IP Library Granted Patent US 8,725,643
Granted Patent B2
US 8,725,643 · App. 12/771,194 · Granted May 13, 2014

System and method for verifying digital signatures on certificates

Inventors: Michael K. Brown (Waterloo, CA); Michael S. Brown (Waterloo, CA)
Assignee: BlackBerry Limited
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,725,643
App. No.
12/771,194
Granted
May 13, 2014
Kind
B2
Abstract

A system and method for verifying a digital signature on a certificate, which may be used in the processing of encoded messages. In one embodiment, when a digital signature is successfully verified in a signature verification operation, the public key used to verify that digital signature is cached. When a subsequent attempt to verify the digital signature is made, the public key to be used to verify the digital signature is compared to the cached key. If the keys match, the digital signature can be successfully verified without requiring that a signature verification operation in which some data is decoded using the public key be performed.

Claims (38)

1. A method of verifying a digital signature on a certificate on a computing device, the method comprising:

a processor of the computing device storing, in a memory store, a stored public key in response to a first successful verification of the digital signature;

the processor receiving a public key associated with an issuer of the certificate, and a request to verify the digital signature of the certificate using the received public key; and

the processor indicating a second successful verification of the digital signature in response to determining that the public key matches the stored public key.

2. The method of claim 1 , wherein the computing device comprises a mobile device.

3. The method of claim 1 , further comprising the processor identifying the stored public key as stale if the stored public key has been stored in the memory store for longer than a pre-determined duration.

4. The method of claim 3 , further comprising deleting the stored public key from the memory store if the stored public key is identified as stale.

5. The method of claim 1 , further comprising the processor marking the stored public key as stale in response to a user request.

6. The method of claim 5 , further comprising deleting the stored public key from the memory store if the stored public key is marked as stale.

7. A method of verifying a digital signature on a certificate on a computing device, the method comprising:

a processor of the computing device storing, in a memory store, a stored public key and a prior verification result in response to a first successful verification of the digital signature;

the processor receiving a public key associated with an issuer of the certificate, and a request to verify the digital signature of the certificate using the received public key;

the processor indicating a second successful verification of the digital signature in response to determining that the public key matches the stored public key and that the prior verification result associated with the stored public key was successful; and

the processor indicating unsuccessful verification of the digital signature in response to determining that the public key matches the stored public key, and that the prior verification result was unsuccessful.

8. The method of claim 7 , wherein the computing device comprises a mobile device.

9. The method of claim 7 , further comprising the processor identifying the stored public key as stale if the stored public key has been stored in the memory store for longer than a pre-determined duration.

10. The method of claim 9 , further comprising deleting the stored public key from the memory store if the stored public key is identified as stale.

11. The method of claim 7 , further comprising the processor marking the stored public key as stale in response to a user request.

12. The method of claim 11 , further comprising deleting the stored public key from the memory store if the stored public key is marked as stale.

13. A device comprising a processor and memory, the processor configured to verify a digital signature on a certificate, wherein the processor is configured to:

store, in a memory store, a stored public key in response to a first successful verification of the digital signature;

receive a public key associated with an issuer of the certificate, and a request to verify the digital signature of the certificate using the received public key; and

indicate a second successful verification of the digital signature in response to determining that the public key matches the stored public key.

14. The device of claim 13 , wherein the device comprises a mobile device.

15. The device of claim 13 , wherein the processor is further configured to identify the stored public key as stale if the stored public key has been stored in the memory store for longer than a pre-determined duration, and to compare the received public key with the stored public key residing in the memory store and indicate successful verification of the digital signature if the stored public key is not identified as stale.

16. The device of claim 15 , wherein the process is further configured to delete the stored public key from the memory store if the stored public key is identified as stale.

17. The device of claim 13 , wherein the processor is further configured to mark the stored public key as stale in response to a user request, and to compare the received public key with the stored public key residing in the memory store and indicate successful verification of the digital signature if the stored public key is not marked as stale.

18. The device of claim 17 , wherein the processor is further configured to delete the stored public key from the memory store if the stored public key is marked as stale.

19. A device comprising a processor and memory, the processor configured to verify a digital signature on a certificate, wherein the processor is configured to:

store in a memory store, a stored public key and a prior verification result in response to a first successful verification of the digital signature;

receive a public key associated with an issuer of the certificate, and a request to verify the digital signature of the certificate using the received public key;

indicate a second successful verification of the digital signature in response to determining that the public key matches the stored public key, and that the prior verification result associated with the stored public key was successful; and

indicate unsuccessful verification of the digital signature in response to determining that the public key matches the stored public key, and that the prior verification result was unsuccessful.

20. The device of claim 19 , wherein the device comprises a mobile device.

21. The device of claim 19 , wherein the processor is further configured to identify the stored public key as stale if the stored public key has been stored in the memory store for longer than a pre-determined duration, and to compare the received public key with the stored public key residing in the memory store and indicate successful or unsuccessful verification of the digital signature depending on the prior verification result if the stored public key is not identified as stale.

22. The device of claim 21 , wherein the processor is further configured to delete the stored public key from the memory store if the stored public key is identified as stale.

23. The device of claim 19 , wherein the processor is further configured to mark the stored public key as stale in response to a user request, and to compare the received public key with the stored public key residing in the memory store and indicate successful or unsuccessful verification of the digital signature depending on the prior verification result if the stored public key is not marked as stale.

24. The device of claim 23 , wherein the processor is further configured to delete the stored public key from the memory store if the stored public key is marked as stale.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
CHANGE OF NAME Recorded Nov 3, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 034150/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2010
From: BROWN, MICHAEL K.; BROWN, MICHAEL S.
To: RESEARCH IN MOTION LIMITED
Reel/Frame 024317/0136 →
Continuity (2)
Continuation 10975988 · Oct 29, 2004
Related Publication 20100211795A1 · Aug 19, 2010