Network system with common secure wireless message service serving multiple applications on multiple wireless devices

Patent No. US9198117 (titled "Network system with common secure wireless message service serving multiple applications on multiple wireless devices") on Mar 24, 2015. The application was issued on Nov 24, 2015.

What is this patent about?

’117 is related to the field of wireless network messaging and application data delivery. Specifically, it addresses the technical challenge of securely and efficiently routing data from multiple network application servers to specific software processes residing on mobile end-user devices over a wireless data connection.

The underlying idea behind ’117 is a centralized network message server that acts as a secure intermediary between various application servers and a fleet of mobile devices. Instead of each application establishing its own independent connection, the system uses a dedicated device messaging agent on each handset to maintain a single secure tunnel. This agent acts as a local dispatcher, using internal logic to route incoming data to the correct destination process on the device.

The claims of ’117 focus on a network system architecture where a central server receives data requests from multiple application servers, each specifying a target device and a target application. The server packages this data with an application identifier and transmits it over a secure Internet connection to a messaging agent on the mobile device. The agent then performs a mapping function to identify the correct software process and delivers the data using a secure interprocess communication service.

In practice, this invention streamlines how mobile apps receive updates or notifications by offloading the complexity of secure connection management to a specialized agent. By including an application identifier in each message, the system ensures that data is not just delivered to the right device, but is handed off to the specific software process intended to handle it. This creates a robust framework for multi-app data synchronization without requiring every app developer to implement their own secure networking stack.

This approach differs from prior methods that often relied on fragmented, application-specific polling or less secure broadcast mechanisms. By utilizing a secure interprocess communication service local to the device, the invention ensures that data remains protected even after it leaves the network interface. This centralized agent model reduces network overhead and improves device battery life by consolidating multiple application data streams into a single, managed secure connection.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2000s when ’117 was filed, mobile data consumption was beginning to outpace network capacity at a time when service access was typically implemented using rigid, all-or-nothing billing models. Systems commonly relied on centralized core network infrastructure to manage traffic policies and deep packet inspection, rather than distributing control to the edge. Hardware and software constraints of the era made the granular classification and real-time management of diverse device types—such as e-readers, cameras, and smartphones—non-trivial for service providers seeking to offer differentiated or sponsored access plans.

Prosecution Position

The disclosed invention represents a meaningful technical advancement through an architectural shift that distributes service policy implementation and billing event capture from the core network directly to the end-user device. By utilizing a device-based service processor in communication with a network-based service controller, the system enables a verifiable and granular monitoring capability that overcomes the technical constraints of traditional centralized traffic shaping. This integration allows for the creation of ambient service profiles and 'bill-by-account' functionalities, enabling specific application or transaction traffic to be partitioned and monetized independently of general data usage, thereby increasing network capacity efficiency and providing refined user-level control.

Claims

The patent contains a total of 18 claims, with claim 1 being the sole independent claim. This independent claim is focused on a network system that utilizes a centralized message server and device-side messaging agents to manage secure data connections between multiple network application servers and mobile end-user devices, specifically handling the mapping of application identifiers to software processes via secure interprocess communication. The dependent claims serve to further define the system by specifying features such as data buffering and transmission triggers, encryption and tunneling methods, secure execution environments, bidirectional data flow between devices and servers, and various authentication and authorization protocols.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Application identifier
(Claim 1)
In some embodiments, the application interface agent 1693 identifies application level traffic, reports virtual service identification tags or appends literal service identification tags to assist service policy implementation. This allows for independent service usage monitoring and control for different end point devices or users based on parameters such as an end point device application layer tag.A unique tag or literal identification marker included within a data message that allows the device messaging agent to distinguish which specific application or software process the incoming data is intended for.
Device messaging agent
(Claim 1)
In some embodiments, the service processor 115 includes various components, such as device agents, that perform service policy implementation or management functions. It will be apparent to those of ordinary skill in the art that the division in functionality between one device agent and another is a design choice. These functions include service control plane communication, device heartbeat services, and other service implementations.A specialized software component or agent residing on a mobile end-user device that manages the reception of application data from a secure network link and routes that data to specific software processes based on application identifiers.
Network message server
(Claim 1)
In some embodiments, control of the device service policies is accomplished with a set of service control plane servers that reside in the access network or any network that can be reached by the device. This server based control plane architecture provides for a highly efficient means of enabling third party control of services and billing. A single named function in the various embodiments can be implemented on multiple servers, or multiple named functions can be implemented on a single server.A server-side architectural element that acts as a centralized hub to receive data requests from multiple application servers and distribute them to specific mobile devices via secure, persistent Internet connections.
Secure Internet data connection
(Claim 1)
Various embodiments described herein disclose a secure and bandwidth efficient control plane that is compatible with any IP based network. Other techniques that could be used for this function include, for example, encapsulating the control plane in the access network control plane channel, running a more conventional VPN or IPSEC channel, and/or using an independent access network connection. The service control device link 1691 facilitates the download of new service processor software elements and revisions.A protected communication channel established between the network message server and a device messaging agent, used to transport control plane or application data across a wireless network in a secure and bandwidth-efficient manner.
Secure interprocess communication service
(Claim 1)
In some embodiments, the access control integrity agent 1694 acts as a central secure communications hub for agent to agent or service controller 122 to agent communication. The access control integrity agent 1694 can be used so that no other software or function can access other agents or so that agents cannot access other agents except through the secure point to multipoint communications hub. This approach further enhances compromise resistance for the agents.A protected internal mechanism within the mobile device's operating environment that allows the messaging agent to pass received data to the destination software process while preventing unauthorized access or tampering by other applications.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
4:25-cv-09558Nov 5, 2025Google LLC v. Headwater Research LLC
5:25-cv-07453Sep 3, 2025Google LLC v. Headwater Research LLC

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9198117

Application Number
US14667516A
Filing Date
Mar 24, 2015
Publication Date
Nov 24, 2015
External Links
Slate, USPTO , Google Patents