Certificate pinning for android applications

Mahesh Bhor, Deepak Chatrabhuj Karia · 2017 International Conference on Inventive Systems and Control (ICISC) · 2017

The use of the Smartphones is increasing day by day and also used as an essential tool for everyday tasks. Most of the smartphone applications are used to fetch the data from the servers and transmit the sensitive user information to the server. This communication is carried on a wireless network, which is more vulnerable than the wired network. This insecure communication channel needs to be protected from the vulnerable attack without compromising the security risk to protect the sensitive information against passive and active attacks. In this paper, we discuss the android security related issues and method to overcome this issue. We have implemented the concept of certificate pinning for Android applications and shown that it can reduce the risk of a Man-in-the-middle attack (MITM).

Read the paper · More papers on PaperTik