Patent No. US8639935 (titled "Automated device provisioning and activation") on Dec 12, 2012. The application was issued on Jan 28, 2014.
’935 is related to the field of network management and device communication, specifically focusing on the secure coordination of control-plane traffic between a network system and multiple software agents residing on an end-user device. In modern wireless environments, managing service policies, billing, and device configuration requires a robust and efficient way to communicate instructions without overwhelming the data path or exposing the system to tampering.
The underlying idea behind ’935 is to establish a dedicated, secure service control link that acts as a private highway for administrative and policy-related messages. By using a link initialization sequence that ties the connection to specific device credentials, the system ensures that control messages are delivered to the correct device. The key engineering insight is the use of unique identifiers within encrypted payloads to route specific instructions to individual device agents, allowing the network to manage different functions—such as billing, monitoring, or security—independently on the same device.
The claims of ’935 focus on a network system that establishes a secured service control link with an end-user device over a wireless network. The system receives payloads from various servers and packages them into encrypted messages that include a specific agent identifier. This identifier is critical as it distinguishes the target agent from all other agents on the device, ensuring that the control-plane communication is precisely routed to the intended functional component after the link has been validated against the device's credentials.
In practice, the invention operates by executing a link initialization sequence that authenticates the device before any policy data is exchanged. Once the secure tunnel is active, the network processor can multiplex messages from different backend servers—such as a billing event server or a policy management server—into a single encrypted stream. On the device side, the service processor uses the embedded identifiers to distribute these messages to the appropriate internal agents, such as a policy implementation agent or a service monitor.
This approach differs from prior methods by providing a granular, multi-agent management framework that is decoupled from standard data-plane traffic. Traditional systems often treat the device as a single entity for control purposes, whereas ’935 allows for a distributed service architecture where specific software components can be updated, queried, or controlled individually. This ensures higher security and efficiency, as control-plane chatter is minimized and the integrity of each functional agent can be verified independently through the secured link.
In the late 2000s when ’935 was filed, mass market digital content distribution was increasingly straining wireless and wireline access networks at a time when network capacity was typically implemented using centralized core infrastructures. During this era, systems commonly relied on deep packet inspection and traffic shaping within the core network rather than distributed intelligence, which made the granular management of diverse device types and specialized service plans non-trivial. Hardware and software constraints of the period often forced service providers to adopt one-size-fits-all billing models, as the architectural complexity of implementing verifiable, per-application service policies across a heterogeneous landscape of smartphones, e-readers, and machine-to-machine devices was high.
The disclosed invention represents a meaningful technical advancement through an architectural shift that distributes service policy implementation and billing event capture from the core network to the end-user device. By utilizing a device-based service processor in coordination with a network-based service controller, the system enables a verifiable control plane that can monitor and categorize service activities—such as specific application usage or content transactions—even within encrypted traffic flows that are opaque to traditional network equipment. This integration overcomes the technical constraint of core network congestion by allowing for flattened architectures where base stations connect directly to the internet, while achieving the technical effect of granular, user-approved policy enforcement and real-time service usage synchronization.
This patent contains 30 claims, with claims 1, 29, and 30 serving as the independent claims. These independent claims focus on a network system and method for establishing a secured service control link with an end-user device to deliver encrypted message payloads to specific device agents using unique identifiers and link initialization sequences. The dependent claims further define the system by specifying types of credentials and servers, detailing the nature of the message payloads such as service plans or software updates, and describing link maintenance, authentication procedures, and the use of ambient services for data transmission.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents