US2005149442A1PendingUtilityA1
Certificate information storage system and method
Est. expiryMar 20, 2022(expired)· nominal 20-yr term from priority
G06F 21/606H04L 12/22H04L 63/0823
46
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A system and method of storing in a computer device digital certificate data from a digital certificate are provided. When a digital certificate is received at the computer device, it is determined whether the digital certificate data in the digital certificate is stored in a first memory store in the computer device. The digital certificate data is stored in the first memory store upon determining that the digital certificate data is not stored in the first memory store.
Claims
exact text as granted — not AI-modified1 . A method of storing digital certificate information from a digital certificate received at a messaging client, the method comprising the steps of:
extracting the digital certificate information from the digital certificate; determining whether the extracted digital certificate information is stored in a data store at the messaging client; and storing the extracted digital certificate information in the data store when the extracted digital certificate information is not stored in the data store.
2 . The method of claim 1 , wherein the step of storing the extracted digital certificate information in the data store comprises the steps of:
creating a new entry in the data store; and storing the extracted digital certificate information in the new entry in the data store.
3 . The method of claim 1 , wherein the step of storing the extracted digital certificate information in the data store comprises the step of storing the extracted digital certificate information in an existing entry in the data store.
4 . The method of claim 1 , wherein the extracted digital certificate information comprises a subject identifier and additional digital certificate information, and the step of determining whether the extracted digital certificate information is stored in a data store at the messaging client comprises the steps of:
determining whether the subject identifier is stored in an existing entry in the data store; and determining whether the additional digital certificate information is stored in the existing entry in the data store where the subject identifier is stored in an existing entry in the data store, wherein the step of storing the extracted digital certificate information in the data store comprises the step of storing the additional digital certificate information in the existing entry in the data store where the additional digital certificate information is not stored in the existing entry in the data store.
5 . The method of claim 4 , further comprising the step of:
creating a new entry in the data store where the subject identifier is not stored in an existing entry in the data store, wherein the step of storing the extracted digital certificate information in the data store further comprises the step of storing the subject identifier and the additional digital certificate information in the new entry in the data store.
6 . The method of claim 1 , wherein the digital certificate is an X.509 digital certificate.
7 . The method of claim 1 , further comprising the steps of:
storing the digital certificate in a digital certificate store at the messaging client upon receiving the digital certificate; and generating a signal that the digital certificate has been stored in the digital certificate store.
8 . The method of claim 7 , wherein the step of extracting digital certificate information from the digital certificate comprises the step of parsing the digital certificate to extract the digital certificate information.
9 . The method of claim 7 , wherein:
the step of storing the digital certificate in a digital certificate store at the messaging client comprises the steps of:
parsing the digital certificate to produce parsed digital certificate data; and
storing the parsed digital certificate data in the digital certificate store; and
the step of extracting digital certificate information from the digital certificate comprises the step of retrieving the digital certificate information from the parsed digital certificate data.
10 . The method of claim 1 , wherein:
the digital certificate includes a subject identifier which identifies an entity associated with the digital certificate; and the step of extracting the digital certificate information from the digital certificate comprises the step of extracting the subject identifier from the digital certificate.
11 . The method of claim 10 , wherein the subject identifier comprises an e-mail address.
12 . The method of claim 11 , wherein the data store comprises an address book.
13 . The method of claim 2 , wherein:
the data store comprises an address book; and the step of creating a new entry in the data store further comprises the step of setting a secure messaging flag associated with the new entry to indicate that a digital certificate associated with the new entry has been received.
14 . The method of claim 13 , further comprising the steps of:
generating a message at the messaging client; accessing the new entry in the data store to address the message to a recipient; and determining whether to perform a security operation on the message based on the secure messaging flag associated with the new entry.
15 . The method of claim 14 , wherein the security operation is an encryption operation.
16 . The method of claim 14 , wherein the step of determining whether to perform a security operation on the message based on the secure messaging flag associated with the new entry comprises the steps of:
determining whether a secure messaging flag associated with the new entry is set; and prompting a user of the messaging client to determine whether to perform a security operation on the message upon determining that a secure messaging flag associated with the new entry is set.
17 . The method of claim 3 , wherein:
the data store comprises an address book; and the step of storing the extracted digital certificate information in an existing entry in the data store further comprises the steps of:
determining whether a secure messaging flag associated with the existing entry has been set; and
setting the secure messaging flag to indicate that the digital certificate information has been stored in the existing entry upon a determination that a secure messaging flag associated with the existing entry has not been set.
18 . The method of claim 17 , further comprising the steps of:
generating a message at the messaging client; accessing the existing entry in the data store to address the message to a recipient; and determining whether to perform a security operation on the message based on the secure messaging flag associated with the existing entry.
19 . The method of claim 18 , wherein the step of determining whether to perform a security operation on the message based on the secure messaging flag associated with the existing entry comprises the steps of:
determining whether a secure messaging flag associated with the existing entry is set; and prompting a user of the messaging client to determine whether to perform a security operation on the message upon determining that a secure messaging flag associated with the existing entry is set.
20 . The method of claim 1 , wherein:
the extracted digital certificate information comprises a subject identifier and digital certificate validity information; and the step of determining whether the extracted digital certificate information is stored in a data store at the messaging client comprises the steps of:
determining whether the subject identifier is stored in an existing entry in the data store; and
determining whether the digital certificate validity information is stored in the existing entry in the data store upon a determination that the subject identifier is not stored in an existing entry in the data store; and
the step of storing the digital certificate information in the data store comprises the steps of:
creating a new entry in the data store and storing the subject identifier and the digital certificate validity information in the new entry in the data store where the subject identifier is not stored in an existing entry in the data store; and
storing the digital certificate validity information in the existing entry in the data store where the subject identifier is stored in an existing entry in the data store.
