Automated device provisioning and activation

Patent No. US8839388 (titled "Automated device provisioning and activation") on Mar 2, 2009. The application was issued on Sep 16, 2014.

What is this patent about?

’388 is related to the field of network service management and automated device provisioning. Specifically, it addresses the technical challenges of activating data services on mobile devices without the cumbersome delays typically associated with back-end billing system synchronization and credential verification in traditional cellular architectures.

The underlying idea behind ’388 is to decouple the immediate availability of a data service from the completion of its formal billing provisioning. By allowing an end-user device to utilize limited temporary access immediately upon requesting a service, the system eliminates the “activation lag” that occurs while network elements verify credentials or establish accounting records, thereby improving the perceived responsiveness of the network.

The claims of ’388 focus on a coordinated handshake between an end-user device and a network element where the device identifies itself using specific credentials and requests a data service. The device is configured to provide or receive access to that service in a restricted capacity while simultaneously awaiting a response from the network regarding the final status of billing provisioning.

In practice, the system utilizes a service processor on the device to manage these early-stage interactions. When a user attempts to access a service, the device sends its credentials and immediately opens a restricted data path. This allows for ambient activation, where the user can interact with a portal or a subset of data services before the central billing system has fully processed the new account or service plan update.

This approach differs from prior solutions that typically blocked all non-emergency traffic until a full AAA (Authentication, Authorization, and Accounting) cycle was completed. By implementing access control settings that permit temporary usage with reduced delay, ’388 ensures a seamless user experience while the network performs the necessary back-end administrative actions to finalize the service agreement.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2000s when ’388 was filed, network capacity management was typically implemented using centralized core network infrastructure where deep packet inspection and traffic shaping were performed at a distance from the end-user device. At a time when mobile systems commonly relied on rigid, one-size-fits-all billing models and basic access controls, the rapid proliferation of diverse connected devices—ranging from smartphones to machine-to-machine telemetry modules—created significant scaling challenges. During this era, hardware and software constraints made the real-time, granular categorization of encrypted traffic and the deployment of highly specialized service plans non-trivial for centralized gateways, which often struggled to maintain per-user performance while managing complex policy enforcement across heterogeneous access technologies like 3G, Wi-Fi, and early LTE.

Prosecution Position

The disclosed invention represents a meaningful technical advancement through an architectural shift that distributes service policy implementation and billing event capture from the core network directly to the end-user device. By integrating a local service processor that communicates with a network-based service controller, the system enables a verifiable control plane capable of granularly monitoring and shaping traffic based on specific application types, content, or transactions. This decentralized approach overcomes the technical constraints of centralized deep packet inspection, particularly regarding scalability and the handling of encrypted flows, while enabling new capabilities such as ambient service provisioning and automated activation. The resulting technical effect is a more efficient utilization of network capacity and the ability to implement complex, multi-tiered service plans without the overhead of propagating exhaustive traffic profiles throughout the core networking equipment.

Claims

US8,839,388 contains a total of 64 claims, with claims 1, 24, 25, 26, 63, and 64 serving as the independent claims. The independent claims focus on systems, methods, and computer program products for managing data service access by utilizing device credentials to provide limited temporary access to a network service while a billing provisioning response is pending, either from the perspective of the end-user device or a network device. The dependent claims further define the technical implementation by specifying types of device credentials such as SIMs or temporary identifiers, detailing the timing of device provisioning relative to the point of sale, describing specific network elements like AAA servers and billing systems involved in the process, and outlining procedures for account reactivation or suspension following periods of inactivity.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Access control settings
(Claim 26, Claim 63, Claim 64)
Aspects of the service policy that are moved out of the core network and into the end user device include, for example, certain lower level service policy implementations, such as access control settings, traffic control settings, billing system settings, user notification settings, user privacy settings, user preference settings, authentication settings and admission control settings. In some embodiments, the aforementioned ambient service is at least partially implemented by gateways, routers or switches in the network that are programmed according to the ambient access profile for the device to implement the ambient policies for network access control, routing control, traffic control or service monitoring and reporting for bill by account. The gateways, router or switches are pre-programmed as discussed herein according to the ambient access profile for the device.A set of policy parameters or rules implemented in the network or device to enforce traffic limits, routing, and service eligibility.
Device credentials
(Claim 1, Claim 24, Claim 25, Claim 26, Claim 63, Claim 64)
The information used to determine this can include device type, service provider, phone number, device ID, SIM ID or configuration, secure information used to qualify the device, IP address, MAC address, user, user group, VSP, OEM, device distributor, service distributor (master agent), service processor presence or configuration. The device credentials can also include secure information, certificate or signature that can be required by the network to perform the activation steps for temporary or permanent service account status. In some embodiments, the device activation information is programmed with dedicated apparatus that connects to the device via a wireless or wire line connection.Identifiers or security tokens used to authenticate an end-user device and associate it with a specific service profile, service plan, or account for network access.
End-user device
(Claim 1, Claim 24, Claim 25, Claim 26, Claim 63, Claim 64)
For example, some industry experts project average wireless device usage of four devices per subscriber, with a mixture of general purpose devices like smart phones and computers along with special purpose devices like music players, electronic readers, connected (e.g., networked) cameras and connected gaming devices. In some embodiments, the service processor 115 includes various components, such as device agents, that perform service policy implementation or management functions. As device processing and memory capacity expands, moving to this distributed service policy processing architecture also becomes more efficient and economical.A communications device, such as a smartphone, computer, or machine-to-machine module, that utilizes a service processor to assist in service policy implementation and monitoring.
Limited temporary access
(Claim 1, Claim 24, Claim 25, Claim 26, Claim 63, Claim 64)
In some embodiments, the service profile that is assigned to the device and/or network during the aforementioned activation is an ambient service profile providing service access before all the user information is available to assign a permanent account. These lower service usage or service activity limit plans will result in more users who are likely run over service usage limits and either experience service shutdown or service cost overages unless they are provided with more capable means for assistance. The activation server either initiates a specific provisioning sequence if device software is present to assist or routes to a website for manual entry if there is no software present.A restricted level of network connectivity provided to a device (often referred to as ambient services) before full billing provisioning or permanent account activation is completed.
Provisioned
(Claim 1, Claim 24, Claim 25)
In some embodiments, the steps for activating service include one or more of the following: provision the device, provision the necessary network databases and equipment to prepare them to recognize the device and associate it with the service profile and/or service plan, create or select the service account, select or create the service profile and/or service plan. Once the activation server has determined the activation information, then the activation server initiates the necessary network settings and billing database entries to be programmed by sending the service profile instructions to the network provisioning and activation apparatus and the service plan instructions to the billing system. This process prevents the network from needing to manage credentials and accounts for devices that have been activated but are not yet on the network.The state of having network databases, billing systems, and device settings configured and synchronized to recognize a device and allow specific data services under a defined service plan.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
3:25-cv-07591Sep 5, 2025Apple Inc v. Headwater Research LLC
5:25-cv-07453Sep 3, 2025Google LLC v. Headwater Research LLC

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US8839388

Application Number
US12380780A
Filing Date
Mar 2, 2009
Publication Date
Sep 16, 2014
External Links
Slate, USPTO , Google Patents