Verifiable service policy implementation for intermediate networking devices

Patent No. US8799451 (titled "Verifiable service policy implementation for intermediate networking devices") on Mar 2, 2009. The application was issued on Aug 5, 2014.

What is this patent about?

’451 is related to the field of network service management and device-assisted traffic control. Specifically, it addresses the challenges of managing network capacity and service costs in environments where end-user devices, such as smartphones or laptops, act as intermediate networking devices or hotspots for other equipment. The background context involves the increasing strain on wireless access networks due to high-bandwidth applications and the need for flexible, verifiable billing and policy enforcement that can distinguish between a device's own data usage and the traffic it forwards for others.

The underlying idea behind ’451 is to decentralize network policy enforcement by moving control logic directly onto the end-user device. By utilizing a service processor on the device, the system can implement distinct, differentiated rules for local traffic versus tethered traffic. This inventive insight allows a device to act as a sophisticated gateway that not only forwards data but also monitors, identifies, and controls that data according to specific provider policies. This shift reduces the computational burden on the core network and enables more granular management of forwarding services, such as hotspots or tethering, which are traditionally difficult to monitor accurately from the network side alone.

The claims of ’451 focus on a first end-user device configured to operate as an intermediate networking device. The device uses one or more modems to bridge a wireless access network with a second network containing other end-user devices. The core of the independent claims is the simultaneous implementation of two differing service policies: a first policy to control traffic being forwarded for other devices, and a second policy to control the first device’s own access to services. Furthermore, the device is specifically tasked with monitoring or identifying the successful or attempted use of this forwarding service to ensure policy compliance.

In practice, the invention works by using a device-based agent to intercept and categorize traffic flows before they reach the modem. When the device acts as a hotspot, the service processor identifies packets originating from tethered devices and applies the first service policy—which might include specific bandwidth limits, billing rates, or access restrictions—while allowing the host device to operate under a separate set of rules. This is achieved through traffic shaping and monitoring at various measurement points within the device's communication stack, ensuring that the network provider can verify exactly how the wireless connection is being shared.

This approach differs from prior solutions that relied almost exclusively on network-side Deep Packet Inspection (DPI) or simple on/off tethering controls. Traditional methods often struggle to distinguish between host and tethered traffic, especially when encrypted, and cannot easily apply different billing models to each. By implementing verifiable device-assisted services, ’451 provides a mechanism to prevent tampering and ensure that the forwarding service is used within authorized limits. This creates a more robust framework for ambient services and complex billing plans that can be updated dynamically without requiring major upgrades to existing network infrastructure.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2000s when ’451 was filed, mass-market digital content distribution was increasingly straining access network capacity at a time when mobile data was typically implemented using early 3G technologies like EVDO and HSPA. During this era, systems commonly relied on centralized core network infrastructure to aggregate and manage all subscriber traffic, which created significant backhaul costs and scalability bottlenecks as the number of networked devices per user began to grow. Hardware and software constraints of the period made the implementation of granular, application-specific billing and real-time traffic shaping non-trivial, as these functions were generally tethered to deep packet inspection (DPI) equipment located deep within the provider's core network rather than at the network edge.

Prosecution Position

The disclosed invention represents a meaningful technical advancement by shifting the architecture of service policy implementation from the core network to the end-user device. By integrating a service processor directly onto the device to monitor and categorize traffic—such as application-specific data, background maintenance chatter, and sponsored content—the system enables a verifiable distributed control plane. This architectural shift overcomes the technical constraint of core network congestion by allowing for local traffic shaping and billing event capture, which facilitates the deployment of flattened network topologies where base stations connect directly to the internet. The resulting capability allows for more refined service plans, such as ambient services and bill-by-account models, while ensuring policy enforcement is tamper-resistant through network-based verification of device-reported usage.

