BYPASSING CERTIFICATE PINNING
A client application performs certificate pinning as a means of authenticating the identity of a server. A proxy is interposed in the communications path of the client and the hosting server and provides a proxy security certificate to the client. In response to the client extracting a proxy authent...
Saved in:
Main Authors | , , |
---|---|
Format | Patent |
Language | English |
Published |
26.10.2017
|
Subjects | |
Online Access | Get full text |
Cover
Loading…
Summary: | A client application performs certificate pinning as a means of authenticating the identity of a server. A proxy is interposed in the communications path of the client and the hosting server and provides a proxy security certificate to the client. In response to the client extracting a proxy authentication component from the proxy security certificate, operation of the client is paused and a hosting server authentication component is extracted from a hosting server security certificate. The client operation is resumed, providing the extracted hosting server authentication component to the client, in substitution for the proxy authentication component. Based on receiving the extracted hosting server authentication component, the client authenticates the proxy to receive communications directed to the hosting server. |
---|---|
Bibliography: | Application Number: US201615138876 |