IP Library Granted Patent US 9,306,933
Granted Patent B2
US 9,306,933 · App. 13/924,194 · Granted Apr 5, 2016

Ensuring network connection security between a wrapped app and a remote server

Inventors: Michael Scott Pontillo (Roseville, CA); James Blaisdell (Novato, CA); Brian H. Pescatore (Natick, MA)
Assignee: Mocana Corporation
H04L63/0823G06F21/51H04L63/0272H04W4/00H04W12/02H04L63/0227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,306,933
App. No.
13/924,194
Granted
Apr 5, 2016
Kind
B2
Abstract

A network connection between an app on a mobile device and a remote server is either enabled or denied based on whether a security wrapped app can verify that the connection is with a known and trusted server. The wrapped app uses a socket interception layer injected into the app code along with a trust store, also part of the wrapped app to determine whether a network connection attempted by the app should be allowed. The layer buffers relevant function calls from the app by intercepting them before they reach the device operating system. If the layer determines that a network connection is attempted, then it snoops the negotiation phase data stream to discern when the server sends a certificate to the app. It obtains this certificate and compares it to data in the trust store and makes a determination of whether the server is known and trusted.

Claims (17)

1. A method of enabling a network connection between an app on a remote device and a remote server, the method comprising:

during execution of an application on the remote device, attempting to open the network connection with the remote server;

intercepting relevant function calls to and from the application, said intercepting done by a sockets interception layer on top of an IP stack specifically for the application, wherein said relevant function calls are re-directed to the sockets interception layer and selected based on socket characteristics;

correlating said relevant function calls with a particular network connection;

discerning a certificate by observing data stream between the application and the remote server;

comparing the certificate with a trust store in the application;

determining whether the certificate can be trusted; and

allowing the network connection if the certificate is authenticated and trusted, the network connection between the application and the remote server.

2. A method of enabling a network connection between an application on a mobile device and a remote server, the method comprising:

intercepting function calls between the application and the remote server;

examining a function call to determine if the function call is over the network connection;

determining whether the application is attempting to make the network connection with the remote server;

observing a data stream between the application and the remote server;

discerning a certificate by observing the data stream;

comparing the certificate with a trust store in the application;

determining whether the certificate is trusted by the application; and

allowing the network connection with the remote server.

Assignments (3)
SECURITY INTEREST Recorded Jul 30, 2019
From: BLUE CEDAR NETWORKS, INC.
To: KREOS CAPITAL VI (UK) LIMITED
Reel/Frame 049909/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2016
From: MOCANA CORPORATION
To: BLUE CEDAR NETWORKS, INC.
Reel/Frame 039744/0142 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2013
From: PONTILLO, MICHAEL SCOTT; BLAISDELL, JAMES; PESCATORE, BRIAN H.
To: MOCANA CORPORATION
Reel/Frame 031103/0279 →
Continuity (4)
Continuation In Part 13875151 · May 1, 2013
Continuation In Part 13025994 · Feb 11, 2011
Provisional Application 61662555 · Jun 21, 2012
Related Publication 20130291086A1 · Oct 31, 2013