Tokenized mobile device update systems and methods
Systems and methods are provided for managing mobile device updates. In some embodiments, the disclosed systems can include a key provisioning system, a key system, and mobile devices. The key provisioning system can provide keys to the mobile devices and the key system. The key system can receive a key from the key provisioning system, receive a request from an application system, calculate a first token, and provide the first token to the application system for transmission to a mobile device. The mobile device can receive a key from the key provisioning system, establish a local connection with a connected device, receive an application and the first token from the connected device, generate a second token using the application and the key, compare the first token and the second token, and update the mobile device according to the application based on a result of the comparison.
1. A key system for managing security of mobile device updates, comprising:
at least one processor, and
at least one computer-readable media containing instructions that, when executed cause the system to perform operations comprising:
receiving, from a key provisioning system, a public key corresponding to a private key provided to a mobile device;
receiving, from an application system, a request for token creation, the request for token creation comprising an application and credentials for at least one of a connected device, the mobile device, or the application system;
generating, based on the application and validation of the credentials, a token, wherein the token comprises a keyed hash of the application generated with the public key; and
providing, to the connected device, the token for authentication of the application by the connected device or the mobile device.
2. The system of claim 1 , the operations further comprising validating the credentials.
3. The system of claim 1 , wherein the request for token creation further comprises a timestamp.
4. The system of claim 3 , wherein the request for token creation is generated based on the timestamp.
5. The system of claim 1 , wherein the request for token creation further comprises a nonce value.
6. The system of claim 5 , wherein the request for token creation is generated based on the nonce value.
7. The system of claim 4 , the operations further comprising providing, to the connected device, the timestamp.
8. The system of claim 6 , the operations further comprising providing, to the connected device, the nonce value.
9. A method for managing security of device updates performed by a key system:
receiving, from a key provisioning system, a public key corresponding to a private key provided to a mobile device;
receiving, from an application system, a request for token creation, the request for token creation comprising an application and credentials for at least one of a connected device, the mobile device, or the application system;
generating, based on the application and validation of the credentials, a token, wherein the token comprises a keyed hash of the application generated with the public key; and
providing, to the connected device, the token for authentication of the application by the connected device or the mobile device.
10. The method of claim 9 , the method further comprising validating the credentials.
11. The method of claim 9 , wherein the request for token creation further comprises a timestamp.
12. The method of claim 11 , wherein the request for token creation is generated based on the timestamp.
13. The method of claim 12 , the method further comprising providing, to the connected device, the timestamp.
14. The method of claim 9 , wherein the request for token creation further comprises a nonce value.
15. The method of claim 14 , wherein the token is generated based on the nonce value.
16. The method of claim 15 , the method further comprising providing, to the connected device, the nonce value.