IP Library › Granted Patent US 10,149,166
Granted Patent B2
US 10,149,166 · App. 14/995,932 · Granted Dec 4, 2018

Verifying a certificate

Inventors: Elliott Michael Guy Mazzuca (Etobicoke, CA); Chang Fung Yang (Mississauga, CA); Jason Songbo Xu (Toronto, CA); Chi Chiu Tse (Markham, CA)
Assignee: BlackBerry Limited
H04W12/08H04L9/3268H04L63/0272H04L63/0823H04L63/101H04L2209/80H04W12/06H04W88/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,149,166
App. No.
14/995,932
Granted
Dec 4, 2018
Kind
B2
Abstract

Systems, methods, and software can be used to verify a certificate. In some aspects, a request to connect to a Virtual Private Network (VPN) server is received from an application on a mobile device. A certificate of the VPN server is obtained at the mobile device. A device-level certificate verification for the certificate is performed. Whether an application-level certificate verification is provisioned for the application is determined. In response to determining that the application-level certification verification is provisioned, the application-level certificate verification for the certificate is performed. In response to verifying that the certificate passes the application-level certificate verification, the mobile device is connected to the VPN server.

Claims (40)

1. A method, comprising:

receiving, from an application on a mobile device, a request to connect to a Virtual Private Network (VPN) server;

obtaining, at the mobile device, a certificate of the VPN server;

performing, at the mobile device, a device-level certificate verification based on the certificate according to a device-level security policy;

in response to the device-level certificate verification being successful, determining, at the mobile device, whether an application-level certificate verification for the certificate of the VPN server is provisioned for the application;

in response to determining that the application-level certification verification is provisioned, performing, at the mobile device, the application-level certificate verification based on the certificate of the VPN server according to an application-level security policy associated with the application, wherein the application-level security policy is different than the device-level security policy; and

in response to verifying that the certificate passes the application-level certificate verification, connecting to the VPN server.

2. The method of claim 1 , wherein whether the application-level certificate verification is provisioned is determined based on a VPN profile associated with the application.

3. The method of claim 2 , wherein the VPN profile is stored at the mobile device prior to receiving the request to connect to the VPN server.

4. The method of claim 2 , wherein the VPN profile is sent to the mobile device from an enterprise server prior to receiving the request to connect to the VPN server.

5. The method of claim 2 , wherein the application-level certificate verification is performed by executing an extension specified by the VPN profile.

6. The method of claim 5 , wherein the extension is sent to the mobile device from an enterprise server prior to receiving the request to connect to the VPN server.

7. The method of claim 1 , wherein the application-level certificate verification is based on a black list of certificate authorities (CAs).

8. A mobile device, comprising:

a memory; and

at least one hardware processor communicatively coupled with the memory and configured to:

receive, from an application on the mobile device, a request to connect to a Virtual Private Network (VPN) server;

obtain, at the mobile device, a certificate of the VPN server;

perform, at the mobile device, a device-level certificate verification based on the certificate according to a device-level security policy;

in response to the device-level certificate verification being successful, determine, at the mobile device, whether an application-level certificate verification for the certificate of the VPN server is provisioned for the application;

in response to determining that the application-level certification verification is provisioned, perform, at the mobile device, the application-level certificate verification based on the certificate of the VPN server according to an application-level security policy associated with the application, wherein the application-level security policy is different than the device-level security policy; and

in response to verifying that the certificate passes the application-level certificate verification, connect to the VPN server.

9. The mobile device of claim 8 , wherein whether the application-level certificate verification is provisioned is determined based on a VPN profile associated with the application.

10. The mobile device of claim 9 , wherein the VPN profile is stored at the mobile device prior to receiving the request to connect to the VPN server.

11. The mobile device of claim 9 , wherein the VPN profile is sent to the mobile device from an enterprise server prior to receiving the request to connect to the VPN server.

12. The mobile device of claim 9 , wherein the application-level certificate verification is performed by executing an extension specified by the VPN profile.

13. The mobile device of claim 12 , wherein the extension is sent to the mobile device from an enterprise server prior to receiving the request to connect to the VPN server.

14. The mobile device of claim 8 , wherein the application-level certificate verification is based on a black list of certificate authorities (CAs).

15. A non-transitory computer-readable medium containing instructions which, when executed, cause a computing device to perform operations comprising:

receiving, from an application on a mobile device, a request to connect to a Virtual Private Network (VPN) server;

obtaining, at the mobile device, a certificate of the VPN server;

performing, at the mobile device, a device-level certificate verification based on the certificate according to a device-level security policy;

in response to the device-level certificate verification being successful, determining, at the mobile device, whether an application-level certificate verification for the certificate of the VPN server is provisioned for the application;

in response to determining that the application-level certification verification is provisioned, performing, at the mobile device, the application-level certificate verification based on the certificate of the VPN server according to an application-level security policy associated with the application, wherein the application-level security policy is different than the device-level security policy; and

in response to verifying that the certificate passes the application-level certificate verification, connecting to the VPN server.

16. The non-transitory computer-readable medium of claim 15 , wherein whether the application-level certificate verification is provisioned is determined based on a VPN profile associated with the application.

17. The non-transitory computer-readable medium of claim 16 , wherein the VPN profile is stored at the mobile device prior to receiving the request to connect to the VPN server.

18. The non-transitory computer-readable medium of claim 16 , wherein the VPN profile is sent to the mobile device from an enterprise server prior to receiving the request to connect to the VPN server.

19. The non-transitory computer-readable medium of claim 16 , wherein the application-level certificate verification is performed by executing an extension specified by the VPN profile.

20. The non-transitory computer-readable medium of claim 19 , wherein the extension is sent to the mobile device from an enterprise server prior to receiving the request to connect to the VPN server.

Assignments (3)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2016
From: MAZZUCA, ELLIOTT MICHAEL GUY; YANG, CHANG FUNG; XU, JASON SONGBO; TSE, CHI CHIU
To: BLACKBERRY LIMITED
Reel/Frame 037811/0698 →
Continuity (1)
Related Publication 20170208469A1 · Jul 20, 2017
Cited By (2)
US 12,254,318 US 12,316,623