Directory Service Certificate Pinning for Secure Server Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies for preventing man-in-the-middle attacks are vulnerable to fraudulent root certificates and require user devices to re-enroll with servers upon certificate changes, causing service interruptions and user inconvenience.

Innovation Solution

A computer-implemented method where a user device performs certificate pinning by requesting and storing public key certificates from a separate directory service, comparing them with the server's certificate to ensure authenticity, and periodically updating certificates to maintain secure communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user devices rely on built-in root certificates for certificate validation, then certificate verification is simplified, but the system becomes vulnerable to fraudulent root certificates being loaded onto the device

Engineering Contradiction:
Improvecertificate verificationVSAvoidsecurity against fraudulent certificates
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a directory service as an intermediary between the user device and the server. Instead of directly trusting server certificates or having fraudulent root certificates compromise the system, the directory service acts as a trusted mediator that provides authoritative certificate information. The user device queries the directory service to obtain the server's public key certificate, and this certificate from the independent directory service is used for validation, preventing fraudulent certificates from being accepted.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the server issues a new certificate, then security is improved with updated credentials, but all user devices must re-enroll causing service interruptions

Engineering Contradiction:
ImprovesecurityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a self-service mechanism where user devices automatically query the directory service for updated server certificates without requiring manual re-enrollment or user intervention. When the server issues a new certificate, the directory service updates its stored certificate information, and subsequent connections automatically retrieve and validate against the new certificate. This eliminates service interruptions while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by having user devices query the directory service for server certificates before establishing connections. This proactive approach ensures that devices have the latest valid certificates on hand, and when certificates are updated on the server side, the directory service makes them available for retrieval, allowing seamless transitions without service disruption.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If certificate pinning is implemented to prevent man-in-the-middle attacks, then security is improved, but the system complexity increases

Engineering Contradiction:
Improveprotection against man-in-the-middle attacksVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the certificate storage and management functionality from the user device itself and places it in a separate, centralized directory service. The user device no longer needs to store multiple certificates or manage certificate rotations locally. Instead, it simply queries the directory service for the current server certificate, significantly reducing device complexity while maintaining certificate pinning security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3414880B1Certificate pinning using a directory service
Publication Date: 2020.09.16 CITRIX SYSTEMS INC
  • EP3414880B1 patent drawingFigure 1
  • EP3414880B1 patent drawingFigure 2
  • EP3414880B1 patent drawingFigure 3

AI summary

A user device obtains a set of one or more public key certificates for a server received from a directory service, and a current public key certificate of the server received from the server. The user device compares the current public key certificate received from the server with the set of public key certificates received from the directory service. If the current public key certificate of the server matches one of the public key certificates in the set of public key certificates for the server, the authenticity of the server is confirmed, and communications are permitted between the user device and the server. Communications between the user device and the server may be prevented unless the current public key certificate from the server matches a public key certificate in the set of public key certificates received from the directory service.