IP Library › Granted Patent US 12,341,905
Granted Patent B2
US 12,341,905 · App. 18/485,044 · Granted Jun 24, 2025

Method and system for providing data security for micro-services across domains

Inventors: Biswaroop Mukherjee (Stittsville, CA); Geordon Thomas Ferguson (Mississauga, CA); Roger Paul Bowman (Kitchener, CA)
Assignee: BlackBerry Limited
H04L9/3247H04L9/0825H04L9/3213H04L63/0823H04L67/10H04L67/12H04L67/63H04W4/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,905
App. No.
18/485,044
Granted
Jun 24, 2025
Kind
B2
Abstract

A method at a network element for securely sharing services across domains, the method including receiving a request at the network element to add a first domain and an edge domain to a system; provisioning a public key of the network element to the first domain and the edge domain; receiving a public key of the first domain; populating, in the network element, a table with services provided by the first domain or the edge domain; populating, in the network element, a second table with applications installed at the first domain or edge domain and permissions for services for the applications; and controlling access to the services by the applications.

Claims (54)

1. A method at a network element for securely sharing services across domains, the method comprising:

receiving a request at the network element to add a first domain and an edge domain to a system;

populating, in the network element, a table with services, the services being provided by the first domain or the edge domain;

populating, in the network element, a second table with applications installed at the first domain or edge domain and permissions corresponding to a subset of the services; and

controlling access to the services by the applications based on the permissions.

2. The method of claim 1 , wherein the controlling access comprises:

receiving a request from an application on the first domain, the request being signed by the first domain;

verifying the request; and

based on the verifying and based on the permissions for the application, providing at least one token for a service back to the first domain, the at least one token including an identifier for the service and a signature of the network element.

3. The method of claim 2 , wherein the token further includes an expiration time.

4. The method of claim 1 , wherein the controlling access comprises:

receiving a request from a domain bridge on the first domain, the request being signed by the first domain and including an application identifier;

verifying the request; and

based on the verifying and based on the permissions for an application associated with the application identifier, providing at least one token for a service back to the domain bridge, the at least one token including an identifier for the service and a signature of the network element.

5. The method of claim 1 , wherein the controlling access comprises:

receiving a request from the first domain to synchronize the second table; and

providing the second table to the first domain.

6. The method of claim 1 , wherein the table with services further includes delegation of permissions for at least one of the services.

7. The method of claim 1 , wherein the first domain and the edge domain belong to a vehicle, and wherein the network element is a fleet manager.

8. A network element for securely sharing services across domains, the network element comprising:

a processor; and

a communications subsystem,

wherein the network element is configured to:

receive a request at the network element to add a first domain and an edge domain to a system;

populate, in the network element, a table with services, the services being provided by the first domain or the edge domain;

populate, in the network element, a second table with applications installed at the first domain or edge domain and permissions corresponding to a subset of the services; and

control access to the services by the applications based on the permissions.

9. The network element of claim 8 , wherein the network element is configured to control access by:

receiving a request from an application on the first domain, the request being signed by the first domain;

verifying the request; and

based on the verifying and based on the permissions for the application, providing at least one token for a service back to the first domain, the at least one token including an identifier for the service and a signature of the network element.

10. The network element of claim 9 , wherein the token further includes an expiration time.

11. The network element of claim 8 , wherein the network element is configured to control access by:

receiving a request from a domain bridge on the first domain, the request being signed by the first domain and including an application identifier;

verifying the request; and

based on the verifying and based on the permissions for an application associated with the application identifier, providing at least one token for a service back to the domain bridge, the at least one token including an identifier for the service and a signature of the network element.

12. The network element of claim 8 , wherein the network element is configured to control access by:

receiving a request from the first domain to synchronize the second table; and

providing the second table to the first domain.

13. The network element of claim 8 , wherein the table with services further includes delegation of permissions for at least one of the services.

14. The network element of claim 8 , wherein the network element is configured to provision during manufacture of a computing device with the first domain and the edge domain.

15. The network element of claim 8 , wherein the network element is configured to provision when a computing device with the first domain and the edge domain is at a trusted service center.

16. The network element of claim 8 , wherein the first domain and the edge domain belong to a vehicle, and wherein the network element is a fleet manager.

17. A non-transitory computer readable medium for storing instruction code, which, when executed by a processor of a network element configured for securely sharing services across domains cause the network element to:

receive a request at the network element to add a first domain and an edge domain to a system;

provision a public key of the network element to the first domain and the edge domain;

receive a public key of the first domain;

populate, in the network element, a table with services, the services being provided by the first domain or the edge domain;

populate, in the network element, a second table with applications installed at the first domain or edge domain and permissions corresponding to a subset of the services; and

control access to the services by the applications based on the permissions.

18. The computer readable medium of claim 17 , wherein the instruction code further causes the network element to control access by:

receiving a request from an application on the first domain, the request being signed by the first domain;

verifying the request; and

based on the verifying and based on the permissions for services for the application, providing at least one token for a service back to the first domain, the at least one token including an identifier for the service and a signature of the network element.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2023
From: MUKHERJEE, BISWAROOP; FERGUSON, GEORDON THOMAS; BOWMAN, ROGER PAUL
To: BLACKBERRY LIMITED
Reel/Frame 065313/0891 →
Continuity (2)
Continuation 17384103 · Jul 23, 2021
Related Publication 20240056311A1 · Feb 15, 2024
References Cited (54)
US 8423651B1 · Grieve et al. · 2013 [cited by applicant]
US 8452881B2 · Boubez et al. · 2013 [cited by applicant]
US 9191391B1 · Stillerman · 2015 [cited by applicant]
US 9445270B1 · Bicket · 2016 [cited by applicant]
US 9819673B1 · Johansson · 2017 [cited by applicant]
US 9959415B1 · Rodriguez et al. · 2018 [cited by applicant]
US 9973625B1 · Voorhees · 2018 [cited by applicant]
US 10382203B1 · Loladia · 2019 [cited by examiner]
US 11108779B2 · Meriac · 2021 [cited by applicant]
US 11231862B1 · Vig · 2022 [cited by examiner]
US 11601348B2 · Gupta · 2023 [cited by applicant]
US 11968310B2 · Mukherjee · 2024 [cited by examiner]
US 12013957B2 · Mukherjee · 2024 [cited by examiner]
US 20130016605A1 · Chen · 2013 [cited by examiner]
US 20140067758A1 · Boldyrev et al. · 2014 [cited by applicant]
US 20150143467A1 · Hebert et al. · 2015 [cited by applicant]
US 20150326529A1 · Morita · 2015 [cited by examiner]
US 20160127514A1 · Maksumov · 2016 [cited by examiner]
US 20160165651A1 · Pathuri · 2016 [cited by examiner]
US 20160277191A1 · Lee · 2016 [cited by applicant]
US 20160277927A1 · Lee · 2016 [cited by examiner]
US 20170093866A1 · Ben-Noon · 2017 [cited by examiner]
US 20170195331A1 · Wu et al. · 2017 [cited by applicant]
US 20190132362A1 · Hutchinson et al. · 2019 [cited by applicant]
US 20190166635A1 · McColgan · 2019 [cited by examiner]
US 20190386957A1 · Leon · 2019 [cited by applicant]
US 20210082210A1 · Sakr · 2021 [cited by applicant]
US 20210092018A1 · Fang et al. · 2021 [cited by applicant]
US 20210144517A1 · Guim Bernat et al. · 2021 [cited by applicant]
US 20210209494A1 · Mukherjee et al. · 2021 [cited by applicant]
US 20210302941A1 · Francis et al. · 2021 [cited by applicant]
US 20210350021A1 · Wang et al. · 2021 [cited by applicant]
US 20220006800A1 · Duchastel · 2022 [cited by applicant]
US 20220043924A1 · Hu et al. · 2022 [cited by applicant]
US 20240223363A1 · Mukherjee · 2024 [cited by examiner]
KR 102172287B1 · 2020 [cited by applicant]
WO 2014169381A1 · 2014 [cited by applicant]
WO 2020168207A1 · 2020 [cited by applicant]
International Search Report, PCT/CA2022/051103, dated Oct. 21, 2022, pp. 1-3. [cited by applicant]
Written Opinion of the International Searching Authority, PCT/CA2022/051103, dated Oct. 21, 2022, pp. 1-5. [cited by applicant]
United States Patent and Trademark Office (USPTO) Office Action for U.S. Appl. No. 17/384,165 dated Oct. 21, 2022, 28 pages. [cited by applicant]
United States Patent and Trademark Office (USPTO) Office Action for U.S. Appl. No. 17/384,165 dated Feb. 3, 2023, 10 pages. [cited by applicant]
United States Patent and Trademark Office (USPTO) Notice of Allowance and Fee(s) Due for U.S. Appl. No. 17/384,165 dated Oct. 25, 2023, 8 pages. [cited by applicant]
Canadian Intellectual Property Office (CIPO) Patent Cooperation Treaty (PCT) International Search Report and Written Opinion of the International Searching Authority for International Application No. PCT/CA2022/051104 d… [cited by applicant]
United States Patent and Trademark Office (USPTO) Office Action for U.S. Appl. No. 17/384,140 dated Apr. 20, 2023, 29 pages. [cited by applicant]
United States Patent and Trademark Office (USPTO) Office Action for U.S. Appl. No. 17/384,140 dated Oct. 13, 2023, 24 pages. [cited by applicant]
Canadian Intellectual Property Office (CIPO) Patent Cooperation Treaty (PCT) International Search Report and Written Opinion of the International Searching Authority for International Application No. PCT/CA2022/051105 d… [cited by applicant]
Bandur et al., “A Domain-Centralized Automotive Powertrain E/E Architecture”, Conference Paper Apr. 2021, 11 pages. [cited by applicant]
Esen et al., “Control as a Service (CaaS)”, SWEC'15: Proceedings of the Second International Workshop on the Swarm at the Edge of the Cloud, Apr. 2015, pp. 13-18 (6 pages). [cited by applicant]
United States Patent and Trademark Office (USPTO) Office Action for U.S. Appl. No. 17/384,165 dated Mar. 20, 2023, 5 pages. [cited by applicant]
United States Patent and Trademark Office (USPTO) Office Action for U.S. Appl. No. 17/384,165 dated Jul. 17, 2023, 26 pages. [cited by applicant]
European Patent Office (EPO): Extended European Search Report (EESR) for Application No. 22844766.0, dated: Apr. 11, 2025, 7 pages. [cited by applicant]
European Patent Office (EPO): Extended European Search Report (EESR) for Application No. 22844767.8, dated: Apr. 29, 2025, 10 pages. [cited by applicant]
Laput et al., “Synthetic Sensors: Towards General-Purpose Sensing”, CHI '17: Proceedings of the 2017 CHI Conference on Human Factors in Computing Systems, date: May 2, 2017, pp. 3986-3999, XP058337840. [cited by applicant]