21 . The method of claim 20 , further comprising the steps of:
determining whether a digital certificate is invalid based on the subject identifier and the digital certificate validity information; and notifying a user of the messaging client that the digital certificate is invalid upon a determination that a digital certificate is invalid.
22 . The method of claim 21 , wherein the digital certificate validity information defines a validity period.
23 . The method of claim 21 , wherein the digital certificate validity information defines an expiry time.
24 . The method of claim 1 , wherein the messaging client implemented on a wireless mobile communication device.
25 . A system for storing digital certificate information at a messaging client, the system comprising:
a digital certificate loader module configured to receive digital certificates; and a digital certificate information injector module configured to extract digital certificate information from a digital certificate after the digital certificate is received by the digital certificate loader module, to determine whether the extracted digital certificate information is stored in an entry in a first data store, and to store the extracted digital certificate information in the first data store where the extracted digital certificate information is not stored in the entry in the first data store.
26 . The system of claim 25 , wherein the digital certificate information injector module is further configured to create a new entry in the first data store upon determining that the extracted digital certificate information is not stored in an entry in the first data store.
27 . The system of claim 26 , wherein:
the extracted digital certificate information comprises a subject identifier and additional digital certificate information; and the digital certificate information injector module is further configured to:
determine whether the subject identifier is stored in an entry in the first data store, and upon determining that the subject identifier is not stored in an entry in the first data store, to create a new entry in the first data store and store the subject identifier and the additional digital certificate information in the new entry in the first data store; and
upon determining that the subject identifier is stored in an entry in the first data store, determine whether the additional digital certificate information is stored in the entry in the first data store, and to store the additional digital certificate information in the entry in the first data store upon determining that the additional digital certificate information is not stored in the first data store.
28 . The system of claim 25 , further comprising a second data store, wherein the digital certificate loader module is configured to store digital certificates in the second data store.
29 . The system of claim 28 , wherein the digital certificate information injector module is further configured to detect storage of a received digital certificate to the second data store and to retrieve the received digital certificate from the second data store upon such detection.
30 . The system of claim 28 , wherein:
the digital certificate loader module is configured to notify the digital certificate information injector module when a received digital certificate has been stored to the second data store; and the digital certificate information injector module is configured to retrieve the received digital certificate from the second data store upon such notification.
31 . The system of claim 25 , wherein:
the system further comprises a digital certificate store; the digital certificate loader module is configured to parse digital certificates to create parsed digital certificate data and to store the parsed digital certificate data in the digital certificate store; and the digital certificate information injector module is configured to retrieve the digital certificate information from the parsed digital certificate data stored in the digital certificate store.
32 . The system of claim 25 , wherein the digital certificate loader module is configured to provide the digital certificate information to the digital certificate information injector module.
33 . The system of claim 25 , wherein the messaging client is a wireless mobile communication device.
34 . The system of claim 28 , wherein the digital certificate information injector module is further configured to extract digital certificate information for a digital certificate from the second data store, to determine whether the digital certificate information extracted from the second data store is stored in an entry in the first data store, and to store the extracted digital certificate information in the first data store upon determining that the digital certificate information extracted from the second data store is not stored in an entry in the first data store.
35 . The system of claim 34 , wherein the first data store comprises an address book store that stores contact information, and an appointment store that stores appointment information.
36 . The method of claim 1 , wherein the messaging client is a mobile communication device, and further comprising:
receiving transmitted digital certificate data at the mobile communication device; and comparing the transmitted digital certificate data to digital certificate data stored in a memory store in the mobile communication device; wherein the step of storing the extracted digital certificate information in the data store where the extracted digital certificate information is not stored in the data store comprises updating the memory store to include transmitted digital certificate data not stored in the memory store.
37 . The method of claim 36 , wherein the step of comparing the transmitted digital certificate data to stored digital certificate data stored in the memory store comprises the steps of:
selecting a digital certificate identifier associated with the transmitted digital certificate data; and determining whether the digital certificate identifier is stored in the memory store.
38 . The method of claim 37 , wherein the step of updating the memory store to include the transmitted digital certificate data not stored in the memory store comprises the steps of:
upon determining that the digital certificate identifier is not stored in the memory store:
storing the digital certificate identifier in the memory store;
storing the transmitted digital certificate data in the memory store; and
associating the transmitted digital certificate data with the digital certificate identifier.
39 . The method of claim 38 , further comprising the steps of:
setting a secure messaging identifier in the memory store; and associating the secure messaging identifier with the digital certificate identifier.
40 . The method of claim 39 , wherein the memory store is an address book store, and the digital certificate identifier is an e-mail address.
41 . The method of claim 40 , further comprising the steps of:
generating a message at the mobile communication device; addressing the message to the e-mail address; and determining whether to perform a security operation on the message based on the secure messaging identifier.
42 . The method of claim 41 , wherein the step of determining whether to perform a security operation on the message based on the secure messaging identifier comprises the steps of:
determining whether the secure messaging identifier is set; prompting a user of the mobile communication device to select the security operation where the secure messaging identifier is set.
43 . The method of claim 36 , further comprising the steps of:
selecting a validity event for a digital certificate based on the digital certificate data stored in the memory store; and notifying a user upon the occurrence of the validity event.
44 . The method of claim 43 , wherein the validity event is the expiration of a validity period of the digital certificate.
45 . The method of claim 43 , wherein the step of selecting a validity event for a digital certificate based on the digital certificate data stored in the memory store comprises the steps of:
storing validity event data in a second memory store; and periodically accessing the second memory store to determine whether the validity event has occurred.
46 . The method of claim 45 , wherein the second memory store is a calendar event store, and the validity event is an expiration of the digital certificate.Join the waitlist — get patent alerts
Track US2005149442A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.