Wireless device with application data flow tagging and network stack-implemented network access policy

Patent No. US9532161 (titled "Wireless device with application data flow tagging and network stack-implemented network access policy") on Dec 22, 2015. The application was issued on Dec 27, 2016.

What is this patent about?

’161 is related to the field of wireless network management, specifically focusing on the granular control of data traffic on end-user devices. As mobile devices increasingly utilize both high-capacity local networks and bandwidth-constrained wide area networks, there is a growing need to manage how individual applications consume data to preserve network capacity and control user costs.

The underlying idea behind ’161 is to move the intelligence of network policy enforcement from the core network directly onto the end-user device. By identifying and tagging specific data flows at the application level, the device can distinguish between different software applications and apply unique access rules to each, such as allowing a critical business app to use cellular data while restricting a high-bandwidth entertainment app to Wi-Fi only.

The claims of ’161 focus on a wireless device equipped with both WWAN and WLAN modems that utilizes an application service interface agent to associate specific data traffic flows with the responsible software application. The device's network stack uses this association to apply application-specific access policies, ensuring that policy instructions for a first application are enforced without affecting the network access of a second application.

In practice, the invention works by monitoring requests made through the network service API and managing them via an IP socket management function. When an application attempts to communicate, the interface agent generates tag information that follows the data flow through the stack. This allows the modem drivers or other stack elements to recognize the source of the traffic and apply the correct throttling, blocking, or routing rules based on the active network connection.

This approach differs from prior solutions that typically relied on coarse, network-side deep packet inspection or device-wide settings that treated all traffic identically. By implementing application-specific control within the device's own communication stack, the system can manage encrypted traffic that network-based tools cannot see and provides a more flexible, user-friendly way to optimize data usage across diverse network environments.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2000s when ’161 was filed, mobile data demand was beginning to outpace network capacity at a time when network service policies were typically implemented using centralized core network infrastructure. Systems commonly relied on rigid, high-level billing models where access providers managed traffic through deep packet inspection (DPI) and traffic shaping profiles hosted entirely within the core networking equipment. During this era, hardware and software constraints made the granular management of diverse device types—such as smartphones, e-readers, and machine-to-machine sensors—non-trivial, as existing architectures struggled to scale service-specific billing and policy enforcement without incurring significant backhaul and maintenance costs.

Prosecution Position

The disclosed invention represents a technical advancement through an architectural shift that distributes service policy implementation and billing event capture from the core network to a service processor residing on the end-user device. This integration enables a verifiable, device-assisted service control platform capable of monitoring and categorizing traffic at a more granular level than traditional network-side inspection, particularly for encrypted flows. The technical effect achieved is a flattened network architecture that reduces the requirement to aggregate all traffic through dedicated core infrastructure, thereby overcoming backhaul capacity constraints. This capability enables flexible, multi-tier service plans and automated provisioning while maintaining synchronization between device-based usage measures and network-based accounting for tamper-resistant verification.

Claims

The patent contains a total of 19 claims, with claim 1 being the sole independent claim. This independent claim focuses on a wireless end-user device equipped with both wide area and local area network modems, utilizing a network stack and an application service interface agent to identify and tag data traffic flows for specific software applications to apply targeted network access policies. The dependent claims further define the system by specifying policy management agents, detailing flow-specific tagging protocols, describing kernel-level implementations, and outlining various policy applications such as firewall blocking, roaming restrictions, user notifications, and data usage monitoring.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Application service interface agent
(Claim 1)
In some embodiments, the application interface agent 1693 identifies application level traffic, reports virtual service identification tags or appends literal service identification tags to assist service policy implementation. It assists with application layer service usage monitoring by passively inspecting and logging traffic or service characteristics at a point in the software stack between the applications and the standard networking stack application interface, such as the sockets API. In some embodiments, the application interface agent 1693 intercepts traffic between the applications and the standard network stack interface API in order to more deeply inspect the traffic, modify the traffic or shape the traffic.A software component within the device processor that identifies and categorizes network data traffic flows by associating them with specific software applications using tag information.
IP socket management function
(Claim 1)
In some embodiments, the application interface agent 1693 assists with application layer service usage monitoring by, for example, passively inspecting and logging traffic or service characteristics at a point in the software stack between the applications and the standard networking stack application interface, such as the sockets API. The traffic from each application can be divided into one or more traffic flows that each flow through a traffic queue, with each queue being associated with one or more additional classifications for that application. In some embodiments, the software files are sent using other delivery means, such a direct TCP socket connection to the service downloader 1663 or some other software installer.A component of the network stack responsible for managing the communication endpoints (sockets) used by applications for Internet service activities.
Network service Application Programming Interface (API)
(Claim 1)
In some embodiments, the application interface agent 1693 assists with application layer service usage monitoring by, for example, passively inspecting and logging traffic or service characteristics at a point in the software stack between the applications and the standard networking stack application interface, such as the sockets API. In some embodiments, the application interface agent 1693 intercepts traffic between the applications and the standard network stack interface API in order to more deeply inspect the traffic, modify the traffic or shape the traffic (e.g., thereby not requiring any modification of the device networking/communication stack of the device OS).A functional interface within the network stack that allows software applications to request and access Internet data services.
Tag information
(Claim 1)
In some embodiments, the application interface agent 1693 identifies application level traffic, reports virtual service identification tags or appends literal service identification tags to assist service policy implementation, such as access control, traffic shaping QoS control, service type dependent billing or other service control or implementation functions. The traffic from each application can be divided into one or more traffic flows that each flow through a traffic queue, with each queue being associated with one or more additional classifications for that application. These identifiers can then be associated with a different service plan or account in the service processor 115 and/or billing system 123.Metadata or identifiers (virtual or literal) generated or appended to data traffic to associate a specific network data flow with the software application responsible for that traffic.
WWAN network access policy
(Claim 1)
Aspects of the service policy (e.g., a set of policies/policy settings for the device for network services, typically referring to lower level settings, such as access control settings, traffic control settings, billing system settings, user notification settings, user privacy settings, user preference settings, authentication settings and admission control settings) are moved out of the core network and into the end user device. In some embodiments, a policy control agent 1692 receives policy instructions from the service controller 122 and/or the user via the billing agent 1695 and adapts device service policy settings. These policies can include access control, routing policy, traffic control, usage limits, and/or policy for usage limit overage.A set of instructions or rules stored in memory that governs how the device accesses the wireless wide area network, specifically including application-specific rules that apply to one application but not another.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
3:25-cv-07591Sep 5, 2025Apple Inc v. Headwater Research LLC
5:25-cv-07453Sep 3, 2025Google LLC v. Headwater Research LLC

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9532161

Application Number
US14979233A
Filing Date
Dec 22, 2015
Publication Date
Dec 27, 2016
External Links
Slate, USPTO , Google Patents