End user device that secures an association of application to service policy with an application certificate check

Patent No. US9973930 (titled "End user device that secures an association of application to service policy with an application certificate check") on May 20, 2016. The application was issued on May 15, 2018.

What is this patent about?

’930 is related to the field of wireless network management and service policy enforcement. Specifically, it addresses the technical challenge of managing how individual applications on a mobile device consume network resources, particularly in scenarios where service providers or third parties wish to sponsor, restrict, or differentially bill for specific application traffic without relying solely on centralized network-based inspection.

The underlying idea behind ’930 is to move the intelligence of application identification and policy enforcement directly onto the end-user device while maintaining a secure link to the network. By using a device agent to verify the identity of an application through specific credentials, the system ensures that network access policies are applied only to legitimate, authenticated software, thereby preventing fraud and ensuring that sponsored or restricted data usage is accurately attributed.

The claims of ’930 focus on a wireless end-user device equipped with a service policy engine that stores application-specific credentials and corresponding agent instructions. The independent claim describes a mechanism where the device receives these credentials from a network element and performs a credential check to verify a match with a local application. Once a correct correspondence is confirmed, the device agent applies specific instructions to manage the application's Internet data communication over a wireless access network.

In practice, the invention works by intercepting or monitoring application-level connection attempts and comparing the application's signature or hash against the authorized credential information provided by the service controller. If the application is verified, the device agent can allow, throttle, or account for the traffic according to the downloaded policy. This allows for granular control, such as permitting a sponsored e-reader application to access a specific bookstore for free while charging other data usage to the user's bulk data plan.

This approach differs from prior solutions by eliminating the need for expensive and privacy-invasive Deep Packet Inspection (DPI) at the network core. Instead of the network trying to guess which application generated a packet based on traffic patterns, the device provides definitive identification. This decentralized model scales more effectively for carriers and enables a flexible Application Service Provider Interface (ASPI), allowing developers to bundle specific connectivity policies directly with their apps across different network types like 3G, 4G, and Wi-Fi.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2000s when ’930 was filed, wireless network management was typically implemented using centralized carrier-side controls where application access was tethered to rigid, user-paid subscription models. At a time when systems commonly relied on network-edge gateways and deep packet inspection to enforce billing and quality-of-service policies, the ability to differentiate traffic based on specific application-layer behavior was often limited by the lack of granular device-side intelligence. Furthermore, when hardware and software constraints made the automated coordination between third-party application service providers and carrier billing systems non-trivial, provisioning sponsored or differentiated access for specific mobile applications required manual, resource-intensive negotiations and static network configurations.

Prosecution Position

The disclosed invention addresses the technical problem of inefficient network resource utilization and the lack of automated, granular control over application-specific access policies. The architectural solution involves a device-assisted service framework that integrates a service processor on the end-user device with a network-based service controller to enable differential network service usage control. This integration allows for the classification of network activities—such as background versus foreground tasks—and the application of distinct traffic control, charging, and notification policies based on real-time network busy states and application credentials. The technical effect achieved is a scalable, automated system that enables sponsored service models and protects network capacity by dynamically managing device-side behavior, thereby overcoming the constraints of traditional network-centric policy enforcement.

Claims

The patent contains a total of 1 claim, which is an independent claim identified as claim 1. This independent claim focuses on a wireless end-user device equipped with modems and memory to manage service policy data, specifically utilizing application credentials and agent instructions to verify applications and control their access to wireless networks for data communication. There are no dependent claims in this patent, as the single independent claim defines the entire scope of the protected invention.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Application credential check
(Claim 1)
The first application credential check comprises comparing the first application credential stored in the policy store against a candidate application configuration that is associated with an application identifier. It may involve a signature checker/hash checker for an app that is part of the OS or sits in secure OS execution as a first fraud detection layer. If the app signature/hash is not correct, the system may suspend, kill, or block the app and notify the service controller.A verification process involving a comparison between a candidate application's actual security attributes and stored/network-verified credential data to prevent fraud or unauthorized network access.
Device agents
(Claim 1)
In some embodiments, the device includes a service processor agent or function to intercept, block, modify, remove or replace UI messages or communications generated by a network service activity. The one or more device agents are configured to identify a potential or actual use of the access network by a candidate application program and provide information about the credential to the network element. These agents can implement traffic control for network services using DAS techniques where the network service usage activity is unaware of network capacity control.Software functions or processors residing on the end-user device that coordinate with network elements to enforce service policies and perform security validations.
First application credential information
(Claim 1)
In a specific implementation, the app credential data (or the app credential itself) comprises a configuration authentication certificate, software security certificate, software security signature or information about a software security hash. The service processor performs app validation using various techniques including code signing, code hash verification and/or certificate based. This information is used to verify that app credentials belong to an app group with a specific app services access policy or service plan.Security data used to uniquely identify and verify the authenticity of a specific software application on the device to ensure it matches a defined service profile.
First device agent instructions
(Claim 1)
In a specific implementation, the at least an aspect of the first access network service policy comprises device agent instructions to restrict first application communication with the first access network. These instructions can include implementation of a network service usage activity policy such as block/allow, throttle, delay, priority queue, or time window. The one or more agents are configured to secure the first access instructions from tampering in a software environment protected from modification by user application software.A set of programmable rules or policies received from a network element that dictate how the device should monitor, restrict, or account for network access for a specific application.
Wireless end-user device
(Claim 1)
Examples of a wireless device include a smart phone, laptop, net book, or eBook. The device service processor records and reports service usage for one or more of the service classes used by the device and reports the service class usage to the service controller. The device is enabled with sponsored services that have differentiated service policies.A mobile communication apparatus, such as a smartphone or laptop, equipped with modems to access wireless networks and a service processor to manage differentiated service policies.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
4:25-cv-09558Nov 5, 2025Google LLC v. Headwater Research LLC
3:25-cv-07591Sep 5, 2025Apple Inc v. Headwater Research LLC
5:25-cv-07453Sep 3, 2025Google LLC v. Headwater Research LLC

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9973930

Application Number
US15160520A
Filing Date
May 20, 2016
Publication Date
May 15, 2018
External Links
Slate, USPTO , Google Patents