Patent No. US9232403 (titled "Mobile device with common secure wireless message service serving multiple applications") on Mar 24, 2015. The application was issued on Jan 5, 2016.
’403 is related to the field of mobile device messaging and secure data delivery. Specifically, it addresses the challenge of efficiently and securely routing data from multiple network-based application servers to specific software processes running on a mobile device over a wireless wide-area network (WWAN).
The underlying idea behind ’403 is to centralize the reception of application-specific data through a single device messaging agent that acts as a secure gateway for all apps on the device. Instead of each application maintaining its own persistent connection to its respective server—which drains battery and bandwidth—a network message server aggregates data from various sources and pushes it to this specialized agent. The agent then uses a local mapping system to identify which application should receive the data and hands it off securely within the device's operating environment.
The claims of ’403 focus on a mobile device equipped with a WWAN modem and a messaging agent that maintains a secure connection to a network message server. The agent is configured to receive data packets that include both application data and a specific application identifier. The core of the claimed invention is the agent's ability to map this identifier to a specific software process and then utilize a secure interprocess communication (IPC) service to deliver that data to the correct application executing on the device.
In practice, this system functions as a secure, multiplexed delivery pipe. When the network message server receives data intended for a device, it wraps that data with a tag identifying the target app. Upon arrival at the device, the messaging agent decodes the message and routes it to the appropriate app via the IPC service. This ensures that data delivery is not only power-efficient but also protected from interception by other malicious processes on the same device.
This approach differs from prior methods where applications typically managed their own network sockets or relied on insecure, non-standardized notification systems. By utilizing a dedicated agent and a secure IPC service, the invention provides a unified security model for data hand-offs. This architecture reduces the overhead of maintaining multiple background connections while ensuring that sensitive application data is only accessible to the intended software process.
In the late 2000s when ’403 was filed, mobile data consumption was beginning to outpace network capacity at a time when wireless service plans were typically implemented using flat-rate, all-you-can-eat billing models. Systems at this time commonly relied on centralized core network infrastructure to perform deep packet inspection and traffic shaping, rather than distributing policy enforcement to the edge. Because hardware and software constraints made real-time, granular monitoring of encrypted or high-bandwidth application traffic non-trivial for centralized gateways, service providers often struggled to differentiate between various types of data usage, such as background maintenance traffic versus user-initiated content downloads.
The disclosed invention represents a meaningful technical advancement through an architectural shift that moves service policy implementation and billing event capture from the core network directly onto the end-user device. By utilizing a device-based service processor in communication with a network-based service controller, the system enables a verifiable integration of local traffic monitoring and policy enforcement. This capability allows for the decomposition of aggregate data usage into refined sub-categories—such as application-specific usage or machine-to-machine telemetry—which overcomes the technical constraint of limited visibility into encrypted or complex traffic flows at the network core. The resulting technical effect is a more efficient management of network capacity and the enablement of flexible, automated provisioning and 'ambient' service models that do not require manual user intervention or extensive custom infrastructure development.
This patent contains 21 claims, with claim 1 serving as the sole independent claim. The independent claim focuses on a mobile end-user device equipped with a wireless wide-area network modem, a messaging agent, and a secure interprocess communication service designed to receive and route secure Internet data messages to specific software applications based on embedded identifiers. The dependent claims generally serve to elaborate on the device's hardware components, such as local area network modems, and specify various security protocols, encryption methods, authentication processes, and data handling techniques for the messaging agent and the interprocess communication channel.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents