Systems and methods for implementing indirect certificate pinning
Abstract:
Disclosed is a system for implementing indirect certificate pinning. The system comprises a client device configured to execute client application having a public signing key pinned thereto, and a certificate information server communicably coupled with client device. Upon execution, the client application is configured to: send, to certificate information server, a connection request; receive, from certificate information server, a security certificate of certificate information server and signing information pertaining to the security certificate, wherein signing information comprises: signatures of security certificate for at least one signing key pair that is valid at a time of receiving connection request, a version number of the at least one signing key pair, expiration details of the at least one signing key pair; and validate the signatures using the security certificate and the public signing key, for enabling connection of the client device with the certificate information server.
Public/Granted literature
Information query
Patent Agency Ranking
0/0