Automated device provisioning and activation

Patent No. US8639935 (titled "Automated device provisioning and activation") on Dec 12, 2012. The application was issued on Jan 28, 2014.

What is this patent about?

’935 is related to the field of network management and device communication, specifically focusing on the secure coordination of control-plane traffic between a network system and multiple software agents residing on an end-user device. In modern wireless environments, managing service policies, billing, and device configuration requires a robust and efficient way to communicate instructions without overwhelming the data path or exposing the system to tampering.

The underlying idea behind ’935 is to establish a dedicated, secure service control link that acts as a private highway for administrative and policy-related messages. By using a link initialization sequence that ties the connection to specific device credentials, the system ensures that control messages are delivered to the correct device. The key engineering insight is the use of unique identifiers within encrypted payloads to route specific instructions to individual device agents, allowing the network to manage different functions—such as billing, monitoring, or security—independently on the same device.

The claims of ’935 focus on a network system that establishes a secured service control link with an end-user device over a wireless network. The system receives payloads from various servers and packages them into encrypted messages that include a specific agent identifier. This identifier is critical as it distinguishes the target agent from all other agents on the device, ensuring that the control-plane communication is precisely routed to the intended functional component after the link has been validated against the device's credentials.

In practice, the invention operates by executing a link initialization sequence that authenticates the device before any policy data is exchanged. Once the secure tunnel is active, the network processor can multiplex messages from different backend servers—such as a billing event server or a policy management server—into a single encrypted stream. On the device side, the service processor uses the embedded identifiers to distribute these messages to the appropriate internal agents, such as a policy implementation agent or a service monitor.

This approach differs from prior methods by providing a granular, multi-agent management framework that is decoupled from standard data-plane traffic. Traditional systems often treat the device as a single entity for control purposes, whereas ’935 allows for a distributed service architecture where specific software components can be updated, queried, or controlled individually. This ensures higher security and efficiency, as control-plane chatter is minimized and the integrity of each functional agent can be verified independently through the secured link.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2000s when ’935 was filed, mass market digital content distribution was increasingly straining wireless and wireline access networks at a time when network capacity was typically implemented using centralized core infrastructures. During this era, systems commonly relied on deep packet inspection and traffic shaping within the core network rather than distributed intelligence, which made the granular management of diverse device types and specialized service plans non-trivial. Hardware and software constraints of the period often forced service providers to adopt one-size-fits-all billing models, as the architectural complexity of implementing verifiable, per-application service policies across a heterogeneous landscape of smartphones, e-readers, and machine-to-machine devices was high.

Prosecution Position

The disclosed invention represents a meaningful technical advancement through an architectural shift that distributes service policy implementation and billing event capture from the core network to the end-user device. By utilizing a device-based service processor in coordination with a network-based service controller, the system enables a verifiable control plane that can monitor and categorize service activities—such as specific application usage or content transactions—even within encrypted traffic flows that are opaque to traditional network equipment. This integration overcomes the technical constraint of core network congestion by allowing for flattened architectures where base stations connect directly to the internet, while achieving the technical effect of granular, user-approved policy enforcement and real-time service usage synchronization.

Claims

This patent contains 30 claims, with claims 1, 29, and 30 serving as the independent claims. These independent claims focus on a network system and method for establishing a secured service control link with an end-user device to deliver encrypted message payloads to specific device agents using unique identifiers and link initialization sequences. The dependent claims further define the system by specifying types of credentials and servers, detailing the nature of the message payloads such as service plans or software updates, and describing link maintenance, authentication procedures, and the use of ambient services for data transmission.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Control-plane communications
(Claim 1, Claim 29, Claim 30)
Control plane traffic between service control servers and device agents implements service policies and can be several orders of magnitude slower than data plane traffic. It supports functions like heartbeat authentication, policy updates, and service usage reporting. This architecture distributes network traffic policy implementation away from the core network.Non-data traffic exchanged between the device and the network used to implement, monitor, and verify service control policies and billing rules.
Credential
(Claim 1, Claim 29, Claim 30)
Credentials can include device type, service provider, phone number, SIM ID, or secure certificates programmed into the device. They are used by the activation server to look up service plan and service profile information in a networked database. Temporary credentials may be used initially and later replaced by permanent credentials in an automated manner.Unique identification data associated with an end-user device, such as a SIM ID, device ID, or secure certificate, used to authorize and provision network services.
Device agents
(Claim 1, Claim 29, Claim 30)
Device agents perform functions such as service policy verification, tamper prevention, application access control, traffic control, and service billing. The division in functionality between one device agent and another is a design choice to manage development and testing complexity. Agents can communicate with each other or the service controller through a secure communications hub.Software components or functional modules residing on the end-user device that perform specific service policy implementation, management, or verification functions.
Link initialization sequence
(Claim 1, Claim 29, Claim 30)
The initialization involves the service processor seeking an activation server as soon as the device is turned on or a pre-programmed event is triggered. The sequence allows the network to read device credentials to determine the appropriate service profile and establish secure communication. This process ensures the device is authenticated and authorized before beginning service usage.A specific procedure or set of communications executed to set up the service control link and associate it with unique device credentials for authentication.
Service control link
(Claim 1, Claim 29, Claim 30)
The service control link facilitates the download of new service processor software elements, revisions, and dynamic refreshes. It provides a secure and bandwidth-efficient control plane compatible with any IP-based network, including the Internet. This link allows for consistent device-assisted service monitoring, control, verification, and billing while roaming across multiple networks.A secure, bandwidth-efficient control-plane communication channel established between a service processor on an end-user device and a network-based service controller to manage service policies, monitoring, and billing.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
4:25-cv-09558Nov 5, 2025Google LLC v. Headwater Research LLC
3:25-cv-07591Sep 5, 2025Apple Inc v. Headwater Research LLC
5:25-cv-07453Sep 3, 2025Google LLC v. Headwater Research LLC

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US8639935

Application Number
US13712184A
Filing Date
Dec 12, 2012
Publication Date
Jan 28, 2014
External Links
Slate, USPTO , Google Patents