Security, fraud detection, and fraud mitigation in device-assisted services systems
Secure architectures and methods for improving the security of mobile devices are disclosed. Also disclosed are apparatuses and methods to detect and mitigate fraud in device-assisted services implementations.
1. A method for use by a system including one or more processors, the method comprising:
receiving, by the one or more processors from a first end-user device of a plurality of end-user devices, a request for a device credential, the request including a device identifier;
generating, by the one or more processors and in response to the request, the device credential;
storing, by the one or more processors and in response to the request, the device credential in a database;
sending, by the one or more processors and in response to the request, the device credential to the first end-user device;
receiving, by the one or more processors, a first application credential associated with a first application installed on the first end-user device;
generating, by the one or more processors, a signed application credential based on the first application credential and the device credential stored in the database; and
sending, by the one or more processors, the signed application credential to the first end-user device.
2. The method of claim 1 , wherein the request further includes a subscriber identifier.
3. The method of claim 1 , wherein the one or more processors receive the first application credential from a trusted source.
4. The method of claim 1 , wherein generating the device credential includes encrypting the device credential with a key.
5. The method of claim 1 , wherein the signed application credential is a run-time application credential.
6. The method of claim 5 , further comprising:
evaluating, by the one or more processors, the run-time application credential.
7. The method of claim 1 , further comprising:
refreshing, based on an event, the signed application credential to create a different signed application credential unique to the first end-user device;
sending the different signed application credential to the first end-user device to supersede the signed application credential.
8. The method of claim 1 , wherein the signed application credential is generated based on a combination of the first application credential and the device credential stored in the database.
9. The method of claim 8 , wherein the combination includes a hash.
10. The method of claim 1 , further comprising:
using the device credential to establish a secure communication with the first end-user device.
11. A system comprising:
one or more processors configured to:
receive, from a first end-user device of a plurality of end-user devices, a request for a device credential, the request including a device identifier;
generate, in response to the request, the device credential;
store, in response to the request, the device credential in a database;
send, in response to the request, the device credential to the first end-user device;
receive a first application credential associated with a first application installed on the first end-user device;
generate a signed application credential based on the first application credential and the device credential stored in the database; and
send the signed application credential to the first end-user device.
12. The system of claim 11 , wherein the request further includes a subscriber identifier.
13. The system of claim 11 , wherein the one or more processors are configured to receive the first application credential from a trusted source.
14. The system of claim 11 , wherein generating the device credential includes encrypting the device credential with a key.
15. The system of claim 11 , wherein the signed application credential is a run-time application credential.
16. The system of claim 15 , wherein the one or more processors are further configured to:
evaluate the run-time application credential.
17. The system of claim 11 , wherein the one or more processors are further configured to:
refresh, based on an event, the signed application credential to create a different signed application credential unique to the first end-user device;
send the different signed application credential to the first end-user device to supersede the signed application credential.
18. The system of claim 11 , wherein the signed application credential is generated based on a combination of the first application credential and the device credential stored in the database.
19. The system of claim 18 , wherein the combination includes a hash.
20. The system of claim 11 , wherein the one or more processors are further configured to:
use the device credential to establish a secure communication with the first end-user device.