IP Library Granted Patent US 11,089,004
Granted Patent B2
US 11,089,004 · App. 16/400,691 · Granted Aug 10, 2021

Method and system for application authenticity attestation

Inventors: Johnathan White (St. Albans, GB); Amit Ghosh (Redmond, WA)
Assignee: BlackBerry Limited
H04L63/0807H04L9/0643H04L9/0869H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,089,004
App. No.
16/400,691
Granted
Aug 10, 2021
Kind
B2
Abstract

A method at a network element for attestation of applications, the method including sending a challenge to an application at an electronic device; receiving a response from the electronic device; processing the response; and upon determining that the response is invalid based on the processing, taking an enforcement action against the application.

Claims (45)

1. A method at a network element for attestation of applications, the method comprising:

sending a challenge to an application at an electronic device, the challenge including a nonce;

setting a grace period for receiving a response;

when the grace period expires before the response is received, taking an enforcement action against the application;

receiving the response from the electronic device, the response including a hash of the nonce with a plurality of identifiers stored at the electronic device;

obtaining the plurality of identifiers from a trusted network server to recompute the hash;

comparing the hash in the response with the recomputed hash; and

upon determining that the response is invalid based on the comparing, taking the enforcement action against the application.

2. The method of claim 1 , wherein the plurality of identifiers includes a team identifier stored in an operating system of the electronic device and obtainable from the network server.

3. The method of claim 2 , wherein the processing further comprises:

receiving, in the response, a device check token;

adding authentication information to the device check token;

sending the device check token with the added authentication information to a device check server; and

receiving a response from the device check server to indicate whether the device check token is valid.

4. The method of claim 1 , wherein the enforcement action comprises at least one of: reporting the failure; blocking the application from accessing network resources; instructing the electronic device to wipe the application; instructing the electronic device to prompt a user to perform an action on the application; and instruct the electronic device to block running of the application.

5. The method of claim 1 , wherein the sending the challenge is performed on activation of the application.

6. The method of claim 1 , wherein the sending the challenge is performed at a configurable challenge frequency.

7. A network element configured for attestation of applications, the network element comprising:

a processor; and

a communications subsystem,

wherein the network element is configured to:

send a challenge to an application at an electronic device, the challenge including a nonce;

set a grace period for receiving a response;

when the grace period expires before the response is received, take an enforcement action against the application;

receive the response from the electronic device, the response including a hash of the nonce with a plurality of identifiers stored at the electronic device;

obtain the plurality of identifiers from a trusted network server to recompute the hash;

compare the hash in the response with the recomputed hash; and

upon determining that the response is invalid based on the comparing, take the enforcement action against the application.

8. The network element of claim 7 , wherein the plurality of identifiers includes a team identifier stored in an operating system of the electronic device and obtainable from the network server.

9. The network element of claim 8 , wherein the network element is further configured to process by:

receiving, in the response, a device check token;

adding authentication information to the device check token;

sending the device check token with the added authentication information to a device check server; and

receiving a response from the device check server to indicate whether the device check token is valid.

10. The network element of claim 7 , wherein the enforcement action comprises at least one of: reporting the failure; blocking the application from accessing network resources; instructing the electronic device to wipe the application; instructing the electronic device to prompt a user to perform an action on the application; and instruct the electronic device to block running of the application.

11. The network element of claim 7 , wherein the network element is configured to send the challenge on activation of the application.

12. The network element of claim 7 , wherein the network element if configured to send the challenge at a configurable challenge frequency.

13. A non-transitory computer readable medium for storing instruction code, which, when executed by a processor of a network element configured for attestation of applications cause the network element to:

send a challenge to an application at an electronic device, the challenge including a nonce;

set a grace period for receiving a response;

when the grace period expires before the response is received, take an enforcement action against the application;

receive the response from the electronic device, the response including a hash of the nonce with a plurality of identifiers stored at the electronic device;

obtain the plurality of identifiers from a trusted network server to recompute the hash;

compare the hash in the response with the recomputed hash; and

upon determining that the response is invalid based on the comparing, take the enforcement action against the application.

Assignments (6)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2019
From: BLACKBERRY UK LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 049786/0781 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2019
From: BLACKBERRY CORPORATION
To: BLACKBERRY LIMITED
Reel/Frame 049786/0811 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2019
From: WHITE, JOHNATHAN GEORGE
To: BLACKBERRY UK LIMITED
Reel/Frame 049053/0454 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2019
From: GHOSH, AMIT
To: BLACKBERRY CORPORATION
Reel/Frame 049053/0508 →
Continuity (1)
Related Publication 20200351260A1 · Nov 5, 2020