Directory Service Certificate Pinning for Secure Server Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies for preventing man-in-the-middle attacks are vulnerable to fraudulent root certificates and require user devices to re-enroll with servers upon certificate changes, causing service interruptions and user inconvenience.
Innovation Solution
A computer-implemented method where a user device performs certificate pinning by requesting and storing public key certificates from a separate directory service, comparing them with the server's certificate to ensure authenticity, and periodically updating certificates to maintain secure communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user devices rely on built-in root certificates for certificate validation, then certificate verification is simplified, but the system becomes vulnerable to fraudulent root certificates being loaded onto the device
Solution Approach 1:
The patent introduces a directory service as an intermediary between the user device and the server. Instead of directly trusting server certificates or having fraudulent root certificates compromise the system, the directory service acts as a trusted mediator that provides authoritative certificate information. The user device queries the directory service to obtain the server's public key certificate, and this certificate from the independent directory service is used for validation, preventing fraudulent certificates from being accepted.
2Reliability
If the server issues a new certificate, then security is improved with updated credentials, but all user devices must re-enroll causing service interruptions
Solution Approach 1:
The patent implements a self-service mechanism where user devices automatically query the directory service for updated server certificates without requiring manual re-enrollment or user intervention. When the server issues a new certificate, the directory service updates its stored certificate information, and subsequent connections automatically retrieve and validate against the new certificate. This eliminates service interruptions while maintaining security.
Solution Approach 2:
The system performs preliminary actions by having user devices query the directory service for server certificates before establishing connections. This proactive approach ensures that devices have the latest valid certificates on hand, and when certificates are updated on the server side, the directory service makes them available for retrieval, allowing seamless transitions without service disruption.
3Reliability
If certificate pinning is implemented to prevent man-in-the-middle attacks, then security is improved, but the system complexity increases
Solution Approach 1:
The patent extracts the certificate storage and management functionality from the user device itself and places it in a separate, centralized directory service. The user device no longer needs to store multiple certificates or manage certificate rotations locally. Instead, it simply queries the directory service for the current server certificate, significantly reducing device complexity while maintaining certificate pinning security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A user device obtains a set of one or more public key certificates for a server received from a directory service, and a current public key certificate of the server received from the server. The user device compares the current public key certificate received from the server with the set of public key certificates received from the directory service. If the current public key certificate of the server matches one of the public key certificates in the set of public key certificates for the server, the authenticity of the server is confirmed, and communications are permitted between the user device and the server. Communications between the user device and the server may be prevented unless the current public key certificate from the server matches a public key certificate in the set of public key certificates received from the directory service.