首页> 外国专利> ACHIEVING CERTIFICATE PINNING SECURITY IN REDUCED TRUST NETWORKS

ACHIEVING CERTIFICATE PINNING SECURITY IN REDUCED TRUST NETWORKS

机译:在减少信任网络中实现证书固定安全性

摘要

Achieving certificate pinning security in reduced trust networks. A client establishes a first communications channel with a server only upon verifying that a first certificate offered by the server is certified by a pinned certificate. The client receives a second certificate from the server over the first communications channel. The server and the client establish second communications channels with an untrusted computer system. The client sends a request towards the server via the second communications channels, and the request is received by the server. The server generates a response comprising a payload, a timestamp, a URI portion, and a signature that is generated using the second certificate, and sends the response via the second communications channels. The client receives the response and uses the second certificate to verify that the response is authentic and that the timestamp and URI portion are valid. The client then processes the payload.
机译:在减少信任网络中实现证书固定安全性。客户端仅在验证服务器提供的第一证书通过固定证书认证时建立具有服务器的第一通信信道。客户端通过第一通信信道从服务器接收第二证书。服务器和客户端用不可信的计算机系统建立第二通信信道。客户端通过第二通信通道向服务器发送请求,并由服务器接收该请求。服务器生成包括使用第二证书生成的有效载荷,时间戳,URI部分和签名的响应,并通过第二通信信道发送响应。客户端收到响应并使用第二个证书来验证响应是真实的,并且时间戳和URI部分是有效的。然后,客户端处理有效载荷。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号