IP Library › Granted Patent US 11,665,592
Granted Patent B2
US 11,665,592 · App. 17/099,157 · Granted May 30, 2023

Security, fraud detection, and fraud mitigation in device-assisted services systems

Inventors: Gregory G. Raleigh (Woodside, CA); James Lavine (Corte Madera, CA); Jeffrey Green (Sunnyvale, CA)
Assignee: Headwater Research LLC
H04W28/10H04L63/105H04L63/20H04W4/24H04W12/08H04W28/02H04W80/04H04W84/12H04W88/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,665,592
App. No.
17/099,157
Granted
May 30, 2023
Kind
B2
Abstract

Secure architectures and methods for improving the security of mobile devices are disclosed. Also disclosed are apparatuses and methods to detect and mitigate fraud in device-assisted services implementations.

Claims (44)

1. An end-user device comprising:

a modem configured to enable the end-user device to communicate over an access network;

a memory configured to store:

a first application program configured to execute on the end-user device and further configured to assist the end-user device in accessing a data service over the access network using the modem;

a first application credential associated with the first application program;

a first policy comprising one or more first policy instructions; and

one or more device agents configured to:

detect an attempted installation of an update software on the end-user device, the update software purporting to be a modification, update, or replacement of the first application program;

obtain an update software credential associated with the update software;

obtain, from the memory, the first application credential;

allow the update software to be installed on the end-user device when the update software credential matches the first application credential, wherein the first application credential is stored in the memory prior to receiving the update software by the end-user device over the access network using the modem; and

apply the one or more first policy instructions when the update software initiates or attempts to initiate a communication over the access network.

2. The end-user device of claim 1 , wherein the one or more device agents include the first application program.

3. The end-user device of claim 1 , wherein the first application program comprises at least one of a kernel component or a library.

4. The end-user device of claim 1 , wherein the first application credential is stored in a secure location in the memory.

5. The end-user device of claim 1 , wherein the first application credential comprises a hash of at least a portion of the first application program.

6. The end-user device of claim 1 , wherein the first application credential comprises at least one of a secure signature or certificate.

7. The end-user device of claim 1 , wherein the one or more device agents are further configured to obtain the first application credential from a secure hash of the first application program.

8. A method for use by an end-user device, the method comprising:

storing, in a memory, a first application program configured to execute on the end-user device and further configured to assist the end-user device in accessing a data service over an access network using a modem of the end-user device;

storing, in the memory, a first application credential associated with the first application program;

storing, in the memory, a first policy comprising one or more first policy instructions;

detecting, by one or more device agents, an attempted installation of an update software on the end-user device, the update software purporting to be a modification, update, or replacement of the first application program;

obtaining, by the one or more device agents, an update software credential associated with the update software;

obtaining, by the one or more device agents from the memory, the first application credential;

allowing, by the one or more device agents, the update software to be installed on the end-user device when the update software credential matches the first application credential, wherein the first application credential is stored in the memory prior to receiving the update software by the end-user device over the access network using the modem; and

applying, by the one or more device agents, the one or more first policy instructions when the update software initiates or attempts to initiate a communication over the access network.

9. The method of claim 8 , wherein the one or more device agents include the first application program.

10. The method of claim 8 , wherein the first application program comprises at least one of a kernel component or a library.

11. The method of claim 8 , wherein the first application credential is stored in a secure location in the memory.

12. The method of claim 8 , wherein the first application credential comprises a hash of at least a portion of the first application program.

13. The method of claim 8 , wherein the first application credential comprises at least one of a secure signature or certificate.

14. The method of claim 8 , wherein the one or more device agents obtain the first application credential from a secure hash of the first application program.

15. A non-transitory computer readable medium having stored therein a first application program configured to execute on an end-user device and further configured to assist the end-user device in accessing a data service over an access network using a modem of the end-user device, a first application credential associated with the first application program, and a first policy comprising one or more first policy instructions, the non-transitory computer readable medium further having stored therein one or more device agents, which when executed by a processor, perform a method comprising:

detecting an attempted installation of an update software on the end-user device, the update software purporting to be a modification, update, or replacement of the first application program;

obtaining an update software credential associated with the update software;

obtaining, from a memory, the first application credential;

allowing the update software to be installed on the end-user device when the update software credential matches the first application credential, wherein the first application credential is stored in the memory prior to receiving the update software by the end-user device over the access network using the modem; and

applying the one or more first policy instructions when the update software initiates or attempts to initiate a communication over the access network.

