Patent No. US9532161 (titled "Wireless device with application data flow tagging and network stack-implemented network access policy") on Dec 22, 2015. The application was issued on Dec 27, 2016.
’161 is related to the field of wireless network management, specifically focusing on the granular control of data traffic on end-user devices. As mobile devices increasingly utilize both high-capacity local networks and bandwidth-constrained wide area networks, there is a growing need to manage how individual applications consume data to preserve network capacity and control user costs.
The underlying idea behind ’161 is to move the intelligence of network policy enforcement from the core network directly onto the end-user device. By identifying and tagging specific data flows at the application level, the device can distinguish between different software applications and apply unique access rules to each, such as allowing a critical business app to use cellular data while restricting a high-bandwidth entertainment app to Wi-Fi only.
The claims of ’161 focus on a wireless device equipped with both WWAN and WLAN modems that utilizes an application service interface agent to associate specific data traffic flows with the responsible software application. The device's network stack uses this association to apply application-specific access policies, ensuring that policy instructions for a first application are enforced without affecting the network access of a second application.
In practice, the invention works by monitoring requests made through the network service API and managing them via an IP socket management function. When an application attempts to communicate, the interface agent generates tag information that follows the data flow through the stack. This allows the modem drivers or other stack elements to recognize the source of the traffic and apply the correct throttling, blocking, or routing rules based on the active network connection.
This approach differs from prior solutions that typically relied on coarse, network-side deep packet inspection or device-wide settings that treated all traffic identically. By implementing application-specific control within the device's own communication stack, the system can manage encrypted traffic that network-based tools cannot see and provides a more flexible, user-friendly way to optimize data usage across diverse network environments.
In the late 2000s when ’161 was filed, mobile data demand was beginning to outpace network capacity at a time when network service policies were typically implemented using centralized core network infrastructure. Systems commonly relied on rigid, high-level billing models where access providers managed traffic through deep packet inspection (DPI) and traffic shaping profiles hosted entirely within the core networking equipment. During this era, hardware and software constraints made the granular management of diverse device types—such as smartphones, e-readers, and machine-to-machine sensors—non-trivial, as existing architectures struggled to scale service-specific billing and policy enforcement without incurring significant backhaul and maintenance costs.
The disclosed invention represents a technical advancement through an architectural shift that distributes service policy implementation and billing event capture from the core network to a service processor residing on the end-user device. This integration enables a verifiable, device-assisted service control platform capable of monitoring and categorizing traffic at a more granular level than traditional network-side inspection, particularly for encrypted flows. The technical effect achieved is a flattened network architecture that reduces the requirement to aggregate all traffic through dedicated core infrastructure, thereby overcoming backhaul capacity constraints. This capability enables flexible, multi-tier service plans and automated provisioning while maintaining synchronization between device-based usage measures and network-based accounting for tamper-resistant verification.
The patent contains a total of 19 claims, with claim 1 being the sole independent claim. This independent claim focuses on a wireless end-user device equipped with both wide area and local area network modems, utilizing a network stack and an application service interface agent to identify and tag data traffic flows for specific software applications to apply targeted network access policies. The dependent claims further define the system by specifying policy management agents, detailing flow-specific tagging protocols, describing kernel-level implementations, and outlining various policy applications such as firewall blocking, roaming restrictions, user notifications, and data usage monitoring.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents