IP Library Granted Patent US 11,985,155
Granted Patent B2
US 11,985,155 · App. 18/088,450 · Granted May 14, 2024

Communications device with secure data path processing agents

Inventors: Gregory G. Raleigh (Incline Village, NV); James Lavine (Denver, NC); Alireza Raissinia (Monte Sereno, CA); Michael J. Sabin (Sunnyvale, CA)
Assignee: Headwater Research LLC
H04L63/1425H04L41/046H04W12/12H04W12/128G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,985,155
App. No.
18/088,450
Filed
Dec 23, 2022
Granted
May 14, 2024
Kind
B2
Art Unit
2457
USPC
455/410
Abstract

Secure device data records (DDRs) are provided. In some embodiments, a system for secure DDRs includes a processor of a wireless communication device for wireless communication with a wireless network, in which the processor is configured with a secure execution environment, and in which the secure execution environment is configured to: monitor service usage of the wireless communication device with the wireless network; and generate a plurality of device data records of the monitored service usage of the wireless communication device with the wireless network, in which each device data record is associated with a unique sequence order identifier; and a memory coupled to the processor and configured to provide the processor with instructions. In some embodiments, the secure execution environment is located in an application processor, in a modem processor, and/or in a subscriber identity module (SIM).

Claims (38)

1. A communications device comprising:

a wide area network port configured to connect the communications device to a wide area network;

a secure memory;

a secure execution environment configured to be inaccessible to a user application software; and

a secure data path processing agent configured to:

execute in the secure execution environment;

generate a unique identifier for communication to a network element in the wide area network;

store the unique identifier in the secure memory;

generate a data record;

associate the unique identifier with the data record; and

send the unique identifier to the network element over a trusted communication link between the secure data path processing agent and the network element.

2. The communications device of claim 1 , wherein the secure data path processing agent includes a device data record mailbox, wherein the device data record mailbox is configured to relay the data record to an agent outside of the secure execution environment for transmission to the network element.

3. The communications device of claim 1 , further comprising:

a subscriber identity module (SIM), wherein at least a portion of the SIM is within the secure execution environment.

4. The communications device of claim 3 , wherein the secure data path processing agent resides on the SIM.

5. The communications device of claim 4 , wherein the secure data path processing agent includes a data path security verifier.

6. The communications device of claim 1 , further comprising:

an applications processor unit within the secure execution environment.

7. The communications device of claim 6 , wherein the secure data path processing agent resides within the applications processor unit.

8. The communications device of claim 7 , wherein the secure data path processing agent includes a data path security verifier in a wireless modem chipset of the communications device.

9. The communications device of claim 8 , wherein the data path security verifier restricts network access to allow only monitored device data communications activity.

10. A method for use by a communications device including a wide area network port configured to connect the communications device to a wide area network, and further including a secure memory, a secure execution environment configured to be inaccessible to a user application software, and a secure data path processing agent, the method comprising:

executing the secure data path processing agent in the secure execution environment;

generating, by the secure data path processing agent, a unique identifier for communication to a network element in the wide area network;

storing, by the secure data path processing agent, the unique identifier in the secure memory;

generating, by the secure data path processing agent, a data record;

associating, by the secure data path processing agent, the unique identifier with the data record; and

sending, by the secure data path processing agent, the unique identifier to the network element over a trusted communication link between the secure data path processing agent and the network element.

11. The method of claim 10 , wherein the secure data path processing agent includes a device data record mailbox, and wherein the method further comprises:

relaying, using the device data record mailbox, the data record to an agent outside of the secure execution environment for transmission to the network element.

12. The method of claim 10 , wherein the communications device further includes a subscriber identity module (SIM), and wherein at least a portion of the SIM is within the secure execution environment.

13. The method of claim 12 , wherein the secure data path processing agent resides on the SIM.

14. The method of claim 13 , wherein the secure data path processing agent includes a data path security verifier.

15. The method of claim 10 , wherein the communications device further includes an applications processor unit within the secure execution environment.

16. The method of claim 15 , wherein the secure data path processing agent resides within the applications processor unit.

17. The method of claim 16 , wherein the secure data path processing agent includes a data path security verifier in a wireless modem chipset of the communications device.

18. The method of claim 17 , further comprising:

restricting, using the data path security verifier, network access to allow only monitored device data communications activity.

Continuity (41)
Continuation 17008031 · Aug 31, 2020
Continuation 15977731 · May 11, 2018
Continuation 15158522 · May 18, 2016
Continuation 14272274 · May 7, 2014
Division 13247998 · Sep 28, 2011
Continuation In Part 13134028 · May 25, 2011
Continuation In Part 12695019 · Jan 27, 2010
Continuation In Part 12695020 · Jan 27, 2010
Continuation In Part 12694455 · Jan 27, 2010
Continuation In Part 13134005 · May 25, 2011
Continuation In Part 12695021 · Jan 27, 2010
Continuation In Part 12380780 · Mar 2, 2009
Provisional Application 61472606 · Apr 6, 2011
Provisional Application 61435564 · Jan 24, 2011
Provisional Application 61422574 · Dec 13, 2010
Provisional Application 61422572 · Dec 13, 2010
Provisional Application 61422565 · Dec 13, 2010
Provisional Application 61420727 · Dec 7, 2010
Provisional Application 61418509 · Dec 1, 2010
Provisional Application 61418507 · Dec 1, 2010
Provisional Application 61407358 · Oct 27, 2010
Provisional Application 61389547 · Oct 4, 2010
Provisional Application 61387243 · Sep 28, 2010
Provisional Application 61387247 · Sep 28, 2010
Provisional Application 61385020 · Sep 21, 2010
Provisional Application 61384456 · Sep 20, 2010
Provisional Application 61381162 · Sep 9, 2010
Provisional Application 61381159 · Sep 9, 2010
Provisional Application 61348022 · May 25, 2010
Provisional Application 61264126 · Nov 24, 2009
Provisional Application 61264120 · Nov 24, 2009
Provisional Application 61252151 · Oct 15, 2009
Provisional Application 61252153 · Oct 15, 2009
Provisional Application 61237753 · Aug 28, 2009
Provisional Application 61275208 · Aug 25, 2009
Provisional Application 61270353 · Jul 6, 2009
Provisional Application 61207739 · Feb 13, 2009
Provisional Application 61207393 · Feb 10, 2009
Provisional Application 61206944 · Feb 4, 2009
Provisional Application 61206354 · Jan 28, 2009
Related Publication 20230125134A1 · Apr 27, 2023