apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
apple patient
No Result
View All Result

Mac & Apple Watch: Apple updates platform security guide

Milan Jovicic by Milan Jovicic
May 17, 2021 - 6:43 PM
in Apple News
Apple Platform Security Guide

Varna, Bulgaria - May 23, 2017: Apple MacBook Pro Retina with macOS Sierra and open tab in Safari browser, iPhone 7 and iPad Pro with iOS 10 on the displays and Apple Watch on the office desk.

WhatsAppFacebookEmail
Threads

Apple released its 2021 Platform Security Guide back in February, detailing M1 Macs, iOS 14, macOS Big Sur, watchOS 7, and more. Now the guide has been updated to include more information on Touch ID on the new Magic Keyboard, as well as unlocking your iPhone with your Apple Watch in iOS 14.5.

The revised Platform Security Guide describes in detail how the new Magic Keyboard with Touch ID that ships with the new M1 iMacs works and more. Apple writes:

Magic Keyboard with Touch ID acts as the biometric sensor; it does not store biometric templates, perform biometric matching, or enforce security policies (such as requiring password after 48 hours of no unlock). The Touch ID sensor in Magic Keyboard with Touch ID must be securely paired with the Secure Enclave on your Mac before it can be used. Only then does the Secure Enclave perform the login and matching processes and enforce security policies in the same way as a built-in Touch ID sensor.

Apple explains communication channel between Magic Keyboard with Touch ID and the Secure Enclave

The documentation also describes secure pairing, secure pairing intent, and Touch ID channel security. To ensure a secure communication channel between the Touch ID sensor in the Magic Keyboard with Touch ID and the Secure Enclave on the paired Mac, the following prerequisites are required:

  • The secure pairing between the Magic Keyboard with Touch ID PKA block and the Secure Enclave as described above
  • A secure channel between the Magic Keyboard with Touch ID sensor and its PKA block

Apple then goes on to explain:

The secure channel between the Magic Keyboard with Touch ID sensor and its PKA pad is set up at the factory with a unique key shared between the two. (This is the same technique used to create the secure channel between the Secure Enclave on the Mac and its built-in sensor for Mac computers with built-in Touch ID.)

Another important update to the guide includes details on the cryptography used to unlock the iPhone with the Apple Watch feature introduced in iOS 14.5.

To make it more convenient to use multiple Apple devices, some devices can automatically unlock others in certain situations.

Automatic unlocking supports three applications:

  • An Apple Watch can be unlocked by an iPhone.
  • A Mac can be unlocked by an Apple Watch.
  • An iPhone can be unlocked by an Apple Watch if a user with their nose and mouth covered is detected.

All three use cases are based on the same foundation:

A mutually authenticated station-to-station (STS) protocol where long-term keys are exchanged at feature activation time and unique ephemeral session keys are negotiated for each request. Regardless of the underlying communication channel, the STS tunnel is negotiated directly between the Secure Enclaves in both devices and all cryptographic material is kept within this secure domain (except for Mac computers without a Secure Enclave, which terminate the STS tunnel in the kernel).

How it works in detail

To understand how it works in detail, there are two phases:

  • A complete unlocking sequence can be divided into two phases. First, the device to be unlocked (the “target”) generates a cryptographic unlocking secret and sends it to the device performing the unlocking (the “initiator”). Later, the initiator performs the unlocking using the previously generated secret.
  • To enable automatic unlocking, the devices connect to each other over a BLE connection. Then, a 32-byte unlock secret randomly generated by the target device is sent to the initiator over the STS tunnel. At the next biometric or passcode unlock, the target device wraps its passcode-derived key (PDK) with the unlock secret and discards the unlock secret from its memory.
  • To perform the unlock, the devices initiate a new BLE connection and then use peer-to-peer Wi-Fi to securely estimate the distance between the devices. If the devices are within the specified range and the required security policies are met, the initiator sends its unlock secret to the target via the STS tunnel. The target then generates a new 32-byte unlock secret and sends it back to the initiator. If the current unlock secret sent by the initiator successfully decrypts the unlock record, the target device is unlocked and the PDK is repackaged with a new unlock secret. Finally, the new unlock secret and PDK are then discarded from the target device's memory.

Along with these updates, Apple added details to the CustomOS Image4 Manifest Hash and edited some details for Express Mode transactions, Secure Multi-Boot, and Sealed Key Protection. For the full 2021 Platform Security Guide, see here. (Photo by alexey_boldin / Bigstockphoto)

  • iOS 14 & Co: Apple updates platform security guidelines
Make Apfelpatient a preferred source One click – and you'll see us more often on Google
Was this article helpful?
YesNo
Tags: Apple WatchiOSiPadOSMacmacOSwatchOS
SendShareSend
Share

Our Amazon Storefront

A handpicked selection of products for iPhone, Mac and more – sorted by topic and updated regularly.

Shop Now

This post contains affiliate links (including Amazon). We earn a small commission on qualifying purchases – at no extra cost to you. Learn more on our Partner Program page.

Milan Jovicic

Milan Jovicic

Milan founded Apfelpatient in 2016 and has written all of its content himself since 2018 – news, rumors, guides and product reviews. Apple devices here aren't test units for a fortnight but everyday tools: from the iPhone to the MacBook Pro, MacBook Air and iMac through to the Apple Vision Pro, at least one device from nearly every product category is in daily use, many of them replaced annually. Every menu path in a guide is verified on the device before it goes live.

Guests in the lobby of the Steve Jobs Theater beneath the circular ceiling element, venue for the keynote at Apple's September event

Apple Event in September: iPhone 18 Pro, Ultra and more

August 5, 2026
Symbolic image of the iPhone 20 showing two tilted device outlines of different sizes=

iPhone 20: All the rumors about the anniversary model

August 4, 2026
Guests outside the Steve Jobs Theater at Apple Park, where Apple will also hold its September event in 2026

Apple is preparing for its September event: the date is approaching

August 4, 2026

About APFELPATIENT

APFELPATIENT brings you the latest Apple news, product updates, guides, reviews and tips across the entire Apple ecosystem — from the iPhone to the Mac to the Apple Vision Pro. From the first rumors to confirmed news: researched responsibly.

Follow Apfelpatient

Facebook Instagram YouTube Threads Threads

Company

  • About Apfelpatient
  • Contact
  • Author Profiles

Community

  • Netiquette
  • Push Notifications
  • RSS feed

Legal

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • Cookie Settings
  • Affiliate Program

Resources

  • Sitemap

© 2026 Apfelpatient. All rights reserved.

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights

© 2026 Apfelpatient. All rights reserved. Page Directory

Change language to Deutsch