IP Library Granted Patent US 8,452,970
Granted Patent B2
US 8,452,970 · App. 12/874,325 · Granted May 28, 2013

System and method for code signing

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,452,970
App. No.
12/874,325
Granted
May 28, 2013
Kind
B2
Abstract

A system and method for code signing. The entities may be software application developers or other individuals or entities that wish to have applications digitally signed. Signing of the applications may be required in order to enable the applications to access sensitive APIs and associated resources of a computing device when the applications are executed on the computing device.

Claims (55)

1. A method of signing code, the method performed at a code signing device, the method comprising:

creating a key pair, the key pair comprising a private key and a public key;

storing the private key of the key pair;

deploying the public key of the key pair;

registering an entity, wherein an account record for the entity is created, and

wherein credit card information associated with the entity is validated;

receiving, at the code signing device, a code signing request from the entity to sign a software application or hash thereof using the private key of the key pair, wherein the private key is associated with a sensitive application programming interface provided on a mobile device, the software application programmed to access the sensitive application programming interface when the software application is run on the mobile device;

digitally signing the software application or hash thereof, wherein a digital signature is generated using the private key; and

returning the digital signature in response to the code signing request;

wherein the code signing request comprises a second digital signature associated with the entity, and wherein the method further comprises successfully verifying the second digital signature before the digitally signing the software application or hash thereof.

2. The method of claim 1 , wherein the public key is associated with the sensitive application programming interface provided on the mobile device.

3. The method of claim 1 , further comprising retrieving a second public key associated with the entity, and using the second public key to verify the second digital signature associated with the entity.

4. The method of claim 1 , further comprising sending an e-mail notification to the entity subsequent to the registering.

5. The method of claim 1 , further comprising maintaining a record of a number of allowable signing requests for the entity, verifying that there are allowable signing requests remaining, and updating the number of allowable signing requests, wherein the digitally signing the software application or hash thereof is performed after successfully verifying that there are allowable signing requests remaining.

6. The method of claim 1 , further comprising verifying that the entity is registered, wherein the digitally signing the software application or hash thereof is performed after successfully verifying that the entity is registered.

7. The method of claim 1 , further comprising verifying that an account of the entity is not expired, wherein the digitally signing the software application or hash thereof is performed after successfully verifying that the account of the entity is not expired.

8. The method of claim 1 , further comprising receiving input, in a user interface, to facilitate management of the account record.

9. The method of claim 1 , wherein the entity is a software application developer.

10. A code signing device configured to sign code, the code signing device comprising:

a processor; and

a memory;

wherein the processor is configured to:

create a key pair, the key pair comprising a private key and a public key;

store the private key of the key pair;

deploy the public key of the key pair;

register an entity, wherein an account record for the entity is created, and

wherein credit card information associated with the entity is validated;

receive, at the code signing device, a code signing request from the entity to sign a software application or hash thereof using the private key of the key pair, wherein the private key is associated with a sensitive application programming interface provided on a mobile device, the software application programmed to access the sensitive application programming interface when the software application is run on the mobile device;

digitally sign the software application or hash thereof, wherein a digital signature is generated using the private key; and

return the digital signature in response to the code signing request;

wherein the code signing request comprises a second digital signature associated with the entity, and wherein the processor is configured to successfully verify the second digital signature before digitally signing the software application or hash thereof.

11. The code signing device of claim 10 , wherein the public key is associated with the sensitive application programming interface provided on the mobile device.

12. The code signing device of claim 10 , wherein the processor is configured to retrieve a second public key associated with the entity, and use the second public key to verify the second digital signature associated with the entity.

13. The code signing device of claim 10 , wherein the processor is configured to send an e-mail notification to the entity subsequent to registering the entity.

14. The code signing device of claim 10 , wherein the processor is configured to maintain a record of a number of allowable signing requests for the entity, verify that there are allowable signing requests remaining, and update the number of allowable signing requests, wherein the software application or hash thereof is digitally signed after successfully verifying that there are allowable signing requests remaining.

15. The code signing device of claim 10 , wherein the processor is configured to verify that the entity is registered, wherein the software application or hash thereof is digitally signed after successfully verifying that the entity is registered.

16. The code signing device of claim 10 , wherein the processor is configured to verify that an account of the entity is not expired, wherein the software application or hash thereof is digitally signed after successfully verifying that the account of the entity is not expired.

17. The code signing device of claim 10 , wherein the processor is configured to receive input, in a user interface, to facilitate management of the account record.

18. The code signing device of claim 10 , wherein the entity is a software application developer.

19. A computer-readable device comprising instructions, which when executed by a processor of a code signing device, causes a method of signing code to be performed at the code signing device, the method comprising:

creating a key pair, the key pair comprising a private key and a public key;

storing the private key of the key pair;

deploying the public key of the key pair;

registering an entity, wherein an account record for the entity is created, and wherein credit card information associated with the entity is validated;

receiving, at the code signing device, a code signing request from the entity to sign a software application or hash thereof using the private key of the key pair, wherein the private key is associated with a sensitive application programming interface provided on a mobile device, the software application programmed to access the sensitive application programming interface when the software application is run on the mobile device;

digitally signing the software application or hash thereof, wherein a digital signature is generated using the private key; and returning the digital signature in response to the code signing request;

wherein the code signing request comprises a second digital signature associated with the entity, and wherein the method further comprises successfully verifying the second digital signature before the digitally signing the software application or hash thereof.

20. The computer-readable device of claim 19 , wherein the public key is associated with the sensitive application programming interface provided on the mobile device.

21. The computer-readable device of claim 19 , the method further comprising retrieving a second public key associated with the entity, and using the second public key to verify the second digital signature associated with the entity.

22. The computer-readable device of claim 19 , the method further comprising sending an e-mail notification to the entity subsequent to the registering.

23. The computer-readable device of claim 19 , the method further comprising maintaining a record of a number of allowable signing requests for the entity, verifying that there are allowable signing requests remaining, and updating the number of allowable signing requests, wherein the digitally signing the software application or hash thereof is performed after successfully verifying that there are allowable signing requests remaining.

24. The computer-readable device of claim 19 , the method further comprising verifying that the entity is registered, wherein the digitally signing the software application or hash thereof is performed after successfully verifying that the entity is registered.

25. The computer-readable device of claim 19 , the method further comprising verifying that an account of the entity is not expired, wherein the digitally signing the software application or hash thereof is performed after successfully verifying that the account of the entity is not expired.

26. The computer-readable device of claim 19 , the method further comprising receiving input, in a user interface, to facilitate management of the account record.

27. The computer-readable device of claim 19 , wherein the entity is a software application developer.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064269/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Oct 15, 2013
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 031413/0921 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2010
From: ADAMS, NEIL P.; KIRKUP, MICHAEL G.; LITTLE, HERBERT A.; TAPUSKA, DAVID F.
To: RESEARCH IN MOTION LIMITED
Reel/Frame 024929/0500 →