Background Security Improvements
- Operating system integrity
- Device pairing and connection security
- BlastDoor for Messages and IDS
- Lockdown Mode security
- Overview of additional macOS system security capabilities
- System security for watchOS
- Random number generation
- Communicating emergency information using satellites
- Apple Security Research Device
-
Encryption and Data Protection
- Encryption and Data Protection overview
- Quantum-secure cryptography with Apple devices
- Passcodes and passwords
- Data Protection
- FileVault
- How Apple protects users personal data
- Digital signing and encryption
-
App security
- App security overview
- App code signing process
- App security in iOS, iPadOS, and visionOS
- App security in macOS
- Supporting extensions
- Secure features in the Notes app
- Secure features in the Shortcuts app
-
Services security
- Services security overview
- Apple Accounts and Managed Apple Accounts
- iCloud
- Passcode and password management
-
Apple Pay
- Apple Pay security overview
- Apple Pay component security
- How Apple Pay keeps users purchases protected
- Credit, debit, and prepaid cards
- Payment authorization with Apple Pay
- Paying with cards using Apple Pay
- Contactless passes in Apple Pay
- Rendering cards unusable with Apple Pay
- Apple Card security
- Apple Cash security
- Tap to Pay on iPhone
- Using Apple Wallet
- iMessage
- Secure Apple Messages for Business
- FaceTime security
- SharePlay security
- Nearby sharing security
- Find My
- Continuity
- Network security
- Developer kit security
-
Secure device management
- Secure device management overview
- Device management
- Apple Configurator security
- Screen Time security
- Glossary
- Document revision history
- Copyright and trademarks
[]Verifying accessories for Apple devices and services
The MFi licensing program provides vetted accessory manufacturers access to the iPod Accessories Protocol (iAP) and the necessary supporting hardware components.
When an MFi accessory communicates with an iPad, iPhone, or Apple Watch, the accessory needs to prove to Apple that its been vetted. (The accessory-device connection is with Thunderbolt, Lightning, Bluetooth, or for specific devices, USB-C.) As proof of authorization, the accessory sends an Apple-provided certificate to the device, which the device then verifies. The device then sends a challenge, which the accessory needs to answer with a signed response. This process is entirely handled by a custom integrated circuit (IC) that Apple provides to approved accessory manufacturers and is transparent to the accessory itself.
Verified MFi accessories can request access to different transport methods and functionalityfor example, access to digital audio streams over the Thunderbolt cable, or location information provided over Bluetooth. An authentication IC is designed to help ensure that only approved MFi accessories are granted full access to the device. If an accessory doesnt support authentication, its access is limited to analog audio and a small subset of serial (UART) audio playback controls.
AirPlay also uses the authentication IC to verify that receivers have been approved by Apple. AirPlay audio and CarPlay video streams use the MFi-SAP (Secure Association Protocol), which encrypts communication between the accessory and device using AES-128 in counter (CTR) mode. Ephemeral keys are exchanged using ECDH key exchange (Curve25519) and signed using the authentication ICs 1024-bit RSA key as part of the Station-to-Station (STS) protocol.
Published Date: May 07, 2024