Methods and apparatus for use in enabling a mobile communication device with a digital certificate

US10015158B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10015158-B2
Application numberUS-3996008-A
CountryUS
Kind codeB2
Filing dateFeb 29, 2008
Priority dateFeb 29, 2008
Publication dateJul 3, 2018
Grant dateJul 3, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In one illustrative scenario, a mobile communication device causes a communication session to be established with a host server of a communication network. The mobile device performs communication operations in the communication session for activating a communication service, such as a data synchronization service, with the host server. In the communication session, the mobile device also receives configuration information which includes information for use in constructing a request message for obtaining a digital certificate from a certificate authority (CA). After receipt of the configuration information, the mobile device constructs the request message for the digital certificate and causes it to be sent to the host server. In response, the host server requests and obtains the digital certificate from the CA on behalf of the mobile device, and thereafter “pushes” the received digital certificate to the mobile device. The mobile device receives the digital certificate and stores it for use in subsequent communications. The host server may be part of a local area network (LAN) which includes a wireless LAN (WLAN) adapted to authenticate the mobile device based on the digital certificate, so that the mobile device may obtain access to the WLAN.

First claim

Opening claim text (preview).

What is claimed is: 1. A method performed by a mobile communication device, the method comprising: the mobile communication device receiving configuration information from a host server over a secure connection; and responsive to the mobile communication device receiving the configuration information: the mobile communication device generating a public-private key pair of a type indicated in the configuration information; the mobile communication device constructing a certificate request that contains the generated public key and signing the certificate request with the generated private key; and the mobile communication device sending the certificate request to a certificate authority indicated in the configuration information. 2. The method as recited in claim 1 , further comprising: responsive to the mobile communication device sending the certificate request, the mobile communication device receiving a digital certificate signed by the certificate authority indicated in the configuration information, the digital certificate containing the generated public key. 3. The method as recited in claim 2 , further comprising: responsive to the mobile communication device receiving the digital certificate, the mobile communication device storing the digital certificate in a certificate keystore at the mobile communication device. 4. The method as recited in claim 2 , further comprising: responsive to the mobile communication device receiving the digital certificate, the mobile communication device presenting the digital certificate to an authentication server in a certificate-based authentication process to obtain communication access in a network. 5. The method as recited in claim 4 , wherein the certificate-based authentication process is an extensible authentication protocol (EAP) process. 6. The method as recited in claim 4 , wherein the network is a wireless local area network (WLAN). 7. The method as recited in claim 6 , further comprising: the mobile communication device receiving from the host server over the secure connection a WLAN profile comprising an identification of the WLAN. 8. The method as recited in claim 1 , wherein the secure connection is established over a radio link between the mobile communication device and a cellular telecommunications network. 9. The method as recited in claim 1 , wherein the secure connection is established over a wired connection between the mobile communication device and a computer connected in a local area network to the host server. 10. The method as recited in claim 1 , further comprising: the mobile communication device causing a communication session to be established with the host server; and the mobile communication device performing communication operations in the communication session with the host server for activating a communication service provided by the host server to the mobile communication device. 11. The method as recited in claim 10 , wherein the communication service comprises a data synchronization service. 12. The method as recited in claim 1 , wherein the mobile communication device sending the certificate request to the certificate authority comprises: the mobile communication device sending the certificate request to the host server over the secure connection for the host server to send to the certificate authority on behalf of the mobile communication device. 13. The method as recited in claim 12 , further comprising: the mobile communication device receiving from the host server a digital certificate signed by the certificate authority indicated in the configuration information, the digital certificate containing the generated public key. 14. A method performed by a host server, the method comprising: the host server sending configuration information to a mobile communication device over a secure connection, the configuration information indicating a key type and a certificate authority; the host server receiving from the mobile communication device over the secure connection a certificate request that contains a public key and that is signed by a private key, the public key and the private key forming a public-private key pair generated by the mobile communication device, the key pair of the key type indicated in the configuration information; and the host server sending, on behalf of the mobile communication device, the certificate request to the certificate authority indicated in the configuration information. 15. The method as recited in claim 14 , further comprising: the host server obtaining, on behalf of the mobile communication device, a digital certificate signed by the certificate authority, the digital certificate containing the generated public key. 16. The method as recited in claim 15 , wherein the digital certificate is intended for presentation by the mobile communication device to an authentication server in a certificate-based authentication process to obtain communication access in a network. 17. The method as recited in claim 16 , wherein the certificate-based authentication process is an extensible authentication protocol (EAP) process. 18. The method as recited in claim 16 , wherein the network is a wireless local area network (WLAN). 19. The method as recited in claim 18 , further comprising: the host server sending to the mobile communication device over the secure connection a WLAN profile comprising an identification of the WLAN. 20. The method as recited in claim 14 , wherein the secure connection is established over a radio link between the mobile communication device and a cellular telecommunications network. 21. The method as recited in claim 14 , wherein the secure connection is established over a wired connection between the mobile communication device and a computer connected in a local area network to the host server. 22. The method as recited in claim 14 , wherein the host server provides the mobile communication device with a communication service. 23. The method as recited in claim 22 , wherein the communication service comprises a data synchronization service. 24. A mobile communication device comprising: a wireless transceiver; one or more processors coupled to the wireless transceiver, the one or more processors being operative to receive configuration information from a host server over a secure connection and responsive to receiving the configuration information, to: generate a public-private key pair of a type indicated in the configuration information; construct a certificate request that contains the generated public key and sign the certificate request with the generated private key; and send the certificate request to a certificate authority indicated in the configuration information. 25. The mobile communication device as recited in claim 24 , the one or more processors being further operative, responsive to sending the certificate request, to receive a digital certificate signed by the certificate authority indicated in the configuration information, the digital certificate containing the generated public key. 26. The mobile communication device as recited in claim 25 , the one or more processors being further operative, responsive to receiving the digital certificate, to store the digital certificate in a certificate keystore at the mobile communication device. 27. The mobile communication device as recited in claim 25 , th

Assignees

Inventors

Classifications

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • using certificates · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10015158B2 cover?
In one illustrative scenario, a mobile communication device causes a communication session to be established with a host server of a communication network. The mobile device performs communication operations in the communication session for activating a communication service, such as a data synchronization service, with the host server. In the communication session, the mobile device also recei…
Who is the assignee on this patent?
Bender Christopher Lyle, Shih Sam Cheng Fu, Adams Neil Patrick, and 1 more
What technology area does this patent fall under?
Primary CPC classification H04L63/0823. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 03 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).