Automated device provisioning and activation

Patent No. US8667571 (titled "Automated device provisioning and activation") on Dec 4, 2012. The application was issued on Mar 4, 2014.

What is this patent about?

’571 is related to the field of wireless network management, specifically focusing on the secure coordination between network-side controllers and multiple software agents residing on end-user devices. In modern mobile environments, managing complex service policies—such as data limits, billing, and application-specific access—requires a robust control-plane that can communicate with specific functional components on a device without being compromised or creating excessive overhead.

The underlying idea behind ’571 is to establish a secure, encrypted management tunnel that allows a central network system to address and command individual device agents independently. By embedding specific agent identifiers within encrypted payloads, the network can precisely orchestrate device behavior—such as updating a billing module or throttling a specific application—across a diverse fleet of devices operating on different wireless access networks.

The claims of ’571 focus on a method and system for managing multiple end-user devices through distinct, encrypted service control links. The system receives a payload from a server intended for a specific device, generates an encrypted message that combines this payload with a unique identifier for a specific agent on that device, and transmits it over the dedicated control link. This ensures that the message is not only delivered to the correct device but is also routed to the correct internal software component for execution.

In practice, the invention functions as a high-integrity coordination layer between the service provider and the device's internal architecture. The network system maintains separate secure channels for different users, potentially using different encryption protocols for each. When a policy change or billing update is required, the system packages the instruction with an agent identifier, allowing the device to demultiplex the control traffic and ensure the intended agent—and only that agent—processes the command.

This approach differs from prior solutions by moving away from generic device management toward a granular, component-level orchestration. Traditional methods often treat the device as a single entity or rely on insecure data-plane communications. By using a dedicated, encrypted control-plane that can target specific agents, the invention provides a more secure and flexible framework for implementing complex service plans, such as ambient services or sponsored data, while protecting the system from tampering.

How does this patent fit in bigger picture?

Technical Landscape

Prosecution Position

Claims

This patent contains 30 claims, with claims 1 and 26 being the independent claims. The independent claims focus on a network system and method for managing secure control-plane communications between a server and multiple end-user devices by providing encrypted service control links that deliver specific message payloads to designated device agents using unique identifiers. The dependent claims generally serve to specify the types of servers and payload data involved, detail the use of credentials and certificates for authorization, define the role of service control device link agents in message routing, and describe the maintenance of asynchronous communication links within ambient service frameworks.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Control-plane communications
(Claim 1, Claim 26)
Because the control plane traffic between the service control servers and the device agents that implement service policies can be several orders of magnitude slower than the data plane traffic, service control server network placement and back-haul infrastructure is much less performance sensitive than the data plane network. This server based control plane architecture provides for a highly efficient means of enabling third party control of services and billing. In some embodiments, a virtual network overlay includes a device service processor, a network service controller and a control plane communication link.Non-data traffic exchanged between the network system and the device used to manage, verify, and implement service policies, typically characterized by lower performance sensitivity and lower speeds than data-plane traffic.
Device agents
(Claim 1, Claim 26)
In some embodiments, the service processor 115 includes various components, such as device agents, that perform service policy implementation or management functions. These functions include service policy or implementation verification, service policy implementation tamper prevention, service allowance or denial, application access control, traffic control, network access control services, and/or other service implementations. The division in functionality between one device agent and another is a design choice.Software components or functional modules residing on an end-user device that perform specific service policy implementation, management, or verification functions, such as monitoring traffic, implementing billing rules, or ensuring system integrity.
Identifier
(Claim 1, Claim 26)
In some embodiments, the application interface agent 1693 identifies application level traffic, reports virtual service identification tags or appends literal service identification tags to assist service policy implementation. This allows for independent service usage monitoring and control for different end point devices or users. The identifier can include an agent serial number and/or a security key look up when agents are updated.A technical tag or address used to distinguish and route communications to a specific device agent among multiple agents, or to associate traffic with a particular service or application.
Message payload
(Claim 1, Claim 26)
In some embodiments, a policy control agent 1692 receives policy instructions from the service controller 122 and adapts device service policy settings. In some embodiments, the software is received as a single file over the service control device link 1691. The file can have encryption or signed encryption beyond any provided by the communication link protocol itself.The substantive data content within a server message intended for a specific device agent, which may include service policy instructions, software updates, or configuration settings.
Service control link
(Claim 1, Claim 26)
In some embodiments, the service control device link 1691 facilitates another important function, which is the download of new service processor software elements, revisions of service processor software elements, and/or dynamic refreshes of service processor software elements. The service control device link 1691 reviews local billing event history and compares such history to billing event reports to verify that a billing agent 1695 is functioning properly. Various embodiments described herein disclose a secure and bandwidth efficient control plane that is compatible with any IP based network.A secure, bandwidth-efficient communication channel established between a service controller and a device agent to facilitate control-plane signaling, such as policy updates, software downloads, or heartbeat authentication, independent of the data plane.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
3:25-cv-07591Sep 5, 2025Apple Inc v. Headwater Research LLC

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US8667571

Application Number
US13705055A
Filing Date
Dec 4, 2012
Publication Date
Mar 4, 2014
External Links
Slate, USPTO , Google Patents