IP Library Granted Patent US 8,291,216
Granted Patent B2
US 8,291,216 · App. 11/455,180 · Granted Oct 16, 2012

Updating certificate status in a system and method for processing certificates located in a certificate search

Assignee: Research In Motion Limited
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,291,216
App. No.
11/455,180
Granted
Oct 16, 2012
Kind
B2
Abstract

A system and method for processing certificates located in a certificate search. Certificates located in a certificate search are processed at a data server (e.g. a mobile data server) coupled to a computing device (e.g. a mobile device) to determine status data that can be used to indicate the status of those certificates to a user of the computing device. Selected certificates may be downloaded to the computing device for storage, and the downloaded certificates are tracked by the data server. This facilitates the automatic updating of the status of one or more certificates stored on the computing device by the data server, in which updated status data is pushed from the data server to the computing device.

Claims (62)

1. A method of processing certificates located in a certificate search, wherein the method is performed at a data server coupled to a computing device, the method comprising:

receiving a certificate search request from the computing device, wherein the computing device comprises a wireless communication device;

initiating a certificate search on one or more certificate servers remote from the computing device, wherein at least one query is submitted to the one or more certificate servers to request retrieval of certificates satisfying the certificate search request;

retrieving one or more certificates from the one or more certificate servers;

for each of the one or more certificates retrieved at the retrieving,

processing the certificate to determine data comprising certificate data identifying the certificate, and status data by verifying at least one status property of the certificate selected from a group consisting of certificate validity, revocation status, encryption key strength, and trust status;

for at least one of the one or more certificates retrieved at the retrieving,

transmitting data comprising the certificate data and the status data determined at the processing to the computing device;

maintaining, on the data server, a copy of at least one certificate stored on the computing device;

automatically re-verifying, periodically according to a defined period, the at least one status property of the at least one certificate stored on the computing device for which a copy is maintained on the data server, to determine updated status data for the at least one certificate stored on the computing device for which a copy is maintained on the data server, wherein the re-verifying is not initiated by the computing device;

transmitting the updated status data to the computing device for each of the at least one certificate stored on the computing device for which a copy is maintained on the data server, wherein the transmitting of the updated status data is not initiated by the computing device; and

for each of the at least one certificate stored on the computing device for which a copy is maintained on the data server,

maintaining a copy, on the data server, of the status data determined at the processing for the certificate stored on the computing device,

comparing the updated status data for the certificate to the copy of the status data maintained on the data server for the certificate, and

transmitting the updated status data for the certificate to the computing device if the updated status data for the certificate differs from the copy of the status data maintained on the data server for the certificate.

2. The method of claim 1 , where at least a subset of the at least one certificate stored on the computing device for which a copy is maintained on the data server has been identified as trusted at the computing device.

3. The method of claim 1 , wherein for each of the one or more certificates retrieved at the retrieving, the status data determined at the processing for the certificate comprises a plurality of verification results, each associated with one of the at least one status property of the certificate.

4. The method of claim 1 , wherein for each of the one or more certificates retrieved at the retrieving, the status data determined at the processing for the certificate comprises a single verification result derived from verification results associated with the at least one status property of the certificate.

5. The method of claim 1 , further comprising:

selecting, prior to the transmitting, the at least one certificate from the one or more certificates retrieved at the retrieving, based on the status data as determined at the processing.

6. The method of claim 1 , further comprising:

for each of the one or more certificates retrieved at the retrieving,

determining, at the data server, additional certificate data usable by the computing device to verify at least one status property of the certificate at the computing device; and

transmitting the additional certificate data for the at least one of the one or more certificates for which the additional certificate data has been determined to the computing device.

7. The method of claim 1 , further comprising:

receiving input from the computing device identifying one or more user-selected certificates of the at least one certificate; and

downloading the one or more user-selected certificates to the computing device.

8. The method of claim 1 , wherein the certificate data is usable by the computing device to identify each of the at least one certificate in a user interface of the computing device and the status data is usable to generate at least one status indicator for each of the at least one certificate for display in the user interface of the computing device.

9. The method of claim 8 , wherein for each of the at least one certificate for which the data comprising the certificate data and the status data determined at the processing is transmitted at the transmitting, the at least one status indicator generated by the computing device for the certificate comprises exactly one icon displayable in a plurality of states.

