Nova Patents
CA2923740C

Software code signing system and method

Abstract

A code signing system and method is provided. The code signing system operates in conjunction with a signed software application having a digital signature and includes an application platform, an application programming interface (API), and a virtual machine. The API is configured to link the software application with the application platform. The virtual machine verifies the authenticity of the digital signature in order to control access to the API by the software application.

CA2923740C, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Expired 20 September 2021, 5 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

23 claims: 14 independent, 9 dependent

  1. 1
    10289-CA-PCD What is claimed is:1. A mobile device comprising: an application platform having a plurality of application programming interfaces (APIs), at least one API having a signature identifier;a system for verifying digital signature identifications and authenticating associated digital signatures provided by respective software applications to access the at least one API;and a control system configured to deny a software application on the device access to the at least one API when the signature identifier of the at least one API does not correspond with the digital signature identification or the digital signature provided by the software application is not authenticated by the system.
  2. 5
    The mobile device of any one of claims 1 to 4, wherein at least one of the APIs of the application platform access at least one of a cryptographic module, which implements cryptographic algorithms, a data store, a proprietary data model, and a user interface (Ul).
  3. 6
    The mobile device of any one of claims 1 to 5, wherein the digital signature is generated by a code signing authority.
  4. 10
    The mobile device of any one of claims 1 to 9, wherein at least one of the APIs further comprises:a description string that is displayed when the software application attempts to access said at least one of the APIs.
  5. 11
    The mobile device of any one of claims 1 to 10, wherein the control system is configured to receive a command from the user granting or denying the software application access to the at least one API.
  6. 12
    A method of controlling access to application programming interfaces (APIs) on a mobile device, including the steps of:verifying a digital signature identification and authenticating an associated digital signature provided by a software application to access at least one of the APIs and denying the software application on the device access to the at least one of the APIs when a signature identifier of the such API does not correspond with the digital signature identification provided by the software application or the associated digital signature provided by the software application is not authenticated. CA 2923740 2017-08-04 10289-CA-PCD
  7. 15
    The method of any one of claims 12 to 14, wherein the digital signature was generated by 10 a code signing authority.
  8. 17
    The method of any one of claims 12 to 16, wherein a description string is displayed to a user when the software application attempts to access the at least one of the APIs. CA 2923740 2017-08-04 10289-CA-PCD
  9. 18
    The method of any one of claims 12 to 16, comprising the additional step of:displaying a description string that notifies a user of the mobile device that the software application requires access to the at least one of the APIs. 5
  10. 19
    The method of any one of claims 12 to 18, comprising the additional step of:allowing the software application to access the at least one of the APIs where the digital signature is authenticated.
  11. 20
    The method of any one of claims 12 to 19, comprising the additional step of:10 receiving a command from the user granting or denying the software application access to the at least one of the APIs.
  12. 21
    The method of any one of claims 12 to 20, wherein the at least one of the APIs is associated with a public signature key used to authenticate the digital signature.
  13. 22
    The method of any one of claims 12 to 21, wherein the at least one of the APIs is associated with a library, the library including a public signature key used to authenticate the digital signature. CA 2923740 2017-08-04 10289-CA-PCD
  14. 23
    The method of any one of claims 12 to 22, comprising authenticating each of a plurality of digital signatures provided by the software application for the purpose of accessing the at least one of the APIs on the mobile device. 5 24. A computer-readable medium storing instructions which when executed by a processor of a mobile device, cause the mobile device to perform the method of any one of claims 12 to 23. CA 2923740 2017-08-04