US2013191633A1PendingUtilityA1

System and method for supporting multiple certificate status providers on a mobile communication device

Assignee: RESEARCH IN MOTION LTDPriority: Mar 20, 2002Filed: Mar 11, 2013Published: Jul 25, 2013
Est. expiryMar 20, 2022(expired)· nominal 20-yr term from priority
H04L 9/3268H04L 12/66H04L 63/045H04L 63/0281H04L 63/126H04L 63/0823
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and system for supporting multiple digital certificate status information providers are disclosed. An initial service request is prepared at a proxy system client module and sent to as proxy system service module operating at a proxy system. The proxy system prepares multiple service requests and sends the service requests to respective multiple digital certificate status information providers. One of the responses to the service requests received from the status information providers is selected, and a response to the initial service request is prepared and returned to the proxy system client module based on the selected response.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, executed in a processor of a proxy system communication device, of obtaining status information of a digital certificate comprising:
 providing a mapping table for maintaining a correspondence between a plurality of digital certificate issuers and at least one of a serial number and a subject name associated with the digital certificate;   upon receiving a request for the status information from a mobile device comprising one of: the at least one serial number and subject name, generating a plurality of service requests, each of the plurality of service requests associated with a respective status information provider and formatted according to at least one of a communication protocol and content for the respective status information provider, the content being generated based on data extracted from the mapping table, the respective status information provider maintaining revocation status information of the digital certificate;   sending the generated plurality of service requests to the respective status information providers associated therewith;   receiving a plurality of responses from the respective status information providers, the responses including the revocation status information of the digital certificate; and   generating as the status information the revocation status information included in at least one of the received responses.   
     
     
         2 . The method of  claim 1 , wherein the request includes a list of status information providers to which the service request is to be sent. 
     
     
         3 . The method of  claim 2 , wherein the list of status information providers is arranged in order of preference between subsequent responses from the status information providers. 
     
     
         4 . The method of  claim 1  wherein the request includes a ranking list that specifies an order of preference between subsequent responses from the status information providers. 
     
     
         5 . The method of  claim 1 , wherein the generated digital certificate status response is utilized in processing a secure message at the communication device. 
     
     
         6 . The method of  claim 5 , wherein the secure message comprises a digital signature. 
     
     
         7 . The method of  claim 1 , wherein the request comprises identification information identifying a target digital certificate for which digital certificate status information is requested, wherein the response from the at least one of the digital certificate status information providers comprises status information for the target digital certificate, and wherein the generated digital certificate status response comprises a status indicator for the target digital certificate. 
     
     
         8 . The method of  claim 1 , wherein a request for a digital certificate status information for a digital certificate in a secure message is received after the communication has received the secure message comprising the digital certificate and generated the request for digital certificate status information. 
     
     
         9 . The method of  claim 1 , wherein the request for digital certificate status information is generated at predetermined time intervals. 
     
     
         10 . The method of  claim 1 , wherein the request for digital certificate status information is generated based on a validity period of the digital certificate. 
     
     
         11 . The method of  claim 1 , wherein the request comprises a revocation status request for a digital certificate stored at the communication device. 
     
     
         12 . The method of  claim 1 , wherein status information for a plurality of digital certificates is requested in the request, and wherein the generated digital certificate status response comprises a status indicator for each of the plurality of digital certificates. 
     
     
         13 . The method of  claim 12 , wherein each of the plurality of service requests comprises a status information request for at least one of the plurality of digital certificates. 
     
     
         14 . The method of  claim 1 , wherein the plurality of service requests and each response from the digital certificate status information providers conform to Online Certificate Status Protocol (OCSP). 
     
     
         15 . The method of  claim 1 , wherein generating the response further comprises formatting each response from the digital certificate status information providers to conform to a format for the mobile device. 
     
     
         16 . A communication device for obtaining status information of a digital certificate the communication device comprising;
 a processor;   a memory encoded with instructions for commanding the processor to perform acts including:   providing a mapping table for maintaining a correspondence between a plurality of digital certificate issuers and at least one of a serial number and a subject name associated with the digital certificate;   upon receiving a request for the status information from a mobile device comprising one of the at least one serial number and subject name, generating a plurality of service requests, each of the plurality of service requests associated with a respective status information provider and formatted according to at least one of a communication protocol and content for the respective status information provider, the content being generated based on data extracted from the mapping table, the respective status information provider maintaining revocation status information of the digital certificate;   sending the generated plurality of service requests to the respective status information providers associated therewith;   receiving a plurality of responses from the respective status information providers, the responses including the revocation status information of the digital certificate; and   generating as the status information the revocation status information included in at least one of the received responses.   
     
     
         17 . The communication device of  claim 16 , wherein the communication device is selected from the group consisting of a handheld communication device, a data communication device, a voice communication device, a dual-mode communication device, a mobile telephone with data communication capabilities, a personal digital assistant (PDA) enabled for wireless communications, a two-way pager, and a wireless modern. 
     
     
         18 . The communication device of  claim 16 , wherein the request is generated at predetermined time intervals.

Join the waitlist — get patent alerts

Track US2013191633A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.