Claims

This patent includes a total of 69 claims, with claims 1, 14, and 15 serving as the independent claims. The independent claims focus on an end-user device, a computer program product, and a method that enable a device to function as an intermediate networking hub by providing a forwarding service for other devices while simultaneously managing distinct service policies for forwarded traffic versus its own local traffic. The dependent claims further specify various operational parameters, including network types such as cellular and Wi-Fi, geographic and time-based policy triggers, traffic throttling and allowance limits, user notification and interface interactions, and authorization controls for specific users or applications.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
First service policy
(Claim 1, Claim 14, Claim 15)
In some embodiments, end point devices connected to an intermediate networking device can have service usage policies implemented in aggregate for all end point devices, or service policies can be implemented differentially for different end point devices. The intermediate networking device service processor can assist in monitoring, control and billing for WWAN service usage for all end point devices in the area covered by the intermediate networking device Wi-Fi link. These multi-end point device or multi-user service profiles in the intermediate networking device service processor can share services equally or can allow more capable access services to some end point devices or users than others.A set of rules or settings (such as access control, traffic shaping, or billing) specifically applied to the traffic generated by or destined for the other end-user devices using the forwarding service.
Forwarding service
(Claim 1, Claim 14, Claim 15)
In some embodiments, an intermediate networking device connects the end point devices to the network by passing, bridging, forwarding, routing, traffic shaping or otherwise allowing the end point devices to communicate with the network. An intermediate networking device can be provided by including a bridging, forwarding or routing function between two modems in a communications enabled device that connects to the network. The service processor can assist in monitoring, control and billing for WWAN service usage for all end point devices in the area covered by the intermediate networking device Wi-Fi link.A function performed by the intermediate device to pass, bridge, or route data traffic between connected end-user devices and a wireless access network.
Intermediate networking device
(Claim 1, Claim 15)
In some embodiments, an intermediate networking device is a communications device in which the service processor is configured at least in part to allow the intermediate networking device to act as a service intermediary or intermediate connection between the network and one or more end point devices. Example intermediate networking device embodiments include a Wi-Fi to WWAN bridge or router device, a Wi-Fi to DSL, cable or fiber gateway device, or a WWAN back up connection device for an enterprise router. It connects the end point devices to the network by passing, bridging, forwarding, routing, traffic shaping or otherwise allowing the end point devices to communicate with the network.A communications device (such as a mobile phone, notebook, or gateway) configured to act as a service intermediary or bridge, allowing other end-point devices to connect to a network system through its own network connection.
Monitor or identify successful use or attempted use
(Claim 1, Claim 14, Claim 15)
In some embodiments, the intermediate networking device also monitors the service use activities of the intermediate networking device and/or the end point devices connected to the intermediate networking device. The access control integrity agent receives agent access attempt reports to determine if unauthorized agent access attempts are occurring. In some embodiments, the individual end point device service usage measures logged or reported from the end point devices and/or the intermediate networking device can be aggregated to form a total intermediate networking device usage measure that is compared to an aggregate intermediate networking device usage measure logged or reported in the network.The act of tracking, logging, or detecting both completed data transfers and failed or unauthorized connection attempts for the purpose of verification, billing, or security.
Second service policy
(Claim 1, Claim 14, Claim 15)
In some embodiments, an intermediate networking device can be associated with one service profile, one service plan or one service account, or an intermediate networking device can be associated with multiple service profiles, multiple service plans or multiple service accounts. The service processor function assisting intermediate networking device implementation can be included on the intermediate networking device, can be included in part on the intermediate networking device and one or more end point devices, or can be implemented mainly or entirely on one or more end point devices. This allows for independent service usage monitoring and control for different end point devices or users.A set of rules or settings applied to the traffic generated by the intermediate device itself for its own services, which is distinct from the policy applied to forwarded traffic.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
4:25-cv-09558Nov 5, 2025Google LLC v. Headwater Research LLC
3:25-cv-07591Sep 5, 2025Apple Inc v. Headwater Research LLC
5:25-cv-07453Sep 3, 2025Google LLC v. Headwater Research LLC

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US8799451

Application Number
US12380773A
Filing Date
Mar 2, 2009
Publication Date
Aug 5, 2014
External Links
Slate, USPTO , Google Patents