- Patent Title: Method and a system for verifying the authenticity of a certificate in a web browser using the SSL/TLS protocol in an encrypted internet connection to an HTTPS website
-
Application No.: US15335136Application Date: 2016-10-26
-
Publication No.: US10313136B2Publication Date: 2019-06-04
- Inventor: Jyrki Salmi
- Applicant: ONLINE SOLUTIONS OY
- Applicant Address: FI Jyvaskyla
- Assignee: ONLINE SOLUTIONS OY
- Current Assignee: ONLINE SOLUTIONS OY
- Current Assignee Address: FI Jyvaskyla
- Agency: FisherBroyles, LLP
- Agent Robert Kinberg
- Priority: FI20155763 20151026
- Main IPC: G06F21/00
- IPC: G06F21/00 ; H04L29/06 ; H04L29/08 ; H04L9/32 ; H04L12/66

Abstract:
A method for verifying the authenticity of a certificate in a web browser using an SSL/TLS protocol in an encrypted Internet connection to an HTTPS website includes establishing an encrypted connection to the HTTPS website using the web browser on a user's terminal device. A certificate including a public key of the HTTPS website and signed by a trusted certificate authority is sent to the user's web browser from the web server using the Internet connection. The certificate authority that signed the certificate is compared against the list of trusted certificate authorities. The certificate authority is verified as being included in the list. The thumbprint of the certificate is sent as an additional security check key using a second messaging channel, external to the Internet connection between HTTPS website and web browser of the user's terminal device, and the contact data in the customer register. The additional security check key is compared with the thumbprint received by the web.
Public/Granted literature
Information query