IP Library Granted Patent US 9,363,669
Granted Patent B2
US 9,363,669 · App. 13/861,510 · Granted Jun 7, 2016

Methods and systems for server-initiated activation of device for operation with server

Inventors: Alexander Truskovsky (Waterloo, CA); Daryl Joseph Martin (Kitchener, CA)
Assignee: BlackBerry Limited
H04W12/06H04L63/0823H04L67/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,363,669
App. No.
13/861,510
Granted
Jun 7, 2016
Kind
B2
Abstract

Methods and systems for enabling activation of a wireless communication device to operate with a server on a wireless communication network. An activation request is pushed from the server to the device, the activation request being authenticated with a signature signed with a server certificate. After the device verifies the activation request using server certificate and signature, a mutually authenticated communication session is established between the device and the server for activation of the device on the server.

Claims (54)

1. A method for enabling activation of a wireless communication device to operate with a server on a wireless communication network, the method comprising:

in absence of any activation request sent from the device, receiving, at the device, an activation request from the server, the activation request being authenticated with a signature signed with a server certificate, the server certificate including server identity information;

verifying, by the device, the activation request by verifying the server identity information and the signature;

receiving pre-setting instructions from the server;

pre-setting the device in accordance with the received pre-setting instructions from the server, pre-settings made on the device being inactive until after receiving the input to accept the activation request;

only after receiving input to accept the activation request, establishing a mutually authenticated communication session between the device and the server for activation of the device on the server, the mutually authenticated communication session being authenticated by a device certificate from the device and the same or different server certificate; and

removing the pre-settings made on the device after receiving an input to reject the activation request.

2. The method of claim 1 , wherein pre-setting the device comprises at least one of:

pre-setting a security perimeter governing usage of one or more resources on the device;

pre-installing an application on the device; and

pre-setting personal information management (PIM) on the device.

3. The method of claim 1 , further comprising:

at a first-time communication with the wireless communication network, receiving the device certificate from a certificate authority, the device certificate including device identity information and device authentication information.

4. The method of claim 1 , wherein the server certificate also includes server authentication information, and the same server certificate is used to establish the mutually authenticated communication session.

5. A wireless communication device configurable to operate with a server on a communication network, the device comprising a processor configured to execute instructions to cause the device to:

in absence of any activation request sent from the device, receive an activation request from the server, the activation request being authenticated with a signature signed by a server certificate, the server certificate including server identity information;

verify activation request by verifying the server identity information and the signature;

receive pre-setting instructions from the server;

pre-set the device in accordance with the received pre-setting instructions from the server, pre-settings made on the device being inactive until after receiving the input to accept the activation request;

only after receiving input to accept the activation request, establish a mutually authenticated communication session between the device and the server for activation of the device on the server, the mutually authenticated communication session being authenticated by a device certificate and the same or different server certificate; and

remove the pre-settings made on the device after receiving an input to reject the activation request.

6. The device of claim 5 , wherein pre-setting the device comprises at least one of:

pre-setting a security perimeter governing usage of one or more resources on the device;

pre-installing an application on the device; and

pre-setting personal information management (PIM) on the device.

7. The device of claim 5 , wherein the device certificate is received from a certificate authority at a first-time communication with the communication network, the device certificate including device identity information and device authentication information.

8. The device of claim 5 , wherein the server certificate also includes server authentication information, and the same server certificate is used to establish the mutually authenticated communication session.

9. A method for enabling activation of a wireless communication device to operate with a server on a wireless communication network, the method comprising:

in absence of any activation request sent from the device, pushing, by the server, an activation request to the device, the activation request being authenticated by a signature signed by a server certificate, the server certificate including server identity information;

pushing pre-setting instructions to the device, the pre-setting instructions causing pre-setting of the device, pre-settings made on the device being inactive until the activation request is accepted, the pre-setting instructions cause removal of any pre-settings made on the device after the device receives an input to reject the activation request; and

after receiving from the device an indication to proceed with activation, establishing a mutually authenticated communication session between the server and the device for activation of the device on the server, the mutually authenticated communication session being authenticated by a device certificate from the device and the same or different server certificate.

10. The method of claim 9 , wherein the pre-settings instructions cause pre-setting of the device including at least one of:

pre-setting a security perimeter governing usage of one or more resources on the device;

pre-installing an application on the device; and

pre-setting personal information management (PIM) on the device.

11. The method of claim 9 , wherein establishing the mutually authenticated communication session comprises verifying identity of the device using the device certificate.

12. The method of claim 9 , wherein the server certificate also includes server authentication information, and the same server certificate is used to establish the mutually authenticated communication session.

13. The method of claim 9 , wherein a different server authentication certificate including server authentication information is used to establish the mutually authenticated communication session.

14. The method of claim 9 , wherein the server certificate is received from a certificate authority, when the server first registers with the wireless communication network.

15. A server configurable to enable activation of a wireless communication device to operate with the server, the server comprising a processor configured to execute instructions to cause the server to:

in absence of any activation request sent from the device, push, by the server, an activation request to the device, the activation request being authenticated by a signature signed by a server certificate, the server certificate including server identity information;

push pre-setting instructions to the device, the pre-setting instructions causing pre-setting of the device, pre-settings made on the device being inactive until the activation request is accepted, the pre-setting instructions cause removal of any pre-settings made on the device after the device receives an input to reject the activation request; and

after receiving from the device an indication to proceed with activation, establish a mutually authenticated communication session between the server and the device for activation of the device on the server, the mutually authenticated communication session being authenticated by a device certificate from the device and the same or different server certificate.

16. A non-transitory machine readable medium having tangibly stored thereon executable instructions for execution by a processor of a wireless communication device configurable to operate with a server on a communication network that, when executed by the processor, cause the wireless communication device to:

in absence of any activation request sent from the device, receive an activation request from the server, the activation request being authenticated with a signature signed by a server certificate, the server certificate including server identity information;

verify activation request by verifying the server identity information and the signature;

receive pre-setting instructions from the server;

pre-set the device in accordance with the received pre-setting instructions from the server, pre-settings made on the device being inactive until after receiving the input to accept the activation request;

only after receiving input to accept the activation request, establish a mutually authenticated communication session between the device and the server for activation of the device on the server, the mutually authenticated communication session being authenticated by a device certificate and the same or different server certificate; and

remove the pre-settings made on the device after receiving an input to reject the activation request.

17. A non-transitory machine readable medium having tangibly stored thereon executable instructions for execution by a processor of a server configurable to enable activation of a wireless communication device to operate with the server that, when executed by the processor, cause the server to:

in absence of any activation request sent from the device, push, by the server, an activation request to the device, the activation request being authenticated by a signature signed by a server certificate, the server certificate including server identity information;

push pre-setting instructions to the device, the pre-setting instructions causing pre-setting of the device, pre-settings made on the device being inactive until the activation request is accepted, the pre-setting instructions cause removal of any pre-settings made on the device after the device receives an input to reject the activation request; and

after receiving from the device an indication to proceed with activation, establish a mutually authenticated communication session between the server and the device for activation of the device on the server, the mutually authenticated communication session being authenticated by a device certificate from the device and the same or different server certificate.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Mar 15, 2016
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 038087/0963 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2013
From: TRUSKOVSKY, ALEXANDER; MARTIN, DARYL JOSEPH
To: RESEARCH IN MOTION LIMITED
Reel/Frame 030203/0439 →
Continuity (1)
Related Publication 20140310777A1 · Oct 16, 2014