Patent No. US9973930 (titled "End user device that secures an association of application to service policy with an application certificate check") on May 20, 2016. The application was issued on May 15, 2018.
’930 is related to the field of wireless network management and service policy enforcement. Specifically, it addresses the technical challenge of managing how individual applications on a mobile device consume network resources, particularly in scenarios where service providers or third parties wish to sponsor, restrict, or differentially bill for specific application traffic without relying solely on centralized network-based inspection.
The underlying idea behind ’930 is to move the intelligence of application identification and policy enforcement directly onto the end-user device while maintaining a secure link to the network. By using a device agent to verify the identity of an application through specific credentials, the system ensures that network access policies are applied only to legitimate, authenticated software, thereby preventing fraud and ensuring that sponsored or restricted data usage is accurately attributed.
The claims of ’930 focus on a wireless end-user device equipped with a service policy engine that stores application-specific credentials and corresponding agent instructions. The independent claim describes a mechanism where the device receives these credentials from a network element and performs a credential check to verify a match with a local application. Once a correct correspondence is confirmed, the device agent applies specific instructions to manage the application's Internet data communication over a wireless access network.
In practice, the invention works by intercepting or monitoring application-level connection attempts and comparing the application's signature or hash against the authorized credential information provided by the service controller. If the application is verified, the device agent can allow, throttle, or account for the traffic according to the downloaded policy. This allows for granular control, such as permitting a sponsored e-reader application to access a specific bookstore for free while charging other data usage to the user's bulk data plan.
This approach differs from prior solutions by eliminating the need for expensive and privacy-invasive Deep Packet Inspection (DPI) at the network core. Instead of the network trying to guess which application generated a packet based on traffic patterns, the device provides definitive identification. This decentralized model scales more effectively for carriers and enables a flexible Application Service Provider Interface (ASPI), allowing developers to bundle specific connectivity policies directly with their apps across different network types like 3G, 4G, and Wi-Fi.
In the late 2000s when ’930 was filed, wireless network management was typically implemented using centralized carrier-side controls where application access was tethered to rigid, user-paid subscription models. At a time when systems commonly relied on network-edge gateways and deep packet inspection to enforce billing and quality-of-service policies, the ability to differentiate traffic based on specific application-layer behavior was often limited by the lack of granular device-side intelligence. Furthermore, when hardware and software constraints made the automated coordination between third-party application service providers and carrier billing systems non-trivial, provisioning sponsored or differentiated access for specific mobile applications required manual, resource-intensive negotiations and static network configurations.
The disclosed invention addresses the technical problem of inefficient network resource utilization and the lack of automated, granular control over application-specific access policies. The architectural solution involves a device-assisted service framework that integrates a service processor on the end-user device with a network-based service controller to enable differential network service usage control. This integration allows for the classification of network activities—such as background versus foreground tasks—and the application of distinct traffic control, charging, and notification policies based on real-time network busy states and application credentials. The technical effect achieved is a scalable, automated system that enables sponsored service models and protects network capacity by dynamically managing device-side behavior, thereby overcoming the constraints of traditional network-centric policy enforcement.
The patent contains a total of 1 claim, which is an independent claim identified as claim 1. This independent claim focuses on a wireless end-user device equipped with modems and memory to manage service policy data, specifically utilizing application credentials and agent instructions to verify applications and control their access to wireless networks for data communication. There are no dependent claims in this patent, as the single independent claim defines the entire scope of the protected invention.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents