IP Library Granted Patent US 8,442,234
Granted Patent B2
US 8,442,234 · App. 12/842,133 · Granted May 14, 2013

System and method for obtaining certificate status of subkeys

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,442,234
App. No.
12/842,133
Granted
May 14, 2013
Kind
B2
Abstract

Systems and methods for updating status of digital certificate subkeys. A request is made to a key server to verify if a given key is revoked. If it is not, then the key with its subkeys is acquired from the key server. If one or more subkeys or signatures of the subkeys are different in the acquired key, then the key is replaced.

Claims (34)

1. A method for verifying a key comprising subkeys for use in a web of trust security environment, the method being for operation on a message server and comprising:

determining at the message server whether the key comprising subkeys has been revoked;

if the key comprising subkeys has not been revoked, receiving a current version of the key comprising subkeys from a key server;

comparing the key comprising subkeys with the current version thereof received from the key server;

if the key comprising subkeys does not match the current version thereof received from the key server, then transmitting, to a mobile device coupled to the message server, at least one subkey of the current version of the key comprising subkeys received from the key server;

determining at the message server whether one or more signatures of the key comprising subkeys are different from corresponding one or more signatures of the current version of the key comprising subkeys received from the key server; and

issuing a notification to the mobile device if the one or more signatures of the key comprising subkeys are different from corresponding one or more signatures of the current version of the key comprising subkeys received from the key server.

2. The method of claim 1 , wherein determining at the message server whether the key comprising subkeys has been revoked comprises the message server making a request to the key server to verify a status of the key and receiving a reply from the key server.

3. The method of claim 1 , wherein the determining is in response to a request received from the mobile device.

4. The method of claim 1 , wherein the determining is according to a predefined schedule.

5. The method of claim 4 , wherein the predefined schedule is periodic.

6. The method of claim 1 , wherein the web of trust security environment is a Pretty Good Privacy (PGP) security environment.

7. The method of claim 1 , wherein the mobile device comprises a wireless mobile device.

8. The method of claim 1 , further comprising: in response to the determining, issuing a notification to the mobile device if the key comprising subkeys has been revoked.

9. The method of claim 1 , further comprising: if the key comprising subkeys has not been revoked, sending a request to the key server for the current version of the key comprising subkeys, wherein the current version of the key comprising subkeys is received from the key server in response to the request.

10. The method of claim 1 , further comprising: if the key comprising subkeys does match the current version thereof received from the key server, replacing the key comprising subkeys at the message server with the current version of the key comprising subkeys received from the key server.

11. The method of claim 1 , wherein the transmitting comprises transmitting, to the mobile device, all of the subkeys of the current version of the key comprising subkeys.

12. The method of claim 1 , further comprising: if the key comprising subkeys does match the current version thereof received from the key server, determining which one or more subkeys of the key comprising subkeys have changed, wherein the transmitting comprises transmitting, to the mobile device, the one or more subkeys that have changed.

13. A non-transitory computer-readable storage medium capable of causing one or more data processors in a message server to verify a key comprising subkeys for use in a web of trust security environment by implementing a method, the method comprising:

determining at the message server whether the key comprising subkeys has been revoked;

if the key comprising subkeys has not been revoked, receiving a current version of the key comprising subkeys from a key server;

comparing the key comprising subkeys with the current version thereof received from the key server;

if the key comprising subkeys does not match the current version thereof received from the key server, then transmitting, to the mobile device, at least one subkey of the current version of the key comprising subkeys received from the key server;

determining at the message server whether one or more signatures of the key comprising subkeys are different from corresponding one or more signatures of the current version of the key comprising subkeys received from the key server; and

issuing a notification to the mobile device if the one or more signatures of the key comprising subkeys are different from corresponding one or more signatures of the current version of the key comprising subkeys received from the key server.

14. The non-transitory computer-readable storage medium of claim 13 , wherein determining at the message server whether the key comprising subkeys has been revoked comprises the message server making a request to the key server to verify a status of the key and receiving a reply from the key server.

15. A system comprising:

a mobile device;

a key server; and

a message server configured to verify a key comprising subkeys for use in a web of trust security environment by implementing a method, the method comprising: determining at the message server whether the key comprising subkeys has been revoked; if the key comprising subkeys has not been revoked, receiving a current version of the key comprising subkeys from the key server;

comparing the key comprising subkeys with the current version thereof received from the key server; if the key comprising subkeys does not match the current version thereof received from the key server, then transmitting, to the mobile device, at least one subkey of the current version of the key comprising subkeys received from the key server; determining at the message server whether one or more signatures of the key comprising subkeys are different from corresponding one or more signatures of the current version of the key comprising subkeys received from the key server; and issuing a notification to the mobile device if the one or more signatures of the key comprising subkeys are different from corresponding one or more signatures of the current version of the key comprising subkeys received from the key server.

16. The system of claim 15 , wherein the web trust security environment is a Pretty Good Privacy (PGP) security environment.

17. The system of claim 15 , wherein the mobile device comprises a wireless mobile device.

18. The system of claim 15 , wherein the message server is an email server that handles messages for the mobile device.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064269/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Jul 7, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 033279/0940 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2010
From: BROWN, MICHAEL K.; KIRKUP, MICHAEL G.; LITTLE, HERBERT A.
To: RESEARCH IN MOTION LIMITED
Reel/Frame 024730/0565 →