Verifiable service billing for intermediate networking devices

Patent No. US8023425 (titled "Verifiable service billing for intermediate networking devices") on Mar 2, 2009. The application was issued on Sep 20, 2011.

What is this patent about?

’425 is related to the field of network service management and policy enforcement, specifically focusing on end point devices that act as intermediate gateways. It addresses the technical challenges of managing data traffic when a primary device, such as a smartphone or laptop, shares its wide area network connection with other secondary devices through local interfaces like Wi-Fi, Bluetooth, or USB.

The underlying idea behind ’425 is to transform a standard end point device into a verifiable service intermediary that can enforce complex network access policies usually reserved for core network infrastructure. By integrating a service processor and a forwarding agent directly into the device's communications stack, the system can monitor, notify, and control tethering or hotspot activities based on specific service profiles provided by a remote activation server.

The claims of ’425 focus on an end point device equipped with both an access network modem and a local area network modem, utilizing a forwarding agent to bridge data between them. This agent includes a policy implementation component and a firewall that can pass or redirect traffic to specific routing paths based on restriction settings. The system is designed to detect service-related events, trigger user notifications for service activation, and dynamically update forwarding policies received from a network-side service controller.

In practice, the invention works by detecting when a user attempts to use a device as a hotspot and responding with a notification that offers a specific service plan. Once the user accepts, the device communicates with an activation server to receive a service profile that dictates how traffic from secondary devices should be handled. This allows the service provider to implement granular controls, such as throttling specific types of traffic or redirecting data to authorized gateways, ensuring that the intermediate device adheres to the provider's business and technical rules.

This approach differs from prior solutions by moving the enforcement point from the carrier's core network to the device itself, allowing for granular tethering control even when traffic might otherwise be obscured. By using a dedicated forwarding agent and firewall within the device stack, the system can verify that the service policy is being implemented correctly, preventing unauthorized data usage and enabling flexible, on-demand activation of hotspot services without requiring manual configuration by the network operator.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2000s when ’425 was filed, access network capacity was increasingly constrained by a shift toward mass-market digital content distribution and the proliferation of diverse networked devices. At a time when network management was typically implemented using centralized core infrastructure, systems commonly relied on deep packet inspection (DPI) and traffic shaping profiles managed within the core network rather than at the device level. Hardware and software constraints of the era made the deployment of dense base station architectures non-trivial due to the high costs and technical complexity of backhauling all traffic through dedicated, hierarchical core network equipment.

Prosecution Position

The disclosed invention represents a meaningful technical advancement through an architectural shift that distributes service policy implementation and billing event logging from the core network to the end-user device. By utilizing a virtual network overlay comprising a device-side service processor and a network-side service controller, the system enables granular monitoring and control of encrypted traffic flows and application-specific data that are often opaque to traditional core network elements. This integration allows for a flattened network architecture where base stations can connect directly to the local loop, overcoming the technical constraints of backhaul congestion and core network latency while providing a verifiable mechanism to prevent tampering or spoofing of device-assisted service reports.

Claims

The patent contains a total of 51 claims, with claims 1, 24, 44, and 51 serving as the independent claims. These independent claims focus on the architecture and operation of an access network forwarding service, specifically describing end point devices, network systems, and methods for managing data traffic between a local area network and a wireless access network based on specific forwarding policies and service profiles. The dependent claims serve to further refine these systems and methods by specifying particular restriction settings, such as usage limits, network traffic classifications, parental controls, and notification protocols for the forwarding service.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Access network forwarding policy
(Claim 1, Claim 24, Claim 44, Claim 51)
A service profile includes a set of one or more service policy settings for the device for a service on the network. Aspects of the service policy moved into the end user device include lower level service policy implementations, such as access control settings, traffic control settings, and admission control settings. These policies are used to identify, manage and bill for service usage categories.A set of rules or instructions, including restriction settings and specific routing paths, that governs how an end point device forwards data between additional devices on a local network and a wide area access network.
Access network forwarding service
(Claim 1, Claim 24, Claim 44, Claim 51)
An intermediate networking device is a communications device in which the service processor is configured at least in part to allow the intermediate networking device to act as a service intermediary or intermediate connection between the network and one or more end point devices. Example intermediate networking device embodiments include a Wi-Fi to WWAN (e.g., 2G, 3G, 4G or other wireless wide area networking access technology) bridge or router device. The intermediate networking device connects the end point devices to the network by passing, bridging, forwarding, routing, traffic shaping or otherwise allowing the end point devices to communicate with the network.A service that allows a first end point device to act as a service intermediary or bridge, enabling one or more additional end point devices to access a 2G, 3G, or 4G wireless network through the first device's access network modem and local area network connection.
Activation server
(Claim 1, Claim 24, Claim 51)
The activation server either initiates a specific provisioning sequence if device software is present to assist or routes to a website for manual entry. Once the activation server has determined the activation information, it initiates the necessary network settings and billing database entries to be programmed. The activation server can then also send any necessary service profile and/or service plan settings required for the device to a provisioning and activation support software function on the device.A network-side functional element that performs activation sequences, processes user responses for new services, and provisions end point devices or network elements with the necessary service profiles and credentials to enable specific network services.
Firewall agent
(Claim 1, Claim 24, Claim 51)
In some embodiments, a modem firewall blocks or passes traffic based on service policies and traffic attributes. The modem firewall assists in virtual or literal upstream traffic flow tagging. The policy control agent adapts device service policy settings in one or more agents including the modem firewall.A component of the forwarding agent that controls data flow by passing or redirecting traffic to specific network routing paths according to the established forwarding policy.
Forwarding agent
(Claim 1, Claim 24, Claim 51)
The service processor includes various components, such as device agents, that perform service policy implementation or management functions. These functions include service policy or implementation verification, application access control, traffic control, and network access control services. The policy implementation agent and modem firewall block or pass traffic based on service policies and traffic attributes.A functional component within an end point device, comprising a policy implementation agent and a firewall agent, that manages the transfer of data between a local area network modem and an access network modem based on defined forwarding policies.
Service processor
(Claim 1, Claim 24, Claim 51)
The service processor includes various components, such as device agents, that perform service policy implementation or management functions. These functions include service policy or implementation verification, service policy implementation tamper prevention, service allowance or denial, application access control, and network access control services. The service processor receives policy instructions from the service controller and adapts device service policy settings.A device-based agent or collection of agents responsible for detecting service events, managing user notifications, communicating with activation servers, and implementing or updating service control policies on the end point device.
Service profile
(Claim 1, Claim 24, Claim 51)
A service profile includes a set of one or more service policy settings for the device for a service on the network. The service profile can be assigned to the device and/or network during over the air activation. It includes information associated with service plans, such as billing/costs information and lower level settings like access control and traffic control.A collection of settings and parameters received from a network server that defines the permissions, restrictions, and specific configurations for the access network forwarding service on a device.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
4:25-cv-09558Nov 5, 2025Google LLC v. Headwater Research LLC
3:25-cv-07591Sep 5, 2025Apple Inc v. Headwater Research LLC
5:25-cv-07453Sep 3, 2025Google LLC v. Headwater Research LLC

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US8023425

Application Number
US12380771A
Filing Date
Mar 2, 2009
Publication Date
Sep 20, 2011
External Links
Slate, USPTO , Google Patents