IP Library Granted Patent US 8,949,597
Granted Patent B1
US 8,949,597 · App. 12/644,233 · Granted Feb 3, 2015

Managing certificates on a mobile device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,949,597
App. No.
12/644,233
Granted
Feb 3, 2015
Kind
B1
Abstract

A system or method of remotely managing security certificates on a mobile device is provided. Certificates on a mobile device may be added to, deleted from, or updated by a server that manages certificates on one or more mobile devices. The server may retrieve new certificates from a certificate authority and push the certificate to the mobile device where it is stored for subsequent use. The management of security certificates on a mobile device may be governed by one or more certificate-management rules that are enforced by the remote server and/or the mobile device.

Claims (45)

1. A method for remotely managing security certificates on a mobile device that subscribes to a telecommunications provider, the method comprising:

at the mobile device, communicating with a certificate distribution server that is maintained by the telecommunications provider to which the mobile device subscribes;

receiving, at the mobile device, a security certificate from the certificate distribution server, wherein the security certificate is received over a wireless interface on the mobile device by way of a radio access network that is controlled by the telecommunications provider, and wherein the security certificate is associated with a content provider;

storing the security certificate in a data store located on the mobile device;

receiving a request to authenticate a communication session using the security certificate;

communicating to a source of the request a response to the request using the security certificate; and

determining that storing the security certificate conforms to certificate-management rules in place for the mobile device that are customized by a user, wherein the certificate-management rules specify at least

authorized certificate authorities, and

wherein the authorized certificate authorities are particular authorities from which new certificates are allowed to be received.

2. The method of claim 1 , wherein the method further comprises displaying an interface on a display associated with the mobile device requesting permission to receive the security certificate.

3. The method of claim 1 , wherein the method further comprises:

receiving a message from the content provider indicating the security certificate is needed to establish the requested communication session; and

communicating a request for the security certificate to a certificate-distribution server.

4. The method of claim 3 , wherein the security certificate is received from the certificate-distribution server.

5. The method of claim 1 , wherein the method further includes displaying an interface of the mobile device through which certificate-management policies may be edited.

6. The method of claim 5 , wherein the certificate-management policies comprise enabling auto installation without user notification.

7. One or more non-transitory computer-readable media having computer-executable instructions embodied thereon that when executed by a computing device perform a method of managing security certificates on a plurality of mobile devices that subscribe to a telecommunications provider, the method comprising:

at a network device controlled by the telecommunications provider, storing user-provided certificate-management rules associated with each of the mobile devices that subscribe to the telecommunications provider;

at the network device, receiving a request to communicate a security certificate to an individual mobile device within the plurality of mobile devices, wherein the security certificate is not presently stored on the individual mobile device, and wherein the security certificate is associated with a content provider; and

at the network device, accessing the user-provided certificate-management rules associated with the individual mobile device;

prior to communicating the security certificate to the individual mobile device, determining that communicating the security certificate to the individual mobile device conforms to the user-provided certificate-management rules associated with the individual mobile device, wherein the certificate-management rules specify at least authorized certificate authorities, and wherein the authorized certificate authorities are particular authorities from which new certificates are allowed to be received;

based on the determination, communicating the security certificate to the individual mobile device over a wireless interface;

at the network device, monitoring data related to the security certificate, the monitored data including usage information.

8. The media of claim 7 , wherein the request is received from the content provider.

9. The media of claim 7 , wherein the request is received from the individual mobile device indicating that the security certificate is required to initiate a communication session with the content provider.

10. The media of claim 7 , wherein the method further comprises retrieving the security certificate from the certificate authority.

11. The media of claim 7 , wherein the method further comprises, at the network device:

making a record of each security certificate on each of the plurality of mobile devices;

monitoring an expiration date associated with said each security certificate; and

editing a specific security certificate on each of the plurality of mobile devices in response to determining the specific security certificate on each of the plurality of mobile devices has expired.

12. The media of claim 7 , further comprising receiving an indication that a particular security certificate on one or more of the plurality of mobile devices has been compromised and communicating an instruction to each of the one or more of the plurality of mobile devices to delete the particular security certificate.

13. One or more non-transitory computer-readable media having computer-executable instructions embodied thereon that when executed by a computing device perform a method of managing security certificates on a mobile device that subscribes to a telecommunications provider, the method comprising:

communicating, from the mobile device, a request to initiate a communication session with a computing device associated with a content provider, wherein the mobile device communicates by way of a radio-access network controlled by the telecommunications provider;

receiving a response from the computing device identifying a security certificate that is required to establish the communication session with the computing device;

requesting the security certificate from a certificate-distribution server that is maintained by the telecommunications provider and that manages security certificates for mobile devices that subscribe to the telecommunications provider;

receiving the security certificate over a wireless interface on the mobile device, wherein the certificate is received from the certificate-distribution server;

determining that storing the security certificate conforms to certificate-management rules in place for the mobile device that are customized by a user of the mobile device, wherein the certificate-management rules specify at least

authorized certificate authorities, and

wherein the authorized certificate authorities are particular authorities from which new certificates are allowed to be received;

storing the security certificate in a data store on the mobile device; and

monitoring data related to the security certificate, the monitored data including usage information.

14. The media of claim 13 , wherein the method further comprises determining that receiving the security certificate does not violate the certificate-management rules in place for the mobile device.

15. The media of claim 13 , wherein the response is an HTTPS redirect.

16. The media of claim 13 , wherein the method further comprises displaying an interface on the mobile device requesting permission to receive the security certificate and receiving an input indicating that permission is granted.

17. The media of claim 13 , wherein the method further comprises displaying an interface on the mobile device that displays present certificate-management-rule settings and allows a user to update the settings.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2009
From: REEVES, RAYMOND EMILIO; WICK, RYAN ALAN; BRYAN, JEFF H.; JONES, JOHN MARVIN, III
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 023687/0168 →