IP Library › Granted Patent US 12,120,551
Granted Patent B2
US 12,120,551 · App. 18/136,255 · Granted Oct 15, 2024

Security, fraud detection, and fraud mitigation in device-assisted services systems

Inventors: Gregory G. Raleigh (Incline Village, NV); James Lavine (Denver, NC); Jeffrey Green (Sunnyvale, CA)
Assignee: Headwater Research LLC
H04W28/10H04L63/105H04L63/20H04W4/24H04W12/08H04W28/02H04W80/04H04W84/12H04W88/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,120,551
App. No.
18/136,255
Granted
Oct 15, 2024
Kind
B2
Abstract

Secure architectures and methods for improving the security of mobile devices are disclosed. Also disclosed are apparatuses and methods to detect and mitigate fraud in device-assisted services implementations.

Claims (43)

1. A method for use by a system including one or more processors, the method comprising:

receiving, by the one or more processors from a first end-user device of a plurality of end-user devices, a request for a device credential, the request including a device identifier;

generating, by the one or more processors and in response to the request, the device credential;

storing, by the one or more processors and in response to the request, the device credential in a database;

sending, by the one or more processors and in response to the request, the device credential to the first end-user device;

receiving, by the one or more processors, a first application credential associated with a first application installed on the first end-user device;

generating, by the one or more processors, a signed application credential based on the first application credential and the device credential stored in the database; and

sending, by the one or more processors, the signed application credential to the first end-user device.

2. The method of claim 1 , wherein the request further includes a subscriber identifier.

3. The method of claim 1 , wherein the one or more processors receive the first application credential from a trusted source.

4. The method of claim 1 , wherein generating the device credential includes encrypting the device credential with a key.

5. The method of claim 1 , wherein the signed application credential is a run-time application credential.

6. The method of claim 5 , further comprising:

evaluating, by the one or more processors, the run-time application credential.

7. The method of claim 1 , further comprising:

refreshing, based on an event, the signed application credential to create a different signed application credential unique to the first end-user device;

sending the different signed application credential to the first end-user device to supersede the signed application credential.

8. The method of claim 1 , wherein the signed application credential is generated based on a combination of the first application credential and the device credential stored in the database.

9. The method of claim 8 , wherein the combination includes a hash.

10. The method of claim 1 , further comprising:

using the device credential to establish a secure communication with the first end-user device.

11. A system comprising:

one or more processors configured to:

receive, from a first end-user device of a plurality of end-user devices, a request for a device credential, the request including a device identifier;

generate, in response to the request, the device credential;

store, in response to the request, the device credential in a database;

send, in response to the request, the device credential to the first end-user device;

receive a first application credential associated with a first application installed on the first end-user device;

generate a signed application credential based on the first application credential and the device credential stored in the database; and

send the signed application credential to the first end-user device.

12. The system of claim 11 , wherein the request further includes a subscriber identifier.

13. The system of claim 11 , wherein the one or more processors are configured to receive the first application credential from a trusted source.

14. The system of claim 11 , wherein generating the device credential includes encrypting the device credential with a key.

15. The system of claim 11 , wherein the signed application credential is a run-time application credential.

16. The system of claim 15 , wherein the one or more processors are further configured to:

evaluate the run-time application credential.

17. The system of claim 11 , wherein the one or more processors are further configured to:

refresh, based on an event, the signed application credential to create a different signed application credential unique to the first end-user device;

send the different signed application credential to the first end-user device to supersede the signed application credential.

18. The system of claim 11 , wherein the signed application credential is generated based on a combination of the first application credential and the device credential stored in the database.

19. The system of claim 18 , wherein the combination includes a hash.

20. The system of claim 11 , wherein the one or more processors are further configured to:

use the device credential to establish a secure communication with the first end-user device.

Continuity (56)
Continuation 17099157 · Nov 16, 2020
Continuation 16218721 · Dec 13, 2018
Continuation 15158526 · May 18, 2016
Continuation 14098523 · Dec 5, 2013
Continuation In Part 13239321 · Sep 21, 2011
Continuation In Part 13247998 · Sep 28, 2011
Continuation In Part 13309463 · Dec 1, 2011
Continuation In Part 13309556 · Dec 1, 2011
Continuation In Part 13237827 · Sep 20, 2011
Continuation In Part 12380778 · Mar 2, 2009
Continuation In Part 12380780 · Mar 2, 2009
Continuation In Part 13134028 · May 25, 2011
Continuation In Part 13237827 · Sep 20, 2011
Continuation In Part 13253013 · Oct 4, 2011
Continuation In Part 13134028 · May 25, 2011
Continuation In Part 12380780 · Mar 2, 2009
Continuation In Part 12695019 · Jan 27, 2010
Continuation In Part 12695021 · Jan 27, 2010
Continuation In Part 13134005 · May 25, 2011
Continuation In Part 12695020 · Jan 27, 2010
Continuation In Part 12694445 · Jan 27, 2010
Continuation In Part 12380778 · Mar 2, 2009
Continuation In Part 12380780 · Mar 2, 2009
Continuation In Part 12380780 · Mar 2, 2009
Continuation In Part 12380780 · Mar 2, 2009
Continuation In Part 12380778 · Mar 2, 2009
Continuation In Part 12380780 · Mar 2, 2009
Provisional Application 61385020 · Sep 21, 2010
Provisional Application 61387243 · Sep 28, 2010
Provisional Application 61387247 · Sep 28, 2010
Provisional Application 61420727 · Dec 7, 2010
Provisional Application 61422565 · Dec 13, 2010
Provisional Application 61418509 · Dec 1, 2010
Provisional Application 61550906 · Oct 24, 2011
Provisional Application 61418507 · Dec 1, 2010
Provisional Application 61384456 · Sep 20, 2010
Provisional Application 61348022 · May 25, 2010
Provisional Application 61381159 · Sep 9, 2010
Provisional Application 61381162 · Sep 9, 2010
Provisional Application 61407358 · Oct 27, 2010
Provisional Application 61389547 · Oct 4, 2010
Provisional Application 61270353 · Jul 6, 2009
Provisional Application 61264126 · Nov 24, 2009
Provisional Application 61275208 · Aug 25, 2009
Provisional Application 61237753 · Aug 28, 2009
Provisional Application 61252151 · Oct 15, 2009
Provisional Application 61252153 · Oct 15, 2009
Provisional Application 61422572 · Dec 13, 2010
Provisional Application 61422574 · Dec 13, 2010
Provisional Application 61435564 · Jan 24, 2011
Provisional Application 61472606 · Apr 6, 2011
Provisional Application 61206354 · Feb 18, 2009
Provisional Application 61206944 · Feb 4, 2009
Provisional Application 61207393 · Feb 10, 2009
Provisional Application 61207739 · Feb 13, 2009
Related Publication 20230269625A1 · Aug 24, 2023