- Patent Title: Achieving certificate pinning security in reduced trust networks
-
Application No.: US17478719Application Date: 2021-09-17
-
Publication No.: US11706037B2Publication Date: 2023-07-18
- Inventor: Brandon T. Hunt , Alexander Burba , Yuval Gross
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Workman Nydegger
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32 ; H04L9/08 ; H04L9/06

Abstract:
Achieving certificate pinning security in reduced trust networks. A client receives a second certificate from a server over a first secured communications channel. The first secured communications channel is established based at least upon a first digital certificate associated with the first secured communications channel being certified by a pinned certificate. The client sends a request towards the server via a second communications channel with an untrusted computer system, and the request is received by the server. The server generates a response comprising a timestamp, a URI portion, and a signature that is generated using the second certificate. The server sends the response via the second communications channel. The client receives the response, and uses the second certificate to verify that the response is authentic and that the timestamp and URI portion are valid. The client then processes the payload.
Public/Granted literature
- US20220006656A1 ACHIEVING CERTIFICATE PINNING SECURITY IN REDUCED TRUST NETWORKS Public/Granted day:2022-01-06
Information query