Security, fraud detection, and fraud mitigation in device-assisted services systems
Secure architectures and methods for improving the security of mobile devices are disclosed. Also disclosed are apparatuses and methods to detect and mitigate fraud in device-assisted services implementations.
1. An end-user device comprising:
a modem configured to enable the end-user device to communicate over an access network;
a memory configured to store:
a first application program configured to execute on the end-user device and further configured to assist the end-user device in accessing a data service over the access network using the modem;
a first application credential associated with the first application program;
a first policy comprising one or more first policy instructions; and
one or more device agents configured to:
detect an attempted installation of an update software on the end-user device, the update software purporting to be a modification, update, or replacement of the first application program;
obtain an update software credential associated with the update software;
obtain, from the memory, the first application credential;
allow the update software to be installed on the end-user device when the update software credential matches the first application credential, wherein the first application credential is stored in the memory prior to receiving the update software by the end-user device over the access network using the modem; and
apply the one or more first policy instructions when the update software initiates or attempts to initiate a communication over the access network.
2. The end-user device of claim 1 , wherein the one or more device agents include the first application program.
3. The end-user device of claim 1 , wherein the first application program comprises at least one of a kernel component or a library.
4. The end-user device of claim 1 , wherein the first application credential is stored in a secure location in the memory.
5. The end-user device of claim 1 , wherein the first application credential comprises a hash of at least a portion of the first application program.
6. The end-user device of claim 1 , wherein the first application credential comprises at least one of a secure signature or certificate.
7. The end-user device of claim 1 , wherein the one or more device agents are further configured to obtain the first application credential from a secure hash of the first application program.
8. A method for use by an end-user device, the method comprising:
storing, in a memory, a first application program configured to execute on the end-user device and further configured to assist the end-user device in accessing a data service over an access network using a modem of the end-user device;
storing, in the memory, a first application credential associated with the first application program;
storing, in the memory, a first policy comprising one or more first policy instructions;
detecting, by one or more device agents, an attempted installation of an update software on the end-user device, the update software purporting to be a modification, update, or replacement of the first application program;
obtaining, by the one or more device agents, an update software credential associated with the update software;
obtaining, by the one or more device agents from the memory, the first application credential;
allowing, by the one or more device agents, the update software to be installed on the end-user device when the update software credential matches the first application credential, wherein the first application credential is stored in the memory prior to receiving the update software by the end-user device over the access network using the modem; and
applying, by the one or more device agents, the one or more first policy instructions when the update software initiates or attempts to initiate a communication over the access network.
9. The method of claim 8 , wherein the one or more device agents include the first application program.
10. The method of claim 8 , wherein the first application program comprises at least one of a kernel component or a library.
11. The method of claim 8 , wherein the first application credential is stored in a secure location in the memory.
12. The method of claim 8 , wherein the first application credential comprises a hash of at least a portion of the first application program.
13. The method of claim 8 , wherein the first application credential comprises at least one of a secure signature or certificate.
14. The method of claim 8 , wherein the one or more device agents obtain the first application credential from a secure hash of the first application program.
15. A non-transitory computer readable medium having stored therein a first application program configured to execute on an end-user device and further configured to assist the end-user device in accessing a data service over an access network using a modem of the end-user device, a first application credential associated with the first application program, and a first policy comprising one or more first policy instructions, the non-transitory computer readable medium further having stored therein one or more device agents, which when executed by a processor, perform a method comprising:
detecting an attempted installation of an update software on the end-user device, the update software purporting to be a modification, update, or replacement of the first application program;
obtaining an update software credential associated with the update software;
obtaining, from a memory, the first application credential;
allowing the update software to be installed on the end-user device when the update software credential matches the first application credential, wherein the first application credential is stored in the memory prior to receiving the update software by the end-user device over the access network using the modem; and
applying the one or more first policy instructions when the update software initiates or attempts to initiate a communication over the access network.
16. The non-transitory computer readable medium of claim 15 , wherein the one or more device agents include the first application program.
17. The non-transitory computer readable medium of claim 15 , wherein the first application program comprises at least one of a kernel component or a library.
18. The non-transitory computer readable medium of claim 15 , wherein the first application credential is stored in a secure location in the memory.
19. The non-transitory computer readable medium of claim 15 , wherein the first application credential comprises a hash of at least a portion of the first application program.
20. The non-transitory computer readable medium of claim 15 , wherein the first application credential comprises at least one of a secure signature or certificate.