IP Library Granted Patent US 11,030,278
Granted Patent B2
US 11,030,278 · App. 16/543,201 · Granted Jun 8, 2021

Code signing system and method

Inventors: David Paul Yach (Waterloo, CA); Herbert Anthony Little (Waterloo, CA); Michael Stephen Brown (Kitchener, CA)
Assignee: BlackBerry Limited
G06F21/10G06F21/121G06F21/51G06F21/629H04L9/321H04L9/3236H04L9/3247H04L63/123H04L63/126H04L63/1483H04W4/60H04L63/067H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,030,278
App. No.
16/543,201
Granted
Jun 8, 2021
Kind
B2
Abstract

A novel code signing system, computer readable media, and method are provided. The code signing method includes receiving a code signing request from a requestor in order to gain access to one or more specific application programming interfaces (APIs). A digital signature is provided to the requestor. The digital signature indicates authorization by a code signing authority for code of the requestor to access the one or more specific APIs. In one example, the digital signature is provided by the code signing authority or a delegate thereof. In another example, the code signing request may include one or more of the following: code, an application, a hash of an application, an abridged version of the application, a transformed version of an application, a command, a command argument, and a library.

Claims (27)

1. A mobile device comprising:

one or more hardware processors enabled to receive a signed application from a software developer, wherein the signed application is signed by a code signing authority, wherein the signed application is to be loaded on the mobile device;

at least one sensitive application programming interface (API), wherein the signed application is authorized to access the at least one sensitive API, and wherein the signed application comprises a digital signature generated by a device external to the mobile device; and

at least one non-sensitive API, wherein access to the at least one sensitive API is further restricted relative to the at least one non-sensitive API.

2. The mobile device of claim 1 , wherein the signed application is signed using a private key.

3. The mobile device of claim 2 , wherein the private key is stored by the code signing authority.

4. The mobile device of claim 1 , wherein the signed application is signed using a hash of a software application, the software application being comprised in code.

5. The mobile device of claim 1 , wherein the signed application is signed using an abridged version of a software application, the software application being comprised in code.

6. The mobile device of claim 1 , wherein the one or more hardware processors enabled are further enabled to verify the digital signature of the signed application using a corresponding public key.

7. The mobile device of claim 6 , wherein the corresponding public key is associated with a manufacturer of the mobile device.

8. A method implemented in a mobile device, the method comprising:

receiving a signed application from a software developer, wherein the signed application is signed by a code signing authority, wherein the signed application is to be loaded on the mobile device,

wherein the mobile device comprises at least one sensitive application programming interface (API), wherein the signed application is authorized to access the at least one sensitive API, wherein the signed application comprises a digital signature generated by a device external to the mobile device, wherein the mobile device further comprises at least one non-sensitive API, and wherein access to the at least one sensitive API is further restricted relative to the at least one non-sensitive API.

9. The method of claim 8 , wherein the signed application is signed using a private key.

10. The method of claim 9 , wherein the private key is stored by the code signing authority.

11. The method of claim 8 , wherein the signed application is signed using a hash of a software application, the software application being comprised in code.

12. The method of claim 8 , wherein the signed application is signed using an abridged version of a software application, the software application being comprised in code.

13. The method of claim 8 , further comprising verifying the digital signature of the signed application using a corresponding public key.

14. The method of claim 13 , wherein the corresponding public key is associated with a manufacturer of the mobile device.

15. A non-transitory computer readable medium storing instructions that when executed by one or more processors of a mobile device, cause the one or more processors to implement a method comprising:

receiving a signed application from a software developer, wherein the signed application is signed by a code signing authority, wherein the signed application is to be loaded on the mobile device,

wherein the mobile device comprises at least one sensitive application programming interface (API), wherein the signed application is authorized to access the at least one sensitive API, wherein the signed application comprises a digital signature generated by a device external to the mobile device, wherein the mobile device further comprises at least one non-sensitive API, and wherein access to the at least one sensitive API is further restricted relative to the at least one non-sensitive API.

16. The non-transitory computer readable medium of claim 15 , wherein the signed application is signed using a private key.

17. The non-transitory computer readable medium of claim 16 , wherein the private key is stored by the code signing authority.

18. The non-transitory computer readable medium of claim 15 , wherein the signed application is signed using a hash of a software application, the software application being comprised in code.

19. The non-transitory computer readable medium of claim 15 , wherein the signed application is signed using an abridged version of a software application, the software application being comprised in code.

20. The non-transitory computer readable medium of claim 15 , wherein the method further comprises verifying the digital signature of the signed application using a corresponding public key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2019
From: YACH, DAVID P.; BROWN, MICHAEL S.; LITTLE, HERBERT A.
To: RESEARCH IN MOTION LIMITED
Reel/Frame 050946/0313 →
CHANGE OF NAME Recorded Nov 7, 2019
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 050950/0012 →
Continuity (10)
Continuation 16037412 · Jul 17, 2018
Continuation 15925284 · Mar 19, 2018
Continuation 15361993 · Nov 28, 2016
Continuation 14459785 · Aug 14, 2014
Continuation 13754162 · Jan 30, 2013
Continuation 10381219
Provisional Application 60270663 · Feb 20, 2001
Provisional Application 60235354 · Sep 26, 2000
Provisional Application 60234152 · Sep 21, 2000
Related Publication 20190392115A1 · Dec 26, 2019