IP Library Granted Patent US 11,405,429
Granted Patent B2
US 11,405,429 · App. 16/907,887 · Granted Aug 2, 2022

Security techniques for device assisted services

Inventor: Gregory G. Raleigh (Woodside, CA)
Assignee: HEADWATER RESEARCH LLC
H04L63/20G06F15/177G06Q10/06315G06Q10/06375G06Q20/102G06Q20/20G06Q20/40G06Q30/0207G06Q30/0241G06Q30/0283G06Q30/0284G06Q30/04G06Q30/0601G06Q40/00G06Q40/12H04L9/32H04L9/3247H04L12/14H04L41/0806H04L41/0893H04L41/5003H04L41/5054H04L47/20H04L47/2408H04L51/046H04L63/0236H04L63/04H04L63/0428H04L63/08H04L63/0853H04L63/0892H04L63/10H04L67/145H04L67/26H04L67/306H04L67/327H04M15/00H04M15/58H04M15/61H04M15/80H04M15/88H04W4/02H04W4/12H04W4/18H04W4/20H04W4/24H04W4/50H04W8/18H04W8/20H04W12/00H04W12/02H04W12/037H04W12/06H04W12/08H04W24/08H04W28/02H04W28/0215H04W28/0268H04W28/12H04W48/14H04W48/16H04W72/0453H04W88/08H04L41/0876H04L41/5025H04L67/2819H04L67/34H04M2215/0188H04W8/02H04W84/04H04W84/042H04W84/12H04W88/06Y02P90/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,405,429
App. No.
16/907,887
Filed
Jun 22, 2020
Granted
Aug 2, 2022
Kind
B2
Art Unit
2434
USPC
726/1
Abstract

Security techniques for device assisted services are provided. In some embodiments, secure service measurement and/or control execution partition is provided. In some embodiments, implementing a service profile executed at least in part in a secure execution environment of a processor of a communications device for assisting control of the communications device use of a service on a wireless network, in which the service profile includes a plurality of service policy settings, and wherein the service profile is associated with a service plan that provides for access to the service on the wireless network; monitoring use of the service based on the service profile; and verifying the use of the service based on the monitored use of the service.

Claims (18)

1. A method of operating a wireless end-user device, the method comprising:

connecting from a secure modem subsystem to a wireless cellular network;

connecting a first secure control channel from the secure modem subsystem through the wireless cellular network to a network service controller;

connecting a second secure control channel from a secure execution environment, separately secure from the secure modem subsystem, through the secure modem subsystem and the wireless cellular network to the network service controller;

receiving at the secure execution environment, via the second secure control channel, one or more messages from the network service controller, the one or more messages comprising one or more service policy settings;

storing the one or more service policy settings in a secure memory partition accessible only from the secure execution environment; and

enforcing, at least in part from the secure execution environment, a network service profile comprising the one or more service policy settings, to control the wireless end-user device use of a service on the wireless cellular network.

2. The method of claim 1 , wherein the network service profile is associated with a service plan that provides for access to the service on the wireless cellular network.

3. The method of claim 1 , wherein the secure modem subsystem comprises a modem control link and a modem local channel, and the first secure control channel connects the modem control link to the network service controller through the modem local channel, and wherein the secure execution environment comprises a host service control link, the second secure control channel coupled to the host service control link, the modem local channel providing secure communication between the modem control link and the host service control link.

4. The method of claim 1 , wherein the secure modem subsystem further comprises a modem agent accessible only by the network service controller through the first secure control channel.

5. The method of claim 4 , wherein the modem agent comprises a service measurement point for use of the service.

6. The method of claim 5 , further comprising the modem agent communicating a first report of the use of the service to the network service controller through the first secure control channel.

7. The method of claim 6 , further comprising the secure execution environment separately communicating a second report of the monitored use of the service through the second secure control channel.

8. The method of claim 1 , wherein the one or more service policy settings include an access control setting, a traffic control setting, and/or an admission control setting.

9. The method of claim 1 , wherein the one or more service policy settings include a network or device management communication setting.

10. The method of claim 1 , wherein the secure execution environment is implemented at least in part as a hardware partition.

11. The method of claim 1 , wherein the secure execution environment is implemented at least in part as a software partition.

12. The method of claim 1 , wherein the secure execution environment is implemented at least in part in a virtual machine executed on a processor.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2020
From: RALEIGH, GREGORY G
To: HEADWATER PARTNERS I LLC
Reel/Frame 053745/0193 →
MERGER AND CHANGE OF NAME Recorded Sep 11, 2020
From: HEADWATER PARTNERS I LLC; HEADWATER MANAGEMENT LLC
To: HEADWATER RESEARCH LLC
Reel/Frame 053745/0256 →
Continuity (11)
Continuation 16034362 · Jul 13, 2018
Continuation 14948065 · Nov 20, 2015
Continuation 13737748 · Jan 9, 2013
Continuation 12694445 · Jan 27, 2010
Continuation In Part 12380780 · Mar 2, 2009
Provisional Application 61252151 · Oct 15, 2009
Provisional Application 61207739 · Feb 13, 2009
Provisional Application 61207393 · Feb 10, 2009
Provisional Application 61206944 · Feb 4, 2009
Provisional Application 61206354 · Jan 28, 2009
Related Publication 20200322802A1 · Oct 8, 2020