16. The non-transitory computer readable medium of claim 15 , wherein the one or more device agents include the first application program.

17. The non-transitory computer readable medium of claim 15 , wherein the first application program comprises at least one of a kernel component or a library.

18. The non-transitory computer readable medium of claim 15 , wherein the first application credential is stored in a secure location in the memory.

19. The non-transitory computer readable medium of claim 15 , wherein the first application credential comprises a hash of at least a portion of the first application program.

20. The non-transitory computer readable medium of claim 15 , wherein the first application credential comprises at least one of a secure signature or certificate.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2021
From: RALEIGH, GREGORY; GREEN, JEFFREY; LAVINE, JAMES
To: HEADWATER PARTNERS I LLC
Reel/Frame 055203/0987 →
MERGER AND CHANGE OF NAME Recorded Jan 28, 2021
From: HEADWATER PARTNERS I LLC; HEADWATER MANAGEMENT LLC
To: HEADWATER RESEARCH LLC
Reel/Frame 055059/0624 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2021
From: RALEIGH, GREGORY; GREEN, JEFFREY; LAVINE, JAMES
To: HEADWATER PARTNERS I LLC
Reel/Frame 055154/0926 →
Continuity (49)
Continuation 16218721 · Dec 13, 2018
Continuation 15158526 · May 18, 2016
Continuation 14098523 · Dec 5, 2013
Continuation In Part 13309463 · Dec 1, 2011
Continuation In Part 13309556 · Dec 1, 2011
Continuation In Part 13253013 · Oct 4, 2011
Continuation In Part 13247998 · Sep 28, 2011
Continuation In Part 13239321 · Sep 21, 2011
Continuation In Part 13134028 · May 25, 2011
Continuation In Part 13237827 · Sep 20, 2011
Continuation In Part 13237827 · Sep 20, 2011
Continuation In Part 13134028 · May 25, 2011
Continuation In Part 13134005 · May 25, 2011
Continuation In Part 12695020 · Jan 27, 2010
Continuation In Part 12694445 · Jan 27, 2010
Continuation In Part 12380778 · Mar 2, 2009
Continuation In Part 12380780 · Mar 2, 2009
Continuation In Part 12380780 · Mar 2, 2009
Continuation In Part 12380778 · Mar 2, 2009
Continuation In Part 12380780 · Mar 2, 2009
Provisional Application 61550906 · Oct 24, 2011
Provisional Application 61472606 · Apr 6, 2011
Provisional Application 61435564 · Jan 24, 2011
Provisional Application 61422565 · Dec 13, 2010
Provisional Application 61422574 · Dec 13, 2010
Provisional Application 61422572 · Dec 13, 2010
Provisional Application 61420727 · Dec 7, 2010
Provisional Application 61418507 · Dec 1, 2010
Provisional Application 61418509 · Dec 1, 2010
Provisional Application 61407358 · Oct 27, 2010
Provisional Application 61389547 · Oct 4, 2010
Provisional Application 61387243 · Sep 28, 2010
Provisional Application 61387247 · Sep 28, 2010
Provisional Application 61385020 · Sep 21, 2010
Provisional Application 61384456 · Sep 20, 2010
Provisional Application 61381159 · Sep 9, 2010
Provisional Application 61381162 · Sep 9, 2010
Provisional Application 61348022 · May 25, 2010
Provisional Application 61264126 · Nov 24, 2009
Provisional Application 61252151 · Oct 15, 2009
Provisional Application 61252153 · Oct 15, 2009
Provisional Application 61237753 · Aug 28, 2009
Provisional Application 61275208 · Aug 25, 2009
Provisional Application 61270353 · Jul 6, 2009
Provisional Application 61207739 · Feb 13, 2009
Provisional Application 61207393 · Feb 10, 2009
Provisional Application 61206944 · Feb 4, 2009
Provisional Application 61206354 · Jan 28, 2009
Related Publication 20210266791A1 · Aug 26, 2021