IP Library Granted Patent US 11,184,336
Granted Patent B2
US 11,184,336 · App. 16/682,205 · Granted Nov 23, 2021

Public key pinning for private networks

Inventor: Jonathon Deriso (Suwanee, GA)
Assignee: AirWatch LLC
H04L63/0442H04L9/3242H04L9/3247H04L9/3263H04L63/0823H04L63/0876H04L63/126H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,184,336
App. No.
16/682,205
Granted
Nov 23, 2021
Kind
B2
Abstract

Disclosed are various approaches for validating public keys pinned to services or servers on private networks. A client device can request a first certificate from a trust service. The client device can then validate that the first certificate from the trust service is signed by a preinstalled certificate stored on the client device. Subsequently, the client device can receive a uniform resource locator identifying a network location of a secure sockets layer (SSL) pinning service, wherein the SSL pinning service is configured to provide a hash value for a first public key issued to a computing device. Finally, the client device can receive a second public key from the trust service, wherein the second public key is configured to encrypt network traffic sent to the SSL pinning service.

Claims (46)

1. A system, comprising:

a computing device comprising a processor and a memory;

an application comprising machine readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least:

validate a trust service by verifying that a first server key from the trust service is signed by a preinstalled certificate stored on the computing device;

in response to transmitting a first request to the trust service, receive a network location of a secure socket layer (SSL) pinning service;

generate a first hash for the first server key;

in response to transmitting a second request, receive a second hash from the SSL pinning service, the second hash being generated from a second server key; and

validate a management service by comparing the first hash associated with the first server key to the second hash, the management service being configured to manage an operation of the computing device.

2. The system of claim 1 , wherein the application further comprises machine readable instructions that cause the computing device to at least:

send an enrollment request to the management service, wherein the enrollment request includes a request for a network location of the trust service; and

in response to receiving the network location of the trust service from the management service, send a key request to the trust service for the first server key.

3. The system of claim 1 , wherein the computing device, the trust service, and the SSL pinning service are connected to a local area network (LAN) in which access is restricted to authorized devices, and the LAN is connected to the Internet.

4. The system of claim 1 , wherein validating the management service indicates that data communication with the management service can be encrypted using the first server key.

5. The system of claim 1 , wherein the preinstalled certificate is stored in association with an installation of a management agent.

6. The system of claim 1 , wherein the application further comprises machine readable instructions that cause the computing device to at least:

transmit to the management service a device identifier associated with the computing device in an instance after the validation of the management service.

7. The system of claim 1 , wherein the second request comprises an identifier of the first server key.

8. A method, comprising:

validating, with a client device, a trust service by verifying that a first server key from the trust service is signed by a preinstalled certificate stored on the client device;

in response to transmitting a first request to the trust service, receiving, with the client device, a network location of a secure socket layer (SSL) pinning service;

generating, with the client device, a first hash for the first server key;

in response to transmitting a second request, receiving, with the client device, a second hash from the SSL pinning service, the second hash being generated from a second server key; and

validating, with the client device, a management service by comparing the first hash associated with the first server key to the second hash, the management service being configured to manage an operation of the client device.

9. The method of claim 8 , further comprising:

sending an enrollment request to the management service, wherein the enrollment request includes a request for a network location of the trust service; and

in response to receiving the network location of the trust service from the management service, sending a key request to the trust service for the first server key.

10. The method of claim 8 , wherein the client device, the trust service, and the SSL pinning service are connected to a local area network (LAN) in which access is restricted to authorized devices, and the LAN is connected to the Internet.

11. The method of claim 8 , wherein validating the management service indicates that data communication with the management service can be encrypted using the first server key.

12. The method of claim 8 , wherein the preinstalled certificate is stored in association with an installation of a management agent.

13. The method of claim 8 , further comprising:

transmitting to the management service a device identifier associated with the client device in an instance after the validation of the management service.

14. The method of claim 8 , wherein the second request comprises an identifier of the first server key.

15. A non-transitory computer readable medium comprising machine readable instructions that, when executed by a processor of a first computing device, cause the first computing device to at least:

validate a trust service by verifying that a first server key from the trust service is signed by a preinstalled certificate stored on the first computing device;

in response to transmitting a first request to the trust service, receive a network location of a secure socket layer (SSL) pinning service;

generate a first hash for the first server key;

in response to transmitting a second request, receive a second hash from the SSL pinning service, the second hash being generated from a second server key; and

validate a management service by comparing the first hash associated with the first server key to the second hash, the management service being configured to manage an operation of the first computing device.

16. The non-transitory computer readable medium of claim 15 , further comprising machine readable instructions that cause the first computing device to at least:

send an enrollment request to the management service, wherein the enrollment request includes a request for a network location of the trust service; and

in response to receiving the network location of the trust service from the management service, send a key request to the trust service for the first server key.

17. The non-transitory computer readable medium of claim 15 , wherein the first computing device, the trust service, and the SSL pinning service are connected to a local area network (LAN) in which access is restricted to authorized devices, and the LAN is connected to the Internet.

18. The non-transitory computer readable medium of claim 15 , wherein validating the management service indicates that data communication with the management service can be encrypted using the first server key.

19. The non-transitory computer readable medium of claim 15 , wherein the preinstalled certificate is stored in association with an installation of a management agent.

20. The non-transitory computer readable medium of claim 15 , further comprising machine readable instructions that cause the first computing device to at least:

transmit to the management service a device identifier associated with the first computing device in an instance after the validation of the management service.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Continuity (2)
Continuation 15196763 · Jun 29, 2016
Related Publication 20200084190A1 · Mar 12, 2020
Cited By (1)
US 12,210,815