Patent No. US8023425 (titled "Verifiable service billing for intermediate networking devices") on Mar 2, 2009. The application was issued on Sep 20, 2011.
’425 is related to the field of network service management and policy enforcement, specifically focusing on end point devices that act as intermediate gateways. It addresses the technical challenges of managing data traffic when a primary device, such as a smartphone or laptop, shares its wide area network connection with other secondary devices through local interfaces like Wi-Fi, Bluetooth, or USB.
The underlying idea behind ’425 is to transform a standard end point device into a verifiable service intermediary that can enforce complex network access policies usually reserved for core network infrastructure. By integrating a service processor and a forwarding agent directly into the device's communications stack, the system can monitor, notify, and control tethering or hotspot activities based on specific service profiles provided by a remote activation server.
The claims of ’425 focus on an end point device equipped with both an access network modem and a local area network modem, utilizing a forwarding agent to bridge data between them. This agent includes a policy implementation component and a firewall that can pass or redirect traffic to specific routing paths based on restriction settings. The system is designed to detect service-related events, trigger user notifications for service activation, and dynamically update forwarding policies received from a network-side service controller.
In practice, the invention works by detecting when a user attempts to use a device as a hotspot and responding with a notification that offers a specific service plan. Once the user accepts, the device communicates with an activation server to receive a service profile that dictates how traffic from secondary devices should be handled. This allows the service provider to implement granular controls, such as throttling specific types of traffic or redirecting data to authorized gateways, ensuring that the intermediate device adheres to the provider's business and technical rules.
This approach differs from prior solutions by moving the enforcement point from the carrier's core network to the device itself, allowing for granular tethering control even when traffic might otherwise be obscured. By using a dedicated forwarding agent and firewall within the device stack, the system can verify that the service policy is being implemented correctly, preventing unauthorized data usage and enabling flexible, on-demand activation of hotspot services without requiring manual configuration by the network operator.
In the late 2000s when ’425 was filed, access network capacity was increasingly constrained by a shift toward mass-market digital content distribution and the proliferation of diverse networked devices. At a time when network management was typically implemented using centralized core infrastructure, systems commonly relied on deep packet inspection (DPI) and traffic shaping profiles managed within the core network rather than at the device level. Hardware and software constraints of the era made the deployment of dense base station architectures non-trivial due to the high costs and technical complexity of backhauling all traffic through dedicated, hierarchical core network equipment.
The disclosed invention represents a meaningful technical advancement through an architectural shift that distributes service policy implementation and billing event logging from the core network to the end-user device. By utilizing a virtual network overlay comprising a device-side service processor and a network-side service controller, the system enables granular monitoring and control of encrypted traffic flows and application-specific data that are often opaque to traditional core network elements. This integration allows for a flattened network architecture where base stations can connect directly to the local loop, overcoming the technical constraints of backhaul congestion and core network latency while providing a verifiable mechanism to prevent tampering or spoofing of device-assisted service reports.
The patent contains a total of 51 claims, with claims 1, 24, 44, and 51 serving as the independent claims. These independent claims focus on the architecture and operation of an access network forwarding service, specifically describing end point devices, network systems, and methods for managing data traffic between a local area network and a wireless access network based on specific forwarding policies and service profiles. The dependent claims serve to further refine these systems and methods by specifying particular restriction settings, such as usage limits, network traffic classifications, parental controls, and notification protocols for the forwarding service.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents