IP Library Granted Patent US 10,797,890
Granted Patent B2
US 10,797,890 · App. 15/905,394 · Granted Oct 6, 2020

Providing inter-enterprise data communications between enterprise applications on an electronic device

Inventors: Johnathan George White (St. Albans, GB); Siavash James Joorabchian Hawkins (Tonbridge, GB); Fraser George Stewart (London, GB)
Assignee: BlackBerry Limited
H04L9/3268G06F9/547G06F21/335G06F21/6218H04L9/3213H04L63/0823H04W12/0609H04W12/0806
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,797,890
App. No.
15/905,394
Granted
Oct 6, 2020
Kind
B2
Abstract

Systems, methods, and software can be used to provide inter-enterprise data communications between enterprise applications on an electronic device. In some aspects, a method comprises: receiving, by a bridge application executing on an electronic device, an interoperation request for a first enterprise, wherein the interoperation request includes a first token and a second token; sending, from the bridge application to an application of the first enterprise, the first token, wherein the application of the first enterprise executes on the electronic device; receiving, by the bridge application from the application of the first enterprise, a certificate in response to the first token, wherein the certificate is encrypted by the second token; decrypting, by the bridge application, the certificate by using the second token; and validating, by the bridge application, the application of the first enterprise based on the decrypted certificate.

Claims (44)

1. A computer-implemented method for secure inter-enterprise data communications between enterprise applications on an electronic device, comprising:

receiving, by a bridge application executing on the electronic device, an interoperation request for a first enterprise, wherein the interoperation request includes a first token and a second token, the interoperation request is received from an enterprise mobility management (EMM) server that is associated with a second enterprise, and the second enterprise is different than the first enterprise;

in response to the interoperation request, sending, from the bridge application to an application of the first enterprise, the first token, wherein the application of the first enterprise executes on the electronic device;

receiving, by the bridge application from the application of the first enterprise, a certificate in response to the first token, wherein the certificate is encrypted by the second token;

decrypting, by the bridge application, the certificate by using the second token; and

validating, by the bridge application, the application of the first enterprise based on the decrypted certificate.

2. The method of claim 1 , further comprising:

after validating the application of the first enterprise, receiving, by the bridge application and from the application of the first enterprise, a data request; and

sending data to the application of the first enterprise in response to the data request.

3. The method of claim 1 , wherein the interoperation request includes certificate signing data associated with the first enterprise.

4. The method of claim 3 , further comprising:

generating, by the bridge application, a certificate signing request by using the certificate signing data associated with the first enterprise; and

sending the certificate signing request to the application of the first enterprise.

5. The method of claim 1 , further comprising: sending, from the bridge application to the application of the first enterprise, a domain User Principal Name (UPN) with the first token.

6. The method of claim 1 , wherein the first token or the second token has an expiration period.

7. The method of claim 1 , wherein the application of the first enterprise is included in a first enterprise container of the electronic device.

8. An electronic device, comprising:

at least one hardware processor; and

a computer-readable storage medium coupled to the at least one hardware processor and storing programming instructions for execution by the at least one hardware processor, wherein the programming instructions, when executed, cause the at least one hardware processor to perform operations comprising:

receiving, by a bridge application executing on the electronic device, an interoperation request for a first enterprise, wherein the interoperation request includes a first token and a second token, the interoperation request is received from an enterprise mobility management (EMM) server that is associated with a second enterprise, and the second enterprise is different than the first enterprise;

in response to the interoperation request, sending, from the bridge application to an application of the first enterprise, the first token, wherein the application of the first enterprise executes on the electronic device;

receiving, by the bridge application from the application of the first enterprise, a certificate in response to the first token, wherein the certificate is encrypted by the second token;

decrypting, by the bridge application, the certificate by using the second token; and

validating, by the bridge application, the application of the first enterprise based on the decrypted certificate.

9. The electronic device of claim 8 , the operations further comprising:

after validating the application of the first enterprise, receiving, by the bridge application and from the application of the first enterprise, a data request; and

sending data to the application of the first enterprise in response to the data request.

10. The electronic device of claim 8 , wherein the interoperation request includes certificate signing data associated with the first enterprise.

11. The electronic device of claim 10 , the operations further comprising:

generating, by the bridge application, a certificate signing request by using the certificate signing data associated with the first enterprise; and

sending the certificate signing request to the application of the first enterprise.

12. The electronic device of claim 8 , the operations further comprising: sending, from the bridge application to the application of the first enterprise, a domain User Principal Name (UPN) with the first token.

13. The electronic device of claim 8 , wherein the first token or the second token has an expiration period.

14. The electronic device of claim 8 , wherein the application of the first enterprise is included in a first enterprise container of the electronic device.

15. A non-transitory computer-readable medium storing instructions which, when executed, cause an electronic device to perform operations comprising:

receiving, by a bridge application executing on the electronic device, an interoperation request for a first enterprise, wherein the interoperation request includes a first token and a second token, the interoperation request is received from an enterprise mobility management (EMM) server that is associated with a second enterprise, and the second enterprise is different than the first enterprise;

in response to the interoperation request, sending, from the bridge application to an application of the first enterprise, the first token, wherein the application of the first enterprise executes on the electronic device;

receiving, by the bridge application from the application of the first enterprise, a certificate in response to the first token, wherein the certificate is encrypted by the second token;

decrypting, by the bridge application, the certificate by using the second token; and

validating, by the bridge application, the application of the first enterprise based on the decrypted certificate.

16. The computer-readable medium of claim 15 , the operations further comprising:

after validating the application of the first enterprise, receiving, by the bridge application and from the application of the first enterprise, a data request; and

sending data to the application of the first enterprise in response to the data request.

17. The computer-readable medium of claim 15 , wherein the interoperation request includes certificate signing data associated with the first enterprise.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2018
From: BLACKBERRY UK LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 045486/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2018
From: WHITE, JOHNATHAN GEORGE; HAWKINS, SIAVASH JAMES JOORABCHIAN; STEWART, FRASER GEORGE
To: BLACKBERRY UK LIMITED
Reel/Frame 045357/0078 →
Continuity (1)
Related Publication 20190268167A1 · Aug 29, 2019