US2021083881A1PendingUtilityA1

Dynamically analyzing third-party application website certificates across users to detect malicious activity

Assignee: OKTA INCPriority: Jun 22, 2018Filed: Nov 25, 2020Published: Mar 18, 2021
Est. expiryJun 22, 2038(~11.9 yrs left)· nominal 20-yr term from priority
H04L 63/0272H04L 9/3268H04W 12/069H04L 63/0823H04W 12/03G06F 21/44G06F 21/51H04L 9/321G06F 21/33H04L 63/0428H04L 9/3263H04L 63/12G06F 2221/2115G06F 2221/2119H04L 9/0643
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A verification server provides certificate verification services to users of third-party application sites. In some embodiments, a verifier component of a user's client device provides the verification server with a certificate of a third-party application site, and the verification server indicates whether the certificate is successfully verified. In response to successful verification, the verifier component of the user's client device takes an action such as permitting the user's credentials to be provided to the third-party application site. In some embodiments, verifier components of numerous client devices provide certificates to the verification server, based on which the verification server learns which certificates are valid for a given third-party application site.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method performed on a client device, the computer-implemented method comprising:
 requesting, by a web browser for a user, a web page of a third-party application web site;   receiving the web page and a corresponding certificate from the third-party application web site;   computing, by a plugin of the web browser of the client device, a fingerprint of the certificate;   sending, by the plugin to a server, the fingerprint of the certificate and an identifier of the third-party application;   receiving, by the plugin from the server, an indication that the fingerprint of the certificate matches a known fingerprint of a certificate of the third-party application that was reported to the server by client devices other than the client device, the reporting being performed by plugins of web browsers of the client devices other than the client device; and   responsive to receiving the indication, automatically sending, by the plugin without express user confirmation, credentials of the user to the third-party application.   
     
     
         2 . A non-transitory computer-readable storage medium storing executable instructions that when executed by a processor of a client device perform actions comprising:
 requesting, for a user, a web page of a third-party application web site;   receiving the web page and a corresponding certificate from the third-party application web site;   sending, to a server by a verifier component of the client device, a representation of the certificate and an identifier of the third-party application;   receiving an indication from the server that the representation matches a stored certificate representation of the third-party application; and   responsive to receiving the indication, permitting, by the verifier component, credentials of the user to be provided to the third-party application.   
     
     
         3 . The non-transitory computer-readable storage medium of  claim 2 , the actions further comprising computing a fingerprint of the certificate as the certificate representation. 
     
     
         4 . The non-transitory computer-readable storage medium of  claim 2 , wherein the verifier component is a web browser plugin. 
     
     
         5 . The non-transitory computer-readable storage medium of  claim 2 , wherein the client device is a smartphone, and the verifier component is a security application installed on the smartphone. 
     
     
         6 . The non-transitory computer-readable storage medium of  claim 2 , further comprising:
 requesting, for a user, a web page of a second third-party application web site;   receiving the web page and a corresponding second certificate;   sending, to the server by the verifier component of the client device, a second representation of the second certificate and an identifier of the second third-party application;   receiving a second indication from the server that the second representation fails to match a stored certificate representation of the second third-party application.   
     
     
         7 . The non-transitory computer-readable storage medium of  claim 6 , further comprising:
 responsive to receiving the second indication:
 initiating a virtual private network (VPN) connection with a trusted server, 
 using the VPN connection to communicate with the second third-party application, 
 receiving a third certificate from the second third-party application website, 
 sending, to the server by the verifier component of the client device, a third representation of the third certificate and an identifier of the second third-party application, 
 receiving a third indication from the server that the third representation matches a stored certificate representation of the second third-party application, and 
 responsive to receiving the third indication, ceasing to use the VPN connection for communication with the second third-party application site. 
   
     
     
         8 . A computer-implemented method performed on a client device, the computer-implemented method comprising:
 requesting, for a user, a web page of a third-party application web site;   receiving the web page and a corresponding certificate from the third-party application web site;   sending, to a server by a verifier component of the client device, a representation of the certificate and an identifier of the third-party application;   receiving an indication from the server that the representation matches a stored certificate representation of the third-party application; and   responsive to receiving the indication, permitting, by the verifier component, credentials of the user to be provided to the third-party application.   
     
     
         9 . The computer-implemented method of  claim 8 , further comprising computing a fingerprint of the certificate as the certificate representation. 
     
     
         10 . The computer-implemented method of  claim 8 , wherein the verifier component is a web browser plugin. 
     
     
         11 . The computer-implemented method of  claim 8 , wherein the client device is a smartphone, and the verifier component is a security application installed on the smartphone. 
     
     
         12 . The computer-implemented method of  claim 8 , further comprising:
 requesting, for a user, a web page of a second third-party application website;   receiving the web page and a corresponding second certificate;   sending, to the server by the verifier component of the client device, a second representation of the second certificate and an identifier of the second third-party application;   receiving a second indication from the server that the second representation fails to match a stored certificate representation of the second third-party application.   
     
     
         13 . The computer-implemented method of  claim 12 , further comprising:
 responsive to receiving the second indication:
 initiating a virtual private network (VPN) connection with a trusted server, 
 using the VPN connection to communicate with the second third-party application, 
 receiving a third certificate from the second third-party application website, 
 sending, to the server by the verifier component of the client device, a third representation of the third certificate and an identifier of the second third-party application, 
 receiving a third indication from the server that the third representation matches a stored certificate representation of the second third-party application, and 
 responsive to receiving the third indication, ceasing to use the VPN connection for communication with the second third-party application site.

Join the waitlist — get patent alerts

Track US2021083881A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.