Mobile device with common secure wireless message service serving multiple applications

Patent No. US9232403 (titled "Mobile device with common secure wireless message service serving multiple applications") on Mar 24, 2015. The application was issued on Jan 5, 2016.

What is this patent about?

’403 is related to the field of mobile device messaging and secure data delivery. Specifically, it addresses the challenge of efficiently and securely routing data from multiple network-based application servers to specific software processes running on a mobile device over a wireless wide-area network (WWAN).

The underlying idea behind ’403 is to centralize the reception of application-specific data through a single device messaging agent that acts as a secure gateway for all apps on the device. Instead of each application maintaining its own persistent connection to its respective server—which drains battery and bandwidth—a network message server aggregates data from various sources and pushes it to this specialized agent. The agent then uses a local mapping system to identify which application should receive the data and hands it off securely within the device's operating environment.

The claims of ’403 focus on a mobile device equipped with a WWAN modem and a messaging agent that maintains a secure connection to a network message server. The agent is configured to receive data packets that include both application data and a specific application identifier. The core of the claimed invention is the agent's ability to map this identifier to a specific software process and then utilize a secure interprocess communication (IPC) service to deliver that data to the correct application executing on the device.

In practice, this system functions as a secure, multiplexed delivery pipe. When the network message server receives data intended for a device, it wraps that data with a tag identifying the target app. Upon arrival at the device, the messaging agent decodes the message and routes it to the appropriate app via the IPC service. This ensures that data delivery is not only power-efficient but also protected from interception by other malicious processes on the same device.

This approach differs from prior methods where applications typically managed their own network sockets or relied on insecure, non-standardized notification systems. By utilizing a dedicated agent and a secure IPC service, the invention provides a unified security model for data hand-offs. This architecture reduces the overhead of maintaining multiple background connections while ensuring that sensitive application data is only accessible to the intended software process.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2000s when ’403 was filed, mobile data consumption was beginning to outpace network capacity at a time when wireless service plans were typically implemented using flat-rate, all-you-can-eat billing models. Systems at this time commonly relied on centralized core network infrastructure to perform deep packet inspection and traffic shaping, rather than distributing policy enforcement to the edge. Because hardware and software constraints made real-time, granular monitoring of encrypted or high-bandwidth application traffic non-trivial for centralized gateways, service providers often struggled to differentiate between various types of data usage, such as background maintenance traffic versus user-initiated content downloads.

Prosecution Position

The disclosed invention represents a meaningful technical advancement through an architectural shift that moves service policy implementation and billing event capture from the core network directly onto the end-user device. By utilizing a device-based service processor in communication with a network-based service controller, the system enables a verifiable integration of local traffic monitoring and policy enforcement. This capability allows for the decomposition of aggregate data usage into refined sub-categories—such as application-specific usage or machine-to-machine telemetry—which overcomes the technical constraint of limited visibility into encrypted or complex traffic flows at the network core. The resulting technical effect is a more efficient management of network capacity and the enablement of flexible, automated provisioning and 'ambient' service models that do not require manual user intervention or extensive custom infrastructure development.

Claims

This patent contains 21 claims, with claim 1 serving as the sole independent claim. The independent claim focuses on a mobile end-user device equipped with a wireless wide-area network modem, a messaging agent, and a secure interprocess communication service designed to receive and route secure Internet data messages to specific software applications based on embedded identifiers. The dependent claims generally serve to elaborate on the device's hardware components, such as local area network modems, and specify various security protocols, encryption methods, authentication processes, and data handling techniques for the messaging agent and the interprocess communication channel.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Device messaging agent
(Claim 1)
The service processor includes various components, such as device agents, that perform service policy implementation or management functions. These functions include service control plane communication and other service implementations. The division in functionality between one device agent and another is a design choice to manage development and testing complexity.A specialized software component residing on the mobile device that manages the reception and routing of secure data messages from a network server to specific local applications.
Mobile end-user-area device
(Claim 1)
The device can be a general purpose device like a smart phone or computer, or a special purpose device like a music player, electronic reader, or connected camera. It includes a service processor and various agents to perform service policy implementation or management functions. The device is capable of connecting to access networks such as wireless, cable, and DSL networks.A portable digital communication device (such as a smartphone, computer, or special-purpose networked device) that serves as the endpoint for a user to access network services.
Network message server
(Claim 1)
Control of the device service policies is accomplished with a set of service control plane servers that reside in the access network or any network that can be reached by the device. The service controller includes one or more server functions that interact with the service processor agents. This server-based control plane architecture enables efficient third-party control of services and billing.A remote server (part of the service control plane) that aggregates data from various application servers and transmits it to the device messaging agent over a secure link.
Secure Internet data messages
(Claim 1)
The software is received as a single file or segmented into smaller packets over the service control device link. The file can have encryption or signed encryption beyond any provided by the communication link protocol itself. This facilitates the download of new service processor software elements or dynamic refreshes in a secure manner.Encrypted or protected data packets transmitted over the Internet that contain both application-specific data and routing identifiers for local software processes.
Secure interprocess communication service
(Claim 1)
The access control integrity agent can act as a central secure communications hub for agent to agent communication. This approach ensures that no other software or function can access other agents except through the secure point to multipoint communications hub. This enhances compromise resistance for the agents within the service processor operating environment.A protected internal communication mechanism that allows the messaging agent to securely transfer data to other software processes within the device's operating environment.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
3:25-cv-07591Sep 5, 2025Apple Inc v. Headwater Research LLC
5:25-cv-07453Sep 3, 2025Google LLC v. Headwater Research LLC

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9232403

Application Number
US14667353A
Filing Date
Mar 24, 2015
Publication Date
Jan 5, 2016
External Links
Slate, USPTO , Google Patents