IP Library Granted Patent US 8,719,565
Granted Patent B2
US 8,719,565 · App. 13/615,046 · Granted May 6, 2014

System and method for processing certificates located in a certificate search

Inventors: Neil Patrick Adams (Waterloo, CA); Herbert Anthony Little (Waterloo, CA); Michael Stephen Brown (Kitchener, CA); Michael Kenneth Brown (Fergus, CA); Michael Grant Kirkup (Waterloo, CA)
Assignee: BlackBerry Limited
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,719,565
App. No.
13/615,046
Granted
May 6, 2014
Kind
B2
Abstract

A system and method for processing certificates located in a certificate search. Certificates located in a certificate search are processed at a data server (e.g. a mobile data server) coupled to a computing device (e.g. a mobile device) to determine status data that can be used to indicate the status of those certificates to a user of the computing device, without having to download those certificates to the computing device in their entirety. The data server is further adapted to transmit the status data to the computing device. In one embodiment, at least one status property of the certificates is verified at the data server in determining the status data. In another embodiment, additional certificate data is determined and transmitted to the computing device, which can be used by the computing device to verify, at the computing device, at least one other status property of the certificates.

Claims (54)

1. A data server comprising a processor and a memory, the processor configured to execute instructions of one or more application modules, the execution of the one or more application modules causing the processor to:

receive a certificate search request from a wireless communication device;

initiate a certificate search on one or more certificate servers, wherein at least one query is submitted to the one or more certificate servers to request retrieval of certificates satisfying the certificate search request;

retrieve one or more certificates from the one or more certificate servers;

for each of the one or more retrieved certificates,

process the certificate prior to transferring the certificate to the wireless communication device to determine data comprising

certificate data identifying the certificate, and status data by determining at least one status property of the certificate;

for at least one of the one or more retrieved certificates,

transmit the certificate data and the status data to the wireless communication device prior to transferring the certificate to the wireless communication device;

wherein the certificate data is usable by the wireless communication device to identify each of the at least one certificate in a user interface of the wireless communication device;

wherein the status data is usable by the wireless communication device to generate at least one status indicator that indicates a result of determining the at least one status property, for each of the at least one certificate located by the data server in response to the certificate search initiated by the wireless communication device, for display in the user interface of the wireless communication device prior to user selection of one or more of the at least one certificate for transfer from the data server to the wireless communication device; and

wherein the processor of the data server receives the certificate search request, initiates the certificate search, and retrieves the one or more certificates from the one or more certificate servers prior to transferring the at least one of the one or more certificates to the wireless communication device.

2. The data server of claim 1 , wherein the at least one status property of each of the one or more retrieved certificates is at least one of certificate validity, revocation status, encryption key strength, or trust status.

3. The data server of claim 1 , wherein for each of the one or more retrieved certificates, the determined status data comprises a plurality of determination results, each associated with one of the at least one status property of the certificate.

4. The data server of claim 1 , wherein for each of the one or more retrieved certificates, the determined status data comprises a single determination result derived from verification results associated with the at least one status property of the certificate.

5. The data server of claim 1 , wherein for each of the at least one certificate for which certificate data and status data determined at the processing is transmitted to the wireless communication device,

the at least one status indicator generated by the wireless communication device for the certificate comprises an icon displayable in a plurality of states.

6. The data server of claim 1 , wherein the execution of the one or more application modules further causes the processor to:

select, prior to the transmitting, the at least one certificate from the one or more retrieved certificates based on the determined status data for each of the one or more certificates.

7. The data server of claim 1 , wherein the execution of the one or more application modules further causes the processor to:

process each of the one or more retrieved certificates to determine, at the data server, additional certificate data usable by the wireless communication device to determine at least one status property of the certificate at the wireless communication device; and

transmit the additional certificate data for the at least one of the one or more certificates to the wireless communication device.

8. The data server of claim 1 , wherein the execution of the one or more application modules further causes the processor to:

receive input from the wireless communication device identifying one or more user-selected certificates of the one or more retrieved certificates; and

transfer the one or more user-selected certificates to the wireless communication device.

9. The data server of claim 1 , wherein the execution of the one or more application modules further causes the processor to:

maintain, on the data server, a copy of the at least one certificate transferred to the wireless communication device.

10. The data server of claim 9 , wherein at least a subset of the at least one certificate transferred to the wireless communication device for which a copy is maintained on the data server has been identified as trusted by a user of the wireless communication device.

11. The data server of claim 9 , wherein the execution of the one or more application modules further causes the processor to:

for each of the at least one certificate transferred to the wireless communication device for which a copy is maintained on the data server,

re-determine the at least one status property of the certificate to determine updated status data for the certificate, and

transmit the updated status data for the certificate to the wireless communication device.

12. The data server of claim 9 , wherein the execution of the one or more application modules further causes the processor to:

for each of the at least one certificate transferred to the wireless communication device for which a copy is maintained on the data server,

maintain a copy of the status data for the certificate.

13. The data server of claim 12 , wherein the execution of the one or more application modules further causes the processor to:

for each of the at least one certificate transferred to the wireless communication device for which a copy is maintained on the data server,

re-determine the at least one status property of the certificate to determine updated status data for the certificate,

compare the updated status data for the certificate to the copy of the status data maintained on the data server for the certificate, and transmit the updated status data for the certificate to the wireless communication device if the updated status data for the certificate differs from the copy of the status data maintained on the data server for the certificate.

14. The data server of claim 1 , wherein the wireless communication device comprises a mobile device.

15. The data server of claim 1 , wherein the data server comprises a mobile data server.

16. The data server of claim 1 , wherein at least one of the one or more certificate servers comprises the data server.

17. A wireless communication device comprising a processor and a memory, the processor configured to execute instructions of one or more application modules, the execution of the one or more application modules causing the processor to:

transmit a certificate search request to a data server;

receive, from the data server, data comprising certificate data identifying a certificate and status data comprising at least one status property of the certificate for one or more certificates retrieved from one or more certificate servers;

the certificate data being usable by the wireless communication device to identify each of the at least one certificate in a user interface of the wireless communication device, and

the status data being usable by the wireless communication device to generate at least one status indicator that indicates a result of determining the at least one status property for display in the user interface of the wireless communication device prior to user selection of one or more of the at least one certificate for transfer from the data server to the wireless communication device; and

receive, from the data server, at least one of the one or more retrieved certificates, wherein a processor of the data server receives the certificate search request, initiates a certificate search, and retrieves the one or more certificates from the one or more certificate servers prior to transferring the at least one of the one or more retrieved certificates to the wireless communication device.

18. The wireless communication device of claim 17 , wherein the execution of the one or more application modules further causes the processor to:

display, in the user interface of the wireless communication device, the received certificate data;

receive input identifying one or more user-selected certificates of the one or more retrieved certificates; and

transmit a certificate request for the one or more user-selected certificates to the data server.

19. The wireless communication device of claim 17 , wherein for each of the at least one certificate for which certificate data and status data is received from the data server, the at least one status indicator generated by the wireless communication device for the certificate comprises an icon displayable in a plurality of states.

20. The wireless communication device of claim 17 , wherein the at least one status property of each of the one or more retrieved certificates is at least one of certificate validity, revocation status, encryption key strength, or trust status.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064269/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Nov 3, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 034150/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2012
From: ADAMS, NEIL P.; LITTLE, HERBERT A.; BROWN, MICHAEL K.; BROWN, MICHAEL S.; KIRKUP, MICHAEL G.
To: RESEARCH IN MOTION LIMITED
Reel/Frame 028958/0335 →
Continuity (2)
Continuation 11417108 · May 4, 2006
Related Publication 20130007446A1 · Jan 3, 2013