IP Library Granted Patent US 11,182,494
Granted Patent B2
US 11,182,494 · App. 16/582,930 · Granted Nov 23, 2021

Processing data on an electronic device

Inventors: Siavash James Joorabchian Hawkins (Tonbridge, GB); Phillip Riscombe-Burton (London, GB); Johnathan George White (St. Albans, GB)
Assignee: BlackBerry Limited
G06F21/62H04L9/0841H04L9/3263H04L9/3273H04W12/033H04W12/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,182,494
App. No.
16/582,930
Granted
Nov 23, 2021
Kind
B2
Abstract

A method of controlling access to data on a first electronic device, the method comprising steps of establishing a shared encryption key with a first software application instance running on a second electronic device, receiving a ‘begin session’ command sent by the first software application instance and responsive to the ‘begin session’ command, creating a storage location in a data store of the electronic device, obtaining a data encryption key, receiving data, encrypting the data using the data encryption key and storing the encrypted data in the storage location, receiving an ‘end session’ command sent by the first software application instance and responsive to the ‘end session’ command, discarding the shared encryption key, and deleting the encrypted data from the storage location.

Claims (69)

1. A method of processing data on an electronic device, the method comprising steps of:

establishing a shared encryption key with a first software application instance running on a second electronic device;

receiving a ‘begin session’ command sent by the first software application instance and responsive to the ‘begin session’ command:

creating a storage location in a data store of the electronic device; and

obtaining a data encryption key;

receiving data;

encrypting the data using the data encryption key and storing the encrypted data in the storage location;

receiving an ‘end session’ command sent by the first software application instance and responsive to the ‘end session’ command:

discarding the shared encryption key; and

deleting the encrypted data from the storage location.

2. The method according to claim 1 , further comprising steps of:

receiving a data request sent by the first software application instance;

decrypting the stored data using the data encryption key;

encrypting the data using the shared encryption key; and

sending the data encrypted using the shared encryption key to the first software application instance.

3. The method according to claim 1 , further comprising steps of:

establishing a second shared encryption key with a second software application instance;

creating a file containing the data encryption key;

encrypting the file using the second shared encryption key; and

storing the encrypted file in the data store.

4. The method according to claim 3 , wherein the second software application instance runs on the second electronic device or a third electronic device.

5. The method according to claim 1 , wherein said data is received from an application running on the electronic device or is received from an application running on a fourth electronic device communicatively connected to the first electronic device.

6. A method of controlling processing of data on an electronic device, the method comprising steps of:

establishing a shared encryption key with the electronic device;

sending a ‘begin session’ command to the electronic device, to cause the electronic device to create a storage location in a data store of the electronic device and obtain a data encryption key; and

sending an ‘end session’ command to the electronic device, to cause the electronic device to discard the shared encryption key and delete the encrypted data from the storage location.

7. The method according to claim 6 , further comprising steps of:

sending a data request to the electronic device;

receiving encrypted data from the electronic device; and

decrypting the encrypted data using the shared encryption key.

8. The method according to claim 6 , wherein the steps are performed by a first software application instance running on a second electronic device, and further comprising a second application instance performing steps of:

establishing a second shared encryption key with the electronic device; and

using the second shared encryption key to obtain access to a data encryption key on the electronic device.

9. The method according to claim 8 , wherein the second application instance runs on the second electronic device or a third electronic device.

10. The method according to claim 6 , wherein the electronic device is an Internet of Things device.

11. An electronic device comprising:

a memory; and

at least one hardware processor communicatively coupled with the memory and configured to:

establish a shared encryption key with a first software application instance running on a second electronic device;

receive a ‘begin session’ command sent by the first software application instance and responsive to the ‘begin session’ command:

create a storage location in a data store of the electronic device; and

obtain a data encryption key;

receive data;

encrypt the data using the data encryption key and store the encrypted data in the storage location;

receive an ‘end session’ command sent by the first software application instance and responsive to the ‘end session’ command:

discard the shared encryption key; and

delete the encrypted data from the storage location.

12. The device according to claim 11 , further configured to:

receive a data request sent by the first software application instance;

decrypt the stored data using the data encryption key;

encrypt the data using the shared encryption key; and

send the data encrypted using the shared encryption key to the first software application instance.

13. The device according to claim 11 , further configured to:

establish a second shared encryption key with a second software application instance;

create a file containing the data encryption key;

encrypt the file using the second shared encryption key; and

store the encrypted file in the data store.

14. The device according to claim 13 , wherein the second software application instance runs on the second electronic device or a third electronic device.

15. The device according to claim 11 , wherein said data is received from an application running on the electronic device or is received from an application running on a fourth electronic device communicatively connected to the first electronic device.

16. A non-transitory computer-readable storage medium having stored thereon, computer program which when executed by at least one processor of an electronic device is configured to

establish a shared encryption key with a first software application instance running on a second electronic device;

receive a ‘begin session’ command sent by the first software application instance and responsive to the ‘begin session’ command:

create a storage location in a data store of the electronic device; and

obtain a data encryption key;

receive data;

encrypt the data using the data encryption key and store the encrypted data in the storage location;

receive an ‘end session’ command sent by the first software application instance and responsive to the ‘end session’ command:

discard the shared encryption key; and

delete the encrypted data from the storage location.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2019
From: HAWKINS, SIAVASH JAMES JOORABCHIAN; RISCOMBE-BURTON, PHILLIP; WHITE, JOHNATHAN GEORGE
To: BLACKBERRY UK LIMITED
Reel/Frame 050799/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2019
From: BLACKBERRY UK LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 050799/0766 →
Priority Claims (1)
EP 18197811 · Sep 28, 2018 · regional
Continuity (1)
Related Publication 20200104517A1 · Apr 2, 2020