Invention Grant
- Patent Title: Bypassing certificate pinning
-
Application No.: US15716130Application Date: 2017-09-26
-
Publication No.: US10091187B2Publication Date: 2018-10-02
- Inventor: Emanuel Bronshtein , Roee Hay , Sagi Kedmi
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Christopher M. Coy
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A client application performs certificate pinning as a means of authenticating the identity of a server. A proxy is interposed in the communications path of the client and the hosting server and provides a proxy security certificate to the client. In response to the client extracting a proxy authentication component from the proxy security certificate, operation of the client is paused and a hosting server authentication component is extracted from a hosting server security certificate. The client operation is resumed, providing the extracted hosting server authentication component to the client, in substitution for the proxy authentication component. Based on receiving the extracted hosting server authentication component, the client authenticates the proxy to receive communications directed to the hosting server.
Public/Granted literature
- US20180013754A1 BYPASSING CERTIFICATE PINNING Public/Granted day:2018-01-11
Information query