10. The method of claim 1 , wherein the data server comprises a mobile data server.

11. The method of claim 1 , wherein at least one of the one or more certificate servers comprises the data server.

12. A physical computer-readable device on which a plurality of instructions executable by a processor is stored, the instructions for performing a method of processing certificates located in a certificate search, wherein the method is performed at a data server coupled to a computing device, the method comprising:

receiving a certificate search request from the computing device, wherein the computing device comprises a wireless communication device;

initiating a certificate search on one or more certificate servers remote from the computing device, wherein at least one query is submitted to the one or more certificate servers to request retrieval of certificates satisfying the certificate search request;

retrieving one or more certificates from the one or more certificate servers;

for each of the one or more certificates retrieved at the retrieving,

processing the certificate to determine data comprising certificate data identifying the certificate, and status data by verifying at least one status property of the certificate selected from a group consisting of certificate validity, revocation status, encryption key strength, and trust status;

for at least one of the one or more certificates retrieved at the retrieving,

transmitting data comprising certificate data and the status data determined at the processing to the computing device;

maintaining, on the data server, a copy of at least one certificate stored on the computing device;

automatically re-verifying, periodically according to a defined period, the at least one status property of the at least one certificate stored on the computing device for which a copy is maintained on the data server, to determine updated status data for the at least one certificate stored on the computing device for which a copy is maintained on the data server, wherein the re-verifying is not initiated by the computing device;

transmitting the updated status data to the computing device for each of the at least one certificate stored on the computing device for which a copy is maintained on the data server, wherein the transmitting of the updated status data is not initiated by the computing device; and

for each of the at least one certificate stored on the computing device for which a copy is maintained on the data server,

maintaining a copy, on the data server, of the status data determined at the processing for the certificate stored on the computing device,

comparing the updated status data for the certificate to the copy of the status data maintained on the data server for the certificate, and

transmitting the updated status data for the certificate to the computing device if the updated status data for the certificate differs from the copy of the status data maintained on the data server for the certificate.

13. A system for processing certificates located in a certificate search, the system comprising a computing device and a data server coupled to the computing device, wherein a processor of the data server is configured to:

receive a certificate search request from the computing device, wherein the computing device comprises a wireless communication device;

initiate a certificate search on one or more certificate servers remote from the computing device, wherein at least one query is submitted to the one or more certificate servers to request retrieval of certificates satisfying the certificate search request;

retrieve one or more certificates from the one or more certificate servers;

for each of the one or more certificates retrieved,

process the certificate to determine data comprising certificate data identifying the certificate, and status data by verifying at least one status property of the certificate selected from a group consisting of certificate validity, revocation status, encryption key strength, and trust status;

for at least one of the one or more certificates retrieved,

transmit data comprising the certificate data and the status data to the computing device;

maintain, on the data server, a copy of at least one certificate stored on the computing device;

automatically re-verify, periodically according to a defined period, the at least one status property of the at least one certificate stored on the computing device for which a copy is maintained on the data server, to determine updated status data for the at least one certificate stored on the computing device for which a copy is maintained on the data server, wherein re-verification is not initiated by the computing device;

transmit the updated status data to the computing device for each of the at least one certificate stored on the computing device for which a copy is maintained on the data server, wherein transmission of the updated status data is not initiated by the computing device; and

for each of the at least one certificate stored on the computing device for which a copy is maintained on the data server,

maintaining a copy, on the data server, of the status data for the certificate stored on the computing device,

compare the updated status data for the certificate to the copy of the status data maintained on the data server for the certificate, and

transmit the updated status data for the certificate to the computing device

if the updated status data for the certificate differs from the copy of the status data maintained on the data server for the certificate.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064269/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Feb 26, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 032360/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2006
From: ADAMS, NEIL P.; LITTLE, HERBERT A.; BROWN, MICHAEL K.; BROWN, MICHAEL S.; KIRKUP, MICHAEL G.
To: RESEARCH IN MOTION LIMITED
Reel/Frame 018008/0416 →
Continuity (2)
Division 11417108 · May 4, 2006
Related Publication 20070260877A1 · Nov 8, 2007