Patent No. US8667571 (titled "Automated device provisioning and activation") on Dec 4, 2012. The application was issued on Mar 4, 2014.
’571 is related to the field of wireless network management, specifically focusing on the secure coordination between network-side controllers and multiple software agents residing on end-user devices. In modern mobile environments, managing complex service policies—such as data limits, billing, and application-specific access—requires a robust control-plane that can communicate with specific functional components on a device without being compromised or creating excessive overhead.
The underlying idea behind ’571 is to establish a secure, encrypted management tunnel that allows a central network system to address and command individual device agents independently. By embedding specific agent identifiers within encrypted payloads, the network can precisely orchestrate device behavior—such as updating a billing module or throttling a specific application—across a diverse fleet of devices operating on different wireless access networks.
The claims of ’571 focus on a method and system for managing multiple end-user devices through distinct, encrypted service control links. The system receives a payload from a server intended for a specific device, generates an encrypted message that combines this payload with a unique identifier for a specific agent on that device, and transmits it over the dedicated control link. This ensures that the message is not only delivered to the correct device but is also routed to the correct internal software component for execution.
In practice, the invention functions as a high-integrity coordination layer between the service provider and the device's internal architecture. The network system maintains separate secure channels for different users, potentially using different encryption protocols for each. When a policy change or billing update is required, the system packages the instruction with an agent identifier, allowing the device to demultiplex the control traffic and ensure the intended agent—and only that agent—processes the command.
This approach differs from prior solutions by moving away from generic device management toward a granular, component-level orchestration. Traditional methods often treat the device as a single entity or rely on insecure data-plane communications. By using a dedicated, encrypted control-plane that can target specific agents, the invention provides a more secure and flexible framework for implementing complex service plans, such as ambient services or sponsored data, while protecting the system from tampering.
This patent contains 30 claims, with claims 1 and 26 being the independent claims. The independent claims focus on a network system and method for managing secure control-plane communications between a server and multiple end-user devices by providing encrypted service control links that deliver specific message payloads to designated device agents using unique identifiers. The dependent claims generally serve to specify the types of servers and payload data involved, detail the use of credentials and certificates for authorization, define the role of service control device link agents in message routing, and describe the maintenance of asynchronous communication links within ambient service frameworks.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents