IP Library Granted Patent US 9,769,323
Granted Patent B2
US 9,769,323 · App. 14/707,891 · Granted Sep 19, 2017

Techniques for zero rating through redirection

Inventors: Lior Tubi (Tel Aviv, IL); Dekel Schmuel Naar (Tel Aviv, IL); Roi Tiger (Tel Aviv, IL); Guy Rosen (Sunnyvale, CA); Joshua Ryan Lauer (San Francisco, CA); Xiaoliang Wei (Palo Alto, CA)
Assignee: FACEBOOK, INC.
H04M15/39H04L67/02H04L67/146H04L67/2866H04W12/08H04L61/1511H04L61/301
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,769,323
App. No.
14/707,891
Granted
Sep 19, 2017
Kind
B2
Abstract

Techniques for zero rating through redirection are described. In one embodiment, an apparatus may comprise a client proxy component operative to receive a proxy network packet from a local gateway application on a client device, the proxy network packet containing an application network packet for delivery to a network server device; and forward the application network packet to the network server device based on a determination that a local user application is authorized to use the proxy server device; and a proxy access component operative on the processor circuit to determine that the application network packet is associated with the local user application on the client device; and determine that the local user application is authorized to use the proxy server device. Other embodiments are described and claimed.

Claims (37)

1. A computer-implemented method, comprising: receiving, at a network interface on a proxy server device, a proxy network packet from a local gateway application on a client device, the proxy network packet containing an application network packet for delivery to a network server device; determining that the application network packet is associated with a local user application capable of execution on the client device; determining that the local user application is authorized to use the proxy server device; and forwarding the application network packet to the network server device based on the determination that the local user application is authorized to use the proxy server device, the application network packet addressed to a network address, further comprising; determining that the network address corresponds to an interceptor address that is distinct from a legitimate network address associated with the network server device: searching an interceptor record using the interceptor address to determine the legitimate network address and an intercepted local application associated with the interceptor address, determining that the determined local user application corresponds to the determined intercepted local application; and forwarding the application network packet to the network server device at the legitimate network address based on the determination that the determined local user application corresponds to the determined intercepted local application.

2. The method of claim 1 , the interceptor record comprising a mapping between interceptor addresses and legitimate network addresses, the interceptor address returned to the client device in response to a domain name query performed on behalf of the local user application, further comprising: determining that the network server device is associated with the local user application based on the receiving of the application network packet addressed to the interceptor address; and authorizing the forwarding of the application network packet to the network server device based on the determination that the network server device is associated with the local user application.

3. The method of claim 1 , further comprising:

receiving a domain name query from the client device, the domain name query performed on behalf of the local user application;

determining that the domain name query is for a domain name associated with the local user application;

performing a domain name lookup based on the domain name to determine a legitimate network address for the network server device;

generating an interceptor address;

recording an interceptor mapping between the interceptor address and the legitimate network address in an interceptor record; and

returning the interceptor address to the client device in response to the domain name query.

4. The method of claim 1 , the proxy server device zero-rated with a mobile data provider for the client device, further comprising:

authorizing the forwarding of the application network packet to the network server device based on a determination that the local user application is authorized to use zero-rated data access.

5. The method of claim 4 , the local user application authorized to user zero-rated data access based on a data plan record on the proxy server indicating the association of a zero-rated application data plan for the local user application with the client device.

6. The method of claim 1 , further comprising:

receiving a secure token from the client device, the secure token uniquely associated with the client device;

extracting a sequence number from the secure token;

determine that the sequence number is a next number in sequence for the secure token; and

authorizing the forwarding of the application network packet to the network server device based on the determination that the sequence number is the next number in sequence for the secure token.

7. The method of claim 1 , the determination of the application network packet being associated with the local user application determined based on one or more of process identifier, application identifier, identification of foreground application, application permissions, and destination network address.

8. An apparatus, comprising: a processor circuit on a proxy server device; a network interface on the proxy server device; a client proxy component operative on the processor circuit to receive, from the network interface, a proxy network packet from a local gateway application on a client device, the proxy network packet containing an application network packet for delivery to a network server device; and forward the application network packet to the network server device based on a determination that a local user application associated with the application network packet and capable of execution on the client device is authorized to use the proxy server device; and a proxy access component operative on the processor circuit to determine that the application network packet is associated with the local user application on the client device; and determine that the local user application is authorized to use the proxy server device, the application network packet addressed to a network address, further comprising; a DNS interceptor operative on the processor circuit to determine that the network address corresponds to an interceptor address that is distinct from a legitimate network address associated with the network server device: search an interceptor record using the interceptor address to determine the legitimate network address and an intercepted local application associated with the interceptor address, the legitimate network address associated with the network server device; determine that the determined local user application corresponds to the determined intercepted local application; and the client proxy component operative on the processor circuit to forward the application network packet to the network server device at the legitimate network address based on the determination that the determined local user application corresponds to the determined intercepted local application.

9. The apparatus of claim 8 , the interceptor record comprising a mapping between interceptor addresses and legitimate network addresses, the interceptor address returned to the client device in response to a domain name query performed on behalf of the local user application, the proxy access component further operative to determine that the network server device is associated with the local user application based on the receiving of the application network packet addressed to the interceptor address and authorize the forwarding of the application network packet to the network server device based on the determination that the network server device is associated with the local user application.

10. The apparatus of claim 8 , further comprising:

the client proxy component further operative to receive a domain name query from the client device, the domain name query performed on behalf of the local user application; and return and interceptor address to the client device in response to the domain name query; and

a DNS interceptor operative to determine that the domain name query is for a domain name associated with the local user application; perform a domain name lookup based on the domain name to determine a legitimate network address for the network server device; generate an interceptor address; and record an interceptor mapping between the interceptor address and the legitimate network address in an interceptor record.

11. The apparatus of claim 8 , the proxy server device zero-rated with a mobile data provider for the client device, the proxy access component further operative to authorize the forwarding of the application network packet to the network server device based on a determination that the local user application is authorized to use zero-rated data access.

12. The apparatus of claim 8 , further comprising, the local user application authorized to user zero-rated data access based on a data plan record on the proxy server indicating the association of a zero-rated application data plan for the local user application with the client device.

13. At least one non-transitory computer-readable storage medium comprising instructions that, when executed, cause a system to: receive, at a network interface on a proxy server device, a proxy network packet from a local gateway application on a client device, the proxy network packet containing an application network packet for delivery to a network server device; determine that the application network packet is associated with a local user application capable of execution on the client device; determine that the local user application is authorized to use the proxy server device; and determine the application network packet to the network server device based on the determination that the local user application is authorized to use the proxy server device, the application network packet addressed to a network address, comprising further instructions that, when executed, cause a system to: determine that the network address corresponds to an interceptor address that is distinct from a legitimate network address associated with the network server device: search an interceptor record using the interceptor address to determine the legitimate network address and an intercepted local application associated with the interceptor address, the legitimate network address associated with the network server device; determine that the determined local user application corresponds to the determined intercepted local application; and forward the application network packet to the network server device at the legitimate network address based on the determination that the determined local user application corresponds to the determined intercepted local application.

14. The computer-readable storage medium of claim 13 , the interceptor record comprising a mapping between interceptor addresses and legitimate network addresses, the interceptor address returned to the client device in response to a domain name query performed on behalf of the local user application, comprising further instructions that, when executed, cause a system to: determine that the network server device is associated with the local user application based on the receiving of the application network packet addressed to the interceptor address; and authorize the forwarding of the application network packet to the network server device based on the determination that the network server device is associated with the local user application.

15. The computer-readable storage medium of claim 13 , comprising further instructions that, when executed, cause a system to:

receive a domain name query from the client device, the domain name query performed on behalf of the local user application;

determine that the domain name query is for a domain name associated with the local user application;

perform a domain name lookup based on the domain name to determine a legitimate network address for the network server device;

generate an interceptor address;

record an interceptor mapping between the interceptor address and the legitimate network address in an interceptor record; and

return the interceptor address to the client device in response to the domain name query.

16. The computer-readable storage medium of claim 13 , the proxy server device zero-rated with a mobile data provider for the client device, comprising further instructions that, when executed, cause a system to:

authorize the forwarding of the application network packet to the network server device based on a determination that the local user application is authorized to use zero-rated data access.

17. The computer-readable storage medium of claim 13 , the local user application authorized to user zero-rated data access based on a data plan record on the proxy server indicating the association of a zero-rated application data plan for the local user application with the client device.

Assignments (2)
CHANGE OF NAME Recorded May 5, 2022
From: FACEBOOK, INC.
To: META PLATFORMS, INC.
Reel/Frame 059858/0387 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2016
From: TUBI, LIOR; TIGER, ROI; NAAR, DEKEL SCHMUEL; ROSEN, GUY; LAUER, JOSHUA RYAN; WEI, XIAOLIANG
To: FACEBOOK, INC.
Reel/Frame 038824/0971 →
Continuity (4)
Provisional Application 62127268 · Mar 2, 2015
Provisional Application 62127251 · Mar 2, 2015
Provisional Application 62127271 · Mar 2, 2015
Related Publication 20160261750A1 · Sep 8, 2016