IP Library › Granted Patent US 12,488,081
Granted Patent B2
US 12,488,081 · App. 18/494,504 · Granted Dec 2, 2025

Communicating credentials between two operating systems

Inventor: Roberto Speranza (Woodbridge, CA)
Assignee: BlackBerry Limited
G06F21/33
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,488,081
App. No.
18/494,504
Granted
Dec 2, 2025
Kind
B2
Abstract

Systems, methods, and software can be used to provide credentials for a provisioning operation. In some aspects, a method includes: generating, by a first operating system (OS), a first transfer key; sending, from the first OS to a second OS, a random salt by using the first transfer key; generating, by the first OS, a second transfer key by using the random salt; and sending, from the first OS to the second OS, provisioning credentials by using the second transfer key.

Claims (40)

1 . A method, comprising:

generating, by a first operating system (OS), a first transfer key;

sending, from the first OS to a second OS, a random salt by using the first transfer key;

generating, by the first OS, a second transfer key by using the random salt;

receiving, by the first OS, a first response from the second OS, wherein the first response comprises data, wherein the data comprises a bitmask, each bit of the bitmask indicates whether a corresponding byte comprises data or filler;

determining, by the first OS, that the data in the first response matches the random salt; and

sending, from the first OS to the second OS, provisioning credentials by using the second transfer key.

2 . The method of claim 1 , wherein the provisioning credentials comprise at least one of a private key of a certificate authority (CA), or a certificate of the CA.

3 . The method of claim 1 , wherein the data comprises an indicator indicating one of a sequential order or a reverse sequential order.

4 . The method of claim 1 , wherein whether the data matches the random salt is determined by performing a hashing function on the random salt to generate a hash result, and determining whether the hash result matches the data.

5 . The method of claim 1 , wherein the first OS and the second OS run on a same device, and the first OS and the second OS perform a multiple Transport Layer Security (mTLS) process.

6 . The method of claim 1 , wherein the provisioning credentials comprise at least one of an entity private key or an entity public key.

7 . The method of claim 1 , wherein the provisioning credentials comprise at least one of an entity certificate or an key encryption key.

8 . A non-transitory computer-readable medium containing instructions which, when executed, cause an electronic device to perform operations comprising:

generating, by a first operating system (OS), a first transfer key;

sending, from the first OS to a second OS, a random salt by using the first transfer key;

generating, by the first OS, a second transfer key by using the random salt;

receiving, by the first OS, a first response from the second OS, wherein the first response comprises data, wherein the data comprises a bitmask, each bit of the bitmask indicates whether a corresponding byte comprises data or filler;

determining, by the first OS, that the data in the first response matches the random salt; and

sending, from the first OS to the second OS, provisioning credentials by using the second transfer key.

9 . The computer-readable medium of claim 8 , wherein the provisioning credentials comprise at least one of a private key of a certificate authority (CA), or a certificate of the CA.

10 . The computer-readable medium of claim 8 , wherein the data comprises an indicator indicating one of a sequential order or a reverse sequential order.

11 . The computer-readable medium of claim 8 , wherein whether the data matches the random salt is determined by performing a hashing function on the random salt to generate a hash result, and determining whether the hash result matches the data.

12 . The computer-readable medium of claim 8 , wherein the first OS and the second OS run on a same device, and the first OS and the second OS perform a multiple Transport Layer Security (mTLS) process.

13 . The computer-readable medium of claim 8 , wherein the provisioning credentials comprise at least one of an entity private key or an entity public key.

14 . A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

generating, by a first operating system (OS), a first transfer key;

sending, from the first OS to a second OS, a random salt by using the first transfer key;

generating, by the first OS, a second transfer key by using the random salt;

receiving, by the first OS, a first response from the second OS, wherein the first response comprises data, wherein the data comprises an indicator indicating one of a sequential order or a reverse sequential order;

determining, by the first OS, that the data in the first response matches the random salt; and

sending, from the first OS to the second OS, provisioning credentials by using the second transfer key.

15 . The computer-implemented system of claim 14 , wherein the provisioning credentials comprise at least one of a private key of a certificate authority (CA), or a certificate of the CA.

16 . The computer-implemented system of claim 14 , wherein the data comprises a bitmask, each bit of the bitmask indicates whether a corresponding byte comprises data or filler.

17 . The computer-implemented system of claim 15 , wherein whether the data matches the random salt is determined by performing a hashing function on the random salt to generate a hash result, and determining whether the hash result matches the data.

18 . The computer-implemented system of claim 14 , wherein the first OS and the second OS run on a same device, and the first OS and the second OS perform a multiple Transport Layer Security (mTLS) process.

19 . The computer-implemented system of claim 14 , wherein the provisioning credentials comprise at least one of an entity private key or an entity public key.

20 . The computer-implemented system of claim 14 , wherein the provisioning credentials comprise at least one of an entity certificate or an key encryption key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2023
From: SPERANZA, ROBERTO
To: BLACKBERRY LIMITED
Reel/Frame 065384/0721 →
Continuity (1)
Related Publication 20250139217A1 · May 1, 2025
References Cited (16)
US 7702906B1 · Karr · 2010 [cited by examiner]
US 10691837B1 · Martel · 2020 [cited by examiner]
US 20050097362A1 · Winget · 2005 [cited by examiner]
US 20100153749A1 · Sakai · 2010 [cited by examiner]
US 20190065747A1 · Gomes de Oliveira · 2019 [cited by examiner]
US 20190102555A1 · Novak · 2019 [cited by examiner]
US 20190123905A1 · Kirner · 2019 [cited by examiner]
US 20210119800A1 · Jung · 2021 [cited by examiner]
US 20230098097A1 · Vaid et al. · 2023 [cited by applicant]
US 20230130256A1 · Savage · 2023 [cited by examiner]
US 20230177146A1 · Dastidar et al. · 2023 [cited by applicant]
WO WO2009044461 · 2009 [cited by applicant]
WO WO2023107233 · 2023 [cited by applicant]
Extended European Search Report in European Appln. No. 24208822.7, mailed on Apr. 3, 2025, 8 pages. [cited by applicant]
Menezes et al., “Chapter 12: Key Establishment Protocols Ed” Handbook of applied cryptography, CRC press, Oct. 1996, 489-541. [cited by applicant]
Office Action in Japanese Appln. No. 2024-160678, mailed on Sep. 10, 2025, 5 pages (with English machine translation). [cited by applicant]