IP Library Granted Patent US 8,955,084
Granted Patent B2
US 8,955,084 · App. 13/293,634 · Granted Feb 10, 2015

Timestamp-based token revocation

Inventors: Tu Dien Do (Waterloo, CA); Scott Peter Gammon (Waterloo, CA); John Andrew McGregor (Ottawa, CA)
Assignee: BlackBerry Limited
G06F21/33H04L9/3213H04L9/3294H04L63/0823H04L63/0807G06F2221/2137G06F2221/2151H04L67/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,955,084
App. No.
13/293,634
Granted
Feb 10, 2015
Kind
B2
Abstract

A token used when a first device authenticates itself to a third device may be associated with a token issue timestamp. Upon receipt of an indication that all previously issued tokens are to be revoked, a second device may store a revocation timestamp. Upon receiving, from the second device, a request for establishing conditions for a file transfer, from the first device, and an indication of a token issue timestamp associated with the request, the second device may compare the token issue timestamp to the revocation timestamp. Responsive to determining, based on the comparing, that the token issue timestamp precedes the revocation timestamp, the second device may deny the request.

Claims (40)

1. A method of handling a communication request representative of an invitation to allow, at a target device, interaction between an origin device and the target device, the method referencing a generated token that has been generated by a server device in response to a token request from the origin device, the generated token having been transmitted from the server device to the origin device, the method including:

receiving, at a processor, an indication of a token revocation command event, the token revocation command event resulting from interaction with an application executed on the target device;

responsive to the receiving the indication, storing, in a memory, a revocation timestamp, the revocation timestamp being indicative of a time of occurrence for the token revocation command event;

receiving, at a communication subsystem and from the server device, the communication request accompanied by an indication of a token issue timestamp for the generated token, wherein the communication request originates from the origin device and is transmitted to the server device with a received token, which has been verified, at the server device, as being the same as the generated token; and

in response to determining, at the processor, that the token issue timestamp temporally precedes the revocation timestamp, denying the communication request.

2. The method of claim 1 wherein the denying the communication request comprises transmitting, to the server device, an indication that the token issue timestamp precedes the revocation timestamp.

3. The method of claim 1 wherein the communication request relates to a transfer of a file to the target device.

4. The method of claim 1 wherein the communication request relates to streaming video to the target device.

5. The method of claim 1 wherein the communication request relates to streaming audio to the target device.

6. The method of claim 1 wherein the communication request relates to streaming text to the target device.

7. The method of claim 1 wherein the communication request relates to video conferencing.

8. The method of claim 1 wherein the communication request relates to instant messaging.

9. The method of claim 1 wherein the communication request relates to receiving media from the target device.

10. The method of claim 9 wherein the media comprises audio.

11. The method of claim 9 wherein the media comprises video.

12. The method of claim 9 wherein the media comprises text.

13. A target device comprising:

a processor adapted to:

execute an application;

receive an indication of a token revocation command event, the token revocation command event resulting from interaction with the application;

store a revocation timestamp, the revocation timestamp being indicative of a time of occurrence for the token revocation command event;

receive a communication request from a server device, the communication request representative of an invitation to allow, at the target device, interaction between an origin device and the target device, the communication request referencing a generated token that has been generated by a server device in response to a token request from the origin device, the generated token having been transmitted from the server device to the origin device, the communication request accompanied by an indication of a token issue timestamp for the generated token, wherein the communication request originates from the origin device and is transmitted to the server device with a received token, which has been verified, at the server device, as being the same as the generated token; and

in response to determining that the token issue timestamp temporally precedes the revocation timestamp, deny the communication request.

14. A non-transitory computer readable device containing computer-executable instructions that,

when performed by a processor, cause the processor to:

execute an application;

receive an indication of a token revocation command event, the token revocation command event resulting from interaction with the application;

store a revocation timestamp, the revocation timestamp being indicative of a time of occurrence for the token revocation command event;

receive a communication request from a server device, the communication request representative of an invitation to allow, at the target device, interaction between an origin device; and the target device, the communication request referencing a generated token that has been generated by a server device in response to a token request from the origin device, the generated token having been transmitted from the server device to the origin device, the communication request accompanied by an indication of a token issue timestamp for the generated token, wherein the communication request originates from the origin device and is transmitted to the server device with a received token, which has been verified, at the server device, as being the same as the generated token; and

in response to determining that the token issue timestamp temporally precedes the revocation timestamp, deny the communication request.

15. A method of handling a communication request representative of an invitation to allow, at a target device, interaction between an origin device and the target device, the method referencing a generated token that has been generated by a server device in response to a token request from the origin device, the generated token having been transmitted from the server device to the origin device, the method including:

receiving, at a processor, an indication of a token revocation command event, the token revocation command event resulting from interaction with an application executed on the target device;

responsive to the receiving the indication, storing, in a memory, a revocation timestamp, the revocation timestamp being indicative of a time of occurrence for the token revocation command event;

receiving, at a communication subsystem and from the server device, the communication request accompanied by an indication of a token issue timestamp for the generated token, wherein the communication request originates from the origin device and is transmitted to the server device with a received token, which has been verified, at the server device, as being the same as the generated token; and

in response to determining, at the processor, that the revocation timestamp temporally precedes the token issue timestamp, allowing the communication request.

16. A method of handling a communication request representative of an invitation to allow, at a target device, interaction between an origin device and the target device, the method referencing a generated second token that has been generated by a server device in response to a token request from the origin device, the generated second token having been transmitted from the server device to the origin device, the method including:

receiving, at a processor, an indication of a token revocation command event for a first token, the token revocation command event resulting from interaction with an application executed on the target device;

responsive to the receiving the indication, storing, in a memory, a revocation timestamp for the first token, the revocation timestamp being indicative of a time of occurrence for the token revocation command event;

receiving, at a communication subsystem and from the server device, the communication request accompanied by an indication of a token issue timestamp for the generated second token, wherein the communication request originates from the origin device and is transmitted to the server device with a received second token, which has been verified, at the server device, as being the same as the generated second token; and

in response to determining, at the processor, that a revocation timestamp for the generated second token has not been stored by the target device, allowing the communication request.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2015
From: MCGREGOR, JOHN ANDREW; GAMMON, SCOTT PETER; DO, TU DIEN
To: RESEARCH IN MOTION LIMITED
Reel/Frame 034610/0865 →
CHANGE OF NAME Recorded Dec 22, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 034688/0899 →
Continuity (1)
Related Publication 20130125228A1 · May 16